Does your business need AI training? Learn what Article 4 of the EU AI Act means for employers, staff using ChatGPT and workplace AI governance.
Do employees using AI need training?
Your employees use ChatGPT, Microsoft Copilot, Gemini or another AI tool at work. Do you now need to train them?
For many organisations operating in the EU, some form of AI literacy measure should already be part of their AI governance. Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures supporting the development of AI literacy among staff and other people dealing with the operation and use of AI systems on their behalf.
The current Article 4 does not require an organisation to guarantee a specific level of AI literacy for every individual. The measures should take account of technical knowledge, experience, education, training and the context in which the AI system is used.
The obligation has applied since 2 February 2025. The European Commission's current AI literacy FAQ states that supervision and enforcement rules apply from 3 August 2026 and separately notes that national market-surveillance authorities start supervising and enforcing the rules from 2 August 2026. In practical terms, Article 4 is now an active governance obligation.
This does not mean every employee needs to become an AI expert.
What does AI literacy actually mean?
AI literacy is the knowledge and understanding people need to use AI appropriately in their role. The appropriate measures depend on the circumstances.
An employee occasionally using generative AI to improve the wording of an email does not need the same depth of knowledge as someone operating an AI system used in recruitment, healthcare or financial decision-making.
The European Commission's current guidance emphasises context. Organisations should consider factors such as technical knowledge, experience, education and training, together with the context and purpose for which an AI system is used.
The objective is not simply to give everyone an identical online course. It is to make sure people understand the AI risks and controls relevant to their work.
Does this apply if employees only use ChatGPT?
Potentially, yes. AI governance is not relevant only to companies developing AI systems. An organisation using an AI system under its authority in its operations may be a deployer under the AI Act, depending on the circumstances and scope of the Regulation.
If staff use generative AI on behalf of the organisation, the organisation should consider what AI literacy measures are appropriate for those users.
The practical risks are familiar. An employee might enter confidential company information or personal data into an unsuitable service, copy an AI-generated answer without checking it, rely on fabricated references, use material that creates intellectual property concerns or make an important decision based too heavily on an AI output.
These are governance issues as much as technical ones.
What should employees actually learn?
For ordinary workplace use of generative AI, a practical AI literacy programme can focus on a small number of areas that employees can apply immediately.
- Understanding AI limitations: generative AI can produce convincing but incorrect information, so outputs should not automatically be treated as verified facts.
- Protecting information: staff need clear rules for personal data, client information, commercially sensitive material, internal documents, credentials and intellectual property.
- Checking AI outputs: employees should know when an output requires independent verification and which sources are appropriate for that check.
- Recognising bias and inappropriate outputs: teams should understand that AI can reproduce or amplify bias, especially where outputs influence decisions involving people.
- Knowing when to escalate: staff should know who to contact after an accidental disclosure, inappropriate output, suspected discrimination or unexpected automated decision.
Do you need formal AI training records?
Documentation is sensible. The Commission's AI literacy FAQ says that Article 4 does not require a specific certificate and suggests that organisations can keep internal records of training and other guiding initiatives.
Useful evidence can include training materials, attendance records, AI usage policies, internal guidance, role-specific training, training dates, policy acknowledgements and updates made when AI systems or risks change.
This should remain proportionate. The amount of documentation should reflect the organisation's actual AI exposure rather than create unnecessary bureaucracy.
Training alone is not enough
A single annual presentation does not give employees the rules they need after the training ends. AI literacy works better when it is connected to the wider AI governance framework.
- Policy: which AI tools may employees use?
- Data: what information may employees provide to them?
- Verification: when must AI-generated information be independently checked?
- Human oversight: which decisions require meaningful human review and control?
- Incident management: what happens if AI causes or contributes to a problem?
Start with the people actually using AI
Companies do not necessarily need a complex organisation-wide programme on day one. A practical starting point is to identify which teams use AI, which systems they use, what they use them for, what information is processed and what could realistically go wrong.
Training can then be designed around those risks. A marketing team using generative AI needs different guidance from an HR team using AI-supported recruitment technology. That is why a proportionate, role-aware approach makes sense.
AI literacy is also good business practice
Employees who understand AI are better placed to recognise where it saves time, where it creates risk and when human judgement remains essential.
Good AI governance should enable useful technology to be used confidently and responsibly, with clear boundaries rather than uncertainty.
Blanche perspective
Blanche can help organisations assess current employee AI use, create practical AI usage policies and develop proportionate AI literacy measures aligned with the EU AI Act. Start with the people and tools already in use, then build deeper guidance only where the risk or responsibility justifies it.
This article provides general information and should not be treated as legal advice.
Sources
Primary and authoritative sources used for this Insight.