
Effective AI literacy training teaches more than how to operate a chatbot. It covers four building blocks: a basic technical understanding, the legal framework of the EU AI Act, the risks including hallucination and distortion (bias), and the safe use of AI in everyday work – tailored to roles and documented in a traceable way. The legal reason is Art. 4 of the EU AI Act (Regulation (EU) 2024/1689): since February 2, 2025, providers and deployers have had to take measures to support the development of the AI literacy of their staff (version of Regulation (EU) 2026/1744, in force since July 27, 2026). Which content underpins this literacy follows from the legal definition of "AI literacy" in Art. 3 no. 56 of the same regulation. This article classifies the content didactically and in general terms, without assessing the individual case. The basis is the wording of the EU AI Act and the guidance of the European Commission and the Bundesnetzagentur (Federal Network Agency). The building blocks build on each other: from understanding through the legal situation and the risks to specific behavior in everyday work. As of September 4, 2026.
The legal definition sets the framework for the content. Under Art. 3 no. 56 of the EU AI Act, "AI literacy" means the skills, knowledge, and understanding that make it possible to deploy AI systems in an informed way and to become aware of the opportunities, risks, and possible harm. These three levels – skills, knowledge, and judgment – set the direction of any training: it is not only about operating skills but also about awareness of limits and dangers. Art. 4 attaches the obligation to this: providers and deployers take measures to support the development of AI literacy, taking into account prior knowledge, tasks, and the systems specifically used. The article on the AI literacy obligation under Art. 4 explores in detail what this obligation means legally; this article is about the content with which this literacy can be taught.
The current legal status must be observed. With the Digital Omnibus Regulation (Regulation (EU) 2026/1744), in force since July 27, 2026, the EU has reworded Art. 4: the obligation to ensure a sufficient level of AI literacy has become the obligation to support its development through measures; a specific level of competence of individual persons does not have to be guaranteed. This changes little for the training content: in both versions, the four building blocks are the core content, and documented training remains the usual proof of the measures taken.
The obligation under Art. 4 applies to both providers and deployers of AI systems. For most companies in the DACH region, the deployer role is the relevant one: anyone who uses AI systems in their own name – from the text assistant to the customer service chatbot to analysis software – must take measures to support the AI literacy of those involved. This covers not only the company's own workforce. In its FAQ, the European Commission clarifies that persons who use or operate AI systems on behalf of the company must also be included – for example contractors, temporary workers, or external service providers. The group of people to be trained is therefore determined by actual AI use, not by the employment contract. For the training content, this means: the shared basic knowledge must be widely available, while in-depth modules follow the roles that actually work with AI. It is also important that the management level knows about its responsibility for competence – it must initiate the process, budget for it, and have it documented.
It starts with a solid basic understanding: What is artificial intelligence, how do models learn from data, and where are the limits? Employees should be able to classify key terms – machine learning, language model, prompt, hallucination – and understand that a language model calculates probabilities for the next word and does not deliver verified facts. The distinction between generative AI (which creates texts or images) and predictive AI (which predicts or classifies decisions) is also helpful, because the two bring different risks. In its FAQ on AI literacy, the European Commission names precisely these basic questions – "What is AI? How does it work? What AI is used in our organisation?" – as the foundation. The knowledge does not have to be deeply technical; what matters is that employees understand how the tools they use every day work and what their typical sources of error are. A shared vocabulary – such as the one offered by the AI glossary – is the basis for this.
The second building block places AI in the legal framework. This includes an overview of the EU AI Act, its risk-based approach with the four risk categories, and the roles of provider and deployer. It also includes the transparency obligations under Art. 50 of the EU AI Act: users must be able to recognize when they are interacting with an AI system and when content is AI-generated – for example with chatbots or synthetically generated images. And finally, the interface with data protection: as soon as AI processes personal data, the General Data Protection Regulation (GDPR) also applies. The goal is not legal education, but a feel for when an AI deployment becomes legally delicate and when consultation is necessary. Because the legal framework continues to evolve – most recently through the Digital Omnibus in July 2026 –, such content should be updated regularly.
The third building block makes the risks tangible. Hallucinations (freely invented but plausible-sounding outputs), distortions (bias) in the results, data protection violations through careless input, and the danger of trusting machine suggestions uncritically (automation bias) – employees should know all of this from specific examples. In its FAQ, the European Commission expressly names hallucinations and algorithmic discrimination as risks that people must be informed about. The article on AI hallucination explores how hallucinations arise and how they can be recognized. Closely linked to this is human oversight: Art. 14 of the EU AI Act requires effective oversight by humans for high-risk systems. The underlying principle – the human checks and is responsible for the result – belongs in every training course as an attitude, regardless of the risk category. The core of this building block is thus less detailed knowledge than a basic attitude: AI is a tool whose results are checked and answered for by humans.
The fourth building block translates knowledge into behavior. This is about practical guardrails: which data may and may not be entered into an AI tool, how results can be cross-checked, which tools are approved, and how sensitive content is to be handled. The conscious handling of "shadow AI" – i.e. tools that have not been approved and are used bypassing IT – also belongs here. This building block has the most immediate effect because it gives employees clear rules for recurring situations. The Commission emphasizes that it is not enough to simply have employees read a system's instructions for use; effective AI literacy develops in a practice- and role-related way, not through merely providing documentation. Specifically, this means, for example: do not enter personal or confidential data into publicly accessible AI services, check every AI output for accuracy and completeness before further use, and consult a second source if in doubt. Such rules can be bundled in a short, binding policy to which the training expressly refers – this turns abstract knowledge into verifiable behavior.
Not every role needs the same depth. In Art. 4, the EU AI Act expressly refers to the context: prior knowledge, tasks, and the systems specifically used must be taken into account. In practice, this means a shared basic module for all employees and in-depth content for groups with a particular connection – for example HR managers who use AI in recruiting (with an increased risk of bias), employees in customer contact with regard to the transparency obligations, or teams that purchase or develop AI systems. In its guidance paper of June 2025, the Bundesnetzagentur also recommends designing the measures in a tailor-made way and aligning them with the need actually identified; the interplay described here between a shared basic module and role-specific in-depth content can be aligned with this needs-based orientation. This keeps the training efficient and yet tailored.
A common misconception: there is no legally required certificate of completion and no mandatory format for AI training. Both the European Commission and the Bundesnetzagentur clarify that an internal, traceable record of the measures carried out is sufficient. The Bundesnetzagentur's guidance paper names four cornerstones: determining the need, designing tailor-made measures, refreshing regularly, and documenting everything (type, duration, content, participants). A simple, traceably maintained documentation therefore makes sense: who received which content when, when a refresher is due, and where the records are filed. This record-keeping is at the same time the practical evidence that a company is meeting its responsibility for competence – and it is quickly available in the event of an inquiry from an authority.
Because the regulation does not prescribe a format, the choice of how to teach remains open. The Bundesnetzagentur's guidance paper names a range from self-study programs through workshops and classic training courses to multi-level professional development programs – depending on the need and the specific context. For a company-wide basic module, standardized e-learning courses are suitable that reach all employees in the same quality and whose completion can be documented automatically; for specialized roles, supplementary classroom or in-depth formats make sense. What matters is not the format itself, but that the content covers the four building blocks, fits the role, and that participation is recorded traceably. It is precisely the combination of a scalable foundation course and targeted in-depth content that takes account of the context dependency to which Art. 4 refers. Regular refreshers – for example annually or in the event of significant changes in the legal situation – keep the competence up to date.
Designing these building blocks yourself, keeping them up to date, and rolling them out by role ties up considerable resources – precisely because the legal framework continues to evolve. A ready-made, standardized solution bundles technical, legal, and ethical content as well as safe everyday work, can be assigned by role via a learning platform, and documents participation traceably, provided that the records are maintained and retained. The advantage lies in being up to date and verifiable: content is maintained centrally as soon as the legal situation changes – for example with the Digital Omnibus – and the participation data comes together in one place. A note on our own behalf: Anyone considering this route will find a ready-made course in line with the EU AI Act in Bridgly's AI training courses, instead of having to build the content themselves. Further articles are bundled in the Artificial Intelligence topic hub.
What content must AI training cover?
Four building blocks have proven themselves: a basic technical understanding, the legal framework of the EU AI Act, risks including hallucination, bias, and human oversight, and the safe use of AI in everyday work. The specific depth depends on the role and prior knowledge of the employees.
Is a certificate of completion required for AI training?
No. Neither the European Commission nor the Bundesnetzagentur requires a specific certificate of completion or format. An internal, traceable record of the training carried out is sufficient.
Do all employees have to receive the same AI training?
No. The EU AI Act refers to the context. A shared basic module plus in-depth content for roles with a particular connection to AI, for example in HR or in development, makes sense.
Regulation (EU) 2024/1689 (EU AI Act) – Art. 3 no. 56, Art. 4, Art. 14, Art. 50 (EUR-Lex, as of 21 Jul 2026)
European Commission – AI Literacy: Questions & Answers (13 May 2025, accessed 21 Jul 2026)
Bundesnetzagentur – Guidance paper on AI literacy under Art. 4 EU AI Act (June 2025, accessed 21 Jul 2026)
Council of the EU – final approval of the "Digital Omnibus" (29 Jun 2026); Regulation (EU) 2026/1744 (OJ L 24 Jul 2026, in force since 27 Jul 2026, Art. 1 no. 5; accessed 4 Sep 2026)
Image: AI-generated (ChatGPT image generator), editorially created and labeled in accordance with Art. 50 EU AI Act; no stock material subject to licensing.
Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.
Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.