There is a requirement in the EU AI Act that receives less attention than the risk classes but affects considerably more companies. In essence it says that organisations must ensure a sufficient level of AI literacy among the people who use these systems on their behalf.
It has applied since the start of 2025 and regardless of risk class. So it also covers the harmless summarisation feature you switched on for three hundred employees last week.
What it does not mean
It does not mean a certificate, a formal examination or a course on how neural networks function. The legislator does not require technical understanding but appropriate understanding: people should know what the tool can do, where it is reliable, where it goes wrong, and what they must not use it for.
That is a lower bar than feared, and a higher one than a one-hour product demonstration achieves.
What is sufficient in practice
- A short, understandable briefing per role: what is this tool intended for in your work, and what is it not intended for?
- Three to five concrete examples of typical errors, using real cases from your own organisation rather than generic warnings.
- Clear guidance on which information belongs in it and which does not.
- A named point of contact for borderline cases that actually responds.
- Evidence that this took place. An attendance list and the materials are enough.
The evidence is the smallest part of the effort. It is simply the part nobody thinks of.
Why this makes sense beyond the regulation
The practical benefit exceeds the obligation. People who understand where a tool goes wrong use it with more confidence and report problems earlier. People who do not understand it do one of two things: they trust it blindly, or they do not use it at all. Both cost you more than the briefing.
Incidentally, the most common problem in practice is not too little trust but too much. Anyone who fails to recognise a fluently written wrong answer for what it is makes a poor decision and feels good about it.
Where I would start
Begin with the roles that carry the greatest potential for damage: HR, finance, legal, customer communication, and everyone who makes statements to customers. Then go broad. The effort is one to two hours per role when the examples come from your own organisation.
And document it. Not because the documentation delivers the benefit, but because otherwise, in two years, you will have met a requirement without being able to show it.