AI literacy for staff.
Seven stops, in order. This is the training obligation EU AI Act Article 4 already places on any organisation whose staff operate or rely on AI systems — not a general primer, a specific legal one.
- What Article 4 actually requires The EU AI Act literacy obligation, in force since 2 February 2025 — who it covers and what it actually asks for.
- The risk this closes Staff operating or relying on an AI system's output without the training to understand its limitations — over-trust, misuse, or both.
- The control that satisfies it Structured training for staff who operate, rely on, or are affected by an AI system's output — covering its limitations, not just its use.
- Prompt injection, recognised Attacker-controlled input overriding system instructions, directly or via retrieved content treated as trusted — the failure mode to spot first.
- Misinformation and confabulation A model stating false or fabricated information with the same linguistic confidence as accurate information — literacy means not trusting confidence as a proxy for correctness.
- Sensitive information disclosure What can end up in a model output that should not have — training, fine-tuning, or retrieval-sourced sensitive data.
- Definitive terminology Cross-referenced with the frameworks and risks that use each term, so you're not guessing at scope.
A working obligation, not a training-catalogue entry.
Article 4 doesn't specify a course format — it asks for staff to have AI literacy appropriate to their role. This path is one way to evidence that.