AI literacy isn't a slide deck. It's a habit.
Article 4 obliges every provider and deployer to take measures that build AI literacy among their staff, suited to their role and the context they work in. It has applied since 2 February 2025. The July 2026 Digital Omnibus softened the wording - no specific level has to be guaranteed - but the measures still have to exist, and you have to be able to show them. One webinar and a filed attendance list changes nobody's behaviour.
Names and email addresses are personal data. We redacted them before the model saw anything - but the safer route is the approved Customer summary prompt, which reads the CRM without ever exposing an identifier.
Providers and deployers shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in. This does not require them to guarantee any specific level of AI literacy of any individual.
The lesson lands where the mistake happens.
Annual training is forgotten by March. StickyPrompts watches the prompt path and teaches in the twenty seconds where it matters - when someone pastes personal data, drifts toward a high-risk purpose, or accepts a third draft without editing it.
- Coach, gate or block depending on what's actually at stake
- Every intervention cites the rule it comes from, in plain language
- The lesson is the record - completion is captured, not chased
Names and email addresses are personal data. We redacted them before the model saw anything - but the safer route is the approved Customer summary prompt, which reads the CRM without ever exposing an identifier.
Your policy, where the work happens.
Your AI use policy, the Annex III cheat-sheet and the handbook live in the workspace, not on an intranet nobody opens. Every approved prompt carries the reasoning behind it - so reusing a colleague's work teaches the rule at the same time.
- Ask the knowledge base your policy questions and get cited answers
- Approved prompts explain why they're safe, not just what they do
- Owner and review date on every artefact, so guidance never goes stale
It summarises an application without ranking or scoring the candidate, so it stays clear of the automated-evaluation line in Annex III(4)(a). The decision stays with the recruiter - and that's what keeps this out of the high-risk column.
Six people, six different obligations, six different paths.
Paths are seeded by department, then corrected by what people actually do in the workspace. Usage is the most honest signal of context you'll get - and context is precisely what Art. 4 asks you to account for.
An untrained approver is not an approver.
For Annex III high-risk systems, Art. 26(2) requires human oversight to be assigned to someone with the necessary competence, training and authority - from 2 December 2027, after the Digital Omnibus moved the date. So we make it a gate rather than a certificate: until the module is done, the name cannot go in the slot - and the workflow will not run.
Progress people want, pointed at judgement instead of volume.
Gamification works - aimed at the wrong metric it also does real damage. Tiers unlock capability, badges reward the behaviour you actually want, and nobody's name appears on a scoreboard.
- Individual usage leaderboards - they reward volume over judgement, and volume is not the goal.
- "AI adoption %" as a manager-facing KPI - that's how a screening use case nobody vetted ends up in production.
- Public per-employee scoring - a works-council conversation in several member states before it's a product decision.
The AI Literacy Starter Kit. No form.
Eight pages you can act on this week: what Art. 4 actually requires, who counts as staff, a six-role curriculum, a 30/60/90 rollout plan, twelve teaching scenarios drawn from real failure modes, and the evidence checklist to keep on file. No email address, no gate, no drip campaign - just the PDF.
- 01 What Article 4 actually requires
- 02 Who counts as “staff and other persons”
- 03 A six-role curriculum outline
- 04 The 30 / 60 / 90 day rollout
- 05 Twelve teaching scenarios
- 06 The evidence checklist to keep on file
Art. 4 asks for measures. These are countable.
"Take measures" is a standard you have to be able to evidence. Every lesson served, module completed and gate held is recorded per person and per system, and drops into the same evidence pack as your logs and oversight records.
- Completion and refresh dates per person, per module
- Gap analysis by team, with the nudge already sent
- Zero uncertified approvers on high-risk workflows, by construction
- One export, alongside the register and the audit log
What L&D and compliance ask us.
Isn't this just an LMS with extra steps?
An LMS teaches on a calendar and hopes it transfers to the moment of the decision. This teaches at the moment of the decision, in the tool where the decision is made - and the completion record is a by-product rather than an administrative chore. It also enforces: someone who isn't certified cannot be named as the human overseer on a high-risk workflow. An LMS can't reach into your systems and hold a gate shut.
How do you decide what each person needs to learn?
From what they actually do. Paths are seeded by department and then adjusted by usage - someone running candidate-screening prompts gets the Annex III path whether or not their job title suggested it. Art. 4 asks you to take people's knowledge, experience and context into account, and observed usage is the most honest signal of context you will get.
Do you rank employees against each other?
No, and that's deliberate. Progress and mastery are individual and private; leaderboards exist at team level only. Ranking named employees on AI usage rewards volume over judgement - exactly the behaviour that gets a company into trouble - and in several member states publishing such a ranking is a works-council matter before it is a product decision.
Can we use our own training material and policies?
Yes. Your compliance team authors modules, attaches policy attestations, and can require re-attestation when a policy changes. The scenario bank also learns from your own blocked-prompt log, anonymised - so the curriculum reflects what your people actually get wrong rather than a generic syllabus.
A plain-language orientation to Article 4 of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), not legal advice. Confirm current requirements with your own counsel. Figures in product mock-ups are illustrative. Last reviewed 28 September 2026. ← Back to the EU AI Act overview
Give every colleague the twenty seconds that change the habit.
Start free with a $5 trial balance. Foundations is live on first login, and the completion record starts writing itself the same day.