EU AI Act — an HR & people-ops field guide
EU AI Act training requirements for employees: what HR actually owes.
Your staff were using AI years before your compliance calendar caught up. Since 2 February 2025, Article 4 of the EU AI Act has required your company to develop their AI literacy — and post-Omnibus rules and guidance have clarified the shape of it: no mandated level, no exams, no certificates. What remains is a duty to take real measures matched to how your people actually use AI. This page is the whole requirement, sized for a people plan.
Who's covered
Who must be trained under the EU AI Act.
The duty lands on the company — and it reaches further than the payroll.
-
Every company whose staff touch AI tools.
If your employees use a chatbot, Copilot, or the AI feature inside your CRM, you're a deployer and Article 4 applies. No headcount floor, no risk-class threshold, no SME exemption. The Commission's own FAQ puts a company whose staff draft ad copy with ChatGPT squarely in scope — informing them of risks like hallucination is the stated minimum.
-
Contractors count too.
The duty covers staff “and other persons dealing with the operation and use of AI systems on their behalf.” Freelancers running AI for you and agency people embedded in your workflows belong in the training plan, at the depth their role requires.
-
Role decides duties — and you're almost certainly the deployer.
Providers build AI systems; deployers use them under their own authority. A company of 10–500 buying and using tools sits in the deployer seat. The seat decides the calendar: literacy measures now; human-oversight training later, and only if a system is high-risk.
One nuance the law adds: measures must fit the person — technical knowledge, experience, education, the context the systems are used in, and the people they're used on. One deck for everyone is not a literacy program.
The actual requirement
What the training must cover.
The Commission's AI literacy FAQ turns Article 4 into four working requirements — then tells you what “effective” looks like.
-
Four things the Commission expects your measures to achieve.
Build organization-wide understanding of what AI is used and its opportunities and risks. Settle whether you build or deploy. Assess the risk of each system you use. Then deliver targeted literacy measures that follow from the first three. That last step is where training lives.
-
Tiered by role, not uniform.
The FAQ confirms training may be tiered by role. Depth for daily users: prompt discipline, hallucination checks, what must never enter a prompt. Awareness for everyone else: what the tools are, where the tripwires are, who to ask.
-
The effectiveness bar is real.
The Commission is blunt about shortcuts: relying on the AI systems' instructions for use, or asking staff to read them, “might be ineffective.” A hands-on session mapped to your actual use cases clears a bar a PDF in an inbox does not.
-
Put the live bans in the room.
Article 5's prohibitions have bound users — not just builders — since 2 February 2025. Emotion inference in the workplace is the classic HR trap; your literacy measures are the natural place to teach where the lines sit.
Don't buy theatre
What the EU AI Act does not require of employees.
The Digital Omnibus made the softening explicit. Spend accordingly.
-
No specific level of literacy.
The Omnibus amended Article 4 so the duty does not require any specific level of AI literacy of any individual. There is no bar exam to pass and no rubric to buy.
-
No testing or measuring.
The Commission confirms there is no obligation to measure or test employees. Nobody has to score 80% on a quiz for the company to be compliant.
-
No certificate.
The Act demands no certificate. Post-Omnibus Article 4 requires no specific level of AI literacy of any individual, and the Commission confirms there is no testing obligation — so there is nothing to certify against. Anyone selling “certified AI literacy” is decorating — a warning we also make in our field guide to Article 4 literacy training.
-
Formal training isn't the only allowed format.
Measures can take many shapes. But documented, hands-on training mapped to your real use cases is the most practical evidence you took the duty seriously — which matters when the measures would otherwise leave no trace.
What the softening didn't touch: the duty itself. Take measures, matched to your stack, and keep enough of a record to show them.
Next to literacy
The other duties that land on your people plan.
Literacy is the foundation. Two more live duties — and one scheduled one — touch HR directly.
-
Article 5 — the bans users actually trip. Live since 2 February 2025.
Prohibited practices bind users as well as builders: manipulative techniques, social scoring, and emotion inference in the workplace. Recruiting and people analytics are where those tripwires live. Two more bans arrive on 2 December 2026 — AI-generated non-consensual intimate imagery (“nudifiers”) and child sexual abuse material (CSAM) — worth a line in your use policy now.
-
Article 50 — disclosure duties on content teams. Live since 2 August 2026.
AI-generated text published to inform the public on matters of public interest must be disclosed. Deepfakes must be labeled. Chatbots must say they're AI — a duty on whoever provides the bot, not on your staff. Human-reviewed editorial content (a natural person holding editorial responsibility) is exempt outright; evidently artistic, creative, satirical or fictional work still owes a lighter-touch disclosure. If marketing ships AI drafts, the disclosure step is theirs — and yours to train.
-
The 2027 headline, sized correctly. Annex III · 2 December 2027
High-risk compliance did not begin on the date many checklists still cite — Regulation (EU) 2026/1744 moved it. If you deploy standalone high-risk AI — recruitment screening is on the Annex III list — the Article 26 duty to train the staff operating it for human oversight begins 2 December 2027; product-embedded systems follow on 2 August 2028. A next-budget-cycle project, not a this-week fire.
Evidence
The paper trail that proves the training.
The Act doesn't grade literacy. It asks whether you took measures — and measures leave evidence.
-
A per-role training matrix.
Who trained, on what, at what depth, when. One spreadsheet, owned by someone, updated as tools arrive.
-
A one-page AI use policy.
What may enter a prompt, what needs human review, who owns each tool, and which uses are banned outright — Article 5 keeps that list short but real.
-
Records you could hand to an authority.
Documentation is what evidence looks like. For inspiration, the Commission maintains a living repository of AI literacy practices — replicating entries isn't automatic proof of compliance, but it shows what real measures look like across industries.
Straight answers
Asked by HR, answered plainly.
Are employees personally liable under the EU AI Act?
The Act's fines attach to companies in their provider and deployer roles, and scale with the company's worldwide turnover. The real exposure is upstream: an untrained employee is how a compliant-looking company drifts into a banned practice or a missed disclosure.
Do contractors and agencies count as staff for Article 4?
Yes. The duty covers staff “and other persons dealing with the operation and use of AI systems on their behalf” — freelancers running AI for you and agency people embedded in your workflows belong in the training plan, at the depth their role requires.
Is an AI literacy certificate mandatory?
No. The Act demands no certificate: post-Omnibus Article 4 requires no specific level of AI literacy of any individual, and the Commission confirms there is no testing obligation — so there is nothing to certify against. What counts is taking measures and keeping the record.
We already ran a generic AI e-learning module. Does that count?
It can, if it was mapped to your real situation. Article 4 asks measures to fit each person's technical knowledge, the context of use, and the people the systems are used on — and the Commission warns that relying on the tools' instructions alone “might be ineffective.” Tie the module to your actual systems and risks, and document who completed it.
What happens if we skip the training?
The duty has been live since 2 February 2025, enforcement machinery activated in August 2026, and member-state penalty regimes have been in force since 2 August 2025 — with caps that scale with worldwide turnover, up to €35 million or 7% for banned practices and €15 million or 3% for most other obligations. When the first invoice arrives? Nobody can say. The duties are live, and the one obligation you can close this week for $30 is literacy.
Does anything change for high-risk HR tools like recruitment screening?
Not until 2 December 2027. Regulation (EU) 2026/1744 moved standalone high-risk duties — recruitment screening is on the Annex III list — to that date, including Article 26's requirement to train the staff operating such systems for human oversight. Product-embedded systems follow on 2 August 2028. Articles 4 and 5 didn't move.
Next
Train the team. Keep the file.
Fast path: the $30 self-serve courses — order tonight, start tonight, 30-day money-back. With your team: UpShift AI runs readiness snapshots, fluency audits, and hands-on bootcamps for EU companies of 10–500 — AI consulting and training for European teams, documented Article 4 literacy training included. Want the wider picture first? Start with the field guide: EU AI Act AI literacy training — the duty that never moved. For every date on one page, the EU AI Act compliance checklist for SMEs. For what skipping it costs, the EU AI Act penalties for companies breakdown.