Somewhere right now, someone is finishing an hour of AI-literacy e-learning that will not make them meaningfully more literate about anything. That is not a knock on them, it is a knock on what got sold to their employer.
Article 4 of the EU AI Act requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among staff and others operating the system on their behalf. It has been in force since February 2025.
What the text does not do is define “sufficient.” No hours-completed threshold, no named competency framework, no pass mark. That silence has been very good for one part of the market and bad for everyone else: training vendors have filled the gap with an hour of e-learning and a completion certificate, priced per seat, sold on the promise that a certificate discharges the obligation.
It does not, on its own.
A regulator asking whether an organisation is compliant is asking whether the literacy in place is adequate to the actual risk the organisation’s AI systems carry.
A blanket e-learning module completed by a marketing team and a machine-learning engineering team in the same afternoon answers a different question than the one being asked, and both teams usually know it, even if nobody says so out loud in the feedback survey.
The fix is not more training.
It is a defined competence and capability standard, mapped to what different roles actually need to know, evidenced against something a regulator can check rather than a private rubric only the vendor holds.
We work from a defined competence standard for the AI ethicist role, extended down to define what “sufficient” looks like at each level of exposure.
Anything looser than that is a certificate for standing near the socket, not for knowing where the current actually runs.