AI Governance, Risk & Red Teaming
Capable · M13 · lesson 13 of 22 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Designing an Article 4 AI Literacy Program - Role-Based Curricula
📖
now learning

Designing an Article 4 AI Literacy Program - Role-Based Curricula

15 min

By May 2026 every defensible AI governance program has shipped the AI inventory, the tiering memo, the acceptable-use policy, the generative-AI policy, the vendor-risk policy, and the incident-response runbook. What most programs have not shipped, and what an ISO 42001 Stage 2 auditor or a national market surveillance authority is going to ask about first, is the Article 4 AI literacy program. The legal text is one paragraph. The operational implementation is a four-tier role-based curriculum, an LMS integration, a refresh cadence, an audit-evidence package, and a management-review loop that has to demonstrate the program is operating, not just that it was launched. This lesson is the L2 playbook for designing that program: tier-by-tier curriculum design, audience scoping, learning objectives, refresh triggers, LMS integration patterns, cross-walks to ISO 42001 Annex A and NIST AI RMF Govern 1, and the six common mistakes that turn an Article 4 program into an audit finding.

Article 4 - The Text, the Scope, and Why It Is Operationally Hard

Article 4 of the EU AI Act is one of the briefest substantive obligations in the entire 113-article regulation. The full operative text:

"Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used."

Five operative pieces. "Providers and deployers", both sides of the value chain are bound. "To their best extent", proportionality, but not exemption. "Sufficient level of AI literacy", the standard is sufficient for the role, not expert-level. "Staff and other persons dealing with the operation and use … on their behalf": employees plus contractors, vendors, and any natural person operating the system in the organization's name. "Taking into account their technical knowledge, experience, education and training and the context …", the curriculum must be role-tailored, not generic.

Article 4 has been in force since Feb 2, 2025, the same applicability date as the Article 5 prohibitions. It is a horizontal obligation. It applies across every in-scope risk tier including minimal-risk. A bank that uses Power BI Smart Insights to surface trend lines for branch managers is in scope. A retailer whose merchandisers use a generative-AI assistant to draft product descriptions is in scope. A municipal authority whose front-desk staff use an AI translation tool is in scope. The "minimal-risk = no obligations" mental model that worked for Article 6 and Annex III does not work for Article 4.

What makes Article 4 operationally hard is exactly what makes it look easy on first read. The legal text says nothing about how to deliver the literacy, what content to cover, how often to refresh, what assessment to apply, or what evidence to retain. Every operational detail is left to the provider or deployer to design, and is exactly what an auditor or regulator will ask about. The Commission's living repository of AI literacy practices (published in late 2024 and updated quarterly) is the de facto operational reference. It is selective, a curated set of practices submitted by Member State authorities, industry associations, and academic institutions, and it is intended as inspiration for curriculum design, not as a verbatim template. A defensible program references the repository for benchmark practices and documents the rationale for any adaptation or deviation.

The Four-Tier Curriculum Design

An audit-defensible Article 4 program in 2026 organizes literacy into four tiers keyed to the population's relationship with AI systems. The four-tier structure is not a regulatory requirement. It is a pattern that has emerged across European banks, insurers, public-sector authorities, and global enterprises building toward ISO 42001 certification. The pattern works because it maps cleanly to existing role taxonomies, integrates with HRIS-driven LMS assignment, and produces an evidence package that an auditor can test in one sitting.

Tier 1 - Executives and Board (90-Minute Briefing)

Audience. The CEO, the Executive Committee, the Board of Directors, the Audit Committee, the Risk Committee, and (in financial services) the SMF holders covering AI accountability. The Article 47 declaration signer for any provider obligations sits in this tier: typically the Chief AI Officer, the Chief Compliance Officer, or the General Counsel depending on the firm's accountability assignment.

Format. A 90-minute facilitated briefing, typically delivered live (in-person or video conference) with a small interactive component (Q&A, scenario discussion). Recorded versions for on-demand re-watch; assessment-light because the population is too small for meaningful psychometric assessment.

Content. The Tier 1 briefing covers nine standing topics:

  • EU AI Act Article 5 prohibited practices. The eight prohibitions in plain English; the workplace emotion-recognition prohibition (Article 5(1)(f)) as the one most likely to surface in HR; the social-scoring prohibition (Article 5(1)(c)) framing; the carve-outs and their narrowness.
  • EU AI Act Article 6 and Annex III high-risk classification. The eight Annex III categories; the firm's portfolio mapped to the categories; the conformity-assessment obligations at a board-comprehensible level.
  • Article 51 GPAI and systemic-risk. The €10²⁵ FLOP threshold; the firm's GPAI relationships (provider or deployer); the cascading downstream obligations.
  • Article 27 Fundamental Rights Impact Assessment. When a FRIA is required (§5(b)/§5(c) systems and public-body deployers of Annex III high-risk); the FRIA workflow; the board's role in reviewing FRIA outcomes for material decisions.
  • Article 73 incident reporting. The 15-day / 10-day / 2-day clock; the serious-incident definition; the board's role on systemic incidents.
  • Article 99 penalty exposure. The four-tier penalty schedule (€35M/7%, €15M/3%, €15M/3%, €7.5M/1%); the firm's worst-case quantification; the mitigation status reducing worst-case to realistic-case.
  • Article 47 declaration of conformity, personal accountability. The named signer; the personal-accountability story; the parallel to the financial-services SMF regime; what happens if the declaration is later found to be inaccurate.
  • The post-Omnibus VII timeline. The dual timeline (Aug 2, 2026 unchanged for prohibitions/GPAI/governance, Dec 2, 2027 deferral for most high-risk obligations under Omnibus VII); the accelerated Article 50(2) Dec 2, 2026 marking obligation; the implications for budget and program pacing.
  • The AI risk appetite statement. The firm's stated tolerance for AI risk (qualitative and quantitative limits); the board's role in approving and refreshing the statement; the AI governance committee's role in operationalizing it.

Refresh cadence. Annual refresh as a standing board calendar item; on-event refresh for material regulatory developments (Omnibus VII implementation, first Article 99 enforcement actions, new Commission Article 50 guidance, material Member State implementing law). On-event refresh is usually a 30-minute briefing delivered at the next regular board meeting or via a dedicated session.

Audit evidence. Slide deck or briefing materials retained per the firm's board-materials retention schedule; attendance record with named participants; minutes of the briefing in the board or committee minutes; on-event briefing materials and attendance.

Tier 2 - Deployers and Decision-Makers (3-4 Hour Curriculum)

Audience. The AI Officer or Chief AI Officer's direct team; the Heads of business functions deploying AI (HR, Credit, Insurance, Operations, Marketing, Customer Service, Compliance); Procurement Directors signing AI vendor contracts; General Counsel and senior legal staff supporting AI matters; Internal Audit's AI specialty staff; the Information Security team's AI-risk leads; the Data Protection Officer's office where applicable. Approximately 50 to 500 people depending on enterprise size.

Format. A 3-4 hour curriculum typically delivered as four 45-60 minute modules, with assessment after each module and a capstone scenario at the end. Combination of live-virtual delivery for the initial launch and asynchronous LMS-hosted modules for subsequent cohorts and refreshes. Assessment is psychometrically meaningful, multiple-choice plus short-scenario response, with an 80% passing threshold and a remediation pathway.

Content. The Tier 2 curriculum covers eight operational topics:

  • AI inventory navigation. The structure of the firm's AI inventory; how to query it; how to interpret tiering memo entries; how to add a new system or update an existing entry. The audience leaves able to answer "is this system in our inventory" and "what tier is it" in under five minutes.
  • The tiering memo process. The Article 5 negative-assurance review; the Article 6 / Annex III high-risk classification logic; the GPAI exposure-map work; the limited-risk Article 50 trigger analysis; the minimal-risk default. The audience leaves able to walk a new intake through the tiering memo end-to-end.
  • Article 26 deployer obligations. The instructions-for-use requirement (Article 26(1)); the human-oversight assignment (Article 26(2)); the input-data quality obligation (Article 26(4)); the logging and record-keeping obligations (Article 26(6)); the decision-affected-person notification obligation (Article 26(9)); the GDPR Article 22 interaction; the cooperation-with-authorities obligation.
  • Article 27 Fundamental Rights Impact Assessment. The FRIA workflow; the §5(b)/§5(c) creditworthiness and insurance triggers; the public-body Annex III high-risk trigger; the document template; the review and approval process; the integration with the broader risk-assessment program.
  • Article 73 incident-response runbook. The 15-day reporting clock for ordinary serious incidents; the 10-day clock for critical-infrastructure disruption; the 2-day clock for fundamental-rights infringement; the harm-severity decision tree; the regulator-coordination playbook; the post-incident learning loop.
  • Procurement-contract clauses, the five-clause framework. The conformity-evidence clause (Article 16, Annex IV, Article 47); the technical-documentation hand-over clause (Annex IV and downstream-deployer information); the incident-coordination clause (Article 73 cooperation and notification); the substantial-modification notice clause (Article 25(1)(b) change-control); the audit-rights clause (provider cooperation with deployer audits and conformity-assessment activity).
  • Substantial-modification change-control gate. What constitutes a substantial modification under Article 25(1)(b) and Article 43(4); the review-and-approval workflow; the documentation requirements; the provider-status transfer implications.
  • GPAI exposure-map work. The firm's GPAI provider relationships; the Annex XII downstream-deployer-information obligations; the systemic-risk overlay (Article 55); the procurement-contract integration; the incident-cooperation overlay.

Refresh cadence. Annual refresh as a calendar artifact, scheduled in Q1 to capture the prior year's regulatory developments; role-change refresh triggered by HRIS events for any movement into a Tier 2 role; on-event refresh for material regulatory developments (Omnibus VII implementation, first Article 99 enforcement, Commission guidance updates, ISO 42001 standard refresh, NIST AI RMF profile updates).

Audit evidence. Curriculum design document; module-level learning objectives and content outlines; LMS completion records by individual and role; assessment results by individual and role with cohort-level pass-rate trends; capstone scenario response samples for quality review; refresh-cadence evidence (annual and on-event); role-change refresh records pulled from the HRIS-LMS integration.

Tier 3 - Users and Operators (60-90 Minute Curriculum)

Audience. The front-line employees who deploy or operate AI systems in the course of their daily work. Recruiters using HR screening AI. Customer-service agents using chatbot supports. Credit analysts using scoring AI. Insurance underwriters using risk-tiering AI. Sales teams using lead-scoring AI. Marketing operators using generative-content AI. Operations analysts using forecasting AI. The population is large, typically thousands to tens of thousands depending on enterprise size, and the curriculum has to scale.

Format. A 60-90 minute curriculum delivered as three 20-30 minute modules through the LMS, with assessment after each module and a passing threshold of 80%. The training is system-specific where possible (the recruiter using the HR screening AI gets a recruiter-focused module covering the specific HR system; the credit analyst gets a credit-focused module covering the specific scoring system) and role-generic where the population is too small to justify per-system content. Multimedia delivery (video plus interactive scenarios plus knowledge-check questions) supports retention.

Content. The Tier 3 curriculum covers five core topics:

  • The specific AI systems the user interacts with. The system's purpose; the inputs it accepts; the outputs it produces; the known limitations and failure modes; the appropriate use cases and the inappropriate use cases; the documentation the user can consult (instructions for use under Article 26(1), system card, user-facing FAQ).
  • Human-oversight responsibilities under Article 14. The user as the human-in-the-loop; the override pathway; the appropriate situations for override; the documentation of override decisions; the escalation pathway when the user is unsure; the meta-awareness of automation bias and over-reliance on AI output.
  • Incident-escalation pathway. What constitutes an incident requiring escalation (e.g., unexpected output, suspected bias, customer complaint, system error, data-quality concern); the escalation channel (typically a ticket system or named escalation contact); the timeline for escalation; the user's role in incident documentation; the assurance that good-faith escalation is protected.
  • Prohibited-use language and Article 5 awareness. The eight Article 5 prohibitions in front-line-friendly language; the user's role in not deploying AI in a prohibited manner; the workplace-emotion-recognition prohibition (Article 5(1)(f)) for HR and customer-service roles; the escalation pathway when a use case looks potentially prohibited.
  • Article 50 disclosures the user is responsible for delivering. The chatbot disclosure script if the user is operating a chatbot or related AI assistant; the deepfake disclosure protocol if the user is producing AI-generated content; the emotion-recognition notice protocol if the user is operating a system with such functionality; the integration with the customer-communication standards.

Refresh cadence. Annual refresh delivered through the LMS as part of the firm's annual compliance-training cycle; on-system-change refresh triggered when a system the user interacts with is materially updated (new model version, new use case, new vendor); new-hire onboarding integration so any new employee in a Tier 3 role completes the relevant module within the first 30 days.

Audit evidence. Module-level learning objectives and content outlines; LMS completion records by individual and role; assessment results by individual and role with pass-rate trends; refresh-cadence evidence (annual and on-system-change); new-hire onboarding completion records; sample multimedia content for quality review.

Tier 4 - Affected Workers and Customers (Brief Notice)

Audience. The natural persons subject to AI systems the firm deploys but who are not operating the systems. Job candidates evaluated by HR screening AI (Annex III §4(a)). Employees subject to workplace-monitoring AI (Annex III §4(b), where not prohibited under Article 5(1)(f)). Customers subject to creditworthiness scoring (Annex III §5(b)) or insurance risk-tiering (Annex III §5(c)). Students subject to education AI (Annex III §3). Members of the public subject to public-sector AI (Annex III §5(a) eligibility for essential services).

Format. A brief role-specific notice delivered at the point of system interaction. For a job candidate, the notice is part of the application process, typically a paragraph in the application portal plus a more detailed FAQ accessible on request. For a credit applicant, the notice is part of the application disclosure, typically in the pre-contractual information pack. For a customer evaluated by an emotion-recognition system, the notice is at the point of interaction (e.g., the verbal disclosure at call start). For a worker subject to monitoring AI, the notice is in the employment handbook and refreshed at any material change.

Content. The Tier 4 notice covers five elements:

  • The system the affected person is subject to. Plain-language identification of the AI system and its purpose; named in a way the person can recognize.
  • The Article 26(9) right to information. For decisions producing legal or similarly significant effects, the affected person has the right to clear and meaningful information about the role of the AI system in the decision-making procedure and the main elements of the decision taken.
  • The Article 86 right to explanation where applicable. For high-risk-system decisions producing legal effects or similarly significantly affecting the person's health, safety, or fundamental rights, the affected person has the right to obtain a clear and meaningful explanation from the deployer.
  • The complaint pathway. The channel for raising a concern (customer-service team, dedicated AI ombudsperson, named contact); the timeline for response; the escalation to a regulator (typically the national market surveillance authority for AI Act matters or the data protection authority for GDPR matters).
  • The GDPR Article 22 right where applicable. For decisions based solely on automated processing producing legal effects or similarly significantly affecting the person, the GDPR right not to be subject to such decisions, with the right to obtain human intervention, express their point of view, and contest the decision.

Delivery cadence. Delivered at the point of system interaction. For applications and customer interactions, this is per-interaction. For employees subject to monitoring AI, this is at onboarding plus on-change. For students, this is at enrollment plus on-change.

Audit evidence. The notice templates retained per the firm's record-retention schedule; the per-interaction or per-cohort delivery records (e.g., timestamped application-portal disclosure receipt); the complaint-pathway response records; the integration evidence with the broader GDPR Article 13/14 transparency obligations.

Audit-Evidence Architecture and LMS Integration

The Article 4 program's audit-evidence package is what an ISO 42001 Stage 2 auditor (Schellman, A-LIGN, BSI, KPMG, DNV, LRQA) or a national market surveillance authority will test. The package has seven components: the curriculum design document, completion tracking, assessment results, refresh-cadence evidence, on-event refresh evidence, Tier 4 notice evidence, and management-review evidence. Lesson 034 covers the assessment and audit-evidence detail; the preview here is what to design for from day one.

LMS or training-platform integration. A defensible program in 2026 runs on an enterprise LMS or learning experience platform that integrates with the HRIS for assignment, the SSO infrastructure for access, and the analytics infrastructure for reporting. The common platforms in 2026 are:

  • Cornerstone Learning. The dominant enterprise LMS in financial services and large global enterprises; deep HRIS-integration capability; rich assessment tooling; mature reporting.
  • Workday Learning. The default for firms standardized on Workday HCM; tight HRIS integration; weaker authoring tooling but improving.
  • Docebo. A learning-experience platform popular for customer-facing and partner-facing literacy use cases; AI-driven content recommendation; mobile-friendly.
  • SAP SuccessFactors Learning. The default for SAP HCM customers; strong compliance-training workflows; integrated with SAP's broader governance tooling.
  • Custom LXPs. Several global banks and insurers have built custom learning experience platforms on top of headless LMS infrastructure to support brand-specific content authoring and analytics. The Article 4 curriculum integrates into the same platform.

HRIS-driven assignment. The literacy curriculum is assigned automatically based on role, function, business unit, and (where applicable) system-access entitlement. A new hire into a credit-analyst role automatically receives the Tier 3 credit-system module assignment with a 30-day completion deadline. A role change into a head-of-HR role triggers the Tier 2 refresh assignment. A vendor-staff augmentation contract that grants AI-system access triggers the Tier 3 assignment with the same deadline. The HRIS-LMS integration is the backbone of the audit-evidence package: without it, the completion-tracking evidence is manual, lagging, and fragile.

Multi-language considerations. The curriculum is delivered in the working language of the audience. For a German-speaking workforce, German. For a French-speaking workforce, French. For a multilingual global workforce, English plus translated versions for major populations. The translation is professional (not machine), reviewed by local-language legal where the content covers regulatory specifics, and refreshed on content change. The Tier 4 affected-person notice is in the language of the affected person where the service is offered in that language, a GDPR-aligned standard.

Onboarding integration. The Tier 3 module is part of new-hire onboarding for any role with AI-system access. The Tier 2 module is part of role-change onboarding for any movement into a deployer or decision-maker role. The Tier 1 briefing is part of director-onboarding for any new board member or Executive Committee appointee. The integration is operationalized through the HRIS onboarding workflow and the LMS auto-assignment rules.

Management review. The Article 4 program reports into the AI Governance Committee (or equivalent) on a quarterly cadence, covering coverage rate by tier, assessment-result trends, on-event refresh status, Tier 4 notice coverage, refresh-cadence gaps, role-change refresh gaps, and corrective action on identified weaknesses. The AI Governance Committee reports up to the Risk Committee or Audit Committee on an annual cadence covering the same metrics at a board-comprehensible level. This is the ISO 42001 clause 9 performance-evaluation evidence and the Article 4 management-review evidence rolled into one.

Cross-Walks - ISO 42001, NIST AI RMF, EEOC Awareness Training

The Article 4 program does not exist in isolation. The same investment satisfies overlapping obligations under ISO 42001, NIST AI RMF, and (in U.S. context) the EEOC's emerging guidance on AI awareness training for personnel involved in employment decisions.

ISO 42001 Annex A.4 resources. Annex A.4 requires the organization to determine and provide resources for the AI management system, including training, awareness, and competence. The Article 4 four-tier curriculum is the core evidence for this control. The audit-evidence package, curriculum design, completion tracking, assessment results, refresh cadence, is the same evidence ISO 42001 Stage 2 auditors will test under Annex A.4.

ISO 42001 Annex A.8 information for users. Annex A.8 requires the organization to provide users of AI systems with the information necessary for safe, effective, and responsible use. The Tier 3 user-operator content and the Tier 4 affected-person notice are the operational evidence for this control. The cross-walk is direct.

NIST AI RMF Govern 1. Govern 1 covers the organization's policies, processes, procedures, and practices for the management of AI risk. Govern 1.4 specifically covers personnel training. The Article 4 four-tier curriculum is the primary evidence for NIST AI RMF Govern 1.4 in a U.S.-facing program. A global program serving both EU AI Act and NIST AI RMF audiences typically uses the same Article 4 program with light supplementation for NIST-specific content.

EEOC awareness training. In U.S. context, the EEOC's enforcement guidance on AI in employment decisions (including the May 2023 technical assistance document and subsequent enforcement positions) emphasizes the importance of training personnel involved in AI-assisted employment decisions to understand the system's limitations, the bias-monitoring obligations, and the candidate-disclosure obligations. The Article 4 Tier 2 (HR leadership) and Tier 3 (recruiters and HR operations) content satisfies this expectation when the curriculum is adapted to cover the U.S. employment-law specifics (Title VII, ADA, ADEA, GINA, state-level AI employment laws including New York's Local Law 144 and Illinois' AI Video Interview Act).

The integration payoff. A global enterprise that builds the four-tier curriculum once, integrates it with the LMS and HRIS, and refreshes it on the cadence above is simultaneously satisfying EU AI Act Article 4, ISO 42001 Annex A.4 and A.8, NIST AI RMF Govern 1.4, EEOC AI-employment-decision awareness expectations, and (where applicable) state-level mandates that reference training as part of compliance. The investment is genuinely cross-jurisdictional.

Six Common Mistakes That Turn the Program Into an Audit Finding

Mistake 1 - Copying a Generic IT-Training Template

The first version of the Article 4 program in many organizations is a 20-minute "Introduction to AI" e-learning module purchased from the generic-content library of the LMS vendor. The module covers what AI is, the difference between supervised and unsupervised learning, and a brief mention of bias. It does not cover Article 5 prohibitions, Article 26 deployer obligations, Article 50 disclosures, or any system-specific operational content. The audit finding writes itself: the program is not "sufficient" for the role, the content does not reflect the firm's actual AI portfolio, and the curriculum design has not been adapted to the populations as Article 4 explicitly requires.

The fix is to design the curriculum from the role and the system inventory outward, not from a generic template inward. The Tier 2 and Tier 3 content must reference the firm's actual systems by name. The Tier 1 briefing must cover the firm's portfolio worst-case Article 99 exposure, not a generic regulatory overview. The investment is higher; the audit posture is durable.

Mistake 2 - Missing the Tier 4 Affected-Worker Notice

The most-frequently-missed component in early Article 4 programs is the Tier 4 affected-person notice. The program covers employees thoroughly, then stops at the organizational boundary. Article 4's text, "other persons dealing with the operation and use of AI systems on their behalf" plus the contextual language about "the persons or groups of persons on whom the AI systems are to be used", extends to the affected-person population. The audit finding is that the program does not address Article 4's full population, and (separately) does not produce the evidence Article 26(9) requires for decisions producing legal or similarly significant effects.

The fix is to design the Tier 4 notice in parallel with the internal tiers, integrate it with the GDPR Article 13/14 transparency overlay, integrate it with Article 26(9) decision-affected-person notification, and retain the per-interaction delivery evidence.

Mistake 3 - One-Time Launch Without a Refresh Cadence

An Article 4 program launched in 2024 or early 2025 and never refreshed is a 2026 audit finding regardless of how thorough the original launch was. Article 4 is a continuous obligation, the regulatory landscape moved materially with Omnibus VII in May 2026, and the operational details, system portfolio, vendor relationships, tier classifications, have shifted. The fix is the multi-cadence refresh architecture: annual refresh as a calendar artifact, on-event refresh for material regulatory developments, role-change refresh through the HRIS-LMS integration, and on-system-change refresh for material updates to systems in the inventory.

Mistake 4 - Weak Assessment Methodology

An Article 4 program that tracks attendance but not understanding is a thin audit-evidence package. "We trained 8,000 employees" answers the wrong question; the question the auditor asks is "what fraction of those 8,000 can correctly identify an Article 5 prohibition or escalate an incident appropriately." The fix is psychometrically meaningful assessment, multiple-choice plus scenario-response, with an 80% passing threshold and a remediation pathway for those who do not pass. The assessment data feeds the management-review loop and surfaces curriculum-content weaknesses.

Mistake 5 - No LMS or HRIS Integration

An Article 4 program delivered through ad-hoc training events with attendance tracked in a spreadsheet is fragile, lagging, and not scalable. When the auditor asks "show me the completion record for everyone in a Tier 2 role as of last quarter," the spreadsheet-driven program cannot answer in the time the auditor will wait. The fix is enterprise-LMS hosting with HRIS-driven assignment, automated reporting, and an audit-friendly export workflow.

Mistake 6 - No Management-Review Evidence

The seventh component of the audit-evidence package, management-review evidence, is the one most-frequently absent in first-generation Article 4 programs. Without it, the auditor cannot verify that the program is operating and improving rather than simply running. The fix is the AI Governance Committee quarterly review with documented agenda items, attendance, decisions, and corrective actions; the annual board or Risk Committee briefing as the upward reporting; and the integration with the ISO 42001 clause 9 performance-evaluation evidence package.

Key Takeaways

  • Article 4 has been in force since Feb 2, 2025 and applies horizontally to every in-scope tier including minimal-risk. The legal text is one paragraph; the operational implementation is a sustained four-tier program.
  • The four-tier curriculum design is the dominant pattern in 2026. Tier 1 executives and board (90-minute briefing). Tier 2 deployers and decision-makers (3-4 hour curriculum). Tier 3 users and operators (60-90 minute curriculum). Tier 4 affected workers and customers (brief notice at point of interaction).
  • The Commission's living repository of AI literacy practices (published late 2024, updated quarterly) is the de facto operational reference for curriculum design. Selective inspiration, not verbatim template; document the rationale for any deviation.
  • Tier 1 covers the regulatory landscape and personal accountability. Articles 5, 6, Annex III, 51, 27, 73, 99, the Article 47 declaration-signer accountability, the post-Omnibus VII timeline, and the AI risk appetite statement. Annual refresh plus on-event briefings.
  • Tier 2 is the deployer-operations curriculum. AI inventory navigation, tiering memo process, Article 26 deployer obligations, Article 27 FRIA, Article 73 incident response, the five-clause procurement framework, substantial-modification change control, and GPAI exposure-map work. Annual plus role-change refresh.
  • Tier 3 is the user-operator curriculum. The specific systems the user interacts with, Article 14 human-oversight, incident escalation, Article 5 prohibited-use awareness, and Article 50 disclosure delivery. Annual plus on-system-change refresh; integrated with new-hire onboarding.
  • Tier 4 is the affected-person notice. The system, Article 26(9) right to information, Article 86 right to explanation, complaint pathway, and GDPR Article 22 right where applicable. Delivered at point of interaction; documented for audit retention.
  • LMS and HRIS integration is the backbone of the audit-evidence package. Cornerstone, Workday Learning, Docebo, SAP SuccessFactors, or a custom LXP: pick one and integrate it with the HRIS for assignment, the SSO for access, and the analytics infrastructure for reporting.
  • Cross-walks satisfy ISO 42001 Annex A.4 and A.8, NIST AI RMF Govern 1.4, and EEOC AI-employment awareness expectations. A single four-tier program serves multiple jurisdictions and standards.
  • The six common mistakes are the audit-finding catalog. Generic IT template; missing Tier 4 notice; one-time launch without refresh cadence; weak assessment; no LMS integration; no management-review evidence. Design around them from day one.