Role-Based AI Literacy at Scale
A learning leader is whiteboarding the AI-literacy program when a director interrupts: "Just put everyone through the same course. It is simpler." She draws three columns instead. In the first, a financial analyst who pastes numbers into a chatbot to draft a summary. In the second, an executive who approves a strategy deck built partly by AI. In the third, a recruiter who runs an AI screening tool that decides which candidates a hiring manager ever sees. Then she asks the room one question: "If the AI is wrong, who gets hurt, and who has to catch it?" The three answers are wildly different. That is the whole reason one course for everyone is the wrong design, and the right design is the subject of this lesson.
Why One Course for Everyone Fails
The duty inside Article 4 of the EU AI Act is for a sufficient level of AI literacy, and the most important word is "sufficient," because it is explicitly scaled to role and context, not fixed at a single bar. Why you care: a flat program that pushes one identical course to the whole workforce is wrong in two directions at once. It wastes the time of people who barely touch AI, and, far more dangerously, it under-trains the small number of people whose AI use can directly harm someone or break a law. Literacy is not a single threshold everyone clears. It is a set of tiers, and the height of each tier is set by the consequence of getting the AI wrong.
Define the core idea cleanly. Role-based AI literacy means scoping what each role must understand and be able to do with AI based on how that role actually uses AI and what is at stake if the AI fails. The analyst, the executive, and the operator do not need the same knowledge, because their relationship to the AI, their power to override it, and the harm if it is wrong are all different. A program that recognizes this is not just more efficient. It is the only shape that can honestly claim to deliver "sufficient" literacy, because sufficiency is defined relative to the role.
There is a second reason the flat course is worse than merely wasteful, and it is the one that actually creates liability. A uniform course makes everyone look equally trained. The completion record shows the analyst, the executive, and the recruiter all marked complete on the same day, side by side, indistinguishable. But only one of those three sits in a role where a wrong AI output can quietly harm a person, and the flat record hides that role inside a sea of green checkmarks. So the flat program does not just fail to train the dangerous role; it actively camouflages it, making the most exposed person in the organization look exactly as covered as the least. When the gap surfaces, it surfaces as a surprise, because the dashboard said everything was fine. A role-based program refuses that false comfort by design: it never lets a high-consequence role hide inside an average.
One course for everyone is not equality. It is over-training the harmless and under-training the dangerous, dressed up as fairness.
The Three Anchor Roles
Most workforces sort into three literacy profiles, anchored by three representative roles. Get these three right and the rest of the org maps onto them.
The Analyst: The Everyday User
The financial analyst uses AI as a drafting and summarizing assistant. They paste figures into a chatbot, ask for a narrative, get a first draft in seconds. Their relationship to the AI is helper-and-checker: the AI assists, they review. The harm if it is wrong is real but contained and catchable, because the analyst is the domain expert reading their own output. They will notice if a number is off. What this role needs is baseline literacy: understand what the tool can and cannot do, understand its central failure mode, that a generation model can produce a fluent, confident, wrong fact, called a hallucination, and never paste output into a deliverable without checking it against the source. They also need the data-handling rule: do not paste confidential or personal data into a tool that may use it to train a vendor model. That is sufficient for the everyday user, and more would be waste.
The Executive: The Accountable Decider
The executive rarely operates the tool directly, which is exactly why a flat program misjudges them. Their AI use is at the level of decisions: they approve strategies, budgets, and communications that AI helped produce, and they sign off on the organization's AI governance. The harm if they get it wrong is not a single wrong number; it is a wrong decision at scale, or a governance gap that leaves the whole organization exposed. What this role needs is not how to prompt. It is oversight and governance literacy: understand where AI is used in the decisions they own, understand the limits and risks well enough to ask the right questions, understand the organization's accountability, that "the model recommended it" is never a defense, and understand the legal and reputational stakes. An executive who cannot ask "what is the source behind this AI-assisted recommendation, and who verified it" is an under-trained executive, no matter how many courses they completed.
The Operator: The High-Risk Supervisor
The recruiter running the AI screening tool is the role the law cares about most, and the role a flat program most dangerously under-serves. This person operates a high-risk AI system, one used in a sensitive domain such as recruitment, worker management, or access to essential services, where a wrong output directly affects a person's rights or opportunities. The harm if the AI is wrong is that a qualified candidate is silently filtered out, or a protected group is disadvantaged by a biased model, with legal and human consequences. What this role needs is the deepest tier: human-oversight competence. The operator must understand how the system works well enough to recognize when it is wrong, know the bias and failure modes specific to that system, and be able to actually intervene, override, or stop it and document the human decision. This is the tier whose training duty is the durable core of Article 4. The in-force text still requires employers to ensure a sufficient level of AI literacy, and the Digital Omnibus (proposed 19 November 2025, endorsed by the European Parliament 16 June 2026, and not yet published in the Official Journal, so not yet law) would soften that general verb to promote and encourage. What the Omnibus does not touch is the duty to train the people who oversee high-risk systems for human oversight. So the operator tier survives whichever way the amendment lands, which is exactly why it is the tier you document most rigorously.
Notice what separates the operator from the analyst even though both use an AI tool every day. The analyst is the domain expert reading their own output, so they are their own safety net; if the AI invents a number, the analyst is exactly the person likeliest to catch it. The operator is often the only safety net for someone else. The candidate the screening tool ranks low never sees the ranking, cannot object to it, and has no one downstream checking it; the recruiter is the single human standing between a biased model and a person's opportunity. That structural fact, the operator as the sole check for an absent third party, is why the operator tier is deep and why its training is about catching and overriding bias rather than just being aware it exists. Awareness is enough when you are checking your own work. It is not enough when you are the last line of defense for someone who is not in the room.
Scoping Each Tier in Practice
Turn the three profiles into a scoping table you can actually build against. Each row sets what "sufficient" means for that tier, derived from the consequence of failure, not from a uniform standard.
| Tier | Anchor role | Relationship to AI | What "sufficient" requires | Primary risk if under-trained |
|---|---|---|---|---|
| Baseline | Analyst / everyday user | Assistant they check | Capabilities, hallucination, verify against source, data-handling rule | A wrong fact slips into a deliverable |
| Oversight | Executive / decider | Accountable for AI-assisted decisions | Where AI sits in their decisions, the right questions, accountability, legal stakes | A wrong decision at scale or a governance gap |
| Operator | Recruiter / high-risk supervisor | Operates a high-risk system | How the system works, its bias and failure modes, ability to intervene, override, stop, and document | A person's rights or opportunities are harmed by an unchecked system |
Read the table as a curve of consequence. The baseline tier protects the quality of a deliverable. The oversight tier protects the quality of a decision. The operator tier protects a person from an unchecked system. The depth of training rises with what is at stake, which is exactly what "scaled to role and context" means in the text of the law. A program built on this table can defend, role by role, why each group got the training it got, and that defensibility is the point.
Mapping the Rest of the Workforce
Three anchor roles are a model, not the whole org. The scaling move is to map every role onto the nearest tier by asking the same diagnostic the leader asked at the whiteboard: if the AI is wrong, who gets hurt, and who has to catch it. A marketer using AI to draft campaign copy maps to baseline. A loan officer whose AI tool influences who gets credit maps to operator, because credit access is a high-risk domain. A department head approving an AI-assisted budget maps to oversight. Some people sit in two tiers, a manager who both operates a high-risk performance tool and approves AI-assisted decisions, and they get both. The map is not bureaucracy; it is the documented reasoning behind your program, and it is itself evidence that you scaled literacy deliberately rather than guessing.
Two practical cautions keep the map honest. First, do not let job titles decide tiers; let AI use decide them. A "senior analyst" might be an operator if their AI tool drives a high-risk decision, and a "director" might be baseline if they only use a chatbot to draft emails. Tier by what the person does with AI and what is at stake, not by seniority. Second, the map is a living document, because AI tools spread through an organization faster than org charts change. When a new AI system lands in a team, you re-ask the diagnostic for that team. A literacy program that mapped roles once and froze is already out of date.
A common objection is that this mapping is too much overhead for a large workforce, and the answer is that the work concentrates, not multiplies. Most people in most organizations cluster into baseline: they use AI as a drafting helper they can check, and they all need roughly the same short baseline path. The careful, individual scoping is reserved for the much smaller set of operator and oversight roles, where it genuinely matters. So the map is not a per-person essay; it is a fast sort of the whole workforce into baseline, with focused attention on the minority of roles that carry real consequence. The effort tracks the risk, which is the same principle the tiers themselves embody. A program that spends its scoping energy where the stakes are highest is not over-engineered; it is correctly engineered, and it scales precisely because the expensive attention is rationed to the roles that earn it.
It also helps to anticipate how the tiers interact with the broader workforce mix. Contractors and temporary staff who operate an AI system on the organization's behalf belong in the same tier as employees doing the same work, because the duty follows the AI use, not the employment status. A vendor's consultant running your screening tool is an operator for your purposes. Conversely, a long-tenured employee who has simply never been given an AI tool is not yet in scope at all, and forcing them through training for a tool they do not use is the over-training the curve is meant to prevent. The diagnostic, applied honestly, sorts all of these cleanly: ask what this person does with AI and what is at stake if it is wrong, and the right tier, including no tier, falls out.
Do not tier by title. Tier by the question: if the AI is wrong, who gets hurt, and who has to catch it. The answer tells you the depth the role needs.
A Worked Example: Three Roles, One Tool
An organization rolls out a single AI assistant across the company. A flat program would train everyone identically on it. Watch what role-based scoping does instead.
Before (flat). Everyone takes the same forty-minute "Using the AI Assistant" course: here is the interface, here are prompt tips, here is the acceptable-use policy. The analyst is mildly bored. The executive learns prompt tricks they will never use and nothing about the governance they own. The recruiter, who uses the same assistant to summarize and rank candidate profiles, learns the interface but never learns the bias failure mode of ranking people, never practices overriding a ranking, and is never told to document the human decision. The course is "complete" for all three. Only one of them is actually a problem, and the flat course made that role look as trained as the harmless ones.
After (role-based). The same tool, three scoped paths. The analyst gets the baseline path: capabilities, the hallucination failure mode, verify-against-source, and the rule against pasting confidential data. Thirty minutes, sufficient. The executive gets the oversight path: where this assistant now sits inside decisions they approve, the questions to ask before trusting an AI-assisted recommendation, and the accountability rule that the model is never the defense. The recruiter gets the operator path: how the ranking works and where it can be biased, a scenario in which they catch and override a skewed ranking, and the requirement to record their own decision and reasoning, with that training documented in detail. Now if a regulator asks "is the recruiter competent to oversee the ranking tool," the answer is a specific, evidenced yes, while the analyst and executive were not over-trained on a competence they do not need. Same tool, same rollout, three different and defensible depths.
One more detail from the after example is worth pulling out, because it is the part people skip. The role-based program did not just train three groups differently; it wrote down why. The reason the eleven recruiters were placed in the operator tier and the rest of recruiting in baseline is itself recorded, tied to the fact that the screening tool drives a high-risk decision and the others do not. That written reasoning is not paperwork for its own sake. It is the answer to the question an auditor asks after the first one: not only "is this operator competent," but "how did you decide who needed to be." A program that can answer both questions, the competence and the scoping logic, is genuinely defensible. A program that scoped by instinct and cannot explain its tiers is exposed even if the training itself was good.
The flat program treated literacy as a checkbox the same height for everyone. The role-based program treated it as a curve, tallest where the consequence is tallest. Only the curve is honest, and only the curve survives the question an auditor will actually ask.
Key Takeaways
- "Sufficient" AI literacy in Article 4 is explicitly scaled to role and context, so a single identical course for the whole workforce is the wrong shape: it over-trains the harmless and under-trains the dangerous.
- Role-based AI literacy scopes what each role must know and do based on how it uses AI and what is at stake if the AI fails; depth rises with the consequence of getting the AI wrong.
- The analyst (everyday user) needs baseline literacy: capabilities, the hallucination failure mode, verify against the source, and the data-handling rule.
- The executive (accountable decider) needs oversight and governance literacy: where AI sits in the decisions they own, the right questions to ask, the accountability rule, and the legal stakes, not prompt tricks.
- The operator of a high-risk system (such as a recruiter running an AI screening tool) needs the deepest tier: human-oversight competence, including bias and failure modes and the ability to intervene, override, stop, and document, the tier whose training duty survives the Digital Omnibus untouched.
- Map every role onto the nearest tier with one diagnostic: if the AI is wrong, who gets hurt, and who has to catch it; tier by AI use and stakes, never by job title or seniority.
- The role-to-tier map is living documentation and is itself evidence that you scaled literacy deliberately; re-run the diagnostic whenever a new AI system lands in a team.
- A role-based program can defend, role by role, why each group got the training it got, which a flat checkbox program cannot do when an auditor asks about a specific high-risk role.
Skill.re