All services

AI training for your staff, and the AI literacy Article 4 asks for

We show your people where AI helps in daily work and where its limits are. That also meets the AI literacy obligation under Article 4 of the EU AI Act.

AI is already in use. Nobody knows quite where.

In most businesses some people are already using AI. Nobody knows exactly who, for what, or with which data. According to the IW Cologne survey of 5,000 employees from March and April 2026, 29.1% of employees already use AI applications at work that their employer never approved. That is not a discipline problem. What is missing is a statement of what is allowed and what a tool is actually good for.

Two things are absent at once. The first is confidence in daily use: three people in a team use the tool well, the rest tried it once and stopped. The second is judgement about when AI is the wrong route, and that one saves more money than the first. The Bitkom Research survey “KI in der deutschen Wirtschaft 2026” finds that 66% of companies rate their workforce’s AI skills as low, and a quarter train nobody at all.

Article 4 of the EU AI Act, in plain terms

Since 2 February 2025, Article 4 of the EU AI Act requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among the staff who operate or use them, taking into account their role, their prior knowledge and the context in which the system is used. It applies to a company using a chat tool in sales as much as to one running its own agent.

The article does not prescribe a course, a number of hours or a certificate. “Sufficient” depends on the role: the accountant who releases a proposed posting needs something different from the managing director who signs the project. What you need to be able to show is what was covered, for whom, and when. We write that record per role, and it stays with you.

How we work

  1. Take stock, without blame. Which tools are in use in which team, approved or not, and for what. A short conversation per team, not an audit.
  2. A session for the teams, on their own cases. A group brings its real work: last week’s enquiries, this month’s quote texts, the report nobody wants to write. We test the tool against it: where it helps, where it hurts, and how to tell the difference.
  3. A short session for decision makers, on cost, limits and liability: what a project takes, what a model cannot do, and where the sign-off has to stay with a person.
  4. One page of internal rules. Which data may go into which tool, who decides in case of doubt, and what to do when unsure. Written with you, in your words.
  5. A named place for questions, so the person who is unsure asks rather than guesses.
  6. A follow-up session where the real cases from the weeks between come back on the table.
  7. The documentation under Article 4, per role.

A worked example: the sales team

Taking stock at a wholesaler in the German Mittelstand finds that two people in sales paste customer emails into a free chat tool for translations, and one uses it to draft quote texts. Customer emails contain names, prices and sometimes contract terms, and none of that was ever meant to leave the company.

The team session starts there. What a customer email contains, which tool the company provides instead, one with a data processing agreement under Article 28 GDPR behind it, how to write the request so the answer is usable, and how to check the answer before it goes out. The one-page rule that comes out of it says: customer data only into the approved tool, no contract text into any tool without the head of department.

At the follow-up, the quote texts of the past weeks are reviewed together. The team’s own collection of requests that worked becomes the standard, and the two people who started it all become the named place for questions.

What you need to bring, and when it is not worth it

You need an approved tool to point people to. Training people on a tool they may not use is pointless, and a rule that only forbids does not get followed. You need management in the room for its own session, because the judgement about what to build is theirs. And you need to plan for the follow-up, because the day on its own does not hold.

It is not worth it as a one-off “AI day” with no follow-up; that is a nice morning and nothing more. It is not a substitute for deciding what to build; that is the assessment. And it is not the first step if you have a project running that your people were never shown; then the session belongs with that project.

How it differs from the neighbouring services

Enablement equips people. The assessment decides what to build, and enablement belongs after it and before the first build, so the people who will work with the system know what it can and cannot do. AI agents and knowledge systems are systems; when one of them goes live, the team session covers that system rather than a general tool, and the Article 4 record names it.

The next step

In the free introductory call, tell us which tools you suspect are in use and which teams you would start with. If AI is already in use at your place without being governed, this is the first step. If nothing is running yet, the assessment comes first.

Common questions

Who is this for?
The people who do the process, and the people who decide. They need different things: the first group safe handling in daily work, the second a judgement on what a project costs and what it cannot do.
Is this training or support?
Both, and the support is the part that works. A training day without the weeks after it leaves three people carrying on and everyone else falling back. So we keep working on your real cases, not on exercises.
What does Article 4 of the EU AI Act require?
Since 2 February 2025, providers and deployers of AI systems must take measures to ensure a sufficient level of AI literacy among the staff who operate or use them, taking their role, their prior knowledge and the context of use into account. The article does not prescribe a course or a certificate. What it does require is that you can show what you did, for whom, and when. That is the record we leave behind.
What is shadow AI, and why does it matter?
AI tools your staff use at work without your approval. According to the IW Cologne survey of 5,000 employees from March and April 2026, 29.1% of employees already do. For those tools nobody has signed a data processing agreement and nobody has assigned a risk class, and customer data may already be going into them. Enablement is the cheapest way to bring that into the open without a witch hunt.
Do we need internal rules for this?
Yes, and short ones. A single page saying which data may go into which tool and who decides in case of doubt gets read. A twenty-page policy gets filed.