What the regulation asks, without alarm
The European regulation on artificial intelligence requires both those who develop and those who use these systems to ensure, as far as possible, a sufficient level of literacy among the staff involved — taking account of those people’s skills and of the context in which the systems are deployed.
It does not prescribe a course of set length, a standard syllabus or any particular certificate. It requires that the competence exists and is proportionate, which in practice means it has to be documented: knowing who received what training and when.
It is a reasonable requirement, and it is also the only part of the regulation that touches practically every company, including those that merely use AI.
The risk is not that people cannot use them
These tools are easy to use — that is their defining trait. The risk is the opposite: that people believe them.
A language system produces plausible answers with the same confidence whether it is right or inventing. It does not flag uncertainty, it does not say “I do not know that”: it constructs a non-existent legal reference, a believable number or a citation nobody ever wrote, in the same tone it uses to report a genuine fact.
Somebody who does not know that finds out late. Somebody who does know checks, and at that point the tool becomes useful.
The second risk is confidentiality, and that is the one that causes immediate damage: the person who pastes a contract, a list of employees or a case file into a public service, in good faith, to have it summarised.
What we teach, in two hours
How they work, in outline. Not the mathematics: just enough to understand why they get things wrong, and why they do it convincingly. It is the knowledge that makes checking feel natural.
What must never be entered. With examples drawn from those people’s real work rather than from a generic list. In a law firm it is a case file; in accounts it is a list of employees; in sales it is the negotiation currently under way with a client.
How to check an output. Which is the part that stays human and that no tool removes: checking the sources cited, recalculating the numbers, asking whether that reference actually exists.
Who to ask when in doubt. A name, not a procedure. It is the simplest lesson and the one that avoids most problems.
For people working with particularly sensitive data — professional firms, healthcare, HR — a module on their specific context is added, where the constraint is not only data protection but professional responsibility.
Why it goes alongside the policy
They are two halves of the same thing and separately they work badly.
A policy without training is read as an arbitrary prohibition and worked around, because nobody explained why. Training without a policy generates enthusiasm and no rules: after two weeks everyone does as they please, with more confidence than before.
We deliver them together, and the training is also the moment the policy gets corrected: the questions that come up in the room almost always reveal a use case the document had not anticipated.
How to measure whether it worked
Not with a multiple-choice test, which measures short-term memory.
The useful measures are behavioural. How many requests for clarification reach the designated person in the following months — they usually increase, which is an excellent sign: it means people have understood when to stop. And whether unapproved tools stop appearing, which is the most concrete check of all.
If nobody ever asks anything after the training, it almost always means it was not understood.
The rest
See also the company AI policy, which is the other half, AI Act, GDPR and AI governance for the regulatory picture, and consulting and training for the other programmes.
The first step
A meeting to establish who in the company is already using these tools and for what. The programme comes out of that, and it changes considerably depending on the roles. Free and without obligation.