Skip to main content

AI literacy policy template, Article 4 ready

Verified July 31, 2026. General information, not legal advice.

A defensible AI literacy policy has eight parts: purpose and scope, roles, the AI systems in scope, literacy requirements by role, the training measures, assessment and records, acceptable use and escalation, and a review cadence. It is how you document the measures EU AI Act Article 4 asks for. Copy the outline below and adapt it to your organization.

The AI literacy policy template

1
Purpose and scope

Why the policy exists (support AI literacy under EU AI Act Article 4) and who it covers: staff and any person operating or using AI on the organization's behalf.

2
Roles and responsibilities

Who owns the policy, who approves training, and each person's duty. Name an accountable owner (often the compliance or governance lead).

3
AI systems in scope

A reference to the organization's AI system inventory: which systems staff operate or use, and their risk classification.

4
Literacy requirements by role

The level of understanding each role needs, calibrated to the systems and risks it faces. A general user, a builder, and an approver need different depth.

5
Training and measures

The training provided, its content and objectives, and how new joiners and role changes are covered. This is the 'measures' Article 4 asks for.

6
Assessment and records

How completion and capability are evidenced (assessed, scored, dated), and where the records live. Attendance alone is weak; assessed capability is strong.

7
Acceptable use and escalation

The rules for using AI at work (data handling, verification, ownership of output) and how to escalate a problem or a risky use.

8
Review and currency

How often the policy and training are reviewed as AI and the law move, and who signs off. A cadence (for example annual, or on a major regulatory change) with a record of each review.

Does the EU AI Act require an AI literacy policy?

Article 4 requires providers and deployers to take measures to support staff AI literacy; it does not name a specific document. A written policy is the standard, defensible way to describe those measures and show you took them, which is why most organizations adopt one.

What is the difference between an AI literacy policy and an AI use policy?

An AI literacy policy is about ensuring people understand AI enough for their role (the Article 4 duty). An AI use or acceptable-use policy is about the rules for using AI at work (data, verification, ownership). They overlap and are often combined; sections 5 and 7 of the template below cover each.

Who should own the AI literacy policy?

A named, accountable person, usually the compliance owner, DPO, or governance lead, with training approval and record-keeping as explicit duties. Ownership with no name is how a policy goes stale.

How to make the records real, not just written

Sections 5 and 6 are where policies usually go thin: the training is named, but the evidence is a sign-in sheet. Article 4 is about capability, so the strongest record is assessed and verifiable. GAGE’s AI Literacy & Professional Conduct program gives each person a credential of per-topic mastery assessments passed, with scores, at a signed URL an employer can check, which fills sections 5 and 6 with evidence instead of attendance. For the full record and what the employer still assembles, see how to document AI literacy for Article 4.

Fill the training sections with real evidence

Assessed, scored, verifiable per-employee records, the parts of the policy an auditor actually reads.

Sources

  • Regulation (EU) 2024/1689 (the EU AI Act), Article 4, EUR-Lex, as amended by the Digital Omnibus (Regulation (EU) 2026/1744).
  • European Commission AI literacy guidance and the AI Act Service Desk.

Verified July 31, 2026. GAGE is not affiliated with, or endorsed by, the European Union. General information, not legal advice; have counsel review your policy.