Skip to content
SimpleAct Logo

Art. 4 AI Act · Excel + Word template

Updated 4 October 2026 · after the Digital Omnibus

Prove AI literacy under Article 4: template & guide

If you provide AI systems or use them at work, you have to support the AI literacy of the people who work with them – from Copilot in the office to a chatbot you built yourself. Since the Digital Omnibus this is a best-efforts duty: measures count, not certificates. This page explains what Article 4 requires today, who you should train, and offers two free templates for your records: an Excel training matrix and a Word attendance confirmation. No sign-up.

XLSX · dropdowns, module catalogue, guide · DOCX · individual and group record

  • Text as amended by the Digital Omnibus
  • Training matrix: people × roles × modules
  • Training plan generator on the page
  • No email, no gate
app.simpleact.de

AI literacy training matrix

Demo Organisation GmbH · Art. 4 AI Act

A
SimpleAct_AI_Literacy_Training_Matrix_EN.xlsx Filter
RoleTrainedn
  • Management3/3
  • Business users38/52
  • Power users / developers7/9
  • Procurement2/4
  • DPO / compliance2/2
  • External / contractors3/8

Trained

71 %

55 / 78

Next refresher

6 people by 31/12/2026

Fictitious sample data · status per person in the matrix

Short answer

What you need to know in one paragraph

Article 4 of the AI Act requires providers and deployers of AI systems to take measures that support the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. It has applied since 2 February 2025 and covers every AI system regardless of its risk class – including ChatGPT, Copilot or DeepL in everyday work.

Since the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) it is clear that you do not have to guarantee that every individual reaches a particular level of competence. You have to make a demonstrable effort. The law does not require a certificate or any particular form of record. The European Commission does, however, recommend keeping an internal record of training and other measures. That is what the two templates on this page are for.

Legal position

What Article 4 requires – and what it doesn’t (since the Omnibus)

The Digital Omnibus did not abolish Article 4; it replaced it in full. A duty to ensure an outcome became a duty to take measures. Many guides online still quote the old text.

Under the original 2024 text, providers and deployers had to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff. In practice that wording was hard to pin down: what is “sufficient”, and how do you prove that a person has reached it? It gave rise to a market for training certificates, mandatory courses and exams that often promised more than the law actually asked for.

Regulation (EU) 2026/1744 – the Digital Omnibus on the AI Act, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 – replaced Article 4 in full. Under the new text, providers and deployers take measures to support the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. In doing so they take into account technical knowledge, experience, education and training and the context in which the systems are used. The text makes clear that no specific level of competence of any individual has to be guaranteed.

Also new: the Commission and the Member States support providers and deployers in fostering AI literacy, in particular small and medium-sized enterprises. That does not change your own duty – but it may mean that more freely available materials, guidance or programmes become available for you to draw on.

In practice the duty is one of best efforts. It is not met by sending out a single video, and it is not breached because a trained person later still makes a mistake. What matters is that you take suitable measures for each role and context of use and that you can show it. If you can trace who received which measure and when, you have a solid basis for conversations with an authority, a customer running a supplier audit or your works council.

Scroll the table sideways →

What Article 4 requires – and what it doesn’t (since the Omnibus)
Aspect2024 text (until 26 Jul 2026)Text after the Digital Omnibus (from 27 Jul 2026)
Core of the dutyMeasures to ensure, to their best extent, a sufficient level of AI literacy of staffMeasures to support the development of AI literacy
Type of dutyOutcome-oriented (“sufficient level”)Best efforts: take measures
Level of individualsHad to be “sufficient” – without a definition of what that meansExplicitly no specific level of any individual to be guaranteed
Who is obliged?Providers and deployersUnchanged: providers and deployers
Who is covered?Staff and other persons dealing with operation and use on their behalfUnchanged: staff and other persons dealing with operation and use on their behalf
YardstickTechnical knowledge, experience, education and training, context of useStill technical knowledge, experience, education and training, context of use
SupportNot addressed in the articleCommission and Member States support providers and deployers, in particular SMEs

Paraphrase of the amended text. The wording of Regulation (EU) 2026/1744 in the Official Journal is authoritative (link under “Sources”).

Target groups

Who needs to be trained?

Article 4 covers everyone who works with AI systems on your behalf – not just IT. Because the measures should fit knowledge, experience and context, it helps to group people into roles. The matrix below is our recommendation, not a legal requirement.

Scroll the table sideways →

Who needs to be trained?
RoleTypical peopleContact with AIFocus of the measureSuggested depthRefresher (recommendation)
ManagementManaging directors, board, heads of departmentDecides on roll-out, budget and riskDuties and roles under the AI Act, accountability, risk picture, approval processCompact (1–2 h)12 months
Business usersAdministration, sales, marketing, HR, customer serviceUses approved AI tools day to dayHow it works and where it fails, checking outputs, data protection in prompts, internal rulesBasic (2–3 h)12 months
Power users / developersIT, data science, software engineering, automation buildersConfigures, integrates or develops AITechnical risks, secure integration, testing, logging, documentationIn depth (4–6 h)6 months
ProcurementPurchasing, vendor management, departments with budgetSelects AI products and vendorsVendor due diligence, contract terms, requesting documents, your own roleBasic + procurement module12 months
DPO / complianceData protection officers, compliance, legal, information securityReviews, assesses and documents AI useAI register, risk classification, incidents, record-keeping, interplay with GDPRIn depth (4–6 h)12 months
External / contractorsFreelancers, agencies, temporary staff, contractors with access to your AI systemsUses your AI systems on your behalfYour rules for the assignment, data handling, contactsBriefing (30–60 min)At start of assignment, then 12 months

According to the European Commission’s Q&A, external people explicitly count: contractors, service providers or even clients, as long as they work with your AI systems on your behalf.

One person can hold several roles – the head of marketing is a manager and a business user at the same time. In the matrix, enter the role with the greatest training need or add a second row. What matters is that in the end everyone who works with one of your AI systems professionally is assigned to at least one role.

Purely personal, non-professional use is not covered: someone who tries out a chatbot in their free time does not become a deployer under the AI Act (Article 3(4)). As soon as the same person uses the chatbot for a customer email – even with a private account – it is professional use within your organisation. That is one reason why an internal AI policy and a basic briefing for all staff make sense, not just for those who officially hold a licence.

Content

What each role should know

The AI Act does not set a curriculum. The yardstick “knowledge, experience, education, context of use” does, however, make it easy to derive what is useful for each role. You will find the module numbers again on the “Modules” sheet of the Excel template.

01

Management

Management does not need to write prompts. It needs to understand what the organisation is accountable for, where AI is used and which decisions it has to take itself.

  • Roles under the AI Act: when is the organisation a deployer, when a provider?
  • Risk classes at a glance and why the intended purpose determines the duties
  • Who is responsible internally: approval process, AI register, contacts
  • Typical risks: confidential data in external tools, wrong outputs, reputational damage
  • How the organisation fosters and records AI literacy

Matching modules

M01M02M05

02

Business users

The largest group – and the one where a good foundation makes the biggest difference. The goal is a realistic picture of what an AI tool can and cannot do.

  • How generative AI produces answers and why it can be convincingly wrong
  • Checking outputs: facts, figures, sources, tone, bias
  • Which data may go into which tool – personal data, trade secrets, customer data
  • Approved tools and the rules in the internal AI policy
  • When a human has to decide and whom to contact when something goes wrong

Matching modules

M01M02M03M04

03

Power users / developers

Anyone who configures AI systems, builds them into processes or develops them carries responsibility for how the system behaves towards others. This is where most depth pays off.

  • Technical risks: prompt injection, data leakage, insecure plugins and agents
  • Choosing models and vendors, limits of benchmarks, testing with your own data
  • Logging, versioning and change management
  • Transparency towards users when a system interacts with people or generates content
  • Providing documentation for the register and risk classification

Matching modules

M01M02M03M04M06

04

Procurement

Many AI systems arrive through procurement – often as a new feature in existing software. Procurement is therefore the first place where AI can be spotted and classified correctly.

  • Spotting AI features in offers, including in updates of existing software
  • Questions for vendors: purpose, data processing, documents, support
  • Contract terms: data processing, confidentiality, changes to the model
  • Handover to the register and compliance before approval

Matching modules

M01M02M03M07

05

DPO / compliance

Data protection and compliance hold everything together: they assess systems, maintain the records and are the contact for authorities and customers.

  • Setting up and maintaining an AI register
  • Risk classification under the AI Act and alignment with GDPR documentation
  • Handling incidents and complaints
  • Record-keeping for Article 4: matrix, confirmations, storage, refreshers
  • Current developments: Commission guidance, national supervision

Matching modules

M01M02M03M05M08

06

External / contractors

Anyone who works for you and uses your AI systems while doing so is included. For external people a short, targeted briefing is often enough – what matters are your rules for that specific assignment.

  • Which AI systems may and may not be used for the assignment
  • Data handling: what may be entered, what never
  • Labelling AI-generated content where agreed or required
  • Contacts and reporting channel for problems

Matching modules

M09M03

Records

What a good training record contains

Article 4 prescribes no documentation and no fields. But if you want to show that you have taken measures, the record needs a few details. These are the fields we recommend – they are also the columns of the Excel matrix.

What a good training record contains
FieldTypeWhat to enterWhy it helps
Person / IDCore fieldName or employee number; for external people, company and contactShows who was reached. An employee number is often enough and protects privacy.
DepartmentAdditionalBusiness unit or teamMakes gaps per unit visible and the matrix filters useful.
RoleCore fieldOne of the six roles from the dropdownLinks the person to the matching module set – the core of the role-based approach.
AI systems usedCore fieldThe systems the person works withContext of use is part of the legal yardstick. Comparing with the AI register shows whether new tools have untrained users.
ModuleCore fieldTitle or module number of the measureShows what was actually taught – more meaningful than just “attended”.
FormatAdditionalClassroom, live online, e-learning, briefing etc.Makes it traceable how the measure took place.
DateCore fieldDay of attendance or completionBasis for the next refresher.
DurationAdditionalIn minutesHelps judge whether the measure fits the role.
Evidence / storageCore fieldWhere the confirmation is kept: folder, DMS path, LMS exportThe matrix is the overview, the evidence lives elsewhere – the path connects the two.
Next refresherAdditionalDate of the planned repeatMakes upkeep plannable and lets you filter people who are due.
StatusCore fieldPlanned, invited, attended, completed, refresher due, not applicableShows at a glance where the organisation stands.

Core fields are our recommendation for a meaningful record, not a legal requirement. The matrix contains employee data – limit access to the people who need to maintain it.

Interactive

Training plan generator

Enter how many people per role work with AI and in which context you use AI. The generator suggests modules, scope and refresher intervals and creates an overview you can copy – for example to agree the plan with management or the works council.

People per role
  • ManagementManaging directors, board, heads of department
  • Business usersUse AI tools in everyday work
  • Power users / developersConfigure, integrate, develop
  • ProcurementBuy AI products
  • DPO / complianceData protection, compliance, legal, IT security
  • External / contractorsWork with your AI systems on your behalf
Context of use
app.simpleact.de

Your training plan

Draft · Art. 4 AI Act

A
People
49
Total training hours (approx.)
132.8 h
  • Management · 2

    135 min per person

    • M01AI basics: how it works and where it fails
    • M02Internal AI policy and approved tools
    • M05AI Act for leaders: roles, risks, accountability

    Refresher: every 12 monthsRecommendation

  • Business users · 40

    150 min per person

    • M01AI basics: how it works and where it fails
    • M02Internal AI policy and approved tools
    • M03Data and confidentiality in AI prompts
    • M04Checking outputs: errors, hallucinations, bias

    Refresher: every 12 monthsRecommendation

  • Power users / developers · 4

    270 min per person

    • M01AI basics: how it works and where it fails
    • M02Internal AI policy and approved tools
    • M03Data and confidentiality in AI prompts
    • M04Checking outputs: errors, hallucinations, bias
    • M06Secure integration and development

    Refresher: every 6 monthsRecommendation

  • Procurement · 2

    165 min per person

    • M01AI basics: how it works and where it fails
    • M02Internal AI policy and approved tools
    • M03Data and confidentiality in AI prompts
    • M07Buying AI: vendor checks and contracts

    Refresher: every 12 monthsRecommendation

  • DPO / compliance · 1

    285 min per person

    • M01AI basics: how it works and where it fails
    • M02Internal AI policy and approved tools
    • M03Data and confidentiality in AI prompts
    • M05AI Act for leaders: roles, risks, accountability
    • M08AI governance: register, classification, incidents, records

    Refresher: every 12 monthsRecommendation

AI literacy training plan (Art. 4 AI Act) – draft
Created with simpleact.eu/ai-literacy-training-record on 05/10/2026

Management (2 people) – 135 min per person, Refresher: every 12 months (Recommendation)
  • M01 AI basics: how it works and where it fails – 45 min, E-learning or classroom
  • M02 Internal AI policy and approved tools – 30 min, Briefing + read confirmation
  • M05 AI Act for leaders: roles, risks, accountability – 60 min, Live briefing

Business users (40 people) – 150 min per person, Refresher: every 12 months (Recommendation)
  • M01 AI basics: how it works and where it fails – 45 min, E-learning or classroom
  • M02 Internal AI policy and approved tools – 30 min, Briefing + read confirmation
  • M03 Data and confidentiality in AI prompts – 30 min, E-learning
  • M04 Checking outputs: errors, hallucinations, bias – 45 min, Hands-on exercise

Power users / developers (4 people) – 270 min per person, Refresher: every 6 months (Recommendation)
  • M01 AI basics: how it works and where it fails – 45 min, E-learning or classroom
  • M02 Internal AI policy and approved tools – 30 min, Briefing + read confirmation
  • M03 Data and confidentiality in AI prompts – 30 min, E-learning
  • M04 Checking outputs: errors, hallucinations, bias – 45 min, Hands-on exercise
  • M06 Secure integration and development – 120 min, Workshop

Procurement (2 people) – 165 min per person, Refresher: every 12 months (Recommendation)
  • M01 AI basics: how it works and where it fails – 45 min, E-learning or classroom
  • M02 Internal AI policy and approved tools – 30 min, Briefing + read confirmation
  • M03 Data and confidentiality in AI prompts – 30 min, E-learning
  • M07 Buying AI: vendor checks and contracts – 60 min, Live online

DPO / compliance (1 people) – 285 min per person, Refresher: every 12 months (Recommendation)
  • M01 AI basics: how it works and where it fails – 45 min, E-learning or classroom
  • M02 Internal AI policy and approved tools – 30 min, Briefing + read confirmation
  • M03 Data and confidentiality in AI prompts – 30 min, E-learning
  • M05 AI Act for leaders: roles, risks, accountability – 60 min, Live briefing
  • M08 AI governance: register, classification, incidents, records – 120 min, Workshop or external course

Total: 49 people, 132.8 h

Note: suggestion, not legal advice. Article 4 AI Act (as amended by Regulation (EU) 2026/1744) requires measures to support AI literacy, but no particular modules, scope, form or certificates.

Suggestion based on our role matrix. Article 4 prescribes no modules, scope or intervals. Not legal advice.

Preview

What the training matrix looks like

One row per person and measure. The sample rows of the fictitious Demo Organisation GmbH show what completed entries look like. In the Excel file they are highlighted – delete them before your first real entry.

“Training matrix” sheet · header frozen, filter onscroll sideways →
What the training matrix looks like
Person / IDDepartmentRoleAI systems usedModuleFormatDateDuration (min)Evidence / storageNext refresherStatus
EMP-0012ExampleManagementManagementMicrosoft 365 CopilotM05 AI Act for leadersLive online12/03/202660DMS/HR/AI-literacy/202612/03/2027Completed
EMP-0147ExampleSalesBusiness usersMicrosoft 365 Copilot, DeepLM04 Checking outputsE-learning05/05/202645LMS export 05/202605/05/2027Completed
EMP-0203ExampleITPower users / developersGitHub Copilot, customer service chatbotM06 Secure integrationWorkshop18/06/2026120Attendance list + slides18/12/2026Refresher due
EMP-0088ExampleProcurementProcurementAI features in the ERPM07 Buying AIClassroom10/09/202660Attendance confirmation (Word)10/09/2027Attended
EXT-004ExampleAgency (external)External / contractorsImage generatorM09 Briefing for external peoplePolicy read confirmation01/07/202630Confirmation by email01/07/2027Completed
EMP-0031ExampleLegal / data protectionDPO / complianceAI register, CopilotM08 AI governanceExternal course22/10/2026240––Planned

Two templates, free to use

Training matrix (Excel)

The overview for the whole organisation: who received which measure when, and when the next one is due.

  • Sheets: training matrix, modules, guide, lists
  • Dropdowns for role, module, format and status
  • 12 modules as a suggested catalogue per role
  • 300 pre-formatted rows, filter, frozen header
Training matrix (Excel)

SimpleAct_AI_Literacy_Training_Matrix_EN.xlsx

Attendance confirmation (Word)

The record per person or session – print and sign, or file digitally.

  • Participant, role, module, content, date, duration
  • Delivering party and signatures
  • Group attendance list for sessions
  • Note: Article 4 prescribes no form
Attendance confirmation (Word)

SimpleAct_AI_Literacy_Attendance_Confirmation_EN.docx

Upkeep

Refreshers and retention

The law sets neither an interval nor a retention period. The points below are our recommendation from practice – adapt them to your organisation.

How often to refresh?Recommendation

AI tools change faster than most other work equipment: new features, new models and new risks arrive month by month. A one-off training at roll-out therefore goes stale quickly. As a rule of thumb we recommend a short refresher every twelve months for all roles and every six months for power users and developers who work more deeply with the technology.

A refresher does not have to repeat the whole course. Often 20 to 30 minutes are enough: what has changed in the approved tools, what incidents or near misses occurred, what is new in the policy? More important than a fixed rhythm are the triggers that should prompt a measure outside the schedule.

How long to keep records?Recommendation

Because Article 4 does not prescribe documentation, the AI Act does not set a retention period for it either. It makes sense to keep the records at least as long as the person works with your AI systems, and afterwards for a period you define and justify yourself – for example so you can answer questions about an incident that happened some time ago.

The matrix and the confirmations contain personal data about employees. Decide who has access and include the training records in your deletion policy. For the overview, employee numbers are often enough instead of full names.

Deletion policy with template

Triggers for an extra measure

  • 01

    New AI system

    A tool is added to the AI register or existing software gains AI features.

  • 02

    New purpose

    A familiar tool is used for a new task, for example in HR or customer communication.

  • 03

    New role

    Someone changes department, takes on a leadership role or starts integrating AI themselves.

  • 04

    Incident

    An error, a data leak or a complaint reveals gaps in knowledge.

  • 05

    New rules

    The internal AI policy changes or new guidance is published.

  • 06

    New contractors

    A service provider starts an assignment in which they use your AI systems.

Delivery

Train in-house or externally?

Both work – Article 4 says nothing about it. In practice a mix works well: the basics from outside or from a learning platform, your own rules and tools from inside.

Train in-house or externally?
AspectIn-house (your own people)External (vendors, trainers, e-learning)
Link to your toolsHigh: real examples from your systems and processesOften generic, tailoring costs extra
Internal rulesPolicy and approvals are taught directlyNeeds to be added
Subject depthDepends on the know-how you haveSpecialist knowledge, e.g. on security or the legal framework
EffortTime of your own expertsBudget, but less internal effort
ScaleClassroom sessions scale poorlyE-learning reaches many people at once
RecordOwn attendance confirmation and matrix neededVendor’s certificate of attendance; a matrix entry still makes sense

A common mistake is to book a standard external course and consider the topic closed. A general introduction to AI is a good start, but it does not answer the questions that actually come up at work: may I put this customer data into our tool? Which assistant may I use for job applications? Whom do I report an error to? Only your organisation can answer those.

Conversely, in-house training does not have to be elaborate. A 30-minute briefing on the AI policy with three examples from your own organisation and a short read confirmation is a good building block for many business users. What matters is that you record who received it and when – with the attendance confirmation or an entry in the matrix.

SimpleAct Academy

When Excel gets too small

The templates work well to get started. When many people need training, the Academy in SimpleAct takes over the organisation – in the same system that holds your AI inventory.

  • Courses on the EU AI Act, GDPR, information security, AI risk management and whistleblower protection
  • Knowledge checks and final tests per course, progress visible per course
  • Downloadable certificates as training evidence per employee

Academy certificates are records of participation. Article 4 does not require a certificate.

See the Academy
app.simpleact.de

E-Learning Academy

Training content on the EU AI Act and GDPR

A

EU AI Act

Certified
8 lessons45 min
Progress100%
Completed

GDPR

10 lessons60 min
Progress40%
Continue learning

AI Risk Management

6 lessons35 min
Progress0%
Start course

Whistleblower Protection

5 lessons25 min
Progress0%
Start course
Certificate "EU AI Act" · Dr. Anna SchmidtDownload

FAQ

Frequently asked questions about AI literacy records

No. Article 4 of the AI Act does not require a certificate, and the European Commission makes clear in its AI literacy Q&A that none is needed. Certificates from training providers can be useful evidence, but they are not a legal requirement. Instead, the Commission recommends keeping an internal record of training and other measures.
Besides your own staff, Article 4 covers other persons dealing with the operation and use of your AI systems on your behalf. The Commission explicitly names contractors, service providers and even clients, as long as they work with your systems on your behalf. For external people a targeted briefing on your rules for the assignment, recorded with a confirmation, is often enough.
The law sets no interval. We recommend a short refresher every twelve months, and every six months for power users and developers, plus extra measures when a new AI system is introduced, a person’s purpose or role changes, or an incident reveals knowledge gaps. This is a recommendation, not a requirement.
The law prescribes no format, so a video can be one building block. Whether it is enough on its own depends on role and context: for a business user working with an approved writing assistant, a good video with a knowledge check and a read confirmation of the policy may fit. For developers or use in sensitive areas it will hardly be sufficient. Record who has watched it.
Article 99 of the AI Act contains no specific fine tier for Article 4. According to the Commission, sanctions follow national law and should be proportionate; supervision lies with the national market surveillance authorities from 2 August 2026. Regardless of fines, a lack of training can become relevant if an AI error causes damage or a customer asks for evidence in an audit.
Article 4 has applied since 2 February 2025. The Digital Omnibus (Regulation (EU) 2026/1744) amended the article; the new text has applied since its entry into force on 27 July 2026. According to the Commission, supervision by national market surveillance authorities starts on 2 August 2026.
Yes. Article 4 applies to all AI systems regardless of their risk class, and to both providers and deployers. Anyone using ChatGPT, Microsoft 365 Copilot or a translation tool at work is a deployer. Only purely personal, non-professional use is excluded. The scope of measures may, however, follow the risk: a writing assistant usually needs less than a system that ranks job applications.
The obligation lies with the organisation as provider or deployer, and ultimately with management. Many delegate implementation to learning and development, compliance, data protection or an AI governance team. What matters is that one function is named to maintain the plan, organise measures and keep the records – and that management itself is trained too.
The Omnibus replaced Article 4 in full. Instead of ensuring, to their best extent, a sufficient level of AI literacy, providers and deployers now take measures to support the development of AI literacy. It is made clear that no specific level of any individual has to be guaranteed. Also new: the Commission and the Member States support providers and deployers, in particular SMEs. An outcome duty became a best-efforts duty.
Article 4 itself does not prescribe documentation. The European Commission does, however, recommend keeping an internal record of training and other measures. In practice, records are the only way to show an authority, customers or the works council that you have taken measures. The Excel matrix and the attendance confirmation on this page are made for that.
Nothing is prescribed. A record becomes meaningful with: person or employee number, role, AI systems used, title and content of the measure, format, date, duration, delivering party and storage location. For refreshers, the date of the next planned measure also helps.
Yes. Both templates are free, need no sign-up and may be freely adapted within your organisation – columns, modules, dropdown values and texts. The templates are a working aid and do not replace legal advice.

More questions? We're happy to help. Send email · Get started

Sources and status

Last checked on · SimpleAct editorial team

This page and the templates are for orientation and do not replace legal advice. Intervals, modules, scope and retention notes are editorial recommendations. The wording in the Official Journal of the EU is authoritative.

Changes to this page

  • 4 October 2026 – First published: Article 4 after the Digital Omnibus, role matrix, training plan generator, Excel training matrix and Word attendance confirmation.

AI literacy and AI inventory in one system

SimpleAct connects your AI inventory with the Academy: you see who works with which system and train them with courses, tests and downloadable certificates.