Skip to content

AI literacy & AI-use policy

AI Act Article 4 (AI literacy) has applied since 2 February 2025. Unlike the high-risk product duties that phase in during 2027–2028, this one is in force now and binds deployers — any organisation that uses AI in a professional capacity — whether or not any of your products are high-risk. It asks you to take measures to ensure a sufficient level of AI literacy among the people who operate AI on your behalf, proportionate to their knowledge, their role, and the context they use AI in.

The Act prescribes no curriculum, exam, or certificate. You demonstrate literacy with measures — a policy, role-appropriate awareness, and records — not with a certificate. Resilic helps you organise and evidence those measures. It does not certify AI literacy, and the templates it provides are starting points, never legal advice.

Under Documents → AI-use policy, draft your organisation’s AI-use policy. It follows the same “AI drafts, you sign” flow as the other policies:

  • Generate a starter template — purpose, scope, acceptable use, human oversight, transparency, prohibited uses, roles & training, and review — grounded and clearly marked as a starting point.
  • Edit it to fit how your organisation actually works.
  • Sign it. Signing records who approved it and when, and stamps a version number.

Versioning matters for attestation. Each approval increments the version. When you approve a new version, staff are prompted to re-confirm they have read it — so a materially changed policy doesn’t sit unread.

Once the policy is approved, issue each employee a personal attestation link from the Employees screen (Attestation link — the link is copied to your clipboard and emailed to them, best-effort). The link is a single-use, expiring token — no account, no seat. The employee opens it, reads the policy, and clicks to confirm; Resilic records who attested which version, and when.

The coverage view on the Employees screen shows each person’s state against the current version:

  • Attested — confirmed the current version.
  • Re-attest — attested an older version; a newer one has since been approved, so they should confirm again.
  • Pending — a link is out, not yet confirmed.
  • Not attested — no link issued yet.

If links sit unconfirmed, subscribers to the “Policy attestations outstanding” notification get a weekly nudge listing who to chase. Approving a new policy version, as above, flips everyone to Re-attest — a materially changed policy is re-confirmed, not assumed.

Under Employees, keep a directory of the people your Article 4 measures apply to — the population that attests to the policy and completes training (both land in the next slices). It is data-minimal by design: name, work email, and an optional role, plus optional links to the AI systems in your inventory that a person works with. Add people one at a time or import a CSV (name, email, optional role), matched by email.

Roles have identity. Typing a role links it to the role registry (case-insensitively — “qa lead” and “QA Lead” are the same role, and the registry’s spelling wins). The Roles panel below the directory manages them centrally: renaming a role updates every employee that holds it, renaming onto an existing role merges the two after a confirmation, and unused roles can be deleted. Because training requirements target the role itself — not its spelling — a rename never changes who must train. A typo’d role would otherwise silently exclude someone from mandatory training; fix it once, centrally, and the training matrix and evidence pack follow immediately.

Employees are not app users — they hold no Resilic seat and log in to nothing here. Removing an employee deletes the row.

Under Training, record the training your Art. 4 measures call for — and, crucially, who it applies to. A requirement carries a title, an external content link (Resilic logs completion; it doesn’t host the content in Phase 1), and an audience:

  • All staff — everyone in the directory.
  • A role — everyone holding one of the roles you list (comma-separated, e.g. “QA lead, Line operator”; known roles appear as clickable chips). One requirement can target several roles at once. Targeting is by role identity, so renaming a role later never changes the audience.
  • AI operators — everyone linked to an AI system in your inventory. This is the vertical twist: the requirement is derived from who actually works with which AI, not an abstract matrix. Link people to AI systems on the Employees screen.

Set an optional repeat cadence (in months) and a completion goes overdue once it’s older than that. The matrix shows, per requirement, the applicable employees and their state — Done, Overdue, or Missing — and a done/applicable count. Record a completion with the date the person finished it.

For a recurring requirement backed by an internal curriculum, Resilic closes the loop for you: when someone’s completion lapses past the cadence, it automatically issues them a fresh portal link and emails it — they simply re-take the training. You don’t have to re-issue by hand, and it fires once per lapse (a reopened, not-yet-completed link isn’t re-issued again until it is completed and lapses anew).

Training content (author your own lessons)

Section titled “Training content (author your own lessons)”

A training requirement can point at an external link — but you can also author the content inside Resilic and keep everything in one place. Under Training content, build a curriculum: a titled set of ordered lessons, each written in Markdown. Nothing leaves Resilic for a third-party LMS.

  • Create a curriculum, give it a title and an optional description. It starts as a draft. Or Start from template to clone a built-in starter AI-literacy curriculum — a general-awareness starting point (what AI is, acceptable use, human oversight, limits, where to ask) that you edit and own. Like every template here it is not legal advice, and it lands as a draft for you to review.
  • Draft with AI — type a topic (e.g. “AI literacy for line operators”) and the integrated AI drafts a whole curriculum — several lessons and a short quiz — as an editable draft. This is the product’s “AI drafts, you sign” rule: the AI produces a starting point, you edit and publish it; it is never auto-published, never legal advice, and never a certification. (With no AI key configured it still works — a built-in fallback produces a sensible draft.)
  • Add lessons and write each in Markdown. Reorder them with the up/down controls; the order is the order staff will read them in. You can also draft a single lesson with AI from a short prompt (e.g. “human oversight for operators”) — it’s appended as an editable draft — or generate a quiz from your lessons with one click. As everywhere, the AI drafts and you edit and publish; nothing is auto-published.
  • Publish when it’s ready. A curriculum needs at least one lesson before it can be published — a draft can’t be assigned to staff. Publishing is reversible: unpublish returns it to draft for edits.

Once a curriculum is published, a training requirement can use it as its content instead of an external link: on the Training screen, pick it under Internal curriculum. Everything else about the requirement is unchanged — the same audiences (all staff, a role, or AI operators), recurrence, and completion matrix from Phase 1 apply. Only a published curriculum can be assigned; a draft is not offered.

For a requirement backed by an internal curriculum, each applicable employee in the matrix gets an Issue link action, and the requirement as a whole has Issue to all — one click issues a link to every applicable employee. Each is a personal magic link — no account, no seat — copied to your clipboard and emailed to the employee (best-effort), valid for 60 days. The employee opens it and reads the curriculum’s lessons right in the browser; nothing is delivered through a third-party LMS.

The matrix then shows each person’s portal state — whether a link has been issued, whether they’ve opened it, and their best quiz score so far — alongside the usual Done / Overdue / Missing.

Reading the material (and, where the curriculum has one, taking its quiz) evidences an Art. 4 training measure — it is not a certificate, and the portal never tells the employee they are “now AI-literate”.

Where the curriculum has a quiz, the employee answers it in the portal and it’s scored on the spot; the correct answers are never sent to their browser before they submit. Passing (a score at or above your pass mark) marks the training complete and flips the matrix cell to Done; a fail can be retried. For a curriculum with no quiz, the employee simply confirms they’ve read it. Either way the completion lands in the same matrix (Done / Overdue / Missing) as external-link training — and every quiz attempt is kept as evidence.

A curriculum is a readiness aid toward your Article 4 measures — content you own and control. It is not a certificate, and Resilic does not certify AI literacy. Delivering a published curriculum to staff and recording who has read it arrives in a later step; assigning one to a training requirement is covered alongside the training matrix.

A curriculum can carry one quiz — a short check of understanding. You set a pass mark (a percentage) and add questions: each has a prompt, 2–6 options, one marked correct, and optional feedback shown after answering. The score is simply correct ÷ total, and a pass is a score at or above your pass mark.

The pass mark is your own quality bar, not a regulatory line — the AI Act sets no exam and no pass threshold, and passing a quiz does not certify that someone is “AI-literate”. It is one more way to organise and evidence a measure. Staff taking the quiz and recording their results is a later phase; here you author the questions.

When someone asks what you do for AI literacy, you shouldn’t have to assemble the answer by hand. From the Training screen, Export Art. 4 evidence produces a single PDF — the “AI Act Article 4 — AI literacy measures” pack — pulling together, as of now:

  • the approved AI-use policy (its version, who signed it and when, and the full text);
  • attestation coverage — who has confirmed the current version, and who is outstanding;
  • the training matrix — each requirement, who it applies to, and their completion state.

It carries a plain disclaimer: it evidences your measures and is not a certification of AI literacy or of compliance. (The policy must be approved before you can export.)

  • A readiness aid to organise and evidence your Article 4 measures — not a certification of AI literacy, and not, by itself, proof of compliance.
  • Yours to own. The template is a starting point; you edit and approve the wording. It is not legal advice.
  • Self-hosted and data-minimal. Nothing about your policy or your people leaves Resilic to a third-party LMS.

Each curriculum has a fixed content language (English or German), chosen when it is created — AI lesson drafting and quiz generation follow it, so the material stays monolingual. The employee training portal renders its buttons and notices in the same language as the curriculum. Assign the right-language curriculum to your staff; the curricula list shows an EN/DE badge.

Under Comply → AI use cases you inventory what your organisation itself uses AI for — including shadow AI — with vendor, your role (deployer or provider), an internal status, and the people using it (linked from Employees). Each use case gets an honest risk-tier triage: the suggestion cites what it screened against (Art. 5 prohibited practices, Annex III high-risk areas, Art. 50 transparency duties) and the common honest answer is minimal risk — the Art. 4 literacy duty still applies. You confirm the tier; your confirmation is the recorded decision, and neither the suggestion nor the confirmation is a legal classification. Gap badges nudge you where something is unfinished (tier unconfirmed, transparency disclosure to document, no users linked), and the register rolls into the Article 4 evidence pack — the measures rest on this inventory.

For each use case you pick the applicable Art. 50 duty — people interacting with AI (50(1)), AI-generated content to be marked (50(2)/(4)), emotion recognition (50(3)) — or record the honest “no duty identified”, which documents the assessment itself. Resilic drafts the disclosure texts from templates (a UI notice, a document footer, a spec paragraph, EN or DE); you edit and approve them, and approved texts become versioned evidence in the Article 4 pack. Editing or regenerating always requires a fresh approval, and none of it is a claim of compliance.