> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 06 AIGO EU AI Act AI Literacy Mapping v0.1

# AIGO — EU AI Act AI Literacy Mapping

## 1. Document Purpose

This document provides the AIGO mapping for Article 4 of Regulation (EU) 2024/1689 concerning AI literacy, as amended by Regulation (EU) 2026/1744.

The mapping translates the AI literacy obligation into the AIGO governance framework covering:

* organizational AI literacy governance;
* applicability;
* provider and deployer responsibilities;
* workforce identification;
* people operating or using AI on behalf of the organization;
* role-based competence;
* technical knowledge;
* experience;
* education and training;
* AI-system context;
* affected persons and groups;
* learning activities;
* competence evidence;
* monitoring;
* management review;
* improvement; and
* assurance.

This document is an operational governance mapping. It is not legal advice, a legal opinion, or a declaration of compliance.

***

## 2. Mapping Information

| Field                      | Value                                          |
| -------------------------- | ---------------------------------------------- |
| Mapping                    | AIGO EU AI Act AI Literacy Mapping             |
| Version                    | 0.1                                            |
| Status                     | Draft                                          |
| Document Identifier        | `AIGO-MAP-EUAI-006`                            |
| Document Type              | EU AI Act Mapping                              |
| Mapping Package            | `AIGO-MAP-EUAI`                                |
| Primary Legal Instrument   | Regulation (EU) 2024/1689                      |
| Current Amendment Baseline | Regulation (EU) 2026/1744                      |
| Primary Provision          | Article 4                                      |
| Original Application Date  | 2 February 2025                                |
| Mapping Architecture       | `AIGO-MAP-EUAI-ARCH-001`                       |
| Registry                   | `00-AIGO-EU-AI-Act-Mapping-Registry-v0.1.json` |

Article 4 entered into application on **2 February 2025**. Regulation (EU) 2026/1744 subsequently amended Article 4 so that providers and deployers must take measures to support the development of AI literacy, while the amended provision expressly states that they are not required to guarantee a specific level of AI literacy for any individual. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/ai-talent-skills-and-literacy)) ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744))

***

## 3. Current Legal Baseline

The amended Article 4 requires providers and deployers of AI systems to take measures supporting the development of AI literacy among:

* their staff; and
* other persons dealing with the operation and use of AI systems on their behalf.

The measures must take into account:

* technical knowledge;
* experience;
* education;
* training;
* the context in which the AI systems are used; and
* the persons or groups of persons on whom the systems are to be used.

The amended provision expressly states that the obligation does not require providers or deployers to guarantee a specific level of AI literacy for any individual. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744))

This is an important change from the earlier formulation and should be reflected throughout AIGO.

***

## 4. AI Literacy Governance Principle

AIGO should treat AI literacy as a **risk- and context-based governance capability**, rather than as a single mandatory training course or universal competency score.

The preferred governance model is:

```text theme={null}
AI System / Use Case
        ↓
People Involved
        ↓
Role / Context Analysis
        ↓
Knowledge / Experience / Education / Training Assessment
        ↓
AI Literacy Needs
        ↓
Learning / Awareness Measures
        ↓
Evidence
        ↓
Monitoring
        ↓
Management Review
        ↓
Improvement
```

***

## 5. Core Legal-to-AIGO Mapping

| Article 4 Element                              | AIGO Implementation          |
| ---------------------------------------------- | ---------------------------- |
| Provider / deployer obligation                 | Governance                   |
| Staff                                          | Roles / AI System Governance |
| Other persons acting on behalf of organization | Third-Party Governance       |
| Technical knowledge                            | Competence Assessment        |
| Experience                                     | Role / Competence Profile    |
| Education                                      | Learning Plan                |
| Training                                       | Training / Development       |
| AI-system context                              | AI System Profile            |
| Persons / groups affected                      | Risk / Impact Assessment     |
| Measures to support literacy                   | AI Literacy Programme        |
| No mandatory individual level                  | Risk-based competence model  |
| Evidence of measures                           | Evidence Schema              |
| Review                                         | Management Review            |
| Improvement                                    | Improvement Schema           |

***

## 6. AI Literacy Control

**Control Name:** AI Literacy and Competence Governance

**Control Objective:**

Ensure that the organization takes proportionate and context-appropriate measures to support the development of AI literacy among people who operate or use AI systems on the organization's behalf.

**Control Owner:**

AI Governance Owner / Human Resources or Competence Owner, with AI System Owners participating as appropriate.

**Frequency:**

* at onboarding;
* before relevant AI-system use;
* when systems materially change;
* when user roles change;
* when risk or context changes;
* periodically according to organizational policy.

**Required Evidence:**

* AI literacy needs assessment;
* learning plan;
* training or awareness records;
* role profiles;
* completion evidence;
* competence-development evidence;
* management review.

***

## 7. Applicability

The organization should determine who falls within its AI-literacy governance scope.

Potential populations include:

```text theme={null}
AI System Developers
AI System Operators
AI System Administrators
AI System Users
AI Decision Makers
AI System Owners
Risk Owners
Control Owners
Managers
Executives
Technical Support
Security Personnel
Data Personnel
Procurement Personnel
Legal / Compliance Personnel
Assurance Personnel
Third-Party Operators
Contractors
Other Persons Acting on Behalf of the Organization
```

The organization should not automatically apply identical training requirements to all individuals.

***

## 8. Staff and Other Persons Acting on Behalf of the Organization

The amended Article 4 expressly covers staff and other persons dealing with AI operation and use on behalf of providers and deployers.

AIGO should therefore consider:

* employees;
* contractors;
* consultants;
* outsourced operators;
* temporary personnel;
* relevant service providers;
* other individuals who operate or use AI on the organization's behalf.

Third-party governance should preserve the distinction between:

```text theme={null}
Direct Employee
```

and:

```text theme={null}
External Person Acting on Behalf of Organization
```

***

## 9. Role-Based AI Literacy

AI literacy should be related to the person's role.

Example:

| Role                | Typical AI Literacy Focus                              |
| ------------------- | ------------------------------------------------------ |
| Executive           | Governance, risk, accountability, decision rights      |
| AI System Owner     | Lifecycle, purpose, limitations, monitoring            |
| AI Operator         | Safe operation, limitations, escalation                |
| Developer           | Model behavior, testing, security, data                |
| Risk Owner          | AI-specific risk identification and treatment          |
| Control Owner       | Control operation and evidence                         |
| Auditor / Assurer   | AI governance, evidence, assurance                     |
| Procurement         | Supplier, contractual, classification, risk            |
| HR / People Manager | Workplace use, role impacts, training                  |
| General User        | Appropriate use, limitations, transparency, escalation |

These are AIGO implementation examples, not statutory competency levels.

***

## 10. Context-Based AI Literacy

The amended Article 4 requires consideration of the context in which AI systems are used.

AIGO should therefore consider:

* intended purpose;
* deployment environment;
* system complexity;
* autonomy;
* decision impact;
* affected-person risk;
* operational criticality;
* security sensitivity;
* privacy sensitivity;
* safety impact;
* regulatory significance.

A person operating a high-risk AI system in a safety-sensitive context may require substantially different learning measures from a person using a low-impact productivity tool.

***

## 11. Affected Persons and Groups

Article 4 requires consideration of the persons or groups on whom AI systems are to be used.

AIGO should incorporate this into AI literacy planning where relevant.

The organization should consider whether users need awareness of:

* affected-person rights;
* bias;
* fairness;
* accessibility;
* human oversight;
* transparency;
* escalation;
* inappropriate use;
* consequences of AI-assisted decisions.

This connects Article 4 to the AIGO Risk and Assessment frameworks.

***

## 12. AI Literacy Versus Competence

AIGO should distinguish:

### AI Literacy

Awareness and understanding needed to engage responsibly with AI systems.

### Professional Competence

The broader knowledge, skills, experience, qualifications, and capabilities required to perform a role.

### Technical Expertise

Specialist capability needed to design, develop, operate, assess, secure, or assure AI systems.

The AI Act's Article 4 obligation does not require AIGO to treat all personnel as AI specialists.

***

## 13. No Universal Minimum Level

The amended Article 4 expressly states that providers and deployers do not have to guarantee a specific level of AI literacy for any individual. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744))

Therefore, AIGO should avoid defining a blanket rule such as:

```text theme={null}
Every employee must achieve AI Literacy Level 3.
```

unless that requirement is adopted voluntarily by the organization for its own governance purposes.

Instead, AIGO should use a:

```text theme={null}
Role
+
System
+
Context
+
Risk
+
Affected Persons
→
Literacy Measures
```

model.

***

## 14. AI Literacy Needs Assessment

AIGO should maintain an AI Literacy Needs Assessment for relevant roles and contexts.

Potential fields:

| Field               | Description                     |
| ------------------- | ------------------------------- |
| Person / Role       | Identifies population           |
| AI System           | Identifies system               |
| Use Context         | Establishes operational context |
| AI Activities       | Identifies tasks                |
| Technical Knowledge | Current state                   |
| Experience          | Relevant experience             |
| Education           | Existing education              |
| Training            | Existing training               |
| Risk                | Governance significance         |
| Affected Persons    | Impact context                  |
| Literacy Needs      | Required measures               |
| Learning Method     | Training / awareness / guidance |
| Owner               | Responsible party               |
| Review Date         | Reassessment                    |

***

## 15. Training Is Not the Only Measure

The legal obligation requires measures to support AI literacy, not necessarily a formal classroom training programme.

AIGO should therefore recognize:

* training;
* workshops;
* practical exercises;
* user guidance;
* role-specific instructions;
* simulations;
* awareness sessions;
* supervised use;
* mentoring;
* technical documentation;
* knowledge bases;
* AI usage policies;
* briefings;
* communities of practice.

The selected measure should be proportionate to the context.

***

## 16. Learning Measures

An AIGO AI literacy programme may include:

```text theme={null}
Awareness
Training
Practical Exercises
Role-Specific Guidance
Technical Training
Human Oversight Training
Risk Training
Security Training
Privacy Training
Fairness Training
Incident Training
Change Awareness
```

The organization should document why particular measures were selected.

***

## 17. AI Literacy Learning Objectives

Learning objectives should be related to the AI systems and roles involved.

Potential objectives include:

* understanding system purpose;
* understanding limitations;
* identifying unreliable outputs;
* understanding appropriate use;
* recognizing prohibited or restricted use;
* understanding human oversight;
* identifying escalation conditions;
* understanding security requirements;
* understanding privacy considerations;
* recognizing bias;
* identifying AI-generated content;
* reporting incidents.

The exact objectives should be contextual.

***

## 18. AI System-Specific Literacy

Each material AI System Profile should identify relevant literacy considerations.

For example:

```text theme={null}
AI System:
High-risk decision-support system

Relevant AI Literacy:
- system purpose;
- limitations;
- uncertainty;
- prohibited use;
- human review;
- override;
- escalation;
- affected-person impact.
```

This creates traceability from system governance to people governance.

***

## 19. High-Risk AI Literacy

High-risk AI systems may warrant enhanced literacy measures because the operating context, impact, and legal obligations may be more complex.

AIGO should consider:

* stronger role-specific training;
* system-specific instruction;
* human oversight competence;
* incident response;
* risk awareness;
* documentation awareness;
* transparency;
* affected-person considerations.

This should be determined by organizational risk and context, not by inventing a statutory universal training level.

***

## 20. GPAI Literacy

Organizations using or providing GPAI systems should consider literacy needs relating to:

* prompt and instruction risks;
* hallucination and reliability limitations;
* model limitations;
* data handling;
* confidentiality;
* copyright;
* content generation;
* transparency;
* security;
* misuse;
* downstream risk.

Where GPAI is integrated into higher-risk systems, literacy should align with the higher-risk operating context.

***

## 21. Prohibited-Practice Awareness

AI literacy programmes should include awareness appropriate to role concerning prohibited AI practices.

Potential topics:

* manipulation;
* exploitation of vulnerabilities;
* social scoring;
* prohibited biometric practices;
* prohibited emotion recognition;
* criminal-offence prediction;
* unlawful facial-recognition database practices;
* prohibited remote biometric identification;
* the amended prohibitions concerning certain non-consensual sexual/intimate content and child sexual abuse material.

The exact depth should depend on role and exposure.

The dedicated Article 5 mapping remains authoritative for prohibited-practice requirements.

***

## 22. Transparency Literacy

Relevant personnel should understand:

* when users must be informed;
* AI-generated content marking;
* deepfake disclosure;
* public-interest AI-generated text;
* biometric categorisation notices;
* emotion-recognition transparency;
* applicable exceptions.

The dedicated Article 50 mapping remains authoritative for detailed transparency requirements.

***

## 23. Human Oversight Literacy

Personnel responsible for human oversight should understand:

* system purpose;
* limitations;
* confidence or uncertainty;
* intervention;
* override;
* escalation;
* abnormal conditions;
* stop authority;
* incident reporting.

Human oversight literacy should be linked to the relevant AI System Profile and Control records.

***

## 24. Risk Literacy

Relevant personnel should understand:

* AI risk concepts;
* intended and foreseeable misuse;
* risk indicators;
* control responsibilities;
* residual risk;
* escalation;
* risk acceptance limitations.

Risk owners require deeper understanding than ordinary users.

***

## 25. Security Literacy

AI users and operators may need awareness of:

* prompt injection;
* data leakage;
* unsafe outputs;
* credential protection;
* access control;
* model manipulation;
* malicious content;
* security incidents.

Security literacy should align with the organization's cybersecurity framework.

***

## 26. Privacy and Data Literacy

Relevant personnel should understand:

* personal data handling;
* confidential information;
* data minimization;
* purpose limitation;
* retention;
* authorized use;
* data leakage;
* privacy escalation.

Detailed privacy obligations remain subject to applicable privacy law and organizational requirements.

***

## 27. Fairness and Bias Literacy

Relevant personnel should understand:

* potential bias;
* affected groups;
* limitations of automated outputs;
* inappropriate reliance;
* escalation;
* human review.

The depth should depend on system use and impact.

***

## 28. AI Literacy for Managers

Managers responsible for teams using AI should understand:

* approved uses;
* prohibited or restricted uses;
* escalation;
* accountability;
* human oversight;
* training needs;
* incident reporting;
* monitoring;
* changes in system capabilities.

Managers should not assume that completion of general AI awareness training is sufficient for governance responsibility.

***

## 29. AI Literacy for Developers

Developers of AI systems may require deeper technical measures covering:

* system limitations;
* data;
* testing;
* security;
* robustness;
* safety;
* bias;
* transparency;
* monitoring;
* incident handling;
* regulatory requirements.

Development competence should be managed separately from general literacy.

***

## 30. AI Literacy for AI System Owners

AI System Owners should understand:

* intended purpose;
* classification;
* risk;
* controls;
* evidence;
* approvals;
* monitoring;
* incidents;
* changes;
* assurance;
* retirement.

The AI System Owner is a critical role in the AIGO lifecycle.

***

## 31. AI Literacy for Risk Owners

Risk Owners should understand:

* AI-specific risks;
* model limitations;
* uncertainty;
* risk treatment;
* controls;
* residual risk;
* monitoring;
* escalation;
* regulatory risk.

***

## 32. AI Literacy for Control Owners

Control Owners should understand:

* control objective;
* operating requirements;
* evidence;
* monitoring;
* exception handling;
* testing;
* assurance;
* change impacts.

***

## 33. AI Literacy for Assurance Personnel

Assurance personnel should understand:

* AI governance;
* system architecture at the relevant level;
* risk;
* controls;
* evidence;
* AI-specific limitations;
* regulatory mappings;
* testing methodologies.

The competence requirements should be matched to the assurance scope.

***

## 34. AI Literacy for Procurement

Procurement personnel should understand:

* AI system identification;
* provider/deployer roles;
* risk classification;
* prohibited practices;
* high-risk systems;
* GPAI;
* transparency;
* contracts;
* documentation;
* supplier changes;
* evidence.

Procurement is an important preventative governance gate.

***

## 35. AI Literacy for Legal and Compliance Personnel

Legal/compliance personnel should understand:

* AI Act applicability;
* classification;
* prohibited practices;
* high-risk requirements;
* GPAI;
* transparency;
* regulatory changes;
* evidence;
* escalation.

Specialist legal analysis remains distinct from general AI literacy.

***

## 36. AI Literacy for Third Parties

Where contractors or suppliers operate AI on behalf of the organization, AIGO should determine appropriate literacy measures.

Potential mechanisms include:

* contractual requirements;
* onboarding;
* training;
* attestations;
* provider documentation;
* role-specific instructions;
* monitoring.

AIGO should record the third-party relationship.

***

## 37. AI Literacy and Human Oversight

Where human oversight is required, the organization should ensure that the people assigned to oversight receive role-appropriate AI literacy measures.

The evidence chain should be:

```text theme={null}
AI System
   ↓
Human Oversight Requirement
   ↓
Assigned Person / Role
   ↓
AI Literacy Need
   ↓
Learning Measure
   ↓
Evidence
   ↓
Oversight Operation
```

***

## 38. AI Literacy Evidence

Potential evidence includes:

* training records;
* attendance;
* completion records;
* learning modules;
* workshop records;
* competency assessments;
* role-specific guidance;
* user acknowledgments;
* simulations;
* practical exercises;
* learning materials;
* knowledge assessments.

Evidence should demonstrate the measures taken rather than merely stating that "AI training exists."

***

## 39. Evidence of Measures Versus Evidence of Competence

Because the amended Article 4 does not require a specific individual literacy level, AIGO should distinguish:

### Evidence of Measures

Evidence that the organization took reasonable and contextual measures to support AI literacy.

### Evidence of Competence

Evidence showing that a person has learned or demonstrated particular knowledge or skills.

Both may be useful, but they are not interchangeable.

***

## 40. AI Literacy Monitoring

Monitoring may include:

* participation;
* completion;
* knowledge checks;
* incident patterns;
* user feedback;
* recurring misuse;
* recurring misunderstandings;
* system changes;
* role changes;
* new regulatory requirements.

Monitoring should focus on whether the organization's measures remain appropriate.

***

## 41. AI Literacy Incident Relationship

AI incidents can identify literacy weaknesses.

Recommended chain:

```text theme={null}
Incident
   ↓
Root Cause
   ↓
Literacy / Competence Gap
   ↓
Improvement
   ↓
Learning Measure
   ↓
Verification
```

An incident should not automatically be attributed to insufficient literacy without investigation.

***

## 42. AI Literacy Change Relationship

Material AI-system changes should trigger review of literacy needs.

Examples include:

* new model;
* new capability;
* new interface;
* new autonomous functionality;
* new affected group;
* new risk;
* new regulation.

Recommended chain:

```text theme={null}
AI Change
   ↓
Impact Assessment
   ↓
Literacy Impact
   ↓
Learning Update
   ↓
Evidence
```

***

## 43. AI Literacy Risk Relationship

AI literacy may itself be managed as a governance risk.

Potential risk:

`AI_LITERACY_GAP`

Risk factors may include:

* inadequate role preparation;
* rapid system changes;
* high system complexity;
* high-impact decisions;
* inexperienced users;
* poor escalation awareness.

Risk treatment may include targeted learning measures.

***

## 44. AI Literacy Control Coverage

The Control Coverage Validator may eventually evaluate:

* AI literacy governance control;
* role-specific measures;
* system-specific measures;
* third-party measures;
* high-risk measures;
* oversight training;
* recurring refresh activities.

Coverage should assess whether applicable measures are represented.

***

## 45. AI Literacy Evidence Coverage

The Evidence Coverage Validator may evaluate:

* learning-plan evidence;
* participation;
* training material;
* review;
* system-specific guidance;
* competence evidence where used.

Missing evidence should not automatically mean no training occurred; it means the governance record cannot demonstrate the required measure.

***

## 46. AI Literacy Traceability

The recommended AIGO traceability chain is:

```text theme={null}
EU AI Act Article 4
        ↓
Provider / Deployer
        ↓
AI System
        ↓
Role / Person
        ↓
Context
        ↓
AI Literacy Need
        ↓
Measure
        ↓
Evidence
        ↓
Review
        ↓
Improvement
```

This is the preferred operational model.

***

## 47. AI Literacy Programme

An organization may establish an AIGO AI Literacy Programme.

The programme should define:

* scope;
* target populations;
* needs assessment;
* learning objectives;
* methods;
* responsibilities;
* evidence;
* monitoring;
* review;
* improvement.

The programme should remain risk- and context-based.

***

## 48. AI Literacy Programme Governance

The programme should have:

* programme owner;
* AI Governance Owner;
* HR / Learning Owner;
* AI System Owners;
* Risk Owners;
* Control Owners;
* assurance support where applicable.

Roles should be documented in the Governance Schema.

***

## 49. AI Literacy Planning

Planning should consider:

* AI portfolio;
* organizational roles;
* system risk;
* affected-person context;
* regulatory requirements;
* current capabilities;
* upcoming deployments;
* changes;
* lessons learned.

***

## 50. AI Literacy Needs Matrix

A future operational matrix may look like:

| Role / Population | AI System | Context | Risk | Literacy Need | Measure | Evidence | Review |
| ----------------- | --------- | ------- | ---- | ------------- | ------- | -------- | ------ |
|                   |           |         |      |               |         |          |        |

This should be treated as an operational management artifact.

***

## 51. Learning Measure Selection

Selection should consider:

* complexity;
* risk;
* frequency of use;
* autonomy;
* user role;
* affected-person impact;
* existing knowledge;
* system change;
* resource constraints.

A generic course should not automatically be assigned to everyone.

***

## 52. Refresher Measures

Refresher activity may be triggered by:

* material AI-system changes;
* incident trends;
* new risks;
* regulatory updates;
* role change;
* extended period without use;
* audit findings.

Refresher frequency should be controlled by organizational policy rather than presented as an AI Act universal requirement.

***

## 53. AI Literacy for New AI Systems

Before deployment, organizations should determine:

* who will use the system;
* what they need to understand;
* what risks they need to recognize;
* what escalation routes exist;
* what learning measures are necessary.

The outcome should be linked to the AI System Approval.

***

## 54. AI Literacy Deployment Gate

The deployment process may include:

```text theme={null}
AI System Approval
      ↓
Literacy Needs Identified
      ↓
Required Measures Completed / Scheduled
      ↓
Evidence
      ↓
Deployment
```

Where literacy measures are materially necessary to safe or lawful operation, deployment governance may require completion before activation.

***

## 55. AI Literacy and Article 5

Personnel should understand where relevant that certain AI uses are prohibited.

A literacy programme should support:

* identification;
* escalation;
* avoidance;
* incident reporting.

The detailed Article 5 requirements remain in the prohibited-practices mapping.

***

## 56. AI Literacy and High-Risk AI

Personnel associated with high-risk AI systems should receive context-appropriate measures relating to:

* human oversight;
* system limitations;
* risk;
* transparency;
* incident handling;
* security;
* affected persons.

The High-Risk mapping remains authoritative for detailed statutory obligations.

***

## 57. AI Literacy and Transparency

Relevant users should understand:

* disclosure;
* content marking;
* deepfake disclosure;
* public-interest AI content;
* biometric/emotion-recognition notifications.

The Transparency mapping remains authoritative for Article 50 requirements.

***

## 58. AI Literacy and GPAI

Relevant personnel should understand:

* provider status;
* model limitations;
* downstream risks;
* copyright;
* confidentiality;
* generated content;
* security;
* transparency;
* model changes.

The GPAI mapping remains authoritative for GPAI-specific obligations.

***

## 59. AI Literacy and Third-Party Governance

Third-party AI operators may require measures appropriate to their role.

The organization should ensure that contractual arrangements address applicable AI literacy responsibilities where relevant.

***

## 60. AI Literacy and Management Review

Management review should evaluate:

* AI literacy programme scope;
* system-specific needs;
* participation;
* recurring gaps;
* incidents linked to user understanding;
* changes;
* upcoming deployments;
* regulatory developments;
* resource requirements.

***

## 61. AI Literacy and Assurance

Assurance may examine:

* whether the organization has identified relevant populations;
* whether contextual measures exist;
* whether evidence exists;
* whether high-risk roles have appropriate support;
* whether third-party operators are covered;
* whether learning measures are refreshed after material changes.

Assurance should not use an invented universal "literacy score" as a substitute for the legal standard.

***

## 62. AI Literacy and Continual Improvement

Improvement sources may include:

* incidents;
* audits;
* assurance;
* management review;
* user feedback;
* system changes;
* new risks;
* regulatory changes;
* technology developments.

Improvement actions should be recorded in the AIGO Improvement Schema.

***

## 63. Commission Support Mechanism

Article 4(2), as amended, requires the Commission to support provider and deployer efforts, particularly for SMEs, including by publishing practical examples of how to comply through the Single Information Platform. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744))

The Commission maintains a living repository of AI literacy practices. It currently contains more than 40 initiatives and is intended to support learning and exchange. Replicating a practice from the repository does not automatically create a presumption of compliance. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/repository-ai-literacy-practices))

AIGO should therefore treat the repository as implementation reference material, not legal certification.

***

## 64. AI Board Recommendations

Article 4(3), as amended, provides for the AI Board to adopt recommendations supporting promotion of AI literacy, taking existing European competence frameworks into account and including common objectives. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744))

AIGO should monitor these recommendations and update the mapping when material recommendations are issued.

***

## 65. Enforcement

The Commission states that supervision and enforcement of Article 4 are within the remit of national market-surveillance authorities, with enforcement beginning from **2 August 2026** according to current Commission information. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/ai-talent-skills-and-literacy))

AIGO should therefore treat Article 4 as an active governance requirement.

***

## 66. Enforcement Evidence

Organizations should be able to demonstrate:

* AI-system scope;
* relevant people;
* literacy needs;
* measures taken;
* contextual reasoning;
* records;
* review;
* improvement.

AIGO should not assume that a training attendance list alone demonstrates an adequate AI-literacy governance process.

***

## 67. Proportionality

AI literacy measures should be proportionate to:

* role;
* system;
* risk;
* context;
* complexity;
* affected persons;
* potential consequences.

This approach aligns the amended Article 4's contextual requirements with the AIGO risk-based governance model.

***

## 68. No Automatic Certification

Completion of an AIGO AI literacy programme should not be described as:

* EU AI Act certification;
* legal certification;
* proof of regulatory compliance.

It is evidence of an organizational governance measure.

***

## 69. AI Literacy Metrics

Organizations may track:

| Metric                           | Purpose                |
| -------------------------------- | ---------------------- |
| Populations Assessed             | Scope                  |
| Systems With Literacy Assessment | System coverage        |
| Learning Measures Implemented    | Measure coverage       |
| Participation                    | Activity               |
| Completion                       | Delivery               |
| Role-Specific Measures           | Contextuality          |
| High-Risk Roles Covered          | Risk coverage          |
| Incident-Related Improvements    | Effectiveness learning |
| Review Completion                | Governance             |
| Outstanding Gaps                 | Remediation            |

Metrics should support management rather than create artificial legal thresholds.

***

## 70. AI Literacy Coverage

A future coverage calculation may distinguish:

```text theme={null}
Population Identified
        ↓
Literacy Need Assessed
        ↓
Measure Defined
        ↓
Measure Implemented
        ↓
Evidence Available
        ↓
Review Completed
```

This should be treated as an AIGO governance metric rather than an EU AI Act legal score.

***

## 71. AI Literacy Findings

Potential findings include:

```text theme={null}
AI_LITERACY_SCOPE_UNRESOLVED
AI_LITERACY_ROLE_UNASSESSED
AI_LITERACY_NEED_UNASSESSED
AI_LITERACY_MEASURE_MISSING
AI_LITERACY_EVIDENCE_MISSING
AI_LITERACY_SYSTEM_CHANGE_NOT_REVIEWED
HIGH_RISK_ROLE_LITERACY_GAP
THIRD_PARTY_AI_LITERACY_GAP
AI_LITERACY_REVIEW_OVERDUE
AI_LITERACY_REGULATORY_UPDATE_PENDING
```

These are AIGO governance findings.

***

## 72. Critical Literacy Findings

Potential high-severity findings may arise where:

* personnel responsible for critical human oversight have no relevant preparation;
* high-risk system operators lack required contextual guidance;
* significant AI changes occur without literacy-needs reassessment;
* critical incident investigation identifies a material knowledge gap;
* third-party personnel operate high-impact AI without appropriate measures.

Severity should be based on actual organizational risk.

***

## 73. AI Literacy Control Matrix

| Area            | AIGO Control                 | Primary Record     |
| --------------- | ---------------------------- | ------------------ |
| Scope           | AI Literacy Scope Control    | Governance         |
| Needs           | AI Literacy Needs Assessment | Assessment         |
| Role            | Role-Based Literacy Control  | Governance         |
| Training        | Learning Measures Control    | Evidence           |
| High-Risk       | High-Risk Literacy Control   | Assessment         |
| Human Oversight | Oversight Competence Control | Control / Evidence |
| Third Party     | Third-Party Literacy Control | Governance         |
| Change          | Literacy Impact Review       | Change             |
| Monitoring      | Literacy Monitoring          | Monitoring         |
| Improvement     | Literacy Improvement         | Improvement        |
| Assurance       | Literacy Assurance           | Assurance          |

***

## 74. AI Literacy Lifecycle Mapping

| AIGO Lifecycle Stage | AI Literacy Activity                    |
| -------------------- | --------------------------------------- |
| Planning             | Identify literacy implications          |
| Design               | Define user and operator needs          |
| Development          | Define technical competence             |
| Data Preparation     | Define relevant data literacy           |
| Testing              | Prepare testers                         |
| Approval             | Confirm required measures               |
| Deployment           | Provide role-specific guidance          |
| Operation            | Monitor needs                           |
| Monitoring           | Identify emerging gaps                  |
| Change               | Reassess literacy requirements          |
| Assurance            | Review literacy governance              |
| Retirement           | Preserve relevant knowledge and lessons |

***

## 75. AI Literacy Traceability

The minimum chain should be:

```text theme={null}
EU AI Act Article 4
        ↓
Provider / Deployer
        ↓
AI System
        ↓
Person / Role
        ↓
Context
        ↓
AI Literacy Need
        ↓
Measure
        ↓
Evidence
        ↓
Review
        ↓
Improvement
```

This traceability should be retained for material governance decisions.

***

## 76. Relationship to AIGO Governance

The Governance Schema should provide:

* responsible owner;
* roles;
* decision authority;
* organizational scope;
* competency responsibility;
* reporting.

AI literacy should therefore be part of governance rather than isolated within an HR training system.

***

## 77. Relationship to AIGO AI System Schema

The AI System record should provide the context required for literacy planning, including where applicable:

* purpose;
* classification;
* risk;
* deployment;
* users;
* affected persons;
* lifecycle stage.

This allows literacy needs to be derived from the system context.

***

## 78. Relationship to AIGO Risk Schema

AI literacy gaps may be represented as:

* risk cause;
* control weakness;
* operational risk;
* human oversight risk;
* compliance risk.

The Risk Assessment should identify when a literacy gap materially affects AI governance.

***

## 79. Relationship to AIGO Control Schema

The Control Schema should represent:

* AI Literacy and Competence Governance;
* role-specific learning controls;
* high-risk human oversight competence;
* third-party AI literacy measures.

Controls should identify:

* owner;
* frequency;
* evidence;
* monitoring;
* exceptions.

***

## 80. Relationship to AIGO Assessment Schema

The Assessment Schema may support:

* AI literacy needs assessment;
* role assessment;
* human oversight competence assessment;
* system-specific literacy assessment;
* change-impact assessment.

***

## 81. Relationship to AIGO Evidence Schema

Evidence may include:

* learning records;
* guidance;
* assessments;
* exercises;
* role assignments;
* review records;
* competence evidence.

Evidence should preserve enough metadata to demonstrate the measure without exposing unnecessary personal information.

***

## 82. Relationship to AIGO Monitoring Schema

Monitoring may track:

* learning measures;
* system changes;
* incidents;
* user behavior;
* recurring errors;
* knowledge gaps;
* management feedback.

The monitoring system should not collect more employee information than necessary.

***

## 83. Relationship to AIGO Assurance Schema

Assurance should evaluate whether the organization has established a reasonable, context-aware AI literacy governance process.

Assurance should focus on:

* scope;
* reasoning;
* measures;
* evidence;
* review;
* improvement.

It should not impose an invented universal literacy threshold.

***

## 84. Relationship to AIGO Management Review

Management review should consider:

* AI literacy coverage;
* significant gaps;
* high-risk roles;
* major incidents;
* new systems;
* regulatory updates;
* programme effectiveness;
* resources.

***

## 85. Relationship to AIGO Improvement

Improvement actions should be created when:

* literacy measures are inadequate;
* system changes create new needs;
* incidents expose gaps;
* assurance identifies weaknesses;
* management identifies strategic requirements.

***

## 86. Relationship to AIGO Change Management

Material AI-system changes should include an AI literacy impact assessment.

Example:

```text theme={null}
Change
  ↓
AI System Impact
  ↓
User / Operator Impact
  ↓
Literacy Need
  ↓
Learning Measure
  ↓
Evidence
  ↓
Change Approval
```

***

## 87. Third-Party Governance

Where third parties operate AI systems on behalf of the organization, AIGO should determine:

* literacy responsibilities;
* contractual obligations;
* required evidence;
* training access;
* system-specific guidance;
* escalation.

The AI Act's provider/deployer obligations should remain distinguishable from contractual implementation responsibilities.

***

## 88. Privacy and Employee Information

AI literacy programmes may process employee information.

AIGO should apply data-minimization principles.

The organization should avoid unnecessarily recording:

* sensitive personal information;
* detailed performance information;
* unrelated employee data.

Only information necessary to demonstrate the governance measure should normally be retained.

***

## 89. AI Literacy and Employment

Where AI systems affect workers, literacy governance should consider:

* role impact;
* transparency;
* human oversight;
* workplace rights;
* changes in work;
* required support.

Article 4 literacy should not be used to shift accountability for system design or employer responsibilities onto employees.

***

## 90. AI Literacy and Accessibility

Learning measures should be accessible to the intended participants.

The organization should consider:

* disability;
* language;
* technical access;
* learning format;
* role schedules;
* geographic distribution.

This supports the contextual model required by Article 4.

***

## 91. AI Literacy and Organizational Culture

AI literacy may include cultural measures such as:

* responsible-use expectations;
* escalation culture;
* challenge culture;
* transparency;
* safe reporting;
* leadership communication.

These are AIGO governance practices rather than individually mandated legal measures.

***

## 92. AI Literacy and AI Policy

The organization should provide a clear relationship between:

```text theme={null}
AI Policy
    ↓
AI Literacy Measures
    ↓
AI System Guidance
    ↓
Role-Specific Practice
    ↓
Evidence
```

Employees should be able to understand the organization's permitted and restricted AI use.

***

## 93. AI Literacy and Responsible Use

AI literacy should support appropriate use, including:

* verification of outputs;
* avoidance of prohibited use;
* protection of confidential data;
* recognition of limitations;
* human oversight;
* reporting.

***

## 94. AI Literacy and Generative AI

For generative AI, relevant literacy may include:

* hallucination;
* prompt sensitivity;
* data leakage;
* copyright;
* generated content;
* bias;
* deepfakes;
* prompt injection;
* confidentiality;
* verification.

The exact requirements should be matched to context.

***

## 95. AI Literacy and Autonomous AI

Where AI systems act with significant autonomy, users and operators may need stronger understanding of:

* system authority;
* boundaries;
* escalation;
* intervention;
* monitoring;
* failure states;
* shutdown.

***

## 96. AI Literacy and Human Oversight

AI literacy should not be used as a substitute for adequate system design.

A well-trained person cannot compensate indefinitely for:

* unsafe system design;
* inadequate controls;
* inadequate testing;
* missing monitoring;
* inappropriate deployment.

AI literacy is one layer of governance.

***

## 97. AI Literacy and Management Accountability

Management remains responsible for establishing appropriate governance measures.

The organization should not claim:

> "The employee was trained, therefore the system is governed."

AI literacy must be integrated with:

* controls;
* risk management;
* human oversight;
* monitoring;
* assurance.

***

## 98. Commission AI Literacy Repository

The Commission's AI literacy repository contains examples of organizational practices and is intended for learning and exchange. It does not create a presumption of compliance merely because an organization replicates an example. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/repository-ai-literacy-practices))

AIGO should record external practices as reference material, not as normative requirements.

***

## 99. AI Board Recommendations

AIGO should monitor future AI Board recommendations under Article 4(3), including common objectives and their relationship to European competence frameworks. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32026R1744))

When material recommendations are published, this document should be reviewed.

***

## 100. Enforcement Baseline

The Commission currently states that Article 4 is supervised and enforced by national market-surveillance authorities and that enforcement begins from **2 August 2026**. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/ai-talent-skills-and-literacy))

The mapping should therefore treat the obligation as active.

***

## 101. AI Literacy Metrics

Recommended organizational metrics include:

```text theme={null}
AI Systems With Literacy Assessment
Relevant Roles Identified
Literacy Needs Assessed
Measures Defined
Measures Delivered
Evidence Available
High-Risk Roles Covered
Third-Party Roles Covered
Material Gaps
Improvement Actions
```

Metrics should not be interpreted as statutory compliance percentages.

***

## 102. AI Literacy Coverage Matrix

A future operational report may use:

| AI System | Role | Context | Literacy Need | Measure | Evidence | Review | Status |
| --------- | ---- | ------- | ------------- | ------- | -------- | ------ | ------ |
|           |      |         |               |         |          |        |        |

***

## 103. AI Literacy Findings

Potential AIGO findings include:

```text theme={null}
AI_LITERACY_SCOPE_UNRESOLVED
AI_LITERACY_NEEDS_ASSESSMENT_MISSING
AI_LITERACY_MEASURE_MISSING
AI_LITERACY_EVIDENCE_MISSING
AI_LITERACY_CONTEXT_NOT_CONSIDERED
AI_LITERACY_ROLE_NOT_CONSIDERED
AI_LITERACY_AFFECTED_GROUP_NOT_CONSIDERED
AI_LITERACY_CHANGE_IMPACT_MISSING
AI_LITERACY_REVIEW_MISSING
AI_LITERACY_THIRD_PARTY_GAP
AI_LITERACY_HIGH_RISK_ROLE_GAP
AI_LITERACY_REGULATORY_UPDATE_PENDING
```

***

## 104. Critical Findings

The following may warrant high or critical severity depending on context:

* no literacy measure for personnel responsible for critical human oversight;
* high-risk system operated by personnel without appropriate system-specific preparation;
* material system change without literacy reassessment;
* repeated serious incidents linked to a verified literacy gap;
* third-party operators performing consequential AI activities without relevant measures;
* management repeatedly failing to address known literacy deficiencies.

***

## 105. Validation Requirements

The mapping should satisfy:

### Legal Source Validation

Article 4 and Regulation (EU) 2026/1744 are identified.

### Applicability Validation

Relevant providers, deployers, staff, and other persons are considered.

### Context Validation

Technical knowledge, experience, education, training, context, and affected persons are represented.

### Measure Validation

Organizational measures are identified.

### Evidence Validation

Evidence of measures can be retained.

### Timeline Validation

2 February 2025 application date and current enforcement baseline are reflected.

### Amendment Validation

The amended Article 4 is used rather than the pre-2026 wording.

### Traceability Validation

Article 4 → people → context → measure → evidence chain exists.

***

## 106. Limitations

This mapping cannot independently determine:

* whether a particular organization's measures are legally sufficient;
* whether an individual has adequate knowledge;
* whether a particular training course satisfies the organizational need;
* whether a national authority will consider the organization's measures appropriate;
* whether an organization is legally compliant.

Article 4 is context-dependent and the amended provision intentionally does not impose a universal individual literacy threshold.

***

## 107. Current Source Baseline

This mapping version uses:

* Regulation (EU) 2024/1689;
* Regulation (EU) 2026/1744;
* European Commission AI literacy guidance and information;
* European Commission AI literacy Q\&A;
* European Commission AI literacy practice repository.

The Commission's current AI literacy page was updated in 2026 following the Digital Omnibus and states that Article 4 remains an obligation while no specific or "sufficient" individual level is mandated. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/ai-talent-skills-and-literacy))

***

## 108. Review Triggers

This mapping should be reviewed when:

* Article 4 is amended;
* new AI Board recommendations are adopted;
* Commission practical examples are materially updated;
* national enforcement guidance materially changes;
* relevant competence frameworks change;
* material organizational AI use changes occur.

***

## 109. Review Frequency

Minimum:

* annual;
* event-driven after legal change;
* before major AIGO releases.

Event-driven review takes precedence over routine review.

***

## 110. Relationship to Other EU AI Act Mappings

| File                                                             | Relationship         |
| ---------------------------------------------------------------- | -------------------- |
| `01-AIGO-EU-AI-Act-Mapping-v0.1.md`                              | Master mapping       |
| `02-AIGO-EU-AI-Act-Prohibited-AI-Practices-Mapping-v0.1.md`      | Article 5            |
| `03-AIGO-EU-AI-Act-High-Risk-AI-Mapping-v0.1.md`                 | High-risk            |
| `04-AIGO-EU-AI-Act-Transparency-Mapping-v0.1.md`                 | Article 50           |
| `05-AIGO-EU-AI-Act-GPAI-Mapping-v0.1.md`                         | GPAI                 |
| `07-AIGO-EU-AI-Act-Governance-and-Enforcement-Mapping-v0.1.md`   | Governance           |
| `08-AIGO-EU-AI-Act-Conformity-and-Documentation-Mapping-v0.1.md` | Conformity           |
| `09-AIGO-EU-AI-Act-Rights-and-Remedies-Mapping-v0.1.md`          | Rights               |
| `10-AIGO-EU-AI-Act-Annexes-Mapping-v0.1.md`                      | Annexes              |
| `11-AIGO-EU-AI-Act-Applicability-and-Timeline-v0.1.md`           | Timeline             |
| `12-AIGO-EU-AI-Act-AIGO-Control-Mapping-v0.1.md`                 | Controls             |
| `13-AIGO-EU-AI-Act-Evidence-and-Assurance-Mapping-v0.1.md`       | Evidence / assurance |

***

## 111. Relationship to AIGO Schemas

| AI Literacy Activity       | AIGO Schema       |
| -------------------------- | ----------------- |
| Organizational scope       | Governance        |
| AI system context          | AI System         |
| Literacy needs             | Assessment        |
| Risk                       | Risk              |
| Literacy control           | Control           |
| Learning / deployment gate | Approval          |
| Monitoring                 | Monitoring        |
| Incident-related learning  | Incident          |
| System change              | Change            |
| Assurance                  | Assurance         |
| Learning evidence          | Evidence          |
| Management review          | Management Review |
| Improvement                | Improvement       |

The mapping does not require a separate AI Literacy schema at this stage.

***

## 112. Relationship to AIGO Templates

Relevant templates include:

* AI Governance Template;
* AI System Registration Template;
* AI System Profile Template;
* AI Classification Template;
* AI Risk Assessment Template;
* AI Control Assessment Template;
* AI Approval Template;
* AI Monitoring Template;
* AI Incident Template;
* AI Change Management Template;
* AI Assurance Template;
* AI Management Review Template;
* AI Continuous Improvement Template;
* AI Evidence Record Template.

An organization may later introduce a dedicated AI Literacy Assessment or Learning Record template if operational requirements justify it.

***

## 113. Relationship to AIGO Tools

The AI literacy mapping should eventually be usable by:

* Schema Validator;
* Reference Validator;
* Traceability Validator;
* Control Coverage Validator;
* Evidence Coverage Validator;
* Framework Consistency Checker;
* Document Integrity Checker;
* Repository Health Checker.

***

## 114. Document Control

| Field                     | Value                              |
| ------------------------- | ---------------------------------- |
| Document                  | AIGO EU AI Act AI Literacy Mapping |
| Version                   | 0.1                                |
| Status                    | Draft                              |
| Document Identifier       | `AIGO-MAP-EUAI-006`                |
| Document Type             | EU AI Act Mapping                  |
| Primary Provision         | Article 4                          |
| Amendment Baseline        | Regulation (EU) 2026/1744          |
| Owner                     |                                    |
| Legal/Compliance Reviewer |                                    |
| Governance Reviewer       |                                    |
| Framework Architect       |                                    |
| Approved By               |                                    |
| Effective Date            |                                    |
| Next Review Date          |                                    |

***

## 115. Document Status

**Document:** AIGO — EU AI Act AI Literacy Mapping

**Version:** 0.1

**Status:** Draft

**Working Name:** AIGO

**Full Name:** AI Governance Operating Framework

**Document Identifier:** `AIGO-MAP-EUAI-006`

**Document Type:** EU AI Act Mapping

This document maps the amended Article 4 AI-literacy obligation to the AIGO AI Governance Operating Framework, emphasizing contextual, role-based measures, organizational evidence, risk, human oversight, system change, monitoring, assurance, and continual improvement.

End of Document
