2. The course certificate proves almost nothing
An auditor asks how you know the people operating your AI-enabled workflow are competent. You show a folder of course certificates. The auditor chooses one name and asks what that person may do, which system version they learned, whether they can recognise a failed output, and what changed after last month's upgrade. The certificates answer none of those questions.
Your six-person pilot from T13-L04 is now ordinary work. A new researcher joined yesterday, the administrator who managed access is leaving on Friday, and the assistant's interface has gained a connector. Everyone attended the launch session, but only one person knows the stop route. If that person leaves, work either stops or continues without its controls.
At Level 5 Operator, literacy is an operating control, not a calendar invitation. You need to map each role to observable capabilities, record current evidence in an owned system, trigger refresh when the work changes, and prove that joining, changing role, and leaving all produce the right access and training state.
3. After this you can
- Map each role to the AI literacy capabilities its tasks, systems, data, decisions, and affected people require.
- Verify capability with observable task evidence rather than attendance or a course title.
- Maintain reviewable records of who, what, when, evidence, version, owner, status, and next trigger.
- Trigger targeted refresh when a tool, workflow, policy, risk, role, incident, or fallback changes.
- Reconcile onboarding, role changes, and offboarding against both training status and effective access.
4. Prerequisites
T13-L04| Rolling it out, including its team, task, policy boundary, support path, and accepted-outcome rule.T12-L05| Governance, evidence and handover, including the current AI-system inventory, risk tier, owners, and handover controls.- One accountable team owner, one literacy-record owner, one system or access owner, and a substitute for each.
- The current role list, AI-system inventory, workflow versions, approved AI usage policy, incident route, and joiner/mover/leaver process.
- An organisation-approved records location with access control, version history, retention and deletion rules, and export capability.
- Permission to process the minimum work-identity and competence evidence needed for the record.
Use public, wholly synthetic, or explicitly approved material for teaching and assessment scenarios. A training register is itself a personnel record: do not upload it to an AI assistant, keep it in a personal spreadsheet, or include protected characteristics, performance commentary, prompts, customer or participant records, unpublished work, credentials, or incident content. Use an approved staff identifier and evidence reference rather than copying sensitive evidence into the register. Existing employment, worker-representation, accessibility, privacy, research, records, security, contractual, and sector rules still apply.
5. The idea in one page
Start from work, not courses. For every role, name the AI-enabled task, system, permitted data, decisions, affected people, normal check, stop condition, and fallback. Then write capabilities as observable verbs: classifies a synthetic input under policy, checks every supplied identifier, stops an unauthorised action, or revokes access and verifies denial. “Understands AI” cannot be assessed consistently.
Use the curriculum ladder as a capability catalogue, not a rank attached to a person:
| Responsibility | Capability pattern | Behaviour it changes |
|---|---|---|
| Use an approved system | Select suitable tasks, protect inputs, verify outputs, disclose use where required | Prevents casual use from crossing the policy boundary. |
| Review team work | Apply a named quality rule, preserve uncertainty, challenge unsupported claims | Prevents fluent output from becoming accepted work without evidence. |
| Maintain a workflow | Test changes, read failures, pause and roll back | Prevents a builder's knowledge from becoming an undocumented dependency. |
| Integrate systems or data | Enforce permissions, approvals, limits, logging, and fallback | Prevents a connector or automation from expanding authority silently. |
| Operate shared service | Monitor, respond, recover, evidence, and hand over | Keeps work safe and recoverable when the original operator is absent. |
A role receives only the capabilities needed for its actual responsibility. A principal investigator or director may need approval, affected-person, and stop-decision capability without needing to administer a model gateway. An administrator may need excellent access lifecycle capability without judging research claims or customer remedies. Prior education can be evidence, but it does not prove knowledge of this team's current policy, system, or fallback.
Keep one controlled AI literacy register with two linked views. The role-to-literacy map says what must be true and why. The individual training record says whether it is currently true and points to evidence. Record not required, with a reason and approver, instead of leaving ambiguous blanks.
Verify the risky behaviour. A short briefing may be enough for awareness; a scenario classification, observed task, negative test, recovery drill, or handover rehearsal is stronger for operational capability. Attendance proves presence only. Record the assessment method, pass rule, actual result, assessor, and capability version.
Refresh on events, not merely anniversaries. Compare a proposed change with the map. If it changes no required behaviour, record reviewed, no refresh. If it changes an interface or ordinary workflow, issue a delta briefing and reassess the affected step. If it changes data, permissions, actions, human oversight, stop conditions, or fallback, suspend the affected authorisation until retraining and reassessment pass. A calendar review remains a backstop for finding missed changes.
Current regulatory note — last verified 2026-09-04: Article 4 of Regulation (EU) 2024/1689, as replaced by Article 1(5) of Regulation (EU) 2026/1744, requires providers and deployers to take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. They must take account of those persons' technical knowledge, experience, education, and training, the context in which the AI systems are to be used, and the persons or groups on whom they are to be used. Crucially, Article 4(1) says this obligation does not require a provider or deployer to guarantee any specific level of AI literacy of any individual. The controlling amendment is the Official Journal text of Regulation (EU) 2026/1744, published 24 July 2026 (opens in a new tab). The Commission's current AI literacy Q&A, updated 27 July 2026 (opens in a new tab), likewise says Article 4 does not mandate a specific or “sufficient” individual level or require measurement of employees' AI knowledge; it also says there is no required certificate or one-size-fits-all training format and that organisations can keep an internal record of training or other guiding initiatives. The Q&A is guidance, not the legal text. The capability tests and register in this book are risk-based operating controls, not statutory minima or proof of compliance. Separate duties may demand more—for example, the Q&A notes the training obligation for staff who ensure human oversight of high-risk AI systems. Check the current legal text, applicable sectoral and national rules, and qualified advice before making a compliance decision.
A context-sensitive measures obligation gives you room to fit learning to real roles. That room is a trap if it becomes no map, no rationale, and no evidence. Do not convert Article 4 into a guarantee of individual attainment; use observed capability where your operational risk calls for it. Preserve the management chain: system and risk -> role and task -> required capability -> learning or guidance -> observed evidence -> current status -> refresh decision.
6. The worked example: turn the pilot into an operated literacy register
Mira and Jonas continue the fictional Northstar pilot from T13-L04. Mira's Lab produces first-draft evidence tables from public papers selected by a researcher. Jonas's Company produces first-draft issue tables from wholly synthetic tickets during training and approved internal inputs in operation. In both lanes, a person checks identifiers, quantities, missing information, and exceptions before accepting a table. The AI system cannot publish, contact a customer, change a sample record, approve a remedy, or alter access.
They create one controlled workbook called AI literacy register. It is the single artifact for this book. It has these tabs:
00-Control
01-Role-map
02-People-record
03-Capability-catalogue
04-Change-log
05-Review-evidence
The workbook lives in the team's approved records service, not Mira's or Jonas's drive. 00-Control names the accountable owner, record owner, substitutes, scope, current version, approved readers, source systems, review date, event triggers, retention rule, deletion owner, and export procedure. It links to the AI-system inventory and access register rather than duplicating them.
Define stable capability IDs
Mira and Jonas give capabilities stable IDs so a renamed course does not break the evidence chain:
| ID | Observable capability | Pass evidence | Refresh trigger |
|---|---|---|---|
LIT-01 | Locates the current AI policy and classifies six synthetic green, yellow, and red cases | Every red case stopped; at least 5/6 correct; correct question route used | Policy, approved tool/account, purpose, or data class changes |
LIT-02 | Completes the role's assisted task and applies its acceptance checklist | Two consecutive synthetic tasks accepted with every critical criterion met | Prompt, model route, workflow, source shape, or acceptance rule changes |
LIT-03 | Recognises a material failure and uses stop, fallback, and incident routes | Scenario drill stops before downstream action and names the correct owner | Stop condition, fallback, incident route, or system action changes |
LIT-04 | Reviews another person's output against source evidence and records accept/reject consistently | Agreement on 4/4 calibrated cases, including one missing value and one exception | Quality rule, source, affected-person consequence, or review interface changes |
LIT-05 | Grants, changes, and revokes role-based access through the approved route | Synthetic joiner and leaver test produces expected access; no second unmanaged path remains | Identity, group mapping, account type, connector, or offboarding process changes |
LIT-06 | Operates and hands over the service control | Substitute reproduces monitor, pause, recovery, and evidence retrieval from the runbook | Architecture, alert, recovery, retention, owner, or provider changes |
LIT-07 | Makes the accountable expand, pause, or stop decision from quality, safety, burden, and incident evidence | Written decision on one synthetic gate pack cites criteria and unresolved risk | Risk tier, legal rule, affected people, decision authority, or gate changes |
Each catalogue row also contains owner, version, effective date, assessment script reference, permitted accommodations, reassessment rule, and superseded version. A capability ID describes an outcome; a particular workshop, course, coached practice, or prior qualification is one route toward it.
Map five Lab roles and five Company equivalents
The role map uses identical mechanics in both lanes:
| Lab role | Company equivalent | AI responsibility | Required capabilities | Why this set, and what is deliberately excluded |
|---|---|---|---|---|
| Principal investigator | Operations director | Own purpose, policy boundary, affected-person consequences, and expand/pause/stop decision | LIT-01, LIT-03, LIT-07 | Must challenge and stop the service; does not need access administration or routine drafting capability. |
| Postdoctoral researcher | Senior operations analyst | Prepare and peer-review tables; act as quality challenger | LIT-01 to LIT-04 | Must preserve evidence and exceptions; cannot publish, contact customers, or approve system access. |
| PhD researcher | Operations analyst | Prepare first drafts from selected inputs | LIT-01, LIT-02, LIT-03 | Can use the bounded workflow and fallback; cannot approve their own critical exceptions. |
| Laboratory technician | Quality specialist | Verify identifiers, missing values, exceptions, and traceability | LIT-01, LIT-03, LIT-04 | Reviews accepted work; does not need to write prompts or manage accounts. |
| Group administrator | Operations coordinator | Onboard, change, and offboard approved access; maintain the register | LIT-01, LIT-03, LIT-05 | Manages lifecycle evidence; does not decide research claims, customer remedies, or policy exceptions. |
LIT-06 is assigned to the named service operator and substitute recorded in the broader governance inventory. If the postdoc or coordinator also holds that operational role, it appears as a separate assignment. Mira and Jonas do not smuggle operator permission into an ordinary job title.
For every role-map row they add: role ID, in-scope system and workflow version, task, data classes, permitted actions, prohibited actions, affected people, source policy, capability IDs and versions, rationale, approver, effective date, and review trigger. That makes a review reproducible: another operator can trace why each capability exists.
Record evidence without building a surveillance file
The people record uses these columns:
staff_id | role_id | engagement_type | start_date | end_date
system_scope | capability_id | required_version | evidence_type
evidence_ref | assessed_on | assessor_role | result | valid_state
restriction | refresh_trigger_ref | next_review | access_reconciled
record_owner | last_checked
valid_state is one of current, gap, suspended, not-required, or left. There is no vague complete. evidence_ref points to an approved assessment record, such as assessment://LIT-02/SYN-POSTDOC-02/2026-09-09; it does not contain the person's prompts, the source paper, a customer ticket, or subjective manager comments. The result records only the declared criterion and necessary observation.
The workbook uses validation lists for IDs and states. Required fields cannot be blank for current rows. A formula or controlled report flags:
active person + required capability + no current matching evidence -> GAP
left person + effective access not confirmed denied -> FAIL
superseded capability version + active assignment -> REFRESH
current record + evidence reference missing -> INCOMPLETE
The formula is a queue, not proof. The record owner investigates every flag against the authoritative role and access sources. They do not mark a row current merely to clear a dashboard.
Lab framing: prove the research-group map
Mira maps the principal investigator, postdoc, PhD researcher, technician, and administrator. For training she uses six synthetic literature cards, including a missing sample size, a correction notice, and an instruction embedded in quoted source text. No unpublished paper, participant record, peer review, credential, or real incident enters the exercise.
The PhD researcher passes LIT-01 at 6/6 and completes two synthetic tables under LIT-02. The first table is rejected because “not reported” became zero. Mira records the first result as failed, gives targeted practice on missingness, and assesses with a different synthetic card. Two consecutive tables then pass. The register points to all three results; it does not erase the failed attempt. LIT-03 passes when the researcher stops a card proposing direct publication and chooses the manual table fallback.
The technician reviews four calibrated tables for LIT-04: ordinary, missing value, correction, and dropped limitation. Their accept/reject decisions match the approved key 4/4. The principal investigator receives a synthetic gate pack showing faster drafting but increased review burden and one unresolved correction failure. They choose pause, cite the declared gate, and name the owner, satisfying LIT-07. This tests accountable judgement rather than whether the PI can operate the assistant.
The administrator runs LIT-05 with synthetic identities. A joiner receives only the researcher group after current LIT-01 and LIT-03 evidence is recorded; the workflow remains unavailable while LIT-02 is a gap. For the leaver, one authoritative offboarding request removes group access, a fresh login and an active protected request are denied, the result is linked, and the literacy row becomes left. The historical record is retained or deleted under the approved schedule; it is not silently erased on departure.
Company framing: prove the equivalent department map
Jonas repeats the same assessments for the operations director, senior analyst, analyst, quality specialist, and operations coordinator. Only the synthetic skin changes. The six cards contain invented ticket IDs, a missing account reference, a cancellation exception, and hostile text asking the assistant to bypass policy. No customer message, employee record, production log, contract, or credential is used.
The analyst's first LIT-02 attempt drops a cancellation exception and fails. Targeted practice and two fresh synthetic cases pass. The quality specialist scores 4/4 on the parallel review set. The operations director receives the same gate pattern and chooses pause until the exception rule and support burden are resolved. The coordinator proves the same staged joiner and complete leaver outcome with Company groups. Lab and Company therefore use the same capability versions, criteria, states, and review queries without pretending their source data is interchangeable.
Refresh the right people after a change
Two weeks later, Northstar adds a connector button. The button's existence does not automatically make the connector approved. Mira and Jonas open one change-log row before enabling it:
| Change question | Finding | Action |
|---|---|---|
| Does it change approved data, destinations, permissions, or actions? | Yes; a user could send a table to another system. | Keep connector disabled for ordinary roles. |
| Which capabilities are affected? | LIT-01, LIT-03, LIT-05, and potentially LIT-06. | Create new versions only after policy, access, stop, and recovery controls are approved. |
| Who is affected now? | Coordinator and service operators; all users if enabled later. | Suspend connector administration until reassessment; ordinary bounded drafting remains current. |
| What evidence closes the change? | Negative unauthorised-action test, approved mapping, stop drill, and substitute handover. | Link results and approve the new effective versions. |
They do not send everyone through the original introduction again. They apply the delta only to affected roles and preserve the reason unaffected capabilities remain current. If the connector cannot be bounded and reversed, it stays disabled.
Make joining, moving, and leaving one control loop
The record owner runs a weekly reconciliation and an event-driven check:
authoritative people/contractor list
-> active role assignments
-> required capability versions
-> current evidence or explicit gap
-> effective system access
-> exceptions with owner and expiry
For a joiner, create the role assignment before access, provide accessible learning, verify mandatory boundary and stop capabilities, then stage task access as remaining capabilities pass. For a mover, recalculate requirements: add new capabilities, remove obsolete permissions, and retain historical evidence under policy. For a leaver, revoke access through the approved route, verify denial, transfer record ownership and open actions, then set the status and retention event. Contractors and service providers acting on the team's behalf enter the same loop when in scope; a purchase-order contact is not evidence of capability.
At month end, the substitute record owner performs five queries and saves results in 05-Review-evidence:
- Every active in-scope role has approved capability versions and rationale.
- Every active assignment is either
currentor a visiblegap/suspendedstate with an owner; no blank is treated as pass. - Every current row has an assessment date, result, assessor role, and resolvable evidence reference.
- Every change-log item has an impact decision and affected assignments, including
no refreshdecisions with reasons. - Every leaver sample has a completed access reconciliation, and every overdue exception is closed or escalated.
The substitute samples one row per role, follows each chain from system inventory to map to evidence to access, and records discrepancies. In the fictional review, they find the coordinator's substitute named in the control tab but absent from LIT-05. The state becomes gap, the primary remains accountable, and the substitute completes the synthetic joiner/leaver test before the row returns to current. The register has done useful work because it exposed dependence on one person.
7. What goes wrong
Attendance is recorded as capability
Symptom: every row says attended webinar, but nobody can show who correctly stops a restricted input or failed action.
Fix: attach an observable capability, assessment method, pass rule, actual result, version, and evidence reference. Keep attendance only as supporting evidence.
Everyone receives the same course
Symptom: the director learns interface tips while the access coordinator never rehearses revocation and the reviewer never sees a missing-value case.
Fix: map tasks and consequences by role, then train and assess only the required capability set. Record exclusions deliberately.
Refresh follows only the calendar
Symptom: records remain green after a connector, policy boundary, model route, or fallback changes.
Fix: make change approval ask which capability versions and assignments are affected. Suspend risky authorisation until the delta assessment passes.
The record lives in a personal spreadsheet
Symptom: the owner is absent, links break, access is uncontrolled, and nobody knows which copy is current.
Fix: use an approved controlled records location with accountable owner and substitute, version history, readers, retention, deletion, and export.
Joiners are invisible
Symptom: a new colleague inherits a group or shared link before appearing in the literacy register.
Fix: make active role assignment create required-capability rows before staged access. Reconcile the people source, register, and effective access on a defined cadence.
Offboarding deletes the evidence but not the access
Symptom: the training row disappears when a person leaves while a local account or active session remains usable.
Fix: preserve or delete the record under the approved schedule, revoke through the authoritative route, test effective denial, transfer open duties, and link the access reconciliation.
Context-sensitive measures become unsupported claims
Symptom: the programme says its measures are “proportionate” but contains no context analysis, affected-person view, rationale, or record of what it did.
Fix: preserve the evidence chain from system and context to role, chosen literacy measure, operational capability where needed, evidence, and refresh decision. Do not describe an internal pass rule as an Article 4 guarantee or statutory threshold. Ask accountable legal or regulatory owners for the current interpretation.
8. Do it yourself: build one real team's register in 90 minutes
Produce one controlled AI literacy register for one real team. Use real role and approved staff identifiers only inside the authorised records system. Use synthetic cases for every assessment; do not ask people to reveal prompts, mistakes, customer or participant data, unpublished work, or credentials.
Minutes 0-10: create the control tab. Name scope, owners and substitutes, canonical location, readers, source systems, retention and deletion route, current workflow versions, and accountable approver.
Minutes 10-25: list each in-scope role's AI tasks, systems, data classes, actions, affected people, quality check, stop condition, fallback, and access. Include contractors acting on the team's behalf where applicable.
Minutes 25-40: write stable capability IDs as observable verbs. For each, define pass evidence, critical failure, owner, version, effective date, accessible alternative, and change triggers. Reuse relevant curriculum capabilities rather than course titles.
Minutes 40-52: map every role to capability versions and write the rationale. Record deliberate not required decisions with approver; do not fill gaps by giving everyone every capability.
Minutes 52-64: populate the people record from the approved role source. Add required fields, controlled states, evidence references, and access reconciliation. Mark missing or stale evidence gap or suspended, never current.
Minutes 64-74: run one synthetic capability check for one user, one reviewer, one accountable decision-maker, and one access or service operator. Record the declared result, including failures, without subjective performance notes.
Minutes 74-82: simulate one joiner, role mover, and leaver with synthetic identities. Confirm requirements are recalculated, access is staged or removed, a protected action is denied after offboarding, and evidence ownership survives departure.
Minutes 82-87: evaluate one plausible tool or policy change. Record affected capabilities, assignments, immediate restriction, refresh method, reassessment, owner, and closure evidence. Include a reasoned no refresh only if behaviour truly does not change.
Minutes 87-90: have the substitute run the five review queries and trace one sample per role. Record findings and correction owners in the same workbook, export an approved review copy, and set the next event and calendar backstop.
If you cannot obtain approved staff data or accountable approval, build the structure with synthetic identities and mark it exercise only. It does not pass the real-team exit check. If a live access test could disrupt production, use an approved test environment and record the production control owner rather than staging an unsafe action.
9. Exit check
Deliver exactly one artifact: one controlled AI literacy register for one real team containing a role-to-literacy map and the linked training record.
It passes when every in-scope role names tasks, systems, data classes, actions, affected people, checks, stop and fallback paths, required capability versions, rationale, approver, and refresh triggers; every active in-scope person has a visible current, gap, or suspended state for each requirement; every current row has who, what, when, actual result, assessment method, assessor role, evidence reference, version, owner, and next trigger; and the register names its canonical location, readers, owners and substitutes, retention, deletion, and export controls. A sampled user, reviewer, decision-maker, and access or service operator must pass their declared synthetic assessment. A synthetic joiner, mover, and leaver must produce the expected requirement and access states, including observed denial after offboarding. The substitute must run all five review queries and trace one sampled row per role without help from the author.
It fails if attendance or a certificate is the only evidence, one course is assigned without role reasoning, blanks count as current, a changed system leaves affected versions current without review, joiners bypass the register, leavers retain effective access, evidence links cannot be resolved, the record is personally owned, or the artifact contains unapproved personal data, real prompts, protected source content, credentials, or incident details.
10. Rule to remember
Capability per role, recorded, with a date.
11. Further reading & tools
- Taught:
T13-L04| Rolling it out - supplies the pilot roles, task, accepted-outcome rule, objections, support route, and change gates that become ongoing literacy requirements. - Taught:
T12-L05| Governance, evidence and handover - connects each training record to an inventoried AI system, risk tier, accountable owner, evidence route, and substitute operator. - Taught: European Commission AI literacy Q&A (opens in a new tab) - official, non-binding guidance updated 27 July 2026 on the amended Article 4: no guaranteed specific or “sufficient” individual level, no knowledge-measurement duty, and no mandatory certificate or single training format.
- Catalogued: Regulation (EU) 2026/1744 in the Official Journal (opens in a new tab) - the controlling 24 July 2026 amendment; Article 1(5) replaces AI Act Article 4, and the enacted wording governs over summaries or older guidance.
- Catalogued: Regulation (EU) 2024/1689 on EUR-Lex (opens in a new tab) - use EUR-Lex's up-to-date document view and pending-amendment information together with Regulation (EU) 2026/1744 and qualified advice.
- Catalogued: European Commission living repository of AI literacy practices (opens in a new tab) - examples for programme design, not automatic proof of compliance.
- Catalogued: NIST AI RMF Playbook (opens in a new tab) - voluntary governance actions that can help connect responsibilities, training, monitoring, and change management; select only what fits the system and context.
- Catalogued: Tools index - compare approved learning and records systems only after capability, evidence, ownership, access, retention, and export requirements are defined.