AI literacy (Art. 4 EU AI Act)
AI literacy is defined in Art. 3(56) of the EU AI Act as the skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations, to make an informed deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause. Art. 4, applicable since 2 February 2025, requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, the context in which the systems are used, and the persons or groups on whom they are used.
The obligation applies to every organisation that uses any AI system in a professional context, not only to those with high-risk systems, and therefore to virtually every life sciences company using generative AI tools, analytics platforms or AI-enabled devices. The Commission's Q&A and the AI Office's living repository of practices indicate that there is no prescribed curriculum or certification; measures should be proportionate and differentiated (general awareness for all staff, deeper technical and legal training for those developing, procuring or overseeing systems, and specific instruction for those exercising human oversight), and organisations should be able to document what they did. National market surveillance authorities may enforce Art. 4 from August 2026, and lack of literacy measures will weigh in the assessment of other breaches.
For pharmaceutical, MedTech and HealthTech organisations, AI literacy programmes typically cover: what AI is and how the organisation uses it; the AI Act's risk categories and the company's role for each system; the interaction with the GDPR (no patient data in public tools, DPIAs for new uses); hallucination, bias and automation bias; sector rules such as EMA and FDA expectations and GxP validation; and the internal policy, approved-tool list and escalation routes. Training records, attendance logs and role-based curricula form the evidence file, and the topic sits naturally within the mandate of an AI Officer alongside the DPO's data protection training. iliomad delivers AI and data protection training as part of its training services.
