EU AI Act Art. 4 AI literacy In-company or digital By professional group

AI course for companies: from AI literacy to concrete impact per team

EU AI Act Article 4: why your employer has been required to provide AI literacy since February

Since 2 February 2025, Article 4 of the European AI Act has required every organisation deploying AI systems to ensure that its staff have an adequate level of AI literacy. This applies to everyone who works with AI, from a marketer using ChatGPT to a finance team working with forecasting models or an HR department screening candidates. Our AI course is not a one-off ChatGPT workshop but a structured programme that builds AI fluency by professional group, while also mapping the areas where AI implementation will have the greatest impact.

Request a quote View the modules
AI-fluency Prompt-skills Tool-stack

Who this programme is for

Our AI course is designed for organisations that want to go beyond the occasional ChatGPT tip. We work with directors and HR managers who want to prepare their teams systematically for a working environment in which AI is a standard part of everyday processes, and who want to identify where AI implementation will deliver the most value.

The reason behind it is almost always a combination of three things. First, the legal obligation: since February 2025, the AI Act has required providers and deployers of AI systems to ensure their staff have sufficient AI knowledge, in proportion to their role and the context in which AI is used. Second, the commercial urgency: employees are already using public AI tools, often without any framework for what is and is not permitted with client or company data. And third, the strategic question: where does the real productivity gain lie, and how do you uncover it when the organisation itself does not yet know what AI can do?

We deliberately do not position ourselves as a training agency selling standalone courses. We are an AI implementation partner: for many clients, the course is the starting point of a longer engagement in which we subsequently build RAG applications, copilots, agent workflows or governance frameworks. The course provides the literacy and the impact report that allow your management team to make well-founded decisions about where AI investments will deliver the highest return.

Modular offering by professional group

An AI course that is identical for the entire organisation misses the point. A marketer needs different prompting skills and tools from a controller or a software developer. That is why we build a dedicated module for each professional group: 4 to 8 hours per group, 30% theory and 70% hands-on work with tools and data from the participants' own workflows.

Sales

Sales AI and account intelligence

Automating lead research with deep research tools, generating account plans based on public signals, summarising call transcripts and populating CRM fields. In this module, participants work on their own account portfolio and leave with concrete prompt templates that can be used straight away in HubSpot, Salesforce or Pipedrive.

Marketing

Content AI and campaign acceleration

Turning briefs into content building blocks, conducting SEO research with AI tools, generating images within your brand identity and tailoring social content for each channel. We also cover the risks: AI content that dilutes your brand voice, and how to guard against this with style guides and review loops.

Customer Service

AI agents for support and inbox

AI agents that classify tickets, prepare replies and retrieve knowledge base articles. We show how a service team shifts from first-line to second-line work when routine questions are handled by an agent, and which escalation rules are needed to safeguard quality.

Finance

Forecasting and data analysis

Speed up spreadsheet work, set up scenario analyses, detect anomalies in transaction data and underpin cash flow forecasts. We train finance staff to correctly interpret AI output and build controls, so that AI remains a support tool rather than a black box the management team relies on blindly.

HR

Sourcing, screening and internal mobility

Optimise job descriptions, speed up LinkedIn sourcing queries, and prepare candidate screening without the bias pitfalls that the AI Act explicitly classifies as high risk. For HR modules, we pay particular attention to transparency and to human decision-making in selection.

Operations

Process AI and workflow automation

Speed up repetitive administration with copilots, map processes using AI, and set up integrations with Make or n8n. In this module, participants identify concrete processes within their own department where AI automation would save the most time, with an initial impact assessment for each process.

Legal

Contract AI and compliance

Contract analysis with AI, faster due diligence, and well-founded legal research. We cover how you can use AI safely with confidential documents, which tools meet professional secrecy obligations, and how legal professionals can check AI output without compromising quality.

Engineering

Copilots, RAG and MCP for developers

Working effectively with GitHub Copilot, Cursor or Claude Code, building RAG applications on internal documentation, and using the Model Context Protocol (MCP) to give AI agents access to internal tools. For engineering teams who want to go beyond code completion.

Management

Governance and AI strategy for management teams

For directors and management team members: translating AI Act obligations into policy, setting up an AI register, risk classification per use case, budget allocation, and assessing AI investment proposals. This is not tool training, but the perspective you need to frame AI decisions.

AI Act Article 4 in plain language

The AI Act has been in force since 1 August 2024. Article 4 — the obligation to ensure AI literacy — is one of the first obligations to take effect, on 2 February 2025. This obligation affects virtually every organisation in the Netherlands.

The legal text states that providers and deployers of AI systems must "take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf". The level must be appropriate to the technical knowledge, experience, education and training of those involved, the context in which the AI is used, and the persons or groups on whom the AI systems are applied.

In practice, this means that a marketing team using ChatGPT for copy needs a different level of literacy than an HR team using AI in recruitment procedures (a high-risk application under the AI Act), or an engineering team building AI agents with access to production systems. The law does not prescribe a specific curriculum, but it does expect you to be able to demonstrate that you have acted proportionately.

Non-compliance falls under the broader enforcement framework of the AI Act. More important than the direct threat of fines is that Article 4 in practice serves as a benchmark: if something goes wrong with an AI application — an incorrect automated decision, a data breach through a prompt, a liability claim — the supervisory authority or the court will examine whether you reasonably ensured that your people knew what they were working with. A structured training programme with certification per employee is the evidence of that.

What we document for you: for each course participant, a certificate listing module content, date and competencies achieved. At organisational level, an AI literacy matrix showing which role has reached which level. This document fits into your AI register and can be used directly as evidence in audits, certification or incident investigations.

Sector-specific modules

Alongside profession-based modules, we offer sector-specific deep dives. AI in healthcare requires a different lens from AI in retail or the financial sector. Compliance requirements, data sensitivity, customer expectations and use cases differ by sector, and we tailor the content accordingly.

Healthcare and wellbeing

AI for administrative burden (reporting, claims), triage support, and internal knowledge access for care professionals. We cover the specific sensitivity of patient data, the requirements of NEN 7510, and the difference between supportive AI and high-risk applications under the AI Act, such as diagnostic systems.

Finance and insurance

AI in fraud detection, customer contact, underwriting and compliance monitoring. For financial institutions under DORA and the AI Act, additional requirements apply around model validation, audit trails and explainability. Our module covers how you can deploy AI tools without jeopardising your supervisory standing.

Retail and e-commerce

Product descriptions, customer segmentation, dynamic pricing, stock forecasting and conversational commerce. We show how retailers use AI tools in marketing and logistics without compromising brand voice or legal consumer protection.

Legal and notarial services

Specifically for law firms, notarial practices and legal departments: contract analysis, due diligence, and legal research using retrieval-augmented generation. We cover the requirements arising from professional privilege and the NOvA guidelines on AI use.

SMEs and professional services

For smaller organisations without their own IT department: establishing the basics well, with safe tool choices, a workable AI policy and an initial impact assessment. Practical and without unnecessarily heavy governance, yet fully compliant with the AI Act.

Industry and logistics

Predictive maintenance, quality control with computer vision, planning optimisation and logistics forecasting. We align AI applications with the operational realities of the factory floor, warehouse and transport planning.

In-company or online: the format that suits you

We train groups of 5 to 50+ employees, in batches that work for your organisation. Two formats, the same content and the same hands-on approach.

In-company

On site at your organisation

A trainer comes to your office and works with your team on real cases from your own workflow. Suitable for organisations that want to activate their teams in a focused way, over a day or a series of half-days. Ideal for departmental training where participants work on the same processes together, such as sales, marketing or customer service teams. We recommend in-company training when there is already a shared context and hands-on collaboration will increase the learning.

Practical: 4 to 8 hours per module, with batches of 8 to 20 participants per group. We split larger companies into consecutive batches so the format stays intensive.

Digital

Live via Teams or Zoom

Live sessions via your own video platform: Microsoft Teams, Zoom or Google Meet. Suitable for organisations with multiple locations, hybrid teams or dispersed workplaces. Participants work in their own environment with their own tools, which speeds up the transfer to everyday practice. Breakout rooms and live coaching preserve the hands-on dynamic.

Practical: sessions of 2 to 3 hours, often spread over several days or weeks. Recordings are available for anyone unable to attend live, plus asynchronous Q&A in the interim period.

We scale with volume: for groups of 30 or more participants, we run multiple trainers in parallel tracks so the hands-on ratio stays high. For smaller teams of 5 to 10 people, we offer custom work, such as a combined session that covers sales and marketing at the same time.

After the course: from literacy to implementation

A course that ends with a certificate on the last day and then gathers dust delivers no return. Our approach therefore includes a follow-up programme as standard, linking the skills learnt to concrete implementation projects.

Pre-course assessment

Before we start, we map out the starting level for each professional group: which tools the team already uses, where the knowledge gaps lie, and which processes could benefit straight away from AI support. The assessment prevents us from wasting time on basics for people who are already further along, or from moving too quickly for those who don't yet have a ChatGPT account.

Interim coaching

Between modules, we offer asynchronous coaching: participants ask questions in a working environment, receive feedback on their prompts and share their successes. This low-threshold follow-up ensures that the techniques learnt actually make it into day-to-day workflows, rather than only working in the course environment.

Post-course assessment

Eight weeks after completion, we measure again: which tools have been integrated, which processes have been accelerated, and which barriers are holding back wider adoption. The assessment feeds into the impact report and gives management clear insight into the return on the course investment.

Impact report per department

Based on the assessments and the hands-on output, we deliver a report for each department: which processes have been identified as high-impact AI candidates, which tools merit organisation-wide rollout, where the risks lie, and which next steps are recommended. Concrete and actionable, not a generic consultancy document.

Bridge to implementation

For clients who want to pursue the impact areas identified, we build the implementation. Think of a RAG application on internal documentation, an agent workflow for customer service, or a copilot for finance reporting. The course provides the starting signal and the mandate; we deliver the system.

Ongoing governance support

Optional: monthly check-ins in which we provide updates on the AI Act, assess new tools for their suitability for your organisation, and maintain the AI register. For organisations that do not want compliance to slip after the first course round.

GDPR, data security and the use of public AI

When we work hands-on with AI tools, we immediately encounter GDPR questions. Which data may be used in which model? What happens to prompts in public ChatGPT? And how do you ensure that your teams, after the course, do not inadvertently paste customer data into a free tool? These questions are an integral part of every module.

What is and isn't allowed in public models

We train participants on a practical decision tree: which information is public or internally non-sensitive and may be entered into ChatGPT, Claude or Gemini? Which data is confidential to the business or contains personal data and does not belong there? And which alternatives does your organisation have, such as Azure OpenAI with data retention controls, a locally hosted model, or an enterprise licence with tailored terms?

GDPR legal basis for AI applications

For each professional group, we cover the GDPR legal basis: what the lawful basis is for processing personal data in an AI model, and how you record that in your record of processing activities. For HR applications, we pay particular attention to profiling and automated decision-making under Article 22 GDPR.

Prompt hygiene and data leakage

The biggest practical risks lie not in model errors but in unintended data leakage through prompts. We train on concrete prompt hygiene: anonymising data before sending it, replacing client names with labels, and setting up company tooling so that no external API call is made by default for sensitive data.

AI register and risk classification

For management modules, we build a working AI register for your own organisation: which AI systems are in use, who is the responsible user, which risk classification applies under the AI Act, and which measures have been taken. This document is immediately usable for audit and accountability.

Frequently asked questions about the AI course

What exactly is AI literacy, as intended in the AI Act?
In the AI Act, AI literacy is defined as the skills, knowledge and understanding needed to deploy AI systems responsibly and to understand the opportunities, risks and potential harm involved. In practice, that means knowing what a model can and cannot do, how to prompt effectively, which data risks exist, and when a human needs to stay in the loop. The level depends on the role: a developer needs deeper knowledge than an end user.
How long does a course take per professional group?
We plan 4 to 8 hours of effective time per module, split into half-days or short sessions. A sales team can cover the basics in one intensive day, whereas engineering or management often need more time because the material is more technical or strategic. For rollout programmes across several departments, we usually plan a track of 6 to 12 weeks.
What determines the cost of a programme?
Costs depend on the number of participants, the number of professional-group modules, the choice between in-company and digital delivery, and whether sector modules or a follow-up track with assessments and impact reporting are included. We always prepare a tailored quote after a short intake in which we define the scope. Request a quote for your specific situation.
What is the difference between your course and a standalone ChatGPT workshop?
A standalone workshop has a mixed group of employees practising prompts on generic examples. Our course works per professional group, using the tools and data from the participants' own workflows, delivers AI Act-compliant certification, and ends with an impact report that allows your management team to make a well-founded decision about where AI implementation will deliver the most value. It is a programme, not a one-off training.
Which tools are covered in the hands-on sessions?
This depends on the professional group and your existing tool stack: ChatGPT, Claude and Gemini for general use, GitHub Copilot and Cursor for engineering, Microsoft Copilot or Google Workspace AI for productivity, n8n and Make for automation, and sector-specific tools such as contract AI or agent platforms. We align with what you already use or are considering, rather than promoting a single vendor.
How do you handle GDPR and business data during the course?
In hands-on sessions we work with anonymised or fictitious sample data, or with data approved by your own team for use in the course. For permanent use, we recommend tools with enterprise terms or Azure deployments where data retention is controllable. GDPR and data security are an integral part of every module, not a separate appendix.
Do participants receive a certificate that complies with Article 4 of the AI Act?
Yes. Every participant receives a certificate showing the module content, hours completed, competencies achieved and date. At organisation level, we deliver an AI literacy matrix that demonstrates the level per role. This documentation fits into your AI register and can be used as evidence during audits, certification or incident investigations. We do not claim a legal guarantee, but we do provide the evidence that Article 4 requires in practice.
Do you also build the AI implementations that come out of the impact report?
Yes. Appfront is primarily an AI implementation partner, and for many clients the course is the starting point of a longer engagement. After the impact report, we can build RAG applications, agents, copilots, integrations or broader AI solutions, if you wish. You are of course under no obligation to take that engagement with us; the report belongs to you and is usable with any implementation partner.

Ready to embed AI structurally in your organisation?

Schedule a no-obligation intake meeting in which we discuss your situation, professional groups and objectives. You will then receive a concrete quote with course content, schedule and optional follow-up, tailored to your organisation rather than taken off the shelf.

Request a quote

Edit content