Lecturer teaching AI literacy, AI governance and auditing neural networks

AI Literacy under Article 4 of the EU AI Act

Using artificial intelligence competently, securely and responsibly

Artificial intelligence is changing workflows, decision-making processes and control environments. Alongside opportunities for more efficient processes, this creates new requirements for the competent and responsible use of AI systems.

Article 4 of Regulation (EU) 2024/1689 – the EU Artificial Intelligence Act – requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and other persons dealing with the operation and use of AI systems on their behalf. This requirement has applied since 2 February 2025.

The measures must take account of, in particular:

  • the technical knowledge and experience of the persons concerned,
  • their education and previous training,
  • the context in which the AI systems are to be used, and
  • the persons or groups of persons on whom the AI systems are to be used.

Article 4 does not prescribe a uniform standard course. The content and depth of appropriate competence measures should reflect the AI systems used, the responsibilities of the staff involved and the associated risks.

Official text of Regulation (EU) 2024/1689

AI literacy goes beyond learning how to operate a tool

Competent use of AI requires staff to understand not only its technical possibilities but also its limitations, sources of error and risks.

Depending on the target group and use case, our training covers:

  • fundamentals and operating principles of generative AI,
  • requirements of the EU AI Act,
  • roles and responsibilities when using AI systems,
  • data protection, confidentiality and information security,
  • possible errors, hallucinations and bias in AI output,
  • secure and purposeful prompting,
  • critical review and validation of results,
  • copyright and organisational considerations,
  • AI governance, internal policies and controls,
  • applications of AI in internal audit and IT audit, and
  • auditing and documenting AI-supported processes.

For a transparent implementation, organisations should appropriately document target groups, learning objectives, training content, participation and required updates.

Practical experience in internal audit, IT audit and AI governance

Andreas H. Schmidt LL.M. speaking at a professional conference
Andreas H. Schmidt LL.M. speaking at a professional conference

Andreas H. Schmidt LL.M., Managing Director of Collegium Auditores GmbH, lectures for professional institutes and training providers, including the German Institute of Internal Auditors (DIIR), Haub + Partner, Management Circle and the ISACA Germany Chapter.

His training is primarily aimed at internal auditors from companies in different industries and from the public sector. The seminars combine regulatory requirements with practical use cases, audit experience and exercises.

A particular focus is how AI systems can be used responsibly, integrated into existing governance structures and appropriately assessed by internal audit or IT audit.

Main training topics

AI literacy under Article 4 of the EU AI Act

Participants gain a practical understanding of the AI Act’s requirements. They learn how to assess the opportunities and risks of AI systems, critically review their output and use AI applications while respecting data protection, information security, confidentiality and internal policies.

AI in internal audit

This seminar presents practical applications of ChatGPT and other AI tools in internal audit. Topics include support for audit planning, risk assessment, data analysis, documentation and reporting, together with relevant limitations and control requirements.

ChatGPT & Co. – AI in Internal Audit at Haub + Partner (German-language seminar)

Auditing cybersecurity management

Cybersecurity is not solely a technical responsibility. This seminar provides a foundation for risk-based audits of governance, responsibilities, safeguards, monitoring and response capabilities.

Foundation Seminar on Auditing Cybersecurity Management at DIIR (German-language seminar)

Project assurance for IT and AI implementation projects

IT and AI projects may create significant strategic, organisational, technical and regulatory risks. Early project assurance enables internal audit to identify material risks and control weaknesses while the project is still under way.

Project Assurance – Supporting IT and AI Implementation Projects through Internal Audit at DIIR (German-language seminar)

Additional audit competence under Section 39 BSIG

The ISACA Germany Chapter certificate course provides additional audit competence for preparing and performing evidence procedures under Section 39 of the German Federal Office for Information Security Act (BSIG). It is particularly relevant for internal auditors, professional auditors, public accountants with IT audit experience, staff of critical infrastructure operators and auditing bodies.

Topics include the legal framework, identification of critical infrastructures, audit preparation, foundational testing, design and operating effectiveness testing, audit reporting and evidence. The official event page identifies Andreas H. Schmidt LL.M. as the instructor.

Additional Audit Competence under Section 39 BSIG at the ISACA Germany Chapter (German-language course)

Training for your organisation

In addition to open seminars, we offer organisation-specific training and workshops on request. Content, examples and exercises are tailored to your organisation, the AI systems used and the responsibilities of the relevant target groups.

Potential target groups include:

  • internal audit and IT audit,
  • compliance and risk management,
  • data protection and information security,
  • specialists and managers,
  • project managers, and
  • staff who use AI systems or assess their output.

Contact us

Would you like to develop AI literacy under Article 4 of the EU AI Act or create a training programme tailored to your organisation?

We can support you in defining appropriate target groups, learning objectives and training content.

office(at)collegium-auditores.de