GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-013 AI Literacy and Role-Based AI Training

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A training standard names the groups of people who operate, build, procure or make decisions with AI systems and states, for each group, the AI content it receives and the competences it is expected to hold. Content for every group covers what the systems in use can and cannot do, the ways their outputs go wrong, the rules for acceptable use and how to report a problem. Content for a person assigned oversight of a specific system also covers that system's performance characteristics and limits, how to interpret its outputs, the effect of automation bias on their own judgement and the technical standards relevant to the role. Training is completed before the person takes up the role and repeated at defined intervals. Completion is recorded per person and per group. The standard reaches contractors and others operating AI systems on the organisation's behalf on the same terms as employees. It is reviewed when the systems in use or the people they are used on change materially.

Rationale

HRS-004 is annual security awareness for all personnel and HRS-005 is security training for elevated security roles before production access. Neither reaches the population named here, the people who operate, build, procure or decide with AI. Neither carries AI content. HRS-013 does not repeat their content: one curriculum can satisfy all three provided the AI modules and their completion are separable in the record. AIG-022 requires oversight persons to have competencies, appropriate training and sufficient time; HRS-013 is the standard and the completion record that make that requirement testable, so the two are tested with different artefacts. AIG-002 documents who holds which role; HRS-013 documents what that role has to know. The standard has to separate the groups: a support agent using a summarisation feature and an underwriter overriding a scoring model need different content. A single module issued to everyone fails the standard for both. The obligation is one of effort rather than of outcome, so the testable claim is that the standard exists, reaches the named groups and is completed, not that any individual reached a stated level. Both seats (ADR-031).

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredrole duty

Art.4 binds deployers directly. The oversight-role content is the deployer's for the persons it assigns under AIG-022.

GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredrisk class duty

Art.4 as replaced by Regulation (EU) 2026/1744 binds providers and deployers whatever the risk class, so it is live ahead of the Art.113 dates. It is a duty to take measures supporting AI literacy rather than to guarantee any level of it in an individual (ADR-025), which is why the evidence is the standard and its delivery rather than a test score. What the high-risk seat adds is a competence standard with a named object: Art.14(4) requires the persons assigned oversight to understand the system's capacities and limits, monitor for anomalies, stay aware of automation bias, interpret the output correctly and decide not to use the system or to override it. Art.14(5) requires the two verifiers of a remote biometric identification to hold the necessary competence, training and authority. The training standard therefore needs a group defined per system and not only per role band.

Public Body Deployer (EU)stablerequiredrole duty

Art.4(1) binds providers and deployers alike, so it binds both seats and it is live now rather than from 2 December 2027 (ADR-025). At a public body the groups it reaches are wider than the operators: the persons assigned oversight under AIG-022 and the officials who take the decisions the system informs, who are the ones an Art.86(1) explanation request reaches. Art.4(1) asks for measures to support the development of AI literacy and says in terms that no specific level has to be guaranteed for any individual, so the test is the training standard and who it covers, not a competence certificate.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (21)

HRS-14AI Competency Trainingfull
EU-AI-Art.14.2Human Oversight — Capabilities Assigned to Oversight Personsinformative
EU-AI-Art.26.2Deployer Obligations — Human Oversight Assignmentinformative
EU-AI-Art.4AI Literacy — Measures to Support Staff and Operator Literacyfull
HIPAA-164.308.a.5.iSecurity Awareness and Traininginformative
A.4.6Human resourcesfull
AML.M0018User Trainingpartial
NIS2-Art.20.2Management Body Cybersecurity Traininginformative
NIS2-CIR-8.1Awareness Raising and Basic Cyber Hygiene Practicesinformative
NIS2-CIR-8.2Security Traininginformative
GV-2.1-003AI Risk Roles and Responsibilities | GV-2.1-003informative
MG-4.1-007Post-Deployment AI System Monitoring | MG-4.1-007partial
MP-3.4-001Operator Proficiency Processes | MP-3.4-001informative
MP-3.4-002Operator Proficiency Processes | MP-3.4-002partial
MP-3.4-003Operator Proficiency Processes | MP-3.4-003partial
MP-3.4-004Operator Proficiency Processes | MP-3.4-004informative
MS-2.6-001AI System Safety Risk Evaluation | MS-2.6-001informative
MS-3.3-004User and Community Feedback Processes | MS-3.3-004partial
GOVERN 2.2AI Risk Management Trainingfull
MAP 3.4Operator Proficiency Processesfull
ASI09Human-Agent Trust Exploitationinformative

Evidence (3)

policydocumentmanual

The AI training standard, naming the groups it covers, the content each group receives, the competences expected and the interval at which training repeats.

Example: AI Literacy and Role Training Standard v1.2, approved 9 January 2026, covering five role groups.

Test: Verify: (1) the standard names groups rather than issuing one module to everyone, (2) each group's content covers capability limits, failure modes, acceptable use and problem reporting, (3) the oversight group's content covers the system's performance characteristics and limits, output interpretation, automation bias and the standards relevant to the role, (4) the standard states that contractors and others operating AI on the organisation's behalf are covered on the same terms.

system_exporttechnicalautomated

Completion export from the learning system, by person and by group, showing the module completed, the completion date and the date the person took up the role.

Example: Learning platform export ai-literacy-completions-2026-06.csv, generated 30 June 2026.

Test: Verify: (1) every person in a named group appears in the export, with the group population reconciled against the human resources system and the contractor register, (2) no person shows a completion date later than the date they took up the role, (3) no completion is older than the interval the standard sets, (4) people in more than one group show completions for each.

recorddocumentmanual

Oversight training record for a named production AI system, showing the content delivered, the system version it was written against and the persons who completed it before taking up oversight of that system.

Example: Oversight briefing pack for Claims Triage Engine v4, delivered 21 May 2026 to six adjusters, with attendance recorded.

Test: Verify: (1) the content names the system and its version rather than describing AI in general, (2) the performance characteristics and limits in the content match the current technical documentation for that version, (3) every person recorded as an oversight person for that system appears as having completed it, (4) where the system version changed materially, the content and the attendance were refreshed.

Questions (3)

boolean

Is there a training standard that names the groups of people who operate, build, procure or decide with AI systems?

Answer yes only where the standard distinguishes groups and sets different content for them. A single all-staff AI module, or an AI slide inside general security awareness training, is a no here.

multi

Which of the following does your AI training cover?

What the AI systems in use can and cannot doThe ways their outputs go wrongThe rules for acceptable use of AI systemsHow to report a problem with an AI systemFor oversight persons, the specific system's performance characteristics and limitsFor oversight persons, the effect of automation bias on their own judgementThe technical standards relevant to the roleNone of the above

The first four items apply to every group; the next two apply only to people assigned oversight of a specific system. Tick an item only where it is in the delivered content, not only in the standard.

select

Who does the AI training reach?

Employees and contractors operating AI on your behalf, on the same terms, with completion recorded for bothEmployees and contractors, with completion recorded for employees onlyEmployees only, with completion recordedEmployees only, with no completion recordNo AI training is delivered

Options run from the widest reach with the strongest record to the narrowest. Contractors here means anyone operating or using AI systems on your behalf, including agency staff and outsourced operations teams.