HRS-013 AI Literacy and Role-Based AI Training
Description
A training standard names the groups of people who operate, build, procure or make decisions with AI systems and states, for each group, the AI content it receives and the competences it is expected to hold. Content for every group covers what the systems in use can and cannot do, the ways their outputs go wrong, the rules for acceptable use and how to report a problem. Content for a person assigned oversight of a specific system also covers that system's performance characteristics and limits, how to interpret its outputs, the effect of automation bias on their own judgement and the technical standards relevant to the role. Training is completed before the person takes up the role and repeated at defined intervals. Completion is recorded per person and per group. The standard reaches contractors and others operating AI systems on the organisation's behalf on the same terms as employees. It is reviewed when the systems in use or the people they are used on change materially.
Rationale
HRS-004 is annual security awareness for all personnel and HRS-005 is security training for elevated security roles before production access. Neither reaches the population named here, the people who operate, build, procure or decide with AI. Neither carries AI content. HRS-013 does not repeat their content: one curriculum can satisfy all three provided the AI modules and their completion are separable in the record. AIG-022 requires oversight persons to have competencies, appropriate training and sufficient time; HRS-013 is the standard and the completion record that make that requirement testable, so the two are tested with different artefacts. AIG-002 documents who holds which role; HRS-013 documents what that role has to know. The standard has to separate the groups: a support agent using a summarisation feature and an underwriter overriding a scoring model need different content. A single module issued to everyone fails the standard for both. The obligation is one of effort rather than of outcome, so the testable claim is that the standard exists, reaches the named groups and is completed, not that any individual reached a stated level. Both seats (ADR-031).
Applicability (9 profiles)
Art.4 binds deployers directly. The oversight-role content is the deployer's for the persons it assigns under AIG-022.
Art.4 as replaced by Regulation (EU) 2026/1744 binds providers and deployers whatever the risk class, so it is live ahead of the Art.113 dates. It is a duty to take measures supporting AI literacy rather than to guarantee any level of it in an individual (ADR-025), which is why the evidence is the standard and its delivery rather than a test score. What the high-risk seat adds is a competence standard with a named object: Art.14(4) requires the persons assigned oversight to understand the system's capacities and limits, monitor for anomalies, stay aware of automation bias, interpret the output correctly and decide not to use the system or to override it. Art.14(5) requires the two verifiers of a remote biometric identification to hold the necessary competence, training and authority. The training standard therefore needs a group defined per system and not only per role band.
Art.4(1) binds providers and deployers alike, so it binds both seats and it is live now rather than from 2 December 2027 (ADR-025). At a public body the groups it reaches are wider than the operators: the persons assigned oversight under AIG-022 and the officials who take the decisions the system informs, who are the ones an Art.86(1) explanation request reaches. Art.4(1) asks for measures to support the development of AI literacy and says in terms that no specific level has to be guaranteed for any individual, so the test is the training standard and who it covers, not a competence certificate.
Framework Mappings (21)
| HRS-14 | AI Competency Training | full |
| EU-AI-Art.14.2 | Human Oversight — Capabilities Assigned to Oversight Persons | informative |
| EU-AI-Art.26.2 | Deployer Obligations — Human Oversight Assignment | informative |
| EU-AI-Art.4 | AI Literacy — Measures to Support Staff and Operator Literacy | full |
| HIPAA-164.308.a.5.i | Security Awareness and Training | informative |
| A.4.6 | Human resources | full |
| AML.M0018 | User Training | partial |
| NIS2-Art.20.2 | Management Body Cybersecurity Training | informative |
| NIS2-CIR-8.1 | Awareness Raising and Basic Cyber Hygiene Practices | informative |
| NIS2-CIR-8.2 | Security Training | informative |
| GV-2.1-003 | AI Risk Roles and Responsibilities | GV-2.1-003 | informative |
| MG-4.1-007 | Post-Deployment AI System Monitoring | MG-4.1-007 | partial |
| MP-3.4-001 | Operator Proficiency Processes | MP-3.4-001 | informative |
| MP-3.4-002 | Operator Proficiency Processes | MP-3.4-002 | partial |
| MP-3.4-003 | Operator Proficiency Processes | MP-3.4-003 | partial |
| MP-3.4-004 | Operator Proficiency Processes | MP-3.4-004 | informative |
| MS-2.6-001 | AI System Safety Risk Evaluation | MS-2.6-001 | informative |
| MS-3.3-004 | User and Community Feedback Processes | MS-3.3-004 | partial |
| GOVERN 2.2 | AI Risk Management Training | full |
| MAP 3.4 | Operator Proficiency Processes | full |
| ASI09 | Human-Agent Trust Exploitation | informative |
Evidence (3)
The AI training standard, naming the groups it covers, the content each group receives, the competences expected and the interval at which training repeats.
Example: AI Literacy and Role Training Standard v1.2, approved 9 January 2026, covering five role groups.
Test: Verify: (1) the standard names groups rather than issuing one module to everyone, (2) each group's content covers capability limits, failure modes, acceptable use and problem reporting, (3) the oversight group's content covers the system's performance characteristics and limits, output interpretation, automation bias and the standards relevant to the role, (4) the standard states that contractors and others operating AI on the organisation's behalf are covered on the same terms.
Completion export from the learning system, by person and by group, showing the module completed, the completion date and the date the person took up the role.
Example: Learning platform export ai-literacy-completions-2026-06.csv, generated 30 June 2026.
Test: Verify: (1) every person in a named group appears in the export, with the group population reconciled against the human resources system and the contractor register, (2) no person shows a completion date later than the date they took up the role, (3) no completion is older than the interval the standard sets, (4) people in more than one group show completions for each.
Oversight training record for a named production AI system, showing the content delivered, the system version it was written against and the persons who completed it before taking up oversight of that system.
Example: Oversight briefing pack for Claims Triage Engine v4, delivered 21 May 2026 to six adjusters, with attendance recorded.
Test: Verify: (1) the content names the system and its version rather than describing AI in general, (2) the performance characteristics and limits in the content match the current technical documentation for that version, (3) every person recorded as an oversight person for that system appears as having completed it, (4) where the system version changed materially, the content and the attendance were refreshed.
Questions (3)
Is there a training standard that names the groups of people who operate, build, procure or decide with AI systems?
Answer yes only where the standard distinguishes groups and sets different content for them. A single all-staff AI module, or an AI slide inside general security awareness training, is a no here.
Which of the following does your AI training cover?
The first four items apply to every group; the next two apply only to people assigned oversight of a specific system. Tick an item only where it is in the delivered content, not only in the standard.
Who does the AI training reach?
Options run from the widest reach with the strongest record to the narrowest. Contractors here means anyone operating or using AI systems on your behalf, including agency staff and outsourced operations teams.