AI Literacy Framework
How our team handles AI systems competently (Art. 4 EU AI Act).
Translation notice — The German version of this document is the legally binding original. This English translation is provided for informational purposes only. In case of any conflict between this translation and the German version, the German text shall govern. View authoritative German version.
Pursuant to Art. 4 EU AI Act, all providers and deployers of AI systems must ensure that their staff have a sufficient level of AI literacy. This document describes our framework for fulfilling that obligation.
Scope
The framework applies to all employees, working students and contractors of Provimedia GmbH who interact with Rankion AI systems — in particular Engineering, Product, Customer Success and Marketing.
Training modules
1. Onboarding training (mandatory, before first AI-system access)
- Fundamentals: what is an LLM, how do hallucinations occur, what is a prompt
- EU AI Act overview: risk classes, what Rankion is (limited-risk deployer)
- Practical risks: prompt injection, data leakage, unintended PII transfer
- Rankion-specific: which models we use, which data is sent to external LLMs
- Prohibited use cases: which applications staff must not perform with Rankion tooling
2. Annual refresh (mandatory)
- Update on regulatory changes (AI Act, GDPR interpretations, supervisory-authority guidance)
- Review of new sub-processors and their risks
- Lessons learned from incidents (internal and external)
3. Role-specific deep dive
- Engineering: secure integration of LLM APIs, prompt hardening, output filtering
- Product: AI risk-assessment methodology, sub-processor evaluation
- Customer Success: educating users about AI fallibility, incident triage
- Marketing: avoiding misleading AI claims ("AI-washing")
Documentation
Training participation is recorded in an internal tool (training date, content, quiz result with ≥ 80% passing threshold). This documentation can be presented to supervisory authorities on request (pursuant to Art. 4 + Recital 20 EU AI Act).
Responsibility
- Framework owner: Management (Provimedia GmbH)
- Operational execution: CTO / Head of Engineering
- Compliance sign-off: Data Protection Officer
Status
First version of this framework: 2026-05-03. Effective: as of publication. First full training round completed by: 2026-06-30. First refresh planned: May 2027.
Questions or audit request? trust@rankion.ai
Last update: 2026-05-03