Before the curriculum design, one legal fact that changes the sequencing: Article 4 of the EU AI Act (Regulation (EU) 2024/1689) places an AI literacy duty on providers and deployers, and a university running AI systems is a deployer. The duty runs first to “their staff and other persons dealing with the operation and use of AI systems on their behalf” — not to students. Most institutional plans invert that order.
The Article requires providers and deployers to “take measures to ensure, to their best extent, a sufficient level of AI literacy” among those people, “taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used”.
Read that last clause carefully. “The persons on whom the AI systems are to be used” is, in a university, the students. So the standard of literacy required of your staff is calibrated by the population affected by the systems — which is an unusually demanding formulation, and a useful one to quote in a committee paper.
Step 1 — Establish whether the duty applies, in writing
Owner: the data protection officer or general counsel, with the CIO. Artefact: a one-page determination.
Answer three questions and record the answers with a date: does the institution deploy AI systems; which ones and in which processes; who operates them on the institution’s behalf, including contractors and third-party services embedded in your platforms. An institution with an EU footprint should treat this as a compliance determination rather than a strategy note. An institution without one should still do it, because it produces the inventory every later step needs.
The output is not a policy. It is a list of systems and a list of people, and it is the only thing that makes the rest of the programme scopeable.
Step 2 — Sequence staff before students
Owner: the pro-vice-chancellor or provost sponsoring the initiative. Artefact: a sequenced plan with dates.
There is a compliance reason and a practical one. The compliance reason is the wording above. The practical reason is that staff decide what students may do: a marker who cannot articulate what is permitted cannot enforce it consistently, and inconsistent enforcement is what generates appeals.
Students themselves report the gap. Across the published sector surveys, a substantial minority say they are unclear whether their institution encourages AI use at all, and the split runs roughly evenly among students at the same institutions — a communication finding rather than an attitude finding. The detail and the caveats are in our reading of what the student AI use numbers actually measure.
Step 3 — Segment by exposure, not by faculty
Owner: the programme lead. Artefact: an audience matrix.
Faculty-based segmentation produces a curriculum nobody needs. Exposure-based segmentation produces four or five short, distinct programmes:
- Markers and assessors — what a detection output can and cannot support, and what to record when raising a concern.
- Research supervisors — what to approve, how to document approval, what the candidate must be able to defend orally.
- Admissions and student casework staff — automated decision-making, bias, and the routes a decision must remain contestable through.
- Professional services using AI in operations — data handling, what may be pasted where, and the sub-processor question.
- Students — see step 5.

Step 4 — Write outcomes as acts, not as awareness
Owner: curriculum lead with the writing centre. Artefact: an outcomes list, one line each.
“Understands the limitations of generative AI” is not assessable and produces no evidence. “Can identify three failure modes in a generated literature summary and state which require checking against the source” is both.
Five outcomes that carry most of the value in higher education:
- Verification. Can resolve a generated reference against the actual record and can state what to do when it does not resolve.
- Attribution. Can describe and cite a tool’s contribution in the form the institution requires.
- Boundary. Can state, for their own programme, what requires prior approval and from whom.
- Data. Can say what must never be pasted into a third-party service — participant data, unpublished work of others, personal data.
- Limits of inference. Can explain why a detection score is not proof, which prevents both over-trust and over-fear.
Outcome five is the one that quietly reduces caseload, because it changes how a concern is raised in the first place. Its substance is in our note on how plagiarism detection and AI detection differ.
Step 5 — Embed the student programme, do not bolt it on
Owner: programme directors. Artefact: a curriculum map.
A standalone AI literacy module competes for credit and loses. Three placements work reliably: induction for the boundary and data outcomes; the first research-methods module for verification and attribution; and the dissertation or thesis briefing for the disclosure requirement. Each is fifteen to forty minutes of contact time, not a course.
Discipline-specific delivery beats a central module on every measure except cost. Where cost forces a central module, make the examples discipline-specific even if the delivery is not.
Step 6 — Fix the tooling question before the teaching
Owner: CIO with procurement. Artefact: a named, supported toolset.
Teaching people to use tools the institution does not provide has a predictable outcome: they use consumer services, on consumer terms, invisibly. A literacy programme without a provided tool trains students to be careful somewhere you cannot see, which is a worse position than before the programme.
Sector surveys show provision lagging student expectation by a wide margin, and the gap has an equity dimension: where capability is bought privately, attainment becomes partly a function of household budget. What that looks like operationally is covered in the AI use your institution cannot see.

Step 7 — Align the curriculum with the policy, in both directions
Owner: academic registrar. Artefact: a cross-reference table.
Every literacy outcome should point at a policy clause, and every policy clause that imposes a student obligation should point at where that obligation is taught. Clauses with no teaching are unenforceable in practice; teaching with no clause is advice. The component list to map against is in what a university AI policy should include.
Step 8 — Generate the evidence as you go
Owner: programme lead. Artefact: a completion and version log.
Article 4 requires measures taken “to their best extent”. That is a proportionate standard, and a proportionate standard is demonstrated by records: who was trained, when, on what version of the material, and what changed at each revision. Retain the materials themselves, not just attendance — a training record without the content it delivered proves attendance at something unspecified.
Step 9 — Review on the system inventory, not the calendar
Owner: the step 1 owner. Artefact: a change-triggered review.
Annual review is the default and it is the wrong trigger. The right trigger is a change to the inventory: a new system deployed, an existing system gaining a new capability, or a supplier withdrawing a product. That last case is not hypothetical — a widely used integrity product was withdrawn in 2026, which invalidated training material at institutions that named it.
What this costs, honestly
The staff programme is the expensive half, because it consumes academic time. The realistic first-year shape is: one determination, four short staff programmes of ninety minutes each, three embedded student touchpoints, and a records system. Nothing on that list requires new headcount; all of it requires someone senior to own the sequencing.
The cheapest way to test the design before committing the institution is to run it in one department alongside a platform pilot, which produces both the training evidence and the usage evidence at the same time — the method is in our guide to running a departmental pilot.
To discuss what the provided-tool half of this looks like at your institution, request an institutional evaluation.
Frequently asked questions
Does the EU AI Act require universities to teach AI literacy?
Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy among their staff and others operating AI systems on their behalf. A university deploying AI systems is a deployer.
Does the duty cover students?
Its direct object is staff and those operating systems on the deployer’s behalf. Students appear in the scoping clause as the persons on whom the systems are used, which calibrates the standard required of staff.
Does it apply outside the EU?
Institutions should take advice on their own footprint. Regardless of jurisdiction, the inventory and records the Article implies are good practice and are what a governing body will ask for.
Where should we start?
With a written determination of which AI systems you deploy and who operates them. Everything else is scoped from that list.
Staff or students first?
Staff. The duty names them first, and they set what students are permitted to do.
Should this be a standalone module?
Rarely. Embedded delivery at induction, in research methods and at the thesis briefing survives timetabling pressure; a standalone module usually does not.
How do we make outcomes assessable?
Write each outcome as an act performed in a role rather than as awareness of a topic.
What evidence should we keep?
Who was trained, when, on which version of the material, and the materials themselves. Attendance alone proves attendance at something unspecified.
How often should the programme be reviewed?
On change to the system inventory rather than annually. A withdrawn product or a new capability invalidates material faster than a calendar does.
Do we need to provide tools as well as training?
If you do not, you are training people to use consumer services on consumer terms, outside your visibility.
Who should own the programme?
An academic owner accountable for assessment outcomes, with the DPO and CIO supporting. Ownership by IT alone produces a systems briefing rather than a curriculum.
How long does the staff programme take?
Ninety minutes per audience segment is a realistic first pass, with the marker and supervisor segments taking priority.
