Effective AI use requires basic knowledge. What a foundation training must cover: tailored to role, prior knowledge and context of use, as Article 4 of the AI Act (Regulation (EU) 2024/1689) requires.[4]
Without a shared basic understanding, one of two things happens in daily practice: AI is either not used at all or used uncritically. Both cost impact. For AI to create real value in healthcare, organisations need a foundation training for employees with and without prior knowledge that is tailored to role, prior knowledge and context of use.
This is not only sound pedagogy; it has been a legal requirement since 2 February 2025. Article 4 of the AI Act obliges providers and deployers to take measures to support the development of AI literacy among their staff. Since the amendment by Regulation (EU) 2026/1744 (in force since 27 July 2026), no specific level of competence is prescribed; role, prior knowledge and context of use remain decisive.[4] The European Commission's questions and answers on AI literacy state explicitly that there is no one-size-fits-all approach and that simply passing on the instructions for use is not enough.[12]
An effective foundation training therefore combines technical principles (AI/ML/Deep Learning, algorithms, foundation models) with clinical practice (fields of application, metrics, prompting), ethical principles and the legal framework (EU AI Act, GDPR, MDR/IVDR). Central to this is the understanding that AI is not a neutral tool: systems can inherit bias from data, labels, measurement processes and organisational decisions.[1,4,6-9]
The content proposed here draws on peer-reviewed reviews, international guidance and applicable EU regulation.[1,4,7,9,13-15]
Not everyone needs the same thing. Tier 1 applies to everyone, Tier 2 to everyone who works with AI outputs, Tier 3 to leadership and project ownership. The specific design follows from role, prior knowledge and the risk class of the systems in use.[4,12]
Regardless of role and prior knowledge: the shared basis.
Differentiation of terms, ML learning types (supervised/unsupervised/reinforcement), classical algorithms (decision trees to neural networks), foundation models and LLMs. Strengths and limitations in the clinical context.[2,7,9]
Fields of application from radiology and imaging through decision support, early detection and automatic coding to monitoring and genomics, each set against error risks, bias, validation limits and the hallucination risk of generative systems.[2,3,7,9]
What must not go into a freely accessible tool, purpose limitation and legal bases under the GDPR for health data, handling of unapproved tools and clear escalation routes in case of doubt.[6,9]
Transparency obligations under Art. 50 of the EU AI Act (e.g. notice when people interact directly with AI systems, labelling of synthetic content), informing patients under the GDPR and medical duties to inform, and documented separation between AI suggestion and human decision.[4,5]
Anyone who assesses AI outputs or lets them feed into decisions needs judgement, not just operating knowledge.
Trade-off between sensitivity and specificity, the importance of prevalence (base-rate problem), calibration and why models can perform significantly worse outside their training and validation context.[7,10]
Representation bias, historical bias, measurement bias, label bias and subgroup performance. XAI methods such as SHAP or Grad-CAM can support analysis and communication, but they do not replace validation, fairness testing and clinical assessment.[7,8]
Human-in-the-loop in concrete terms: recognising automation bias, being able to contradict the system with reasons, and keeping professional responsibility clearly assigned. Oversight must be defined operationally, not just on paper.[1,4,9]
Effective prompting (context, role, requesting sources, addressing uncertainty), critical review of generative outputs and separate documentation of AI recommendations and human decisions.[2,4,9]
Anyone deciding on adoption, procurement and oversight needs both the regulatory and the strategic frame.
7 EU HLEG requirements for trustworthy AI,[1] the EU AI Act with its risk-based approach, prohibited practices, high-risk obligations and transparency requirements,[4,5] GDPR for personal health data and MDR/IVDR when there is an intended medical purpose.[3,4,6] In addition, the European Health Data Space (EHDS, Regulation (EU) 2025/327) addresses the use of health data.
Four design principles (human centredness, traceability, relief, distributed control) and the three key questions before any deployment. Plus go / wait / stop as decision logic, allocation of liability and measurable KPIs for adoption.[1,7,9]
This outline addresses a practical gap in many healthcare organizations: employees who work with AI outputs or accompany AI implementation projects need basic knowledge of data quality, validation, bias, human oversight and regulatory classification. Without this knowledge, the strengths and limitations of real AI systems are difficult to assess, with consequences for patient safety, compliance and trust.[1,7,9]
The gap is documented: reviews identify the lack of standardised AI education as a key barrier to adoption and note at the same time that consistent curriculum frameworks are still missing and need to be adaptable.[14,15] Targeted training substantially improves AI knowledge and the effect is largely maintained; role-specific adoption gaps are visible in the evidence, which is a further argument against a single format for everyone.[13]
The content follows the European regulatory framework.
Unless otherwise stated, retrieved: April 2026; sources [12]–[15] retrieved in August 2026.
Note on the evidence base: reviews [13]–[15] come predominantly from nursing and medical education settings. They support the effectiveness of training and the existence of role-specific adoption gaps; transfer to industry and administrative settings is plausible but not separately evidenced.
This material was created with the greatest possible care. It is not a substitute for legal, medical or professional advice. References to the EU AI Act, GDPR and MDR/IVDR are provided for orientation and do not constitute legal advice. No guarantee for completeness or topicality.
Parts of this document were created and editorially checked with the support of generative AI. According to EU AI Act Art. 50, the use of AI is transparently pointed out.