Buyer's standard

The AI Literacy Program Standard: the questions to ask before you buy or assign one

By Lindsay Hiebert, CISSP · Founder, PIGENAI LLC
· 7-minute read
Card: The AI Literacy Program Standard, with a clipboard checklist beside a verification record

The market for AI-literacy training describes itself the same way from every direction: modules, certificates, "compliant", "aligned with the EU AI Act". None of that can be compared, because none of it is a claim about anything you can check.

This is a standard instead. A set of questions to put to any AI-literacy program, ours included, grouped by what they test for. It names no vendor and ranks nothing. At the end we score the Academy against every question in full, with the places it falls short in bold, because a standard its author will not be measured by is a brochure.

If you are a compliance officer, ask these before you sign. If you are a training director, a dean or an HR lead, ask them before you assign anything to a room of people, because they will hold you to the answers.

One sentence to keep: a certificate records who attended. It cannot tell you who is competent, and it cannot be checked by anyone who was not in the room.

Legal basis

1. Which obligation is the program built to, and does the vendor say what that obligation does not require?

Name the instrument and the article. Article 4 of the EU AI Act, as replaced by Regulation (EU) 2026/1744 on 27 July 2026, asks providers and deployers to take measures to support the development of AI literacy of their staff, taking account of their role and the context, and states that it does not require any specific level of AI literacy of any individual. The European Commission's guidance on Article 4 says no certificate is needed and an internal record of training suffices. A vendor who tells you the law requires a certificate, a test or a score is not reading the text. Ask them to show you the article.

2. What happened in the program when the text changed, and is the change dated where you can see it?

The obligation was rewritten this summer. Ask what the vendor changed in response and on what date. A program that cannot show a dated change through the period when the law moved was not being maintained when maintenance mattered.

Provenance

3. Does every question cite the source its answer rests on, and can you open that source?

Not the vendor's own explanation. The regulation, the standard, the guidance or the reference text the answer comes from. A citation turns an answer key into something a learner, a manager or an auditor can check. Without it, a dispute between a learner and the program has no referee.

4. What does the vendor do when a source shows they were wrong, and where is the correction recorded?

Every question bank has errors. Ask for the most recent correction, what it was checked against, and where it is dated. A vendor who has never found an error in their own bank has never looked.

Role fit

5. Is the curriculum by role, and does the instruction know which role it is teaching?

Article 4 asks for measures that take account of the person's role and the context. One course for everyone is the shape that ignores that sentence. Ask which roles the program names, what differs between them, and whether the tutor or instructor knows which one it is addressing.

Measurement

6. Is the method stated in advance: what is tested, how it is scored, what passes, and does the same set of answers always produce the same result?

A stated method can be checked. Ask whether a model is anywhere in the scoring path, whether the pass threshold is written down before the sitting, and whether a second marking of the same answers would produce the same number.

7. Can a learner or a manager see which topics were weak, not just the total?

An overall percentage hides the topic that matters. Ask what is shown after a sitting, to whom, and whether a manager can see anything at all.

8. Does the vendor claim the result predicts anything beyond what was answered?

A knowledge test shows what a person answered against a bank on a date. Ask whether the vendor claims it predicts compliance, prevents harm or satisfies a regulator. The honest answer is that it does not, and a vendor who says otherwise is selling you a number.

Proof

9. Can a third party open a person's record without an account, without a PDF, and without trusting the vendor? What does the record contain, and what does it leave out?

Ask for a live sample and open it yourself before you buy. Then ask what the record deliberately does not show, because a record that shows everything is a privacy problem, and a record that shows nothing is a badge.

10. Can the record expire or be withdrawn, and does the verifier see that?

Rules change and people leave. Ask what happens to a record after the validity period and after a withdrawal, and whether someone opening the link would know.

Instruction

11. Is instruction available while the person studies, is it constrained to the cited source, and are its limits stated before purchase?

If there is an AI tutor, ask what it is allowed to draw on, whether it can see or influence the exam, and how much of it a seat may use each month. Limits are fine. Unstated limits are not.

Administration and privacy

12. What personal data does the program hold, where is that stated, what does an administrator see, and what happens to a record when a seat changes hands?

For an organisation this is the question the compliance office will ask you. Ask for the page that lists the data held, the exact administrator view, and whether reassigning a seat touches the departing person's record.


How the Academy measures against it

We built SanctumShield Academy, so this is not a neutral scoring. It is an honest one, and the shortfalls are in bold with the rest. Every row is something you can confirm by opening the Academy.

#QuestionWhere the Academy stands
1Legal basisBuilt to Article 4 of the EU AI Act as replaced by Regulation (EU) 2026/1744, which asks for measures that support AI literacy by role and context and requires no specific level of any individual. We state on the pricing page and in the credential that this is knowledge certification by examination, and we make no compliance claim. Whether an organisation's measures are adequate is a judgment for that organisation and its counsel.
2Rule changesRegulation (EU) 2026/1744 entered into force on 27 July 2026. The Academy's superseded-claims guard was updated on 14 September 2026 for the new dates, and the July post on this blog carries a dated note as of 24 September 2026 saying it quotes the 2024 wording. The tutor's canon and the pricing page still use phrasing written to the 2024 text; that is stated here, dated, rather than hidden.
3CitationsEvery one of the 210 questions served across the 5 role exams carries a source reference into the AI Governance 101 Field Guide or the public glossary, and the build refuses a reviewed item without one. The Field Guide is the course reading, open to every enrolled learner. Item-by-item review by the founder is in progress and is not yet recorded on the items themselves.
4CorrectionsRecorded as dated changes in the repository, with a regression guard added when a claim is superseded (most recently 14 September 2026, the Digital Omnibus publication status). There is no public corrections page yet; a reader sees a dated note on the affected post, not the log.
5Role fit5 tracks, named on the curriculum page: Board & CEO, CISO / Security Leader, CTO / CIO / IT, Legal / Compliance, Employee Essentials. Each has its own module list from the 19 modules and its own exam. The tutor takes the learner's role and teaches within that track's modules.
6MethodTimed, per track. Score is correct answers over total; "select all that apply" items are all-or-nothing. 80% passes, 92% earns Distinction. No model is in the scoring path; the same answers always produce the same result, and a stored seed lets the server re-derive the served order rather than trust the browser. Retakes after 24 hours.
7TopicsShortfall. A learner sees a percentage and a count, not the correct answers and nothing per topic. A manager sees nothing. And each sitting serves the track's whole bank in a new order, so a retake presents the same questions reordered.
8PredictionNone. The record states what a person answered against a cited bank on a date. The credential page says "knowledge certification via a randomized, timed, deterministic examination, not an identity-proofed proctored credential", and we do not claim it predicts compliance or satisfies a regulator.
9ProofOpen a record with no account: status, track, result band, issue and expiry dates, content version, a SHA-256 fingerprint of the record, and the holder's name when they chose to show it. Not shown: the score, the questions, the email. A JSON version sits at the same id under /api/verify/credential/. Shortfall. The page invites you to recompute the fingerprint from a downloaded JSON, and there is no download; the public JSON leaves out fields the fingerprint covers, so a stranger cannot recompute it today. The fingerprint and the server-side signature let the Academy detect a changed record; a third party can check the status, not the arithmetic.
10ExpiryValid for 3 years from issue; the page computes expiry when opened and shows "expired". A "revoked" status exists and would show the same way; withdrawing a record is an operator action with no self-serve process.
11InstructionA tutor is available throughout the course, not attached to exam questions. It is grounded in retrieved passages of the course corpus, told to answer from them and to cite the module, and told that it cannot see, rehearse or score the exam. It asks its own questions and marks a progress map that records, but does not certify. Voice read-aloud is included. The monthly message allowance per plan is stated on the pricing page before purchase.
12AdministrationShortfall. The Team page shows seat emails and add or revoke, up to 10 seats. It shows no pass state, no credential list and no results; a manager learns who passed by asking for the link. Revoking a seat ends tutor and exam access at once and leaves the credential and its public link untouched. The data held is an email address, per-message tutor counts, module progress, exam attempts with the answers given, and the credential record; tutor conversations are not stored, which the tutor page states. There is no single Academy page that lists this; the footer links to the SanctumShield trust page.

Take the questions into any evaluation. If a program answers all of them well, use it, whoever makes it.

Canonical: https://academy.sanctumshield.com/blog/ai-literacy-program-standard. Copies on other platforms link back here. SanctumShield Academy is operated by PIGENAI LLC. All posts →

The AI Literacy Program Standard: the questions to ask before you buy or assign one — SanctumShield Academy