AI Literacy - Role-based training: marketing, sales, HR, and finance
Your company finally decides: we need AI training. HR director sends a memo, one session, 90 minutes, everyone together. The lawyer and the salesperson in the same room. The finance technician gets the same material as the designer. Result: nobody learns what they need.
The reason is simple. A copywriter using ChatGPT for brainstorming needs to know something completely different from the accountant using Claude to analyse invoices. The risks aren't the same. The tools they touch are different. Neither is the depth of technical knowledge required.
The AI Act Article 4 is clear on this: "proportionality". The law doesn't ask for a 40-hour certificate for everyone. It asks that each role knows the bare minimum needed to avoid breaking things.
Here are those minimums. Four roles, four distinct risks, four checklists you can pull out at audit time.
Marketing: ideation, copywriting, images, SEO
Marketing teams are heavy users. They run dozens of prompts a month. ChatGPT, Gemini, Claude. They generate copy, break down ideas, test headlines, sometimes generate images.
Real cases:
Copywriting: Carmen is an SEM specialist. She uses ChatGPT for headline brainstorming. She asks for "50 variations on titles for an ebook about liability insurance". Reviewable, useful, zero risk if she doesn't upload actual client data.
Campaign ideation: The content team puts a full brief into ChatGPT: "We're an estate agent, we sell flats ranging from €300k to €800k in Madrid, audience is aged 40–55, all executives". Next project, ChatGPT remembers that data. Risk: someone queries from home on a cafe WiFi with the company laptop.
SEO writing: Jorge uses Claude to structure a 2,000-word article. He uploads the keyword "house mortgages new builds Madrid", the outline, two case studies. Claude analyses, structures, suggests in two minutes. Jorge then rewrites it with his own examples. Efficient. No technical risk.
Image generation: Design uses Gemini or Midjourney to prototype mockups before hiring a freelancer. ChatGPT doesn't generate images, nor does Claude. Gemini does. Risk: copyright. If you upload a client logo to Gemini to "vary it", that logo enters Google's training data.
Specific risks:
Image copyright. Using image generators (Midjourney, DALL-E, Gemini Images) to create variations of existing design can breach rights. A campaign with 50 AI-generated images you sell as your own work: legal risk if ownership isn't clear.
Plagiarism and attribution. ChatGPT generates text statistically, not from imagination. If you ask for "200 words on Spain's housing crisis", it might reconstruct passages similar to published articles. Not word-for-word copying. Plausible. Not necessarily legal if you don't verify.
Data accuracy. The biggest risk in marketing with AI: hallucinations. ChatGPT generates false data with confidence. If you ask "market share of Spanish telecoms in 2025" for a competitive report, ChatGPT gives a figure. It doesn't know it. If that figure makes it into your pitch deck and the client catches it, you lose credibility.
Privacy policies breached. If you upload a client list (names, emails, sectors) for ChatGPT to segment it, you breach GDPR without explicit consent. Free tools train on what you upload.
Brand changes without review. ChatGPT rewrites existing text, shifts tone without warning, drops important information, adds data that sounds good but you didn't verify. Published unreviewed: problem on social media.
Verification checklist:
- Every team member knows what information is safe to upload (briefs, keywords, structure). What isn't: client data, contracts, sales figures.
- The team understands what a hallucination is. ChatGPT doesn't search the internet (except Plus with web search turned on). If you ask for "latest news on X company", ChatGPT makes it up.
- Internal policy exists: which tools are permitted (ChatGPT, Claude, Gemini yes; Midjourney only for internal mockups, not for publishing without legal review).
- Everyone reviews AI output before publishing. Not optional. Minimum: read once, verify figures if any, check brand changes.
- AI-generated images are marked as such if published, or reworked so they don't look human-made (transparency requirement in some contexts).
- If you publish AI-generated copy, at least one touchpoint is reviewed by a person (don't automate publishing).
Marketing training: 45 minutes.
- 10 minutes: what an LLM is, how it works, why it hallucinates.
- 15 minutes: tools your team uses (ChatGPT, Claude, Gemini). Practical differences.
- 10 minutes: sector-specific cases. "If we're writing about insurance, what risks does ChatGPT carry?" Cases from your projects, not generic.
- 10 minutes: internal policy. What yes, what no. Concrete examples.
- Material: checklist above, printed or in shared Notion.
Sales: research, proposals, email, call prep
Salespeople use AI differently than marketers. Not to create, but to speed up repetitive work. Lead research, proposal writing, call preparation. The tool changes too: often it's a CRM with integrated AI (HubSpot AI, Pipedrive, Salesforce Einstein), not ChatGPT.
Real cases:
Lead research: Sergio is a software salesman. He gets a list of 20 leads from marketing. In Pipedrive, there's a "Resume prospect" button. Pipedrive pulls from LinkedIn, the company website, recent news, CRM notes, generates a paragraph: "This company merged three months ago, expanded the IT team, likely budget €50k–€100k". Saves 20 minutes. But Sergio believes it unverified: the company didn't merge, it expanded. He sends a proposal to an IT team that doesn't exist. Wasted time, bad impression.
Meeting prep: Paula is an account manager. She has a video call with a client in 30 minutes. She uploads the previous contract, recent conversations, rejected proposals to Claude. She asks for "key points to discuss today". Claude summarises, gives context, suggests angles. Paula enters the call better prepared. Zero risk.
Proposal writing: Manuel writes sales proposals. Copilot in Word helps: he writes half, Copilot completes sentences, suggests paragraphs. In 40 minutes he has a draft. He reviews, adjusts figures, personalises. Proposal done. But if he doesn't review properly: promises capabilities you don't have (hallucination), wrong figure that doesn't match your price list, timings that aren't realistic.
Email sequences: The CRM suggests templates for each stage. "If the client opened email 1 three days ago and didn't reply, send email 2". The template is AI-made. Generic. Sounds like bulk mail. If Sergio sends it as is: lower response rate.
Specific risks:
Client data in public tools. This is the big one. A salesman uploads a spreadsheet with 50 clients, name, email, phone, annual purchase quota, to ChatGPT for "automatic segmentation". That data enters OpenAI's training set. GDPR: fine. Client contract: breach. Reputation: lost.
Hallucinated figures. "What's the price of our premium package?" The salesman asks ChatGPT with no context. ChatGPT generates a figure. If you haven't documented the actual price internally (usually negotiated per account), he quotes it in a proposal. Client checks, sees inconsistency, sees you as sloppy.
Unwarranted promises. ChatGPT writes "our system processes 10,000 transactions per second with 99.99% uptime". Sounds credible. A salesman puts it in a proposal without technical validation. Client signs, then discovers the max is 5,000 transactions. Contractual breach.
Data loss in syncs. Some CRMs with integrated AI push your data to the vendor's cloud. If the vendor (HubSpot, Salesforce) lacks client data encryption or has unclear privacy terms, it's a compliance issue.
No review on automatics. If you set email sequences the CRM sends automatically based on AI triggers (client opened email twice = fire email 3), and you don't check what email 3 says, you might be sending outdated or wrong content at scale.
Verification checklist:
- Nobody uploads client data (names, phones, emails, purchase history) to ChatGPT, Gemini, or public tools. Non-negotiable. If you need AI to process client data, use enterprise tools with privacy contracts.
- The team knows what a hallucination is. And that a hallucination in sales is a broken promise. Example: "ChatGPT said we can handle 100k transactions, so we put it in the proposal". Not without technical validation.
- Figures (prices, volumes, timelines) are validated against internal sources. If a salesman drafts a proposal with AI help, someone reviews before sending.
- CRM tools you use have acceptable privacy terms. If using HubSpot, Pipedrive, or Salesforce, verify they don't train on your data or have a contract forbidding it.
- Email sequences on automation are reviewed before activation. Minimum: one person reviews the draft for each stage.
- The sales team has a list of "what to ask AI" vs "what not to". "Summarise this contract": yes. "What's the price of our premium package?": no, ask finance.
Sales training: 50 minutes.
- 5 minutes: what a hallucination is and why it matters in sales. One example: "ChatGPT said we can deliver in 3 weeks, but your timeline is 6. The proposal loses credibility".
- 15 minutes: tools the team uses (ChatGPT, HubSpot AI, Pipedrive, Copilot). What each does well, what risks.
- 10 minutes: data policies. What data is public and safe to upload (sector, website), what isn't (client name, purchase history).
- 15 minutes: hands-on exercise. Draft a proposal with AI help, then review together what you'd change (false figures, unvalidated promises, wrong tone).
- Material: "5 real risks we've seen", checklist template before sending proposals.
HR: CV screening, job ads, feedback, onboarding
HR uses AI for bulk admin work. CV filtering, job description writing, candidate analysis, automatic feedback, onboarding. The risk is different: bias, GDPR, algorithmic discrimination.
Real cases:
CV screening: A company gets 300 applications for one role. It uses an AI bot (ATS with automatic screening, like Workable or Talenteria) that scores CVs. The bot flags as "suitable" any CV mentioning "elite universities" or "Fortune 500 companies". A CV from someone trained through hands-on work, 15 years in SMEs: low score. Systematic bias. If that person was the best but didn't pass the filter: indirect discrimination.
Job ad writing: HR uses ChatGPT to write a job description. ChatGPT generates: "We're seeking a dynamic, energetic, young-at-heart developer ready to take on bold challenges". That's indirect age discrimination. It doesn't say "under 35", but the language implies it. A labour inspector sees it. Legal risk.
Candidate analysis: Claude is used to "assess cultural fit". You give CV plus company values, Claude writes a paragraph: "Candidate shows strong results focus, might tend to skip processes". Nice. But: what data did it use? Is that a hallucination? And the candidate has a right to know how they were evaluated.
Performance feedback: Automatic system: employee takes assessment in app, chatbot adds up responses, generates feedback: "Poor communication performance. Recommendation: training". No context, no supervisor nuance. The employee gets that as gospel truth. Demoralised.
Onboarding: New employee gets AI-made material about "company culture", tasks, processes. It's generic (made by AI with no real company context). Ineffective onboarding. Plus: if the new hire is from another country (foreign national), the AI material might carry cultural insensitivity.
Specific risks:
Algorithmic bias in selection. AI algorithms train on historical data. If your company historically hired more men in tech roles, the algorithm learns it and repeats. Woman with perfect CV: low score. Discrimination. Illegal in Europe (Directive 2000/78/EC, against LGBTQ+ discrimination, age, origin).
GDPR breached. An AI tool analyses CVs, saves candidate data, processes it without explicit consent or keeps it longer than necessary (should be: only during the selection process). Rejected candidate: right to have their data deleted. If the AI tool keeps it "for future campaigns", breach.
Right to explanation violated. Candidate rejected by an AI system. They ask: why? Company: the algorithm decided. Not sufficient. GDPR article 22 and AI Act article 86 require intelligible explanation if a decision is automated. "The algorithm" isn't an explanation.
Indirect discrimination in language. Job description made by AI saying "young and dynamic" (age), "native Spanish speaker" (origin), "willing to work 50-hour weeks" (gender discrimination, disproportionately affects carers). Illegal.
Unvalidated evaluation data. An AI system analyses employee interactions (emails, meetings, task timeline) to "measure performance". Without validation: conclusions based on noise (someone sent fewer emails because they were on leave, the algorithm marks them as unproductive).
Verification checklist:
- If using automatic CV screening, a human reviews borderline cases. If a candidate scored in the top 5% but the algorithm marked them "unsuitable", investigate why.
- Job descriptions made by AI are reviewed for bias. Forbidden: age words ("young", "dynamic", "digital native"), gender words ("ambitious", "aggressive"), origin words ("native"), or indirectly discriminatory requirements.
- Candidate analysis tools document what criteria they use. Not "the AI decided", but "AI analysed these dimensions: experience in similar role, listed technical skills, average tenure in previous roles".
- Candidates rejected by automatic systems have right to human review if they request it.
- Candidate data is deleted after 6 months from process end (GDPR). AI tool configured to respect that.
- AI-generated feedback includes context. Not "poor communication performance". Yes: "in the last 2 months, meeting participation dropped from 80% to 40%, verified with supervisor".
HR training: 60 minutes.
- 10 minutes: why does AI matter in HR? Speed at scale. Biased algorithm = hundreds of candidates affected in parallel.
- 15 minutes: bias in AI. Concrete examples. "If you've historically hired more men, the algorithm learns it and repeats it". How to spot it.
- 15 minutes: GDPR in recruitment. What rights candidates have. What "right to explanation" means.
- 15 minutes: tools you use (if any). ATS, screening chatbots, candidate analysis. Specific risks for each.
- 5 minutes: review job descriptions. Language that seems neutral but discriminates.
- Material: "Prohibited words in job descriptions", GDPR checklist for selection.
Finance: analysis, reports, accounting, audit
Finance is the most sensitive role. Confidential data, accuracy-critical, audit. A hallucination here costs real money, not just reputation.
Real cases:
Invoice analysis: The accountant uses Claude or ChatGPT to process 50 supplier invoices. Uploads PDFs to Claude, asks to "extract: vendor, description, amount, due date". Claude analyses, extracts. Seconds later, they have a table. Useful. But Claude sometimes hallucinates amounts (sees "€1,500" as "€15,000" if the scan is poor). If they don't review: accounts are wrong.
Monthly reports: Uses Copilot in Excel to "analyse this month's spending vs last month". Copilot pulls data from columns, generates a chart, writes an interpretive paragraph: "Marketing spend dropped 20%". But doesn't mention the drop was because that month had no summer campaign (temporary). A correct conclusion but lacking nuance. If the director uses it for "2026 budget decision", it's incomplete.
Cash flow forecast: CFO uses Gemini or Claude to "forecast Q4 cash flow based on the last 3 years". AI analyses, generates forecast: "Positive flow of €50k". Based on patterns. But doesn't know Q4 this year has a big inventory purchase scheduled (not in historical data). Wrong forecast. Decisions about debt/investment based on bad data.
Expense audit: Automatic system flags "suspicious" transactions: "€5k spend on 'training' Friday at 8pm". Suspicious. But it was legit (online intensive workshop ending at 8pm). If the AI auto-rejects it, valid expenses get blocked.
Specific risks:
Confidential data privacy. An analyst uploads customer data (names, income, transaction history) to ChatGPT for "credit risk pattern analysis". That data enters OpenAI's training. If those customers are individuals, GDPR breach. If they're companies in a regulated sector (finance), you breach sector regulation (Basel III, sensitive data rules).
Numerical accuracy is critical. Hallucinated figures. ChatGPT doesn't use a calculator. If you ask "what's 523 times 47", ChatGPT gives an approximate figure, not exact. Acceptable for estimates. Not for accounting. A CFO trusting AI for provision calculations: risk.
Missing documentation and traceability. An AI analysis generates "recommendation: cut inventory 30%". Why? What data did it use? Did it validate the forecast against historical reality? If an auditor (internal or external) asks, you have no answer. Compliance failed.
Data unencrypted in transit. Analyst uploads bank data to Claude without a VPN. Access isn't encrypted. If the connection is intercepted, data compromised. Not Claude's fault. Whoever uploaded it. But: Claude does keep that data for a time.
Outdated model. AI trained on data through February 2024 analyses 2026 trends. Context lost (regulation changes, market shifts, inflation). Forecasts can be biased toward old data.
Verification checklist:
- Confidential or regulated data NOT uploaded to public tools. If you need AI to process customer, account, or investment data: use enterprise tools with privacy contracts.
- Figures from AI are always verified. If ChatGPT says "month total: €234,567", check it against the balance.
- AI analyses document: input data, which tool, which model, what assumptions, confidence range.
- AI forecasts reviewed against reality each period. "AI forecast +€50k flow, actual was +€35k. Why the gap?"
- Business decisions based on AI analysis require specialist validation (don't let AI decide alone).
- Internal audit has access to explain which AI was used, where, when, by whom. Full traceability.
Finance training: 70 minutes.
- 10 minutes: why is finance critical? Hallucination here = money lost.
- 15 minutes: tools you use (ChatGPT, Claude, Copilot, maybe finance-specific AI). Capabilities, limits.
- 15 minutes: accuracy and validation. How to verify AI output, which validations are mandatory, which are best practice.
- 15 minutes: data privacy. What data can be processed with public AI, what can't. Difference between historical data (aggregated, public) and customer data (sensitive).
- 10 minutes: documentation and audit. What record do we keep of where that analysis came from, who did it, what it was based on.
- 5 minutes: exercise. Intentionally flawed analysis (with hallucinated errors). The team spots where the mistake is.
- Material: validation checklist before using AI analysis, examples of real finance hallucinations.
How this training materialises
Right, you have what to teach per role. How do you do it without adding to the paperwork pile?
Live session per role. A meeting of 45–75 minutes depending on role. Not async video (gets forgotten). Not a PDF (nobody reads it). Live: 40 minutes content, 10 minutes Q&A, 5 minutes checklist printed or in Notion.
Who runs it: someone internal who understands both AI and the role. Ideally not an outsider (sounds generic). Could be: IT lead, internal consultant, or you if you know the subject.
When: before they start using AI at scale. If they've already been running ChatGPT for three months, training afterwards limits damage but doesn't prevent it.
Material:
- Presentation with real cases from your sector.
- Checklist in Notion or shared document (not paper, it gets lost).
- If digital: links to tools (ChatGPT, Claude, GitHub Copilot links), don't install them during training (just demo).
- Point of contact: "If you're stuck, ask X. This isn't form-filling. It's for real use".
Periodic refreshers. One initial session doesn't meet the law. "Continuous or regular", says the AI Act. Minimum: annual review, or when new tools arrive.
January every year: all areas. "What changed in AI since last year. New tools. New risks." 30 minutes.
If you adopt Copilot in Office mid-year: quick 15-minute session for those tool users.
Mistakes companies make when training by role
Not everyone does it well.
Mistake 1: Same material for everyone, then contextualised.
"We'll make one AI presentation, each role adapts it after". Result: 20% retention. The salesman doesn't see how it applies to their work. The accountant thinks it doesn't touch them.
Fix: role-specific presentation from minute one. 8 minutes of each 10 are role-specific, 2 are general.
Mistake 2: No exercises.
90-minute theory session. Everyone listens, nobody practises. They leave not knowing what it looks like in their actual work.
Fix: 10-minute hands-on exercise. Marketing: "Draft a headline with ChatGPT live, show me for review". Sales: "Write a proposal with AI help, we'll check what needs validating". Finance: "This analysis has a hallucinated error. Where is it?"
Mistake 3: Single owner with no delegation.
"The CTO trains everyone on AI". One person. CTO's always in meetings. Training gets delayed. Or it's generic because there's no time to customise.
Fix: compliance lead (could be HR or IT) who coordinates, but each team lead runs their session with their people. CTO sets the frame, each team goes deep.
Mistake 4: No updates.
"We trained in 2025, done". 2026: ChatGPT releases GPT-5, changes everything. Users still believe in 2025 risks that don't exist. Or don't know new ones.
Fix: update calendar. Every January: 30 minutes minimum. If regulated sector (finance, legal): every four months.
Mistake 5: No attendance record.
Training happens but nobody logs who came. Audit arrives: "Did you train the sales team on AI?" Company: "Yes, March session". Auditor: "Proof?" Silence. Failed compliance.
Fix: 30-second Google Form. "I attended the AI session on 15/03/2026. I confirm I understand the risks described." Google logs responses, auto-list. 2 minutes to set up.
Why this closes the gap
Chapter 1 tells you you have to train. Chapter 3 (coming) covers privacy policy and governance. This chapter tells you: here's what training looks like per role, in concrete terms.
It's not generic. It's not "get to know AI". It's:
- Marketing: know what data not to upload, how to review output, what hallucination is.
- Sales: understand hallucinations in figures equal broken promises, protect client data.
- HR: spot bias, respect GDPR, explain why someone was rejected.
- Finance: validate numbers, document analyses, don't blindly trust forecasts.
Each person actually knows what they need. And when an inspector asks "did you train this team?", you have a documented session, signed checklist, evidence.
Next chapter covers prompt engineering: specific patterns that work for each role. First, make sure everyone understands where the ground is.
Next chapters in this series
- Ch 1: What AI Act Article 4 requires.
- Ch 2: Basics. How an LLM works without jargon.
- Ch 3: Data and privacy when using generative AI.
- Ch 4: Role-based literacy (marketing, sales, HR, finance). You are here.
- Ch 5: Applied prompt engineering. 7 patterns for your team.
- Ch 6: Shadow AI, internal policy, and Article 4 audit.
Sources
- Regulation (EU) 2024/1689 - Article 4 on EUR-Lex
- Directive 2000/78/EC on equal treatment in employment (discrimination protection)
- GDPR - Right to explanation of automated decisions (Art. 22)
- AI Act - Right to explanation in AI systems (Art. 86)
- ICO (UK) guidance on AI and GDPR
- CNIL (France) - Recommendations on generative AI
- AEPD (Spain) - Position on AI and right to explanation
