- Art. 4 requires a “sufficient level of AI literacy” among staff and persons acting on the company’s behalf — proportionate to roles and use context. It covers providers and deployers, with no size threshold.
- The key is not training alone, but proof: programme, register, role-based scopes, cadence. Training without documentation does not exist in a regulator’s eyes.
- Compliance can be reached in 2 weeks and 5 steps — without certificates, LMS platforms, or 40-hour courses.
What Art. 4 actually says
The provision is short — and that is why it misleads. In plain terms: providers and entities using AI systems take measures to ensure a sufficient level of AI competence for their staff and other persons acting on their behalf when operating AI systems — taking into account their knowledge, experience, education and the context in which the systems are to be used.
Three implications that are easy to miss:
- “Take measures” — an obligation of action, not of outcome. But action you cannot evidence legally did not happen.
- “Staff and other persons acting on their behalf” — also covers B2B contractors and external collaborators operating your AI systems.
- “Taking into account the context” — one training for everyone fails by definition, because the rule demands proportionality.
Who is covered — short answer: almost everyone
| Organisation type | In scope? | How far |
|---|---|---|
| Company building AI systems (provider) | Yes | Broadest: engineering, product, AI solution sales. |
| Any company using AI (deployer) — from a chatbot to Copilot in Word | Yes | Proportionate to roles: who uses what, at what risk. |
| Micro and small firms | Yes | No exemption. Proportionality helps — scope can be modest, but it must exist and be documented. |
| Public bodies | Yes | As deployers — with extra reputational exposure. |
| Contractors acting for the company | Yes | Duty sits with the company — include them in the programme or require proof of competence. |
What “sufficient level” means
The rule deliberately gives no hour count or syllabus. The measure is role risk. The practical rule we use: the closer AI sits to decisions about people and money, the deeper the human competence next to it must be.
- Receptionist using ChatGPT for email — must understand basics: hallucinations, ban on pasting personal/confidential data, which tools are allowed.
- Marketing generating content and graphics — additionally: copyright, AI content labelling duties (Art. 50 — covered next).
- HR using AI in recruitment — much more: bias risk, candidate right to human review (GDPR Art. 22), awareness this is high-risk under Annex III.
- Team deploying AI systems — full scope: architecture, security, model limits, company policy.
Training without documentation does not exist to a regulator
This is the sentence worth taking from this article into a board meeting. When a supervisory authority — or, far more often, your corporate client’s procurement team — asks about Art. 4 compliance, they will not ask “did you train people?”. They will ask for documents:
- Training programme — what, for whom, at what depth, with role-based scope rationale.
- Participant register — who, when, what scope completed. With dates.
- Role matrix — proof that scope is proportionate to use context (required by the provision itself).
- Update cycle — AI changes every quarter; a one-off 2024 training does not show a “sufficient level” in 2026.
- Path for new joiners — onboarding module and its trail in the register.
Notice the implication: a company that ran an excellent workshop and has no paper trail is in a worse evidentiary position than one that ran modest e-learning with a complete document set. Unfair — and entirely typical of law. Play the game that is actually in force.
Compliance in 2 weeks: 5 steps
- Days 1–3 — AI use inventory. Formal and informal (shadow AI): a short survey “which AI tools do you use at work?” with a no-penalty guarantee for honesty. Without this step the role matrix is fiction.
- Days 3–5 — role × risk matrix. Split the organisation into 3–5 groups (e.g. everyone / power users / HR & finance / tech / board) and assign required scope to each.
- Days 5–8 — programme. Three modules suffice: (1) AI basics and limits, (2) regulation and duties, (3) company policy and safe use. The board needs a separate short briefing — under NIS2/KSC-style rules, management liability can be personal.
- Days 8–12 — delivery. Mixed formats: e-learning for all, workshop for power users, 90 minutes for the board.
- Days 12–14 — register and cycle. Certificates, dated register, calendar review every 6–12 months, and an onboarding module.
- Buy external certificates — Art. 4 requires no certification.
- Send everyone on 40-hour courses — proportionality cuts both ways.
- Teach everyone prompt engineering — reception does not need to prompt; they need to know what not to paste into a prompt.
- Deploy an LMS platform — a dated spreadsheet register with sign-offs meets the evidentiary function.
The cheapest insurance policy in the whole AI Act
Art. 4 itself has no dedicated sanction — which is why it gets ignored. That is an accounting error. From December 2026 software, including AI systems, enters the product liability regime (PLD). In a civil dispute, lack of training becomes the simplest negligence evidence for the other side: “the company deployed AI and did not train the people who used it”. The reverse also holds: a documented programme is ready-made due diligence evidence — cheap to produce, priceless in a dispute. More on that chain in the article on fines.
Compliance checklist: Art. 4 + Art. 50 before 2 August
One page: 12 control points, fields for dates and owners. A completed checklist = the first document in your evidence file.
Download checklist (PDF)Common questions
Is a one-off webinar enough?
Alone — no. Without a role matrix, register and update cycle it shows neither the proportionality nor the continuity the rule demands.
Does e-learning count?
Yes — as a baseline for everyone, with documented completions. Teams working intensively with AI should get an additional workshop.
What about new employees?
AI literacy module in onboarding + register entry. The duty is continuous, not one-off.
Who in the company should “own” this?
One owner (usually COO, HR or compliance). Diffused ownership is no ownership in practice — and no documents when the question comes.
We run closed Art. 4 workshops — with full documentation for the regulator
Role-fitted programme, delivery before 2 August, and a complete document pack: programme, role matrix, register, certificates, update schedule. On Friday we publish the full programme openly — you can also implement it yourself.
See the training programme →This article is informational and is not legal advice. Cited duties come from Regulation 2024/1689 (AI Act); verify the current legal state before business decisions.