
AI Literacy — Mandatory AI Training Under Article 4 of the AI Act: Who, What, and How
The owner of a five-person accounting office uses Claude to summarize financial statements. A marketing agency pastes client briefs into ChatGPT to speed up research. Neither company builds AI, sells AI, or has an IT department bigger than one person — yet both are "deployers" under the AI Act, and both, right now in September 2026, have an active obligation under Article 4 to give their staff a "sufficient level of AI competence." This is the most widely applicable — and least understood — requirement in the entire regulation. It applies to literally anyone with any AI system in their company, regardless of its risk level.
If anyone at your company uses ChatGPT to draft emails, you're a “deployer” under the AI Act — and since August 2, 2026, national market surveillance authorities can check whether you've given that person a “sufficient level of AI competence.” There's no single training template or required certificate — but there is a concrete methodology: who the obligation covers, how to design a role-based program (leadership, operations, IT), and how to document the result so it survives an inspection.
This post closes the fourth piece of the compliance triangle I've been building: the AI Act describes the legal obligations in general, AI policy and ISO/IEC 42001 shows how to organize them into a management system, and Shadow AI diagnoses what happens when nobody has done any of this. This post answers the question left over after those three: specifically who, on what, and how to train, so a document labeled "AI literacy" isn't fiction.
Who Article 4 covers — spoiler: even the one-person company with ChatGPT
/// THREE FACTORS OF "SUFFICIENT LEVEL" (EC GUIDANCE)
Independent of the AI system's risk level
Article 3(56) of the AI Act defines AI literacy as the skills, knowledge, and understanding that allow providers, deployers, and affected persons to make informed decisions about deploying AI systems and to be aware of the opportunities, risks, and possible harms it can cause. Critically, the Article 4 obligation doesn't depend on the system's risk level. It doesn't matter whether your automation is "minimal risk" under the classification in the AI Act guide — the mere fact that anyone in the organization operates an AI system triggers the obligation to give them adequate competence.
Three factors that, per the European Commission's May 2025 guidance (AI Literacy — Questions & Answers), determine what "sufficient level" means for a specific person:
- 1.The person's technical knowledge, experience, education, and training — a junior marketer using ChatGPT for drafts needs a different scope of knowledge than a CTO deploying credit-scoring systems.
- 2.The context in which the AI system will be used — an internal brainstorming chatbot is a different risk level than a system evaluating loan applications.
- 3.The people the AI system affects — if the outputs reach customers or employees, the competence bar rises.
There's no single template or required certificate — the Commission explicitly rejected a one-size-fits-all approach and instead published a repository of more than 40 real-world practices from AI Pact companies as inspiration, not a mandatory checklist.
What "sufficient level of competence" means in practice
Since there's no rigid template, a defensible program — one that survives an inspection — follows three steps: assess, train, document. Each step leaves evidence you can point back to later — and that's exactly what national market surveillance authorities have been looking for since August 2, 2026, when they gained formal powers to check Article 4 compliance.
The scale of the gap this reveals: according to Docebo's 2026 report (2,000 employees and L&D leaders at large organizations), 85% of employees say the AI training they received doesn't help them in their actual job, and one in five received no training at all. This isn't just a business-effectiveness problem — it's a direct compliance risk, because training that doesn't work doesn't meet the "sufficient level of competence" standard no matter how many hours it formally ran for.
A role-based training program — three tiers, not one session for everyone
/// ROLE-BASED PROGRAM — NOT ONE SESSION FOR EVERYONE
Role-proportionality is a requirement in the Commission's guidance, not a suggestion
The biggest mistake I see at client companies: one generic "introduction to AI" session for the whole company, regardless of role. That's the exact opposite of the role-proportionate approach the Commission's guidance requires. A real program splits into three tiers:
- Leadership and decision-makers. They don't need to know how to write prompts — they need to understand legal exposure (fines up to €35M or 7% of turnover), decision frameworks for buying AI tools, and when a project needs the AI owner described in the AI policy post.
- Operations teams and general users. Practical knowledge: which tools are allowed, what data to never paste in, and when to escalate an AI output to a human instead of trusting it blindly. This is the group most exposed to Shadow AI if the training doesn't cover it.
- IT and implementation specialists. Deeper technical knowledge: model limitations, hallucinations, prompt injection, and how to design human oversight and an audit trail for the systems they're responsible for.
For content and marketing teams using AI for research and content creation, I build a complete, structured competence path in the SEO & GEO course; for people deploying and overseeing the systems themselves, in the AI Engineer course. Completing a program like this, documented with a certificate and a syllabus, is exactly the evidence of "real effort" an inspector is looking for.
How to measure the result — attendance isn't proof of competence
A sign-in sheet from a training session isn't proof of "sufficient level of competence" — it's proof someone sat in the room. A rigorous measurement looks different:
| Measurement method | What it checks | When to use it |
|---|---|---|
| Pre/post-training test | Whether knowledge actually increased, not just whether someone attended | Always — this is the evidentiary minimum |
| Decision scenarios ("what would you do if...") | Whether the person can apply the knowledge in a real situation, not just recite it | For roles with direct AI contact (operations, customer service) |
| Audit of actual AI use after training | Whether behavior at work actually changed (less PII pasted, more escalation) | 30-60 days after training, tied to the AI systems register |
| Confidence self-assessment survey | Subjective sense of competence — a useful supplement, not a substitute for a knowledge test | As an add-on to the pre/post test, never standalone |
An audit of actual use after training is also the best test of whether the Shadow AI problem is actually shrinking rather than just moving further underground — a mechanism I cover in more depth in Shadow AI.
Enforcement since August 2026 — what it actually means
/// AI LITERACY — TIMELINE AND NUMBERS
The AI literacy obligation has applied since February 2, 2025, but for a year and a half it was effectively unenforceable — no authority had formal enforcement powers. That changed on August 2, 2026: national market surveillance authorities across the EU can now check it. The Digital Omnibus package (agreed May 7, 2026, in force since July 27, 2026) softened the wording from a "duty to ensure" to a "duty to support the development" of competence — but that's a rhetorical change, not a removal of the obligation, as I cover in more depth in AI policy and ISO/IEC 42001. In practice this means: a company must show a real, documented process, not just intent. Having no evidence of training at all is prima facie proof the obligation hasn't been met.
The most common mistakes building an AI literacy program
/// THE MOST COMMON MISTAKES BUILDING A PROGRAM
A sign-in sheet is not proof of competence
- →A separate scope per role (leadership / operations / IT)
- →A recurring refresh, at least once a year
- →Recorded: who, when, pre/post test results
- →Tied to an audit of actual AI use
- →One generic "intro to AI" session for everyone
- →Trained once, never refreshed
- →No record or documentation at all
- →Disconnected from what the team actually uses
- One session for every role. Ignores the proportionality requirement in the Commission's guidance — leadership and a junior marketer don't need the same knowledge.
- Training once and never again. The AI tool landscape changes faster than most internal policies — a program with no recurring refresh is stale within a few months.
- No documentation. Running the training without a record (who, when, what it covered, what the test results were) leaves no evidence for an inspection.
- Treating it as an HR project, not an operational policy. AI literacy should be part of the same AI policy the AI owner manages — not a separate, disconnected training initiative.
- No connection to actual usage. Training that doesn't answer "what does my team actually use" misses the mark — a Shadow AI audit should come before a training program, not after it.
---
I design and run AI literacy programs tailored to a company's actual structure — from a per-role needs assessment, through training materials, to documentation that survives an inspection. I do this as part of AI training for teams and AI consulting, and I run full, certified competence paths in the SEO & GEO course and the AI Engineer course. Reach out — I'll start by assessing which roles at your company actually need which level of competence, and design a program that can be documented.
Worth reading next:
/// RELATED_SERVICES
Need these concepts implemented? Explore the services related to this topic.
AI Training & Workshops
AI training for businesses and hands-on workshops in prompt engineering, n8n automation, and generative AI. Build AI competency in your team.
View serviceServiceAI Consulting
Independent AI consultant for businesses. AI readiness audit, implementation strategy, and board-level advisory — before you engage any vendor.
View service/// SOURCES
- 01EU AI Act – Explorer, Article 4 (AI literacy)
- 02European Commission – AI Literacy Questions & Answers
- 03European Commission – AI talent, skills and literacy (repository of practices)
- 04Regulation (EU) 2024/1689 (AI Act) – EUR-Lex
- 05Docebo – The AI Readiness Gap: The 2026 Enterprise Learning Wake-Up Call Report
- 06Consilium – Artificial Intelligence: Council and Parliament agree to simplify and streamline rules (07.05.2026)
/// RELATED_RECORDS
AI Policy at Your Company and ISO/IEC 42001 — Governance That Doesn't Kill Innovation
Six weeks ago, national market surveillance authorities across the EU got formal powers to check whether companies actually meet the Article 4 AI literacy obligation — and whether they have documents to prove it, not just good intentions. Most SMEs that have deployed AI are missing one thing: a written AI policy. Here's what such a policy must contain, how to build an AI systems register, when to reach for ISO/IEC 42001 instead of an internal document, and who at a small company should be the “AI owner” without a Chief AI Officer title.
GDPR and AI — Personal Data in Prompts, DPIA and LLM Vendor Agreements (Practically)
Pasted a customer's email into ChatGPT to speed up your reply? That's already personal data processing under GDPR — with the full weight of obligations most teams have never heard of. Six weeks ago Poland's data protection authority (UODO) published the first official self-assessment checklists for AI/GDPR compliance — proof the regulator is already watching, not just theorizing. When does a prompt trigger a DPIA, how does the “meaningful human involvement” test from Article 22 hold up against a lead-scoring chatbot, and how do OpenAI's, Anthropic's and Google Cloud's DPA agreements actually differ — a practical guide without the legal jargon.
Shadow AI — Your Employees Are Using AI Without Your Knowledge and That's Your Problem
68% of employees use unsanctioned AI tools without IT's knowledge. They paste contracts, customer data, source code, and strategies into public chatbots — and the company has no idea. Shadow AI isn't a technology problem, it's a governance problem. I explain how to detect what your team is actually using, how to write an AI policy that actually works, and why an outright ban is the worst possible solution.
Signal received?
Terminate
Silence
Initiate protocol. Establish connection. Let's build something loud.
