You may have read that every employee needed certified AI training from February 2025.
That claim is far too broad.
Article 4 of the EU AI Act has applied since February 2, 2025. The revised wording, published on July 24, 2026, requires suitable measures supporting AI literacy from July 27. It does not name one compulsory course, a fixed number of hours, or a mandatory certificate.
Ignoring the issue is not a sensible option either. If people use AI on behalf of your business, they should understand the opportunities, limits, and risks relevant to their tasks.
In this guide, I show you who is covered, how to choose proportionate measures, and what to document.
- Article 4 has applied since February 2, 2025. Its revised wording takes effect on July 27, 2026, requiring providers and professional deployers to support AI literacy through suitable measures.
- The provision does not prescribe one course, certificate, or minimum duration. Measures should match existing knowledge, tasks, context, and affected groups.
- Record systems, roles, goals, measures, and review triggers. A short role-specific briefing can be more useful than a generic full-day seminar for a low-risk use.
What Article 4 requires
The amended Article 4 takes effect on July 27, 2026. It applies to providers and deployers of AI systems. They must take measures supporting the AI literacy of people who deal with those systems on their behalf.
The choice of measures should account for:
- technical knowledge, experience, education, and training,
- the context in which the AI system is used, and
- the people or groups affected by that use.
The 2026 wording also clarifies that providers and deployers do not have to guarantee one particular competence level. They must take suitable supporting measures.
My EU AI Act guide explains how Article 4 fits alongside roles, risk categories, and the rest of the regulation.
Why “mandatory AI training” is misleading
Training can be an appropriate measure. Article 4 does not require every business to buy a product called AI compliance training.
Depending on the use case, a briefing, clear work instructions, practical exercises, checklists, an approval workflow, or regular short updates can be suitable.
The opposite is also true. A generic webinar about ChatGPT may be inadequate when someone uses AI for recruitment, sensitive health information, or consequential customer decisions.
Who is covered in your business?
Do not begin with a list of every employee. Begin with tasks in which people deal with AI systems on your behalf.
The relevant group may include:
- staff creating text, images, video, or presentations with AI,
- customer support teams checking suggestions from an AI assistant,
- recruiters using AI for applications or evaluations,
- engineers and product teams integrating AI features,
- managers approving systems and use cases, and
- freelancers or agencies using AI under your authority.
Contractors do not disappear from the analysis because they are not employees. Set responsibilities, instructions, and evidence in the contract and workflow.
What people actually need to know
AI literacy does not mean everyone has to build a model. People need enough knowledge to use their assigned system responsibly and recognize when human intervention is necessary.
How to implement Article 4 in 7 steps
1. Inventory your AI systems
Include approved purchases, AI features inside existing software, and accounts that workers opened themselves. Record the purpose, users, data types, provider, and possible effects.
2. Assign roles and tasks
Identify who operates the system, reviews outputs, approves decisions, and owns technical or business risk. One person can hold several roles, but critical tasks still need clear ownership.
3. Assess existing knowledge and risk
Do not ask only whether someone has used AI before. Check whether the person understands the limits of the specific system and the consequences of wrong output.
Internal brainstorming has a different risk profile from automated decisions about applicants, credit, or healthcare.
4. Define observable learning goals
A content specialist should be able to verify AI claims against sources, avoid confidential data, and recognize when a disclosure is required. That is clearer than saying the person “understands artificial intelligence.”
5. Choose proportionate measures
A short briefing, policy, and checklist may be enough for low-risk assistance. High-impact systems call for specialist instruction, practical exercises, knowledge checks, and closer oversight.
A guide people use during real work often beats two hours of slides they never open again.
6. Document the implementation
Article 4 does not impose one standard form. A concise record still helps you explain your choices and keep the measures current.
Record at least:
- the AI system and use case,
- the role or group covered,
- existing knowledge and main risks,
- learning goals and measures delivered,
- date, participants, and responsible person,
- the result of any exercise or knowledge check, and
- the date or trigger for the next review.
7. Update measures when the use changes
AI literacy is not a one-time checkbox. Review your measures when a vendor changes a major feature, your business introduces a new purpose, or an incident shows that a rule was misunderstood.
How much documentation is proportionate?
A small business does not need a complicated learning management system because one employee uses a writing assistant.
A simple table can be enough. Documentation should become deeper when a system handles sensitive data, affects people, or supports consequential decisions.
A useful record answers five questions:
- Who works with which system?
- Which mistakes or harm are possible?
- What does that person need to know?
- Which measure was delivered?
- When will it be reviewed?
What sole traders and small teams should do
A sole trader can be a deployer. Article 4, however, frames the duty around staff and other people operating or using AI systems on that deployer's behalf. If you work entirely alone, the wording does not expressly require you to train yourself or issue yourself a participation certificate.
It is still sensible to keep a list of your AI tools, rules for sensitive data, a source-checking and approval process, and a habit of updating your knowledge. Other EU AI Act duties and other laws can make that knowledge practically necessary.
As soon as workers or contractors join the process, document role-specific measures and build them into everyday workflows.
Why an AI policy makes Article 4 easier
A policy collects shared rules for approved tools, prohibited data, human review, disclosures, incident reporting, and ownership.
A policy cannot replace role-specific instruction, but it prevents contradictory advice and gives everyone the same starting point.
You can adapt my complete AI policy template for businesses to your systems and teams.
A colorful certificate is secondary. What matters is whether people can recognize the mistakes their system makes, respond appropriately, and know when a human must take responsibility.






