What Article 4 actually says
Article 4 requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The level is then calibrated by three things the article names: the technical knowledge, experience, education and training of those persons, the context the AI systems are to be used in, and the persons or groups of persons on whom the systems are to be used.
Four phrases carry the whole obligation, and each one does specific work.
- Providers and deployers. Both sides of the market, not just the builders. This is what makes Article 4 reach an organisation running nothing but bought-in tools, whatever those tools do.
- To their best extent. An effort standard, measured against what your organisation can reasonably do. It scales down for a small team. It does not scale to zero.
- A sufficient level. An outcome standard with no floor number attached, no hour count and no syllabus.
- The persons on whom the systems are used. The limb most often skipped. Literacy is judged partly by who is on the receiving end, so the same tool warrants more in a school or a lender than in a back-office spreadsheet.
That date is the point of this article. Article 4 has been binding for close to eighteen months. It is older than the general-purpose model obligations, older than the penalty provisions, and considerably older than the transparency duties that apply on 2 August 2026. Nothing about it is pending, and the sequence it sits at the front of is set out on the AI Act timeline as amended.
Who counts as your staff
The article covers "staff and other persons dealing with the operation and use of AI systems on their behalf". The second limb is wider than the first on purpose, and the test in it is not employment. It is whether the person deals with the operation and use of the system, and whether they do so on your behalf.
That pulls in contractors and freelancers embedded in a team, agency staff, an outsourced support desk answering your customers, and an external agency operating a generative tool under your brand. It also pulls in people nobody thinks of as users of AI, such as a recruiter reviewing a shortlist a system produced, or a claims handler acting on a model's output.
It does not pull in your customers or the general public. They appear elsewhere in the same sentence, as the persons on whom the systems are used, which is a factor for setting the level rather than a group you owe training to. Their disclosure rights come from a different place, namely the Article 50 transparency duties, most of which apply on 2 August 2026.
The boundary matters most at procurement. If an outsourced team operates an AI system on your behalf, you cannot discharge Article 4 by assuming their employer handled it. The workable answer is a contractual training obligation with evidence returned to you, which belongs in the same conversation as role determination, because a supplier relationship is also where provider and deployer status gets settled.
Why "sufficient" is deliberately relative
Practitioners want a number here and there is not one. The relativity is not an oversight, it is the mechanism: the same words have to work for a two-person studio and for a systemic bank, so the article fixes the outcome and leaves the calibration to the named factors.
Take a five-person design studio using a general-purpose assistant to draft copy. The context of use is low stakes, the persons on whom the system is used are largely the staff themselves, and the resources are small. A one-page written policy, a short session at induction covering what the tool is, where it fails and what must never be pasted into it, and a note of who attended, is a defensible answer to "to their best extent".
Now take a bank running credit scoring. The words are identical and the answer is not remotely the same. The context of use is an Annex III use case, the persons on whom the system is used are consumers with no visibility of it, and the staff who act on its output need to understand the intended purpose, the limits, and when to override. That is a structured programme with role-specific content, and it sits alongside the wider duties on high-risk systems that apply to standalone Annex III systems from 2 December 2027.
The trap in a relative standard is reading it as an empty one. "To their best extent" is still an effort standard, and it is straightforward to fail: an organisation that took no measures at all has nothing to weigh, whatever its size.
There is no certificate and no approved body
Article 4 carries no certification requirement, no prescribed curriculum and no EU-approved training provider. There is no register of accredited courses and no document an authority is looking for by name. The regulation says what has to be achieved and is silent on how.
"AI Act certified training" is a product, not a legal requirement. Nothing in Regulation (EU) 2024/1689 makes any course mandatory or gives any certificate standing. That does not make the courses worthless, and a well-built one can be an entirely reasonable measure. Buy it as training and judge it on whether the content matches the roles you actually have. Do not buy it in the belief that the certificate is the compliance artefact, because the certificate is not the thing Article 4 asks for.
The same caution applies in the other direction. Because no format is prescribed, measures that are not courses count too: written guidance, a tool-specific checklist, supervised first use, a standing channel for questions. For most organisations a mixture is both cheaper and better evidence than a single annual video that nobody remembers.
How it is actually enforced
Start with what Article 4 is not. It does not carry one of the three Article 99 ceilings. Those are €35,000,000 or 7% of total worldwide annual turnover for Article 5 prohibited practices, €15,000,000 or 3% for most other obligations including Article 50 and the high-risk regime, and €7,500,000 or 1% for supplying incorrect, incomplete or misleading information to authorities, with SMEs and start-ups paying the lower of the two figures under Article 99(6). The tiers themselves have been enforceable since 2 August 2025, and the full breakdown sits on the penalties and enforcement page.
What Article 99(1) does require is that member states lay down their own rules on penalties and other enforcement measures for infringements. Supervision of Article 4 runs nationally, through the competent authorities designated under Article 70, rather than through the AI Office, whose remit is general-purpose models.
That is where the map gets uneven. Member states had to designate their national competent authorities by 2 August 2025, and only 8 of the 27 did so on time, with the DGCCRF in France, AESIA in Spain and the Bundesnetzagentur in Germany among the front-runners. Who is likely to ask you an Article 4 question therefore depends heavily on where you operate, and the current state of designation is tracked on the national authorities page.
The realistic exposure is indirect. The likely sequence is that something else goes wrong, a workplace tool that infers emotion and has been prohibited since 2 February 2025, an unlabelled piece of generated content once the Article 50 duties apply on 2 August 2026, a high-risk system operated against its instructions for use, and the first question in the file is what the people involved were told and when. A dated training record answers that question. A recollection does not.
A proportionate programme, role by role
Article 4 is easier to discharge if you stop treating it as one course for everybody. The article calibrates by role and context, so the programme should too. What follows is a starting map, to be cut down to the roles you actually have.
| Role | What they touch | What sufficient looks like |
|---|---|---|
| Everyone who uses a general assistant | Drafting, summarising, translation, search | What the tool is and is not, that fluent output can be confidently wrong, what data must never be pasted in, when a human has to check, who to ask |
| Managers who buy or renew tools | Procurement, vendor contracts, renewals | Provider and deployer roles, the three Article 25 acts that flip a deployer into a provider, what to ask a vendor before signing |
| Staff operating an Annex III system | CV screening, credit decisions, exam scoring, benefits | The intended purpose and the instructions for use, human oversight in practice, when and how to override, that the high-risk duties land on 2 December 2027 |
| Customer-facing and marketing teams | Chat assistants, generated images, synthetic voice | Which Article 50 limb applies to their surface, that the disclosure and deepfake labelling duties apply from 2 August 2026, and where the label goes |
| Engineers integrating models | Model APIs, fine-tuning, retrieval, agents | Classification against Article 6, what turns you into a provider, logging, and the machine-readable marking duty under Article 50(2) |
| Legal, compliance and the accountable executive | The system inventory and sign-off | The whole obligation map, the GDPR overlap, the Article 99 tiers, and who decided what on which date |
On cadence, three triggers cover most organisations: at induction, on a yearly refresh, and whenever something material changes. A new tool, a new use for an existing tool, or a change in the law all count as material, and the transparency duties arriving on 2 August 2026 are exactly the kind of change that should push an update to the customer-facing content rather than wait for the annual cycle.
The evidence is the artefact
Here is the part that changes how you spend the budget. An authority cannot inspect what your people know. It can only inspect what you can produce. A dated record of who was trained, on what, and when will do more for you in that conversation than a better course with no paper trail.
A minimum viable record is small:
- The role map: which roles deal with the operation and use of AI systems on your behalf, including the non-employees.
- The level decision and the reasoning: what you concluded was sufficient for each role, against the context of use and the persons the systems are used on.
- The delivery log: who attended or completed what, on which date, with the material kept in the version actually delivered rather than the version you have since improved.
- The standing material: the written policy staff were pointed at, and the contractual clause covering suppliers, with their evidence returned.
Article 4 imposes no documentation obligation of its own, so this is not a statutory register and it does not need to look like one. A shared folder with dated files and a spreadsheet is enough. Compare that with reconstructing eighteen months of ad hoc sessions after a question has already been asked, and the case for keeping it makes itself.
Three things are worth doing this week if none of this exists yet. List the AI systems your organisation actually uses, including the ones bought on a departmental card. Map those systems to the roles that operate them, and mark which of those roles are filled by people you do not employ. Then write down what you have already done, because most organisations have done something, and undocumented measures are worth considerably less than the same measures with a date on them.
If you are not sure which other obligations reach your systems, the free triage classifier walks the tests in order and names the article each answer rests on.