1. The obligation almost nobody knows about
Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among the staff dealing with their operation and use, taking into account their knowledge, their training and the context of use.
Two things worth being clear about:
- It has applied since 2 February 2025. This is not a future obligation: it was one of the first to come into force, alongside the prohibited practices.
- It reaches almost any company using AI in its operations, not only whoever develops it. If your team uses an assistant to draft, classify or summarise, you are in scope.
The regulation sets no syllabus and no number of hours, and that is where the trap is: “sufficient” is judged by the context of use. A generic two-hour session on what AI is can hardly be sufficient for somebody making decisions with it every day. That is why the training is planned by role and around the systems actually in use.
The full timetable of the Regulation and the detail of each risk level are on the AI compliance page, which we keep up to date every time the regulation changes.
2. What we actually solve
- “We bought the licences and hardly anybody uses them.” The most expensive case: the tool is paid for and the process carries on exactly as before.
- “Everybody uses it their own way and some people put in data they should not.” With no shared criterion, the risk comes in through the side door.
- “The team believes everything it is told.” Or the opposite: they trust none of it and do not use it. Both come from not understanding how it fails.
- “We have been told there is a training obligation and we do not know whether we meet it.” Usually not, and there is almost never a record of anything.
3. What the training looks like
- On your processes, not on textbook examples. The exercises are built with the company’s real documents, emails and cases — anonymised where necessary. It is the difference between understanding the idea and knowing how to apply it on Monday.
- By role. The board, middle management and the operational team need different things, and mixing them in the same session guarantees that half the room switches off.
- With the tools you are actually going to use, with their real limits and their privacy settings, not with a demo of something you have not bought.
- Insisting on how it fails. Where it makes things up, why it sounds just as confident when it is right as when it is wrong, and what always has to be verified. That is the part that turns a user into somebody who can be trusted without supervision.
- With a record of attendance and content. Without paperwork there is no way to evidence anything, and Article 4 is either demonstrated or not met.
4. What each role takes away
Operational team
They use an assistant to draft and summarise, each in their own way. Nobody knows what can be pasted into the chat and what cannot, or when something has to be verified.
A shared criterion, clear limits on data, and practice on their own documents.
Middle management
They are asked to decide what gets automated and what does not, without ever having seen it work. The decision is made on intuition, and the eye-catching process usually wins over the repetitive one.
The judgement to recognise a good candidate and to insist on measuring the starting point.
The board
They have to approve investment and carry the legal responsibility for the use. Without understanding where the technology fails, either everything gets bought or nothing does.
Which obligations reach them, how the return is measured and what to ask a supplier.
5. What you need before we start
- Knowing which tools the team uses today, including the ones nobody approved. That list is usually the most revealing part of the preparation.
- Real material we can use in the exercises, even if it has to be anonymised.
- Protected time. Training interrupted by day-to-day work is not training.
- A usage policy, even a one-pager. If there is none, we write it as part of the work: training without saying what is allowed leaves the job half done.
6. When this is NOT the answer
- All you want is the certificate. A generic session to have the paperwork probably does not meet the “sufficient” standard in Article 4, which is judged by the context of use. It ends up costing twice.
- The problem is the process, not the people. If the process is broken, training the team to run it better does not fix it. Start with the diagnosis.
- There is nothing to use yet. Training on tools the company has not yet decided to deploy is forgotten before they arrive.
7. How it is measured
Training is measured badly if all you count is who attended. What we look at:
- Real use of the tools weeks later, not the next day.
- Hours saved on the tasks where the team has started applying it.
- Incidents avoided: data that no longer gets pasted where it should not.
- Documentary record available to evidence compliance with Article 4 if anybody asks.
Note: this page is for information only; it is not legal advice nor a guarantee of results. The figures quoted are usual ranges in real projects, not contractual commitments, and they depend on the scope and the starting point of each company.
8. Frequently asked questions
Is AI training mandatory for companies?
Article 4 of Regulation (EU) 2024/1689 requires providers and deployers to ensure a sufficient level of AI literacy among the staff dealing with the operation and use of these systems, taking into account their knowledge, their training and the context of use. It has applied since 2 February 2025 and reaches almost any company using AI in its operations, not only whoever develops it.
Who exactly has to be trained?
The staff dealing with the operation and use of the AI systems. In practice that includes whoever uses them day to day, whoever decides where they are applied and whoever answers for their use. That is why the training is planned by role: the board, middle management and the operational team need different things, and putting them in the same session guarantees that half the room switches off.
How long is it and how is it delivered?
It depends on the role and the starting point. Sessions for the operational team are short and very practical, with exercises on the company’s real documents; board sessions are shorter and focus on obligations, investment criteria and what to ask a supplier. It can be delivered in person or remotely, and several short sessions work better than one long day: retention is noticeably higher.
Does it evidence compliance with Article 4?
We provide a record of attendance and of the content delivered, which is what makes it possible to show that something was done and what. That said, the regulation sets no syllabus and no hours: “sufficient” is judged by the context of use, so nobody can guarantee in advance that a particular course will be enough for your case. What we can say is that a generic two-hour session will hardly be enough for somebody deciding with AI every day. This is general information and not legal advice.
How is it different from a generic AI course?
The exercises are built with your documents, your emails and your cases, and time is spent on how the tool fails: where it makes things up, why it sounds just as confident when it is right as when it is wrong, and what always has to be verified. A generic course explains what a language model is; this one aims to have somebody do their job differently on Monday.
And if the team already uses AI on its own without us knowing?
That is the most common situation, and finding out is part of the preparation. The list of tools the team uses without approval is usually the most revealing part of the groundwork, and it normally uncovers company data circulating through services nobody has reviewed. Training without first setting out what is allowed leaves the job half done, so if no usage policy exists, we write it as part of the project.
Services that usually go with this one: AI strategy consulting · AI agents.