AI Act Article 4: what your organisation must have in place on AI training
Article 4 of the European Artificial Intelligence Regulation (Regulation (EU) 2024/1689, the AI Act) has applied since 2 February 2025. It requires providers and deployers of AI systems to take the necessary measures to ensure a sufficient level of AI literacy among their staff. This obligation applies with no size threshold: an SME with five employees using ChatGPT in a professional context is concerned just as much as a large industrial group. National authorities, including the CNIL in France, have been able to inspect and sanction since 2 August 2026.
Who is concerned?
The regulation distinguishes providers (those who develop or place AI systems on the market) and deployers (those who use AI systems in a professional context). Article 4 addresses both categories.
The concept of deployer is intentionally broad. It covers any professional use of an AI system, including use of mainstream tools such as Copilot, Claude, ChatGPT or Gemini at work. A communications agency generating visuals with an AI tool, an accountancy firm using a writing assistant, or an HR department using an AI-powered CV screening tool all fall within scope.
There is no size threshold. The European Commission explicitly confirmed this in its official FAQ on AI literacy published in 2025.
What does the AI literacy obligation mean in practice?
The text of Article 4 refers to "appropriate measures taking into account the deployment context". It does not prescribe a specific training format or minimum number of hours. What is expected is an approach proportionate to role and risk.
The European Commission published in September 2025 guidance that structures the expected level by three profiles.
Occasional user (email drafting assistant, occasional chatbot use): awareness of 1 to 2 hours covering how language models work, the concept of hallucination, data not to enter into a public LLM, and basic usage rules.
Regular user (content production, task automation, data analysis via AI): training of 4 to 6 hours, differentiated by business area, also covering algorithmic bias, personal data risks and human oversight of AI outputs.
Power user or decision-maker (deployment, procurement, governance): training of one to two days covering risk assessment, data governance, AI Act obligations and deployment ethics.
What must be documented?
Training delivered, target populations, content covered, dates and attendance. The CNIL may request this documentation during an inspection.
What are the risks of non-compliance?
Administrative sanctions under the AI Act, and increased liability if AI use causes harm without evidence of AI literacy measures.