In brief. Article 4 of the European AI Act has been in force since 2 February 2025: anyone who develops or uses AI systems must ensure an adequate level of "AI literacy" among the people working with them. It applies to smaller companies too, even if you only use third-party tools like ChatGPT or Copilot. There are no minimum hours or mandatory certifications, but you have to train staff proportionately and be able to document it. This article is a practical guide, not legal advice.
A business owner I spoke to recently discovered article 4 of the AI Act through a client, inside a supplier questionnaire: "how do you ensure the AI literacy of your staff?". First reaction, a fair one: another piece of European regulatory paperwork, another form to fill in to keep working with the accounts that matter.
It is not that, and it is worth saying before getting into the details. Article 4 does not add a separate obligation to maintain alongside everything else. It asks, with the force of law, for the same thing a company that genuinely wants to recover margin from AI would do anyway: people who know what they are using. Paperwork, if you treat it as paperwork, gets written once and forgotten in a drawer. Competence, if you build it properly, is what decides whether AI in the company works or quietly switches itself off after three months.
What article 4 of the AI Act actually says
Article 4 introduces the obligation of "AI literacy": whoever makes available or uses artificial intelligence systems has to ensure that the people involved have sufficient skills and awareness to use them in an informed way, understanding their risks and limits. It is one of the first provisions of the AI Act to become applicable, from 2 February 2025, well before the bulk of the regulation.
This is not a technicality for lawyers. It is the rule that says, in different words, what anyone who has seen enough AI implementations inside companies already knows: the most powerful tool in the hands of somebody who does not know what they are doing produces damage, not value.
"Who in this department really understands what this tool does?" That is the question article 4 asks you to be able to answer, with a document in hand.
Does it apply to my company?
Yes, and this is where the most common misunderstanding sits. The obligation does not only concern those who develop AI systems, but also those who use them, the so-called "deployers". There are no size thresholds: it applies to the large corporation as much as to the ten-person firm.
It applies even if you have built nothing in-house and limit yourself to third-party tools. If ChatGPT, Copilot, Gemini or any AI system is used in the company to get work done, the scope covers you. That client's questionnaire was not a contractual whim: it was simply applying the rule upstream in its supply chain.
The real signal. The question does not come from the legislator, it comes from the client. In a supply chain, compliance transfers upstream: if you cannot answer, you drop off the shortlist before price is even discussed.
From the workbench: what happens when the competence is not there
In the projects we have run at Morfeus, the pattern repeats almost identically. A company buys AI, tries it enthusiastically for two weeks, and then leaves it there. Not because the tool does not work: because nobody in the department turned the initial enthusiasm into a repeatable way of working. Without somebody who understands what is happening, every mistake the tool makes becomes a good excuse to abandon it, and every possibility becomes an anecdote nobody turns into a system.
That is where our AI Champion Program came from: not a course identical for everyone, but one person per department, not necessarily from IT, who experiments on the real work, works out what genuinely functions in their context, turns it into procedure and passes it to colleagues. With this method we have trained more than 2,500 people on applied AI. The point is not the number itself: it is that those 2,500 people work today in companies where somebody can answer the question "who in this department really understands what this tool does?". That is exactly the question article 4 asks you to be able to answer, with a document in hand.
What "adequate" means in practice
The rule does not set a rigid recipe, and at first that frightens more than it reassures. In fact it is reasonable: it asks for a level proportionate to the context, the roles and the risks of how you use AI. Somebody drafting marketing copy with AI needs a different kind of awareness from somebody using it on sensitive data or on decisions that affect customers.
Concretely, "adequate" means people know what the tool does and does not do, which data they can put into it and which they cannot, how to recognise a wrong output before it becomes a problem, and what the internal rules are for their specific case.
Capability
Knowing what the tool does and does not do in their actual task.
Data
Which information can go in and which cannot, by role and context.
Errors
Recognising a wrong output before it enters a decision or a document.
The concrete moves, in order
No complex formalities are needed. Four steps are, done properly and not for show:
- Map where AI is used. Which tools, in which departments, for which concrete tasks.
- Assess risk per use. The more a use touches sensitive data or significant decisions, the higher the awareness required of whoever does it.
- Train proportionately. Awareness calibrated to the role and to real cases, not a theoretical course identical for everyone.
- Document it. Keep track of who was trained, on what, when. Being able to demonstrate it counts as much as the training itself.
| Move | What you actually do | Output you keep |
|---|---|---|
| 1. Map | List AI tools, departments, concrete use cases | AI usage register |
| 2. Assess risk | Assign a level per use based on data and decisions touched | risk matrix |
| 3. Train by role | Calibrated awareness, not one identical course for all | training plan |
| 4. Document | Who, on what, when. Traceable on a client's request | skills register |
When it applies and what you actually risk
Article 4 has been applicable since 2 February 2025. The AI Act's supervision regime and penalties come into force gradually in the following months. But the most concrete risk is not the fine: it is using AI every day without anybody in the company being able to do it safely. That gets paid for regardless, penalty or no penalty, in wrong decisions taken on blind trust in an output, or in an investment in tools nobody will be using well in six months.
In short
Article 4 does not ask you to invent something new. It asks you to do, with a deadline and a documentation requirement, what anyone who wants a real return from AI would do anyway: put one person per department in a position to understand the tool, turn that into practice, and keep a record. If you already have an AI Champion in every key function, article 4 is a formality you complete in an afternoon. If you do not, it is a good occasion to build one, before somebody in your sector does and asks you, as a client or as a supplier, to demonstrate the same thing.
Want to be compliant and operational at the same time? The AI Champion programme builds and documents internal competence. For the basics, start from Learn AI.