Insights · Training
Training · June 29, 2026 · 6 min

The AI Act and smaller companies: the 'AI literacy' you are obliged to have (since 2025)

Article 4 of the European AI Act has been in force since 2 February 2025: anyone who develops or uses AI systems must ensure an adequate level of 'AI literacy' among the people working with them. It applies to smaller companies too, even if you only use third-party tools like ChatGPT or Copilot. There are no minimum hours or mandatory certifications, but you have to train staff proportionately and be able to document it. This article is a practical guide, not legal advice.

MA
Matteo Arnaboldi
CEO & Co-Founder, Morfeus

Updated on July 9, 2026

TRAINING
In brief

Article 4 of the European AI Act has been in force since 2 February 2025: anyone who develops or uses AI systems must ensure an adequate level of 'AI literacy' among the people working with them. It applies to smaller companies too, even if you only use third-party tools like ChatGPT or Copilot. There are no minimum hours or mandatory certifications, but you have to train staff proportionately and be able to document it. This article is a practical guide, not legal advice.

In brief. Article 4 of the European AI Act has been in force since 2 February 2025: anyone who develops or uses AI systems must ensure an adequate level of "AI literacy" among the people working with them. It applies to smaller companies too, even if you only use third-party tools like ChatGPT or Copilot. There are no minimum hours or mandatory certifications, but you have to train staff proportionately and be able to document it. This article is a practical guide, not legal advice.

A business owner I spoke to recently discovered article 4 of the AI Act through a client, inside a supplier questionnaire: "how do you ensure the AI literacy of your staff?". First reaction, a fair one: another piece of European regulatory paperwork, another form to fill in to keep working with the accounts that matter.

It is not that, and it is worth saying before getting into the details. Article 4 does not add a separate obligation to maintain alongside everything else. It asks, with the force of law, for the same thing a company that genuinely wants to recover margin from AI would do anyway: people who know what they are using. Paperwork, if you treat it as paperwork, gets written once and forgotten in a drawer. Competence, if you build it properly, is what decides whether AI in the company works or quietly switches itself off after three months.

What article 4 of the AI Act actually says

Article 4 introduces the obligation of "AI literacy": whoever makes available or uses artificial intelligence systems has to ensure that the people involved have sufficient skills and awareness to use them in an informed way, understanding their risks and limits. It is one of the first provisions of the AI Act to become applicable, from 2 February 2025, well before the bulk of the regulation.

This is not a technicality for lawyers. It is the rule that says, in different words, what anyone who has seen enough AI implementations inside companies already knows: the most powerful tool in the hands of somebody who does not know what they are doing produces damage, not value.

"Who in this department really understands what this tool does?" That is the question article 4 asks you to be able to answer, with a document in hand.

Does it apply to my company?

Yes, and this is where the most common misunderstanding sits. The obligation does not only concern those who develop AI systems, but also those who use them, the so-called "deployers". There are no size thresholds: it applies to the large corporation as much as to the ten-person firm.

It applies even if you have built nothing in-house and limit yourself to third-party tools. If ChatGPT, Copilot, Gemini or any AI system is used in the company to get work done, the scope covers you. That client's questionnaire was not a contractual whim: it was simply applying the rule upstream in its supply chain.

$ client --compliance-questionnaire
ref. AI Act art. 4 · applicable 02.02.2025
▸ "how do you ensure the AI literacy of your staff?"
size threshold · none · applies to smaller companies too

The real signal. The question does not come from the legislator, it comes from the client. In a supply chain, compliance transfers upstream: if you cannot answer, you drop off the shortlist before price is even discussed.

From the workbench: what happens when the competence is not there

In the projects we have run at Morfeus, the pattern repeats almost identically. A company buys AI, tries it enthusiastically for two weeks, and then leaves it there. Not because the tool does not work: because nobody in the department turned the initial enthusiasm into a repeatable way of working. Without somebody who understands what is happening, every mistake the tool makes becomes a good excuse to abandon it, and every possibility becomes an anecdote nobody turns into a system.

That is where our AI Champion Program came from: not a course identical for everyone, but one person per department, not necessarily from IT, who experiments on the real work, works out what genuinely functions in their context, turns it into procedure and passes it to colleagues. With this method we have trained more than 2,500 people on applied AI. The point is not the number itself: it is that those 2,500 people work today in companies where somebody can answer the question "who in this department really understands what this tool does?". That is exactly the question article 4 asks you to be able to answer, with a document in hand.

What "adequate" means in practice

The rule does not set a rigid recipe, and at first that frightens more than it reassures. In fact it is reasonable: it asks for a level proportionate to the context, the roles and the risks of how you use AI. Somebody drafting marketing copy with AI needs a different kind of awareness from somebody using it on sensitive data or on decisions that affect customers.

Concretely, "adequate" means people know what the tool does and does not do, which data they can put into it and which they cannot, how to recognise a wrong output before it becomes a problem, and what the internal rules are for their specific case.

Capability

Knowing what the tool does and does not do in their actual task.

Data

Which information can go in and which cannot, by role and context.

Errors

Recognising a wrong output before it enters a decision or a document.

The concrete moves, in order

No complex formalities are needed. Four steps are, done properly and not for show:

  1. Map where AI is used. Which tools, in which departments, for which concrete tasks.
  2. Assess risk per use. The more a use touches sensitive data or significant decisions, the higher the awareness required of whoever does it.
  3. Train proportionately. Awareness calibrated to the role and to real cases, not a theoretical course identical for everyone.
  4. Document it. Keep track of who was trained, on what, when. Being able to demonstrate it counts as much as the training itself.
Article 4 in practice · the four moves
MoveWhat you actually doOutput you keep
1. MapList AI tools, departments, concrete use casesAI usage register
2. Assess riskAssign a level per use based on data and decisions touchedrisk matrix
3. Train by roleCalibrated awareness, not one identical course for alltraining plan
4. DocumentWho, on what, when. Traceable on a client's requestskills register

When it applies and what you actually risk

Article 4 has been applicable since 2 February 2025. The AI Act's supervision regime and penalties come into force gradually in the following months. But the most concrete risk is not the fine: it is using AI every day without anybody in the company being able to do it safely. That gets paid for regardless, penalty or no penalty, in wrong decisions taken on blind trust in an output, or in an investment in tools nobody will be using well in six months.

In short

Article 4 does not ask you to invent something new. It asks you to do, with a deadline and a documentation requirement, what anyone who wants a real return from AI would do anyway: put one person per department in a position to understand the tool, turn that into practice, and keep a record. If you already have an AI Champion in every key function, article 4 is a formality you complete in an afternoon. If you do not, it is a good occasion to build one, before somebody in your sector does and asks you, as a client or as a supplier, to demonstrate the same thing.

Want to be compliant and operational at the same time? The AI Champion programme builds and documents internal competence. For the basics, start from Learn AI.

Frequently asked

In three answers

Does the AI literacy obligation apply to my small company?

Yes. Article 4 of the AI Act applies both to those who develop and to those who use AI systems (the 'deployers'), with no size thresholds. It applies even if you only use third-party tools like ChatGPT, Copilot or Gemini.

How many hours of training do you need to be compliant?

The rule sets no number of hours and no mandatory certification. It asks for an 'adequate' level, proportionate to the context and the risks of how you use AI. What counts is being able to demonstrate it.

When does it apply from and what is the risk?

Article 4 has been applicable since 2 February 2025. The AI Act's supervision and penalty regime comes fully into force in the months that follow. Beyond penalties, the concrete risk is using AI without the people being able to do it safely.

Measure, before anything

The problem you don't see has a price.

Try the ROIometro: pick a department and see, in euros, where your company loses value every day.