Since the summer the same offer has been landing in European inboxes under six different senders: «Mandatory AI training · Art. 4 AI Act · certificate · limited seats». The pitch is identical every time and it always ends at a payment button. The uncomfortable part is that the obligation is real — it is not a sales invention. What is invented is almost everything that comes after the word «mandatory».
The thesis in one line: mandatory AI training for employees has been live since February 2025, but the regulation does not ask for a course, a syllabus, a number of hours or a certificate. It asks for measures proportionate to the context and the risk, and it asks you to be able to show them. What you will be asked for is not a training invoice: it is an inventory of systems, a use policy per role, and a record of who got what and when.
Two notes before going further. First, this is an operating map for knowing what to ask and what to have ready, not legal advice; the exact scope in your case turns on which systems you use, for what, and with whom. Second, if you are reading this from the US and filing European law under «somebody else’s problem»: the Act reaches providers who place AI systems on the EU market regardless of where they are established, and it reaches providers and deployers in third countries where the system’s output is used in the EU. There is no federal US equivalent to argue with — which means this text is, for now, the one writing your documentation requirements the moment you have a team in Madrid or a customer in Berlin.
Mandatory AI training for employees: what Article 4 says, and what changed in July 2026
Article 4 of Regulation (EU) 2024/1689 has applied since 2 February 2025, with no transition period and no size threshold: it binds a multinational exactly as much as a twelve-person company, as long as AI systems are in use. And it does not stop at payroll. The text also covers «other persons dealing with the operation and use» of those systems on the organisation’s behalf — the contractor who runs your agent, the vendor who configures it. Source: AI talent, skills and literacy, European Commission, accessed 3 October 2026.
What almost nobody has checked is that the article was rewritten in July 2026. The Digital Omnibus on AI — Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July and in force since the 27th — rewrote Article 4 without deleting it: where it required providers and deployers to «ensure a sufficient level» of AI literacy, it now requires them to «take measures to support the development» of it. The duty did not disappear. The verb got softer. Sources: Regulation (EU) 2026/1744, EUR-Lex, and EU AI Omnibus enters into force, amending the AI Act, White & Case, both accessed 3 October 2026.
| Element of Article 4 | Until 26 July 2026 | From 27 July 2026 |
|---|---|---|
| The verb of the duty | Ensure a sufficient level of AI literacy | Take measures that support the development of AI literacy |
| The standard you are held to | An outcome: your people reach a level | A demonstrable effort: the measures exist and fit the context of use |
| Who it covers | Staff plus third parties operating the systems on your behalf | Staff plus third parties operating the systems on your behalf |
| What was never in the text | No named course, no hours, no certificate | No named course, no hours, no certificate |
Read the last row twice, because it is what holds this article up. Neither the original nor the current wording names a course, a syllabus, a number of hours or a qualification. What the text asks is that the measures take account of prior knowledge, experience, education, the context of use and the people affected. That is a proportionality test. And a proportionality test cannot be bought — it has to be applied.
Is there a fine for not training? The $35 million figure on the landing page belongs to a different article
This is where the sales argument stops being shaky and becomes simply false. The regulation sets no specific penalty for breaching Article 4. The headline figures of up to €35 million or 7% of worldwide turnover attach to the prohibited practices of Article 5 — manipulation, social scoring, certain biometric categorisation — not to having trained nobody. What Article 99 does is require each member state to lay down penalties that are «effective, proportionate and dissuasive», with a range that starts at a warning. Showing the Article 5 ceiling as the price of skipping a course is selling with a number from someone else’s file.
What did change date is who looks. From 2 August 2026, national supervisory authorities in the member states move into inspection and enforcement on this part of the Act. Before that, the duty existed and nobody asked. Since then, the duty is identical and somebody has standing to ask. That is the whole novelty of this summer, and it is enough.
Why the generic course is not what the law asks for
The problem with the two-hour «what is generative AI» session is not that it is bad. It is that it answers a question the regulation never asked. The regulation asks about the fit between what your people know and what your people are allowed to do with the systems you actually run. A single syllabus cannot fit that by construction:
- It does not distinguish between someone drafting emails with an assistant and someone pointing a model at ranking job applications. The law does: it calibrates measures by context of use and by the people affected.
- A certificate proves somebody sat down, not that your operation is covered. The Commission has approved no qualification for Article 4: what the AI Office published was a Q&A on AI literacy and a repository of literacy practices — roughly the opposite of a mandatory diploma.
- It leaves out the third parties operating systems on your behalf, and the article names them explicitly. They are almost never on the attendance list, because they are not on the payroll.
- It trains whoever uses the tool and not whoever signs off on it. Human oversight without the competence and the authority to stop is just watching — the same gap that human in the loop for AI automation closes for reasons that have nothing to do with regulators.
None of this means a course is useless. It means a course is one of the measures, not the proof. And that if you only buy the part that comes with an invoice, the hard part stays undone. We already wrote up the cost of that shortcut from the other side: training is the budget line nobody budgets, and cutting it is what fills companies with dead licences. This is the same coin, other face — with one difference: now somebody can ask.
The three things you actually have to be able to show
If someone asks for Article 4 evidence tomorrow, they will not ask for a diploma. They will ask you to explain what you run, who is allowed to run it, and what you did so those people knew how. That is three artefacts, and none of the three comes inside a course.
1. An inventory of the AI systems actually in use
This is deliverable one, not three: nobody can calibrate training to the risk of a system they do not know exists. And the real list never matches the official one, because the distance between corporate licences and what people open in a browser tab only shows up when you ask without consequences. We described that gap in the AI agent inventory your company does not have, and the rule of thumb is blunt: if your inventory matches your licence list exactly, the inventory has not been done.
2. A use policy per role, not one PDF for everybody
A policy worth having does not say «use AI responsibly». It says, per role, which systems that person may touch, for which tasks, what data may go in, which decisions may not be delegated, and who gets told when something looks wrong. It is the organisational translation of what, inside an agent, is the permissions an AI agent holds: with no written scope, oversight has nothing to compare against and training has nothing to calibrate to.
3. A training record with dates, scope and names
The cheapest piece and the one most often missing. Who received what, when, on which systems, with what content — contractors included. It does not need a platform; it needs to exist and be current, because it is the only thing that turns «we did things» into «these are the measures we took». Give it versions, too: the moment you switch tools or widen a system’s permissions, the previous measure stops covering you.
The three together are the file. No course sells any of them, and all three are exactly what governance and control of AI automation builds for purely operational reasons. Whoever already has it complies with Article 4 almost by accumulation; whoever does not finds out the law is asking them to build the operation they never built. We ship it as AI adoption for teams — per-department playbooks, training and a use policy — and, when the problem is the full regulatory file, as complying with the AI Act while operating AI.
How much AI is already inside (and why the official number is low)
To size who this reaches, in the market where the Act actually bites: 20.0% of EU enterprises with 10 or more employees used AI technologies in 2025, up from 13.5% in 2024. Source: 20% of EU enterprises use AI technologies, Eurostat, December 2025. Spain, to pick one member state, sat at 21.1% of companies with 10 or more employees in the first quarter of 2025, 8.7 points above the previous year. Source: ICT usage and e-commerce in enterprises survey, INE, press release of 22 October 2025. Both figures are EU-scope and EU-member-state-scope respectively; they are not US adoption rates.
And both measure adoption as declared by the company. Article 4 is not triggered by declared adoption — it is triggered by use. The distance between what a company says it uses and what its people actually use is captured by no statistic, because the question is asked neither in the survey nor in-house. That is why the inventory comes first: it is the only way to find out whether you are in the 20% or whether you have been in it for two years without counting.
What to do in the next two weeks
- Ask without consequences. A three-field form — which AI tool you use, for which task, with what data — and an explicit promise that nobody gets in trouble for answering. The inventory comes from here or it does not come at all.
- Classify by risk, not by tool. Two columns: which decision the system touches, and who it affects. An assistant drafting copy and a system screening applicants cannot carry the same measure.
- Write the per-role policy on one page. Permitted scope, forbidden data, non-delegable decisions, who gets told. One page that gets read beats twenty that get filed.
- Cover contractors in the same pass. The freelancer, the agency and the vendor operating something on your behalf are inside the article. If they are not in the record, they are not covered.
- Open the record today, even half empty. A sheet with dates, people, systems and content. What separates a measure from an intention is that it has a date.