EU AI Act Training: Article 4 Checklist
EU AI Act training requirements explained: a practical Article 4 compliance checklist for L&D leads and compliance officers, with assessment guidance.
EU AI Act training obligations are now law, and Article 4 is the provision that makes AI literacy a compliance requirement — not a nice-to-have. If you're a compliance officer or L&D lead trying to figure out what "sufficient measures" actually means in practice, this post translates the legal text into a concrete checklist you can act on today.
We published a full legal analysis of Article 4 earlier this year. This post builds on that foundation with a practical implementation guide: what training elements the regulation implies, how to document compliance for auditors, and the mistakes that will get you flagged.
What Article 4 Actually Says
Article 4 of the EU AI Act requires that providers and deployers of AI systems take measures to ensure a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. The obligation applies proportionally, considering the context, the technical knowledge of the persons involved, and the specific AI systems they interact with.
Three things stand out in the legal text:
The "Sufficient Measures" Standard
The regulation does not prescribe a specific curriculum, certification, or training programme. It uses the phrase "sufficient measures" — which means the burden falls on each organisation to define, deliver, and prove adequacy. This is deliberately flexible, but that flexibility is a double-edged sword. Without a prescribed standard, you need to build your own defensible framework.
Proportionality and Context
Article 4 explicitly ties the literacy requirement to context. A marketing team using a chatbot for brainstorming has different literacy needs than an engineering team deploying a high-risk classification system. Your training programme must reflect these differences. A single, uniform webinar for all staff is unlikely to satisfy the proportionality requirement.
Scope: Staff and "Other Persons"
The obligation extends beyond employees to "other persons dealing with the operation and use of AI systems on their behalf." That includes contractors, consultants, and potentially agency workers. If someone touches your AI systems, they're in scope.
For the full legal breakdown — including recital context and interaction with other articles — see our Article 4 deep dive.
Who Must Comply: Providers, Deployers, and the Sufficiency Bar
Article 4 applies to two categories of organisation, and the compliance bar differs for each.
Providers
Providers are organisations that develop or place AI systems on the market. If you build AI products — whether SaaS tools, embedded models, or custom systems — you're a provider. Your literacy obligation covers everyone involved in development, testing, deployment, and post-market monitoring. The expectation is higher here: your people are building the systems, so their understanding must be deeper.
Deployers
Deployers are organisations that use AI systems under their authority. This is the broader category and captures most enterprises. If your company uses AI tools — from code assistants to customer service bots to HR screening software — you're a deployer. Your obligation is to ensure the people operating, overseeing, or making decisions based on these systems understand them well enough to do so responsibly.
What "Sufficient" Means in Practice
The regulation doesn't define a pass/fail threshold. Based on the text, recitals, and early guidance from the AI Office, sufficiency likely requires demonstrating:
- A baseline assessment of current literacy levels
- Role-appropriate training that reflects the AI systems actually in use
- Ongoing measurement — not just a one-time event
- Documentation that an auditor can review
This is where most organisations will struggle. You can't prove sufficiency without measurement, and you can't measure what you haven't defined.
5 Training Elements Article 4 Implies — Mapped to Competency Dimensions
The regulation doesn't list specific competencies, but the text — combined with the U.S. DOL AI Literacy Framework and Anthropic's AI Fluency Index — points to five clear areas. These map directly to the five dimensions used in AISA's AI readiness assessment framework.
| Training Element | What Article 4 Implies | AISA Dimension | Weight |
|---|---|---|---|
| Communicating with AI systems | Staff must know how to interact with AI effectively | Prompting & Communication | 23% |
| Evaluating AI outputs | Staff must not blindly trust AI-generated content | Critical Thinking | 22% |
| Understanding how AI works | Proportional technical knowledge of the systems in use | Technical Understanding | 20% |
| Integrating AI into workflows | Practical ability to use AI in job-relevant contexts | Workflow & Application | 25% |
| Responsible use and risk awareness | Understanding of bias, privacy, and safety obligations | Safety & Responsibility | 10% |
Element 1: Prompting and Communication
Staff need to know how to give AI systems clear, effective instructions. This isn't about memorising prompt templates — it's about understanding that the quality of input determines the quality of output. For deployers, this means training on the specific interfaces and tools your organisation uses. Across 1,911 AISA assessments, the average score in Prompting & Communication is 44.5 out of 100 — firmly in the Developing tier. Most workforces are starting from a lower baseline than leadership assumes.
Element 2: Critical Thinking and Output Evaluation
Article 4's proportionality requirement implies that people making decisions based on AI outputs must be able to evaluate those outputs critically. This includes recognising hallucinations, checking claims against sources, and understanding when AI confidence doesn't equal accuracy. The average Critical Thinking score across AISA assessments is 42.7 — the second-lowest dimension.
Element 3: Technical Understanding
The regulation requires literacy proportional to the "technical knowledge" of the persons involved. Engineers deploying models need deeper understanding than HR managers using a screening tool, but both need some grasp of how the systems work: what training data means, what a model can and can't do, and why outputs vary. Technical Understanding averages 39.1 across all roles in AISA data — the lowest of all five dimensions.
Element 4: Workflow Integration
Knowing about AI isn't the same as knowing how to use it. Article 4's focus on "operation and use" means staff must demonstrate practical competence in their actual workflows. Can they identify which tasks benefit from AI assistance? Do they know when to override or escalate? Workflow & Application scores average 47.6 — the highest dimension, but still in the Developing tier.
Element 5: Safety and Responsible Use
The EU AI Act is fundamentally a safety regulation. Article 4's literacy requirement exists to support the Act's broader goals around risk management, transparency, and human oversight. Staff must understand AI ethics frameworks, data privacy implications, bias risks, and their organisation's specific policies. Safety & Responsibility averages 41.2 across AISA assessments.
How to Document AI Literacy Compliance
Documentation is where Article 4 compliance will be won or lost. An auditor won't accept "we did some training" — they'll want evidence of a systematic approach.
Step 1: Establish a Baseline
Before any training, measure where your workforce stands. This serves two purposes: it identifies gaps that your training must address, and it creates a dated record that proves you took the obligation seriously from the start.
A baseline assessment should cover all five competency areas and be role-differentiated. AISA data shows a significant gap between self-assessed and actual competence: across 1,001 assessments with prediction data, people predicted an average score of 62.7 but actually scored 43.9 — an overestimation gap of 18.8 points. Self-assessment alone won't satisfy an auditor.
Step 2: Design Role-Appropriate Training
Map your training to the AI systems each role actually uses. A training needs assessment should identify:
- Which AI systems each team interacts with
- The risk classification of those systems under the AI Act
- The current competency level of each team (from your baseline)
- The target competency level required for their role
Step 3: Maintain Training Records
For each employee or contractor in scope, document:
- Date of baseline assessment and scores
- Training completed — content, format, duration, provider
- Post-training assessment and scores
- Re-assessment schedule and results
- AI systems the person is authorised to use
This creates the audit trail that demonstrates "sufficient measures." Store records for at least the duration of your AI system deployments, plus any retention period your national authority specifies.
Step 4: Schedule Re-Assessment
AI literacy isn't static. Models change, tools change, your organisation's AI deployments change. A defensible compliance programme includes periodic re-assessment — at minimum annually, and whenever significant new AI systems are deployed. Track score changes over time to demonstrate continuous improvement. For guidance on measuring training effectiveness, see how to measure AI training ROI.

Curious about your AI Fluency?
AISA helps you measure, prove and improve your AI skills — free report in a 20-minute chat.
Common Mistakes That Won't Satisfy Article 4
Patterns we see organisations falling into — and why each one creates compliance risk.
Mistake 1: The One-Off Webinar
A single awareness session does not constitute "sufficient measures." The regulation's proportionality requirement and its focus on ongoing operation imply a continuous programme, not a calendar event. A 45-minute webinar on "What is AI?" doesn't build the competence to operate AI systems responsibly — and it certainly doesn't demonstrate sufficiency to an auditor.
Mistake 2: Self-Assessment as Evidence
Some organisations plan to use self-reported confidence surveys as their compliance evidence. This is risky. AISA data shows people overestimate their AI competence by an average of 18.8 points on a 100-point scale. Students overestimate by 31.8 points. Even experienced engineers overestimate by 13.6 points. Self-assessment without independent verification is not a credible measure of literacy.
Mistake 3: One-Size-Fits-All Training
Article 4 explicitly requires proportionality to context and technical knowledge. Giving your data science team the same training as your legal team fails the proportionality test. Role-specific content mapped to actual AI system usage is the minimum defensible approach.
Mistake 4: No Baseline, No Measurement
If you can't show where your workforce started and where they are now, you can't demonstrate that your measures were sufficient. Training without assessment is activity without evidence.
Mistake 5: Ignoring Contractors and Third Parties
The regulation covers "other persons dealing with the operation and use of AI systems on their behalf." If your contractors use your AI systems, they're in scope. Many organisations overlook this entirely.
How AISA Supports Article 4 Compliance
AISA provides the measurement layer that makes AI literacy training auditable. It doesn't replace your training programme — it bookends it with defensible, independent assessment.
Pre-Training Baseline
Run your workforce through an AI readiness assessment before training begins. Each person receives scores across all five dimensions (Prompting & Communication, Critical Thinking, Technical Understanding, Workflow & Application, Safety & Responsibility), mapped to clear proficiency tiers. This gives you a dated, role-differentiated baseline that documents your starting point.
Post-Training Verification
After training, re-assess. The delta between pre and post scores is your evidence that training was effective — or your signal that it wasn't. Because AISA uses conversational assessment with an independent AI evaluator (not multiple-choice quizzes), it's resistant to cognitive surrender and surface-level memorisation. Anti-gaming measures detect copy-paste, style shifts, and suspicious response speed.
Audit-Ready Documentation
AISA generates per-person and team-level reports with timestamped scores, dimension breakdowns, and persona classifications. These reports map directly to the five competency areas Article 4 implies. When an auditor asks "how do you know your staff have sufficient AI literacy?" you have specific, dated, independently-assessed evidence — not a sign-in sheet from a webinar.
Alignment with Recognised Frameworks
AISA's rubric is validated against the U.S. DOL AI Literacy Framework (100% coverage of all competency areas) and Anthropic's AI Fluency Index (93% overlap). This matters for compliance because it demonstrates your measurement approach is grounded in recognised, external standards — not an internal invention. Details on the rubric methodology are available at the AISA rubric.
Timeline: Enforcement Dates and What to Do Now
Article 4 is already in force. Here's the timeline and a prioritised action list.
Key Dates
| Milestone | Date | Implication |
|---|---|---|
| EU AI Act entered into force | 1 August 2024 | Clock started |
| Article 4 (AI literacy) applies | 2 February 2025 | Already enforceable |
| Prohibited practices apply | 2 February 2025 | Already enforceable |
| High-risk obligations apply | 2 August 2026 | Imminent — months away |
| Full enforcement | 2 August 2027 | All provisions active |
Article 4 is not a future obligation. It has been enforceable since February 2025. If you haven't started, you're already behind.
What to Do This Quarter
- Inventory your AI systems. List every AI tool in use across the organisation, who uses it, and its risk classification under the Act.
- Identify in-scope personnel. Employees, contractors, and third parties who operate or make decisions based on AI systems.
- Run a baseline assessment. Use an independent assessment — not self-reporting — to measure current literacy across all five competency areas. An AI fluency assessment provides this.
- Design role-appropriate training. Use baseline results to target gaps. Prioritise high-risk system operators and decision-makers.
- Establish a re-assessment cadence. Quarterly for high-risk roles, annually for others, plus ad-hoc when new systems deploy.
- Document everything. Dates, scores, training content, attendance, re-assessment results. Build the audit trail now.
The high-risk system obligations hitting in August 2026 will compound the pressure. Organisations that have a functioning AI literacy programme with documented baselines will be in a far stronger position than those scrambling to retrofit compliance.
For a broader view of how AI literacy fits into your team's capability planning, see our AI competency framework guide.
Related reading: How Do I Know If I'm AI Literate? — a practical self-check against the competencies that matter.
Related reading: AI Fluency Framework for HR Teams [2026] — how to build an AI literacy programme that scales across departments.
Related reading: How Good Is My Team at AI? [2026 Data] — first-party data on where teams actually stand, by role and dimension.
Frequently Asked Questions
Does the EU AI Act require AI training?
Yes. Article 4 of the EU AI Act requires providers and deployers of AI systems to ensure sufficient AI literacy among staff and other persons involved in operating or using AI systems. This obligation has been enforceable since 2 February 2025. The regulation doesn't prescribe a specific training format, but it does require organisations to take "sufficient measures" proportional to the context and technical knowledge of the people involved.
What counts as sufficient AI literacy under the EU AI Act?
The regulation defines sufficiency through proportionality: literacy measures must account for the context of use, the technical knowledge of the persons involved, and the specific AI systems they interact with. In practice, this means role-appropriate training covering how to interact with AI, evaluate its outputs, understand its limitations, integrate it into workflows, and use it responsibly. A single generic awareness session is unlikely to meet the standard — documented, assessed, ongoing programmes are the defensible approach.
How do I prove AI literacy compliance?
Compliance evidence requires documented baselines, training records, and post-training assessments with dated, per-person results. Self-reported confidence surveys are insufficient — AISA data shows people overestimate their AI competence by an average of 18.8 points. Independent assessment across recognised competency dimensions, with periodic re-assessment and clear audit trails, provides the evidence an auditor or national authority will expect.
When does Article 4 of the EU AI Act take effect?
Article 4's AI literacy obligation has been enforceable since 2 February 2025. It was among the first provisions to apply after the Act entered into force on 1 August 2024. Organisations that haven't begun implementing literacy measures are already non-compliant. The broader high-risk system obligations take effect on 2 August 2026, adding further urgency to workforce readiness programmes.

Curious about your AI Fluency?
AISA helps you measure, prove and improve your AI skills — free report in a 20-minute chat.

