Article 4 of the European AI Regulation has applied since 2 February 2025. It requires both providers and deployers of AI systems to ensure AI literacy among their staff, proportionate to role, level of knowledge and context of use. No lower limit on company size, no exemption for low risk categories: if you use ChatGPT, Copilot or Claude in your work processes, you fall under it. Supervision started on 2 August 2026.
Why is this regulated at all? The thinking behind Article 4 is that AI systems make mistakes that don't look like mistakes. A candidate rejected because of a pattern in old data. A summary in which one figure is just slightly wrong. An answer that sounds fluent and convincing and is factually incorrect. If you don't know that can happen, you don't check for it. The legislator therefore places the responsibility with the organisation deploying the system: make sure the people working with it understand what they have in front of them.
What gets mentioned far less often: Article 4 was rewritten a week before that date. The Digital Omnibus, Regulation (EU) 2026/1744, has been in force since 27 July. Where the old text asked organisations to ensure a sufficient level, the new text asks for measures that support its development. The Commission sums it up this way: the obligation remains, but no specific level is prescribed, and you don't have to guarantee any particular level for any individual.
So how is this enforced? The honest answer: that isn't clear yet. Article 4 carries no fine of its own under the regulation. In its Q&A, the European Commission states that national supervisory authorities can enforce and impose penalties, but this has to be arranged in national legislation, and the Dutch implementing act for the AI Regulation is still in preparation. The regulation also creates no criminal offences and no right to compensation.
What remains is this. The Commission notes that a penalty becomes more likely where there is evidence of an incident caused by inadequate training and guidance. Not as a standalone infringement, then, but as a circumstance at the moment your organisation is being looked at for another reason. No certificate is required, and no AI officer either: an internal record of what you have done is enough.
In short: the obligation stands, the bar sits lower than it did six months ago, and anyone who bought a course to avoid a fine bought something against a risk that works differently than the brochure suggested.