Short answer: Article 4 requires providers and deployers to take measures ensuring a sufficient level of AI literacy among staff and others dealing with AI systems on their behalf, taking into account their technical knowledge, experience, education and the context of use. There's no prescribed curriculum or certification. In practice, a usage policy, role-appropriate training and a record of who received it satisfies it.
General information, not legal advice.
Why this is the obligation most businesses have already missed
It's been applicable since February 2025 — well before the transparency rules that dominated 2026 coverage — and it applies to any organisation in scope that uses AI systems, regardless of size or risk category. There's no small-business exemption.
Most SMEs using ChatGPT or Copilot are technically subject to it and have done nothing, largely because it received a fraction of the attention given to the high-risk regime that doesn't apply to them.
What "sufficient" means
Deliberately proportionate. The Act asks you to account for the technical knowledge, experience, education and training of the people involved, and the context in which the systems are used. A marketing assistant using an AI writing tool needs different literacy from an operations lead building automated workflows.
The practical reading: everyone using AI should understand what the tool does, its limitations, what data must not go into it, and when output needs checking. Those doing more technical work need more.
What training should actually cover
A workable curriculum for a small business, running to perhaps ninety minutes:
- What these tools are and aren't. Enough grounding that people understand output is generated, not retrieved, and can be confidently wrong.
- Failure modes. Hallucination, outdated information, plausible-sounding fabrication of sources and figures. Show real examples rather than describing them.
- Data rules. What must never be entered, and why the distinction between consumer and enterprise tiers matters.
- Approved tools. Which ones, and what to do about a tool someone wants to try.
- Review requirements. Where a human must check before anything goes out.
- Disclosure. When AI use must be told to a client or the public.
- Where to ask. A named person.
What evidence to keep
The obligation is to take measures. The evidence is the record:
- A dated AI usage policy with a version history.
- Training materials — slides, a document, a recording.
- An attendance and acknowledgement record: name, date, what they covered, confirmation they've read the policy.
- Onboarding inclusion, so new starters are covered automatically.
- A review date.
A spreadsheet is entirely sufficient. What matters is that it exists and is current.
The commercial reason to do this properly
Regulatory exposure at SME scale is modest. The more likely scenario is a client's procurement questionnaire asking whether you have an AI policy and staff training. Increasingly, larger organisations ask this before contracting, because their own compliance requires it of their supply chain.
Businesses that can answer yes with evidence pass through; businesses that can't spend a fortnight assembling something under time pressure. That, more than enforcement, is what makes this worth an afternoon.
Frequently asked questions
Does this apply to contractors and freelancers?
The obligation covers those dealing with AI systems on your behalf, so it reaches contractors using AI in work for you. Cover it in your contractor terms.
Is there a certification we need?
No. There's no mandated certification, and vendors selling one as a legal requirement are overstating the position.
How often should training be repeated?
Annually as a baseline, plus whenever the policy changes materially or a significant new tool is adopted.
We deliver documented AI literacy training that satisfies Article 4 — policy, session and record. See what's included.
