If someone at your company uses ChatGPT to write emails, a copilot to code, or a chatbot to serve customers, the European Artificial Intelligence Regulation already applies to you. Its Article 4 requires you to train the staff who use these tools, and since August 2026 national authorities can supervise compliance.
In recent months, plenty of alarmist messages have circulated about an "obligation to certify" employees. The reality is more nuanced, and the article also changed in July 2026 with the so-called Digital Omnibus. In this guide we explain what the law requires today, what it doesn't require, and how to get your company ready for an inspection without turning it into a bureaucratic headache.
What AI literacy is
AI literacy is the set of knowledge and skills that allow a person to use artificial intelligence systems in an informed and responsible way. Regulation (EU) 2024/1689 defines it in Article 3 and links it to understanding both the opportunities of AI and its risks and the possible harm it can cause.
In practice, an AI-literate employee knows three things:
- How the tool they use works: what it does well, what it does poorly, and why a language model can confidently make up data (so-called hallucinations).
- What information they must not enter: customers' personal data, financial information or trade secrets in unauthorized tools.
- When to review the output: which outputs need human oversight before being sent, published or used to make decisions.
The goal isn't to turn the whole team into machine learning engineers. The required level depends on the role and the risk: someone who uses an assistant to summarize meeting minutes doesn't need the same as someone who operates a system that screens candidates or grants loans.
What Article 4 of the AI Act says after the Digital Omnibus
Article 4 requires providers and deployers of AI systems to take measures that support the AI literacy of their staff and of those who operate these systems on their behalf. That is the wording in force since 27 July 2026.
Until that date, the original text was more demanding: it required ensuring "to their best extent" a sufficient level of literacy. The Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744, rewrote the article entirely:
| Original wording (2025) | Current wording (since 27/07/2026) | |
|---|---|---|
| Type of obligation | Obligation of result: ensure a sufficient level | Obligation of means: take measures that support training |
| Individual level | Implicitly required | Explicitly, no specific level per person must be guaranteed |
| Criteria | Knowledge, experience, training and context of use | The same criteria, plus the persons affected |
| Public role | Secondary | The Commission and Member States take a more active role in promoting it |

Who it affects: almost certainly, your company
Article 4 applies to any organization that is a provider or deployer of an AI system, regardless of its size or sector. "Deployer" simply means that you use AI under your authority in a professional context.
These are common cases that fall within the scope of the regulation:
- Marketing and sales: copywriting, image generation or translations with generative AI.
- Customer service: a customer service chatbot that answers queries on your website or via WhatsApp.
- Operations and administration: automations that classify invoices, extract data from documents or connect your CRM with AI.
- Technology: teams that code with copilots or integrate language models into corporate software.
- Human resources and finance: tools that screen CVs or assess risk, which may also be high-risk and carry additional obligations.
The obligation also covers people who aren't on the payroll but use your systems on your behalf, such as freelancers, subcontractors or temporary agency staff. If you work with an external development team, the contract should make clear who is responsible for their training.
AI Act timeline and who supervises it in Spain
The literacy obligation has applied since 2 February 2025, and since August 2026 national authorities can supervise it. These are the key dates according to the European Commission:
| Date | Milestone |
|---|---|
| 1 August 2024 | The AI Act enters into force |
| 2 February 2025 | Prohibited practices and the literacy obligation (Article 4) apply |
| 2 August 2025 | Governance rules and obligations for general-purpose AI models |
| 27 July 2026 | The Digital Omnibus enters into force and Article 4 is rewritten |
| 2 August 2026 | General application of the regulation; supervision and penalties by national authorities begin |
| 2 December 2027 | Obligations for Annex III high-risk systems (HR, credit, education…) |
| 2 August 2028 | Obligations for high-risk systems embedded in regulated products (Annex I) |
In Spain, the reference body is the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), headquartered in A Coruña.
Are there fines for not training staff? The AI Act's penalty regime doesn't set a specific amount for Article 4, and it's up to each Member State to determine how it is sanctioned. The real risk lies elsewhere: if an incident occurs (a data leak, a discriminatory decision, a serious error), not being able to prove that you trained your team weakens your position before the authority, a judge and the affected customer.
How to demonstrate compliance during an inspection
What an authority will ask for isn't a diploma, but a coherent record that links the AI tools you use to the training each person has received. A solid record usually includes:
| Document | What it should show |
|---|---|
| AI systems inventory | Which tools are used, in which department, with what data and for what purpose |
| Role map | Which roles use each tool and what level of knowledge they need |
| AI use policy | Authorized tools, prohibited data and when human review is mandatory |
| Role-based training plan | Content tailored to the role and the risk, not a single course for everyone |
| Training log | Person, date, content, duration and, if applicable, assessment or certificate |
| Periodic review | Updates when tools, models or processes change |
Traceability is key. If AI is used in a scattered way, with each department on its own accounts and no central control, rebuilding this record after the fact is almost impossible. That's why AI governance starts with knowing what is used and where.
The real risk: shadow AI
The biggest compliance problem usually isn't the lack of a course, but "shadow AI": employees using tools on their own, with personal accounts and without the company knowing.
This uncontrolled use creates three concrete risks:
- Data leaks: customer information or internal documents that end up in external services without a data processing agreement, with GDPR implications as well. It's an area worth reviewing alongside your cybersecurity strategy.
- Undetected errors and biases: made-up answers that reach a customer, or biased criteria applied without human review. The same goes for code: that's why we recommend a technical audit of AI-generated code.
- Inability to demonstrate due diligence: if you don't know which tools are being used, you can't train anyone on them or document it.
Banning AI rarely works: people keep using it, just in secret. The effective alternative is to offer an authorized, convenient and controlled corporate environment, and to train the team to use it well.
How to solve compliance simply with Naios.net
Compliance comes down to three steps: know what AI is being used, centralize it, and train the team while keeping a record. This is how we approach it with our clients.
1. Take inventory of the AI already in use
Go department by department and note which tools are used, with what data and for what purpose. You'll find more than you expect. This exercise is also the starting point for knowing whether your company is ready to integrate AI in an orderly way.
2. Centralize operations in a controlled environment
Instead of dozens of scattered accounts, the team should work from a single corporate environment with access to the models it needs, permission controls and usage traceability. For this we work with naios.net, an AI orchestration platform that securely unifies tools, models and data. You can read more about our partnership with naios for AI orchestration.
If you also need AI to work with your internal information, we develop AI integration into corporate software with LLMs and RAG so your data stays under your control.
3. Train by role and document it
From within the naios.net platform itself, organizations can access a training program on responsible AI use and obtain a named certificate for each employee. As we've seen, the certificate isn't a legal requirement, but it is a simple way to keep the record an inspection will ask for, built into the same environment where your team uses AI.
As a naios Diamond partner, at MiTSoftware we help you deploy the platform, tailor the training to each role and connect AI with your systems.
Is your team using AI without a common framework? At MiTSoftware we help you take inventory, deploy naios.net and connect AI with your systems, from consulting to integration. Talk to our team and we'll show you how to get your company ready.