Legislation
The AI Act obligations start with one paragraph that affects everyone.
No size threshold, no mandatory curriculum and no certificate you can buy. But an outcome you have to be able to justify. Here's what it says, who it applies to, and what enforcement since August 2026 means.
What it says
01 · The text
Article 4 requires both providers and deployers of AI systems to ensure a sufficient level of AI literacy among everyone operating those systems on their behalf.
Three words carry the whole article. 'Sufficient' means there's no fixed measure: what's enough depends on what you do with AI. 'Taking into account' refers to technical knowledge, experience, education and the context of use, that's the phrase that makes one programme for everyone inadequate. And 'on their behalf' widens the circle: contractors and suppliers operating your systems fall under it too.
What it doesn't say matters just as much. No hours, no exam, no recognised certificate, no register to enrol in. The legislator prescribes an outcome and leaves the route to you. That's comfortable until someone asks why your approach was sufficient, because then there's nothing to hide behind but your own reasoning.
Note also the distinction between provider and deployer. Nearly every Dutch organisation is the latter: you use AI someone else built. That doesn't lessen your responsibility under this article, the literacy obligation applies to both, but it matters enormously for the rest of the regulation, where the heavy obligations sit with the provider.
Not legal advice
This is a plain-language explanation of how we read the article, written from the training side. For the legal assessment of your specific situation you need a lawyer, and we can't replace one.
The timeline
02 · What happens when
1 Aug 2024
The regulation enters into force
The AI Act takes effect, with phased application. Most obligations get a one- to three-year run-up; Article 4 belongs to the earliest group.
2 Feb 2025
The literacy obligation applies
From this date Article 4 applies to every organisation using AI systems. There is no transitional arrangement and no size threshold.
2 Aug 2026
Enforcement begins
Dutch supervisors can act from now on, with the Data Protection Authority coordinating. The obligation had already existed for eighteen months; what changes is that consequences attach to it.
What enforcement means in practice
03 · A realistic view
The maximum fine is €15 million or 3% of annual turnover. That figure is being quoted a lot right now, and it gives a distorted picture of what is likely to happen.
Regulators rarely start at the maximum, and rarely with the smallest breach. The first years of a new regulation typically focus on high-risk applications and on parties where the harm is visible: recruitment screening, credit scoring, facial recognition. A municipality that rolled out Copilot without a role analysis isn't top of that list.
That's no reason to do nothing, for two practical reasons. The first is that the obligation surfaces at moments you don't expect: in a tender, during an audit, in a data processing agreement, or when the works council asks. At those moments 'we ran a training' is a weaker answer than a measurement with a date on it.
The second is that it's cheap to cover. The four steps Article 4 implies, inventory, level assessment, training, recording, are exactly the steps you'd go through anyway if you want to know whether your AI investment delivers. Compliance is then a by-product of adoption work done properly, not a separate cost line.
Questions about Article 4
04 · Short answer
What does Article 4 literally say?
That providers and deployers of AI systems take measures to ensure a sufficient level of AI literacy among their staff and others operating the systems on their behalf, taking into account technical knowledge, experience, education and the context in which the systems are used.
What is a deployer?
The organisation using an AI system under its own authority. That's you the moment you deploy Copilot, ChatGPT or an AI feature in an existing package for work. You needn't have built or procured the system, using it is enough. The Dutch text calls this a gebruiksverantwoordelijke.
Are there exemptions for small organisations?
No. Unlike many other obligations, Article 4 has no threshold in headcount or turnover. The standard is 'sufficient', though, and what counts as sufficient depends on the risk. A five-person design studio having copy rewritten demonstrably needs less than an insurer having claims assessed.
Who supervises this in the Netherlands?
The Dutch Data Protection Authority is the coordinating supervisor for AI and algorithms; for technical requirements it works with the Dutch Authority for Digital Infrastructure. Sectoral regulators also remain competent in their own domain, so in healthcare or finance you may deal with more than one.
How high can the fine be?
Breaches of deployer obligations fall under Article 99(4): up to €15 million or 3% of worldwide annual turnover, whichever is higher. That's the middle band; the heaviest fines are reserved for prohibited AI practices. For SMEs and start-ups the lower of the two amounts applies.
Is there a mandatory curriculum or certificate?
No, and that's deliberate. The legislator prescribes an outcome, not a method. Which means no provider can sell you an officially recognised AI Act certificate, there is no such thing. What does exist is a file in which you argue why what you did is sufficient for your situation.
Read it yourself
05 · Sources
We summarise, but the law speaks for itself. Below are the original text and the regulators responsible for it.
- EUR-Lex, Publications Office of the EURegulation (EU) 2024/1689, the full text(opens in a new tab)
- European CommissionThe regulatory framework for AI(opens in a new tab)
- Dutch Data Protection AuthorityAlgorithms and AI supervision(opens in a new tab)
- Dutch Authority for Digital InfrastructureArtificial intelligence and market surveillance(opens in a new tab)
Read on
- Arranging AI literacy
The four steps from obligation to file, and why a course alone doesn't cover it.
- Measuring Copilot adoption
The same measurement work, approached from whether the rollout delivers anything.
- Our privacy statement
What we record, for how long, and how we handle your data.
From article to file
The obligation becomes concrete once you know who uses which system and at what level. That's one five-minute measurement per employee, and after that you have something to show.
