Itjoe
ENNL

AI Act Article 4

AI literacy is no longer a good intention, it's an obligation.

Since 2 February 2025, every organisation using AI must ensure its people can handle it. Since 2 August 2026 that is enforced. So the question is no longer whether you arrange it, but how you show that you have.

What AI literacy is

01 · The definition

Your employees' ability to use AI responsibly: understanding what a system does, recognising the risks, and knowing when not to simply accept the output.

The AI Act describes it as skills, knowledge and understanding. Note what it doesn't say: no hour count, no mandatory curriculum, no certificate. It's about what people can do, not what they attended. That distinction looks formal but decides in practice whether your reasoning holds up.

In practice it comes down to three things someone has to grasp. That a model writes convincingly regardless of whether it's right. That it adopts your assumption rather than challenging it. And that what you enter ends up somewhere, and that where matters. Anyone who grasps those three uses any AI system more responsibly than someone who has memorised fifty prompts.

It's deliberately broader than one product. The obligation attaches to the use of AI systems, not to the vendor, so Copilot, ChatGPT, Gemini and the AI feature in your HR suite all fall under it. Which is why the knowledge base should be vendor-neutral: it doesn't change with the next product update.

Good to know

There is no officially recognised AI Act certificate; the legislator prescribes an outcome, not a method. What you can record is who was trained and what the level did. That's exactly what we deliver, in a file you can hand over as is.

The four steps

02 · From obligation to file

Step 01

Take inventory

Which AI systems are in use, by whom and for what. The official list holds Copilot and perhaps a translation service; the real list also holds the free ChatGPT accounts, the AI feature in the HR suite and the plug-in someone found handy.

Step 02

Set the level per role

Article 4 asks for a level appropriate to role, context and risk. A lawyer having a contract summarised runs a different risk than someone tidying meeting notes. This is the step most organisations skip, and exactly where a uniform programme falls short.

Step 03

Train

The knowledge base for everyone, the ninety-minute e-learning, plus whatever a role additionally needs. Where the matrix leaves an area pale, a targeted session is added.

Step 04

Record and repeat

Who did what and when, and did the level actually change. That last part is what almost nobody has, and the only thing that shows the difference between offering training and it working.

Why step two makes the difference

03 · The trap

The market is responding to this obligation with whatever sells fastest: one course, identical for everyone. That's better than nothing, and it isn't what's being asked.

The problem isn't the quality of such a course, we sell one ourselves. The problem is that an organisation starts at step three with it. Without an inventory you don't know which systems to cover, without a level assessment you don't know who needs more, and without a follow-up measurement you're left with an attendance list.

A uniform programme is demonstrably easy, but not demonstrably appropriate. Article 4 asks for literacy fitting the role, context and risk, and that difference is exactly what a regulator looks at. The good news: step two takes five minutes per employee and immediately produces the rationale for why one group needed more than another.

There's a second reason to look beyond one session, and it has nothing to do with the law. What people learn in ninety minutes fades if nothing follows. That was true before the AI Act. So reinforcement isn't an add-on to compliance; it's the part that makes the compliance mean something.

Two routes, depending on where you are

04 · What you can do

90 minutes · €49

The knowledge base for everyone

The ninety-minute e-learning with a participant certificate, for all employees and whichever tool you use. One-off, no annual subscription, no minimum order. This is step three, and for many organisations the fastest start.

5 minutes p.p.

The rationale and the file

The measurement per role, repeated after 60 days. It produces the matrix showing which group needs more, and the difference between the two measurements is the only figure proving the level actually changed. Those are steps two and four.

The bar is higher in the public sector

05 · Public sector

Municipalities, public bodies and educational institutions get the same obligation as everyone else, but with two things on top.

The first is visibility. A council question, a freedom-of-information request or an audit office review arrives sooner than an inspector, and at those moments 'we ran a training' is a weaker answer than a measurement with a date on it. The national audit office and the data protection authority also publish on this themselves, so the question arrives with a frame of reference.

The second is that the risk profile varies sharply per task. A communications adviser having a press release sharpened is somewhere else entirely than someone summarising an objection or preparing a decision affecting a citizen. That's exactly where the level assessment per role stops being a formality and becomes the core of your case.

Frequently asked questions about AI literacy

06 · Short answer

What is AI literacy?

Employees' ability to use AI responsibly: understanding what a system can and cannot do, recognising the risks, and knowing when not to simply accept the output. The AI Act describes it as skills, knowledge and understanding, so not a certificate but something people actually do.

Is AI literacy mandatory?

Yes, since 2 February 2025, through Article 4 of the AI Act. Enforcement by the Dutch supervisory authorities started on 2 August 2026, with the Data Protection Authority coordinating. There's no transitional arrangement and no size threshold.

Does it apply to us too?

If anyone in your organisation uses an AI system for work, yes. A municipality that has only rolled out Copilot falls under it just as much as a company training its own models. What differs is the weight of what you have to arrange: that depends on the risk of the use.

What does a 'sufficient level' mean?

That there's no fixed measure. The text says: taking into account technical knowledge, experience, education and the context in which the systems are used. That's exactly the phrase making one programme for everyone formally insufficient, a lawyer having a contract summarised runs a different risk than someone tidying up notes.

Is an e-learning enough to comply?

For the knowledge base, yes; for the whole obligation, no. Article 4 asks four things: knowing which systems are used, determining the level per role, training, and recording it. An e-learning is step three. Doing only that leaves you with an attendance list, and that proves attendance, not literacy.

Is there an official AI Act certificate?

No. The legislator prescribes an outcome, not a method, so there's no recognised mark and no register to enrol in. What you can record is who was trained, when, and what the level did afterwards. The judgement ultimately sits with the regulator.

What is the potential fine?

Breaches of deployer obligations fall in the middle band of Article 99: up to €15 million or 3% of worldwide annual turnover. That figure is quoted a lot right now and gives a distorted picture, the first years of a regulation address high-risk applications, not a Copilot rollout.

Read on

Start with the measurement or the base

Want something everyone can get through quickly? Start with the e-learning. Want to know where your people stand and why one group needs more? Start with the five-minute measurement. Either works, and the second is what you can still show a year later.