Czas czytania: 10 minut
EU AI Act checklist: does your company comply with the mandatory training in Article 4?

The EU AI Act doesn't require a course. It requires you to prove your team understands the AI they use: what it can do, what it can't, and what risks it carries.
Article 4 of Regulation (EU) 2024/1689 sets out something more concrete than it first appears: it's not enough for employees to use AI systems. The organization must be able to demonstrate that they understand what they're using: what the system can do, what it can't, and what the consequences are of trusting its output without applying their own judgment.
Updated as of September 2026, with two dates worth keeping apart. The AI literacy obligation has applied since February 2, 2025.¹ What began on August 2, 2026 is the general application of the Regulation and effective supervisory power, exercised in Spain by the AI supervisory authority (AESIA).
The question we hear most often from L&D teams right now isn't "what does the law say?" It's: "how do I know if what we have is already enough?"
That's exactly what this checklist is for. It's not a complete guide to the Regulation, which is in our detailed guide to Article 4. It's a diagnostic tool: seven questions that help you see where the work is done and where the real gaps are, now that the supervisory window is open.
Article 4 applies to those who deploy AI systems, not only those who build them. That includes any AI tool your employees use: writing assistants, predictive analytics platforms, recommendation systems, AI-powered hiring tools, content generators.
Without an inventory, you can't know who needs training or on what. The obligation isn't generic, it's tied to the specific systems each role actually uses.
What you should have: an up-to-date register of which AI systems are in use, in which departments, and for which functions. It doesn't need to be sophisticated, a spreadsheet works. What doesn't work is not having one at all.
The Regulation classifies AI systems into four categories: unacceptable risk (prohibited), high risk, limited risk, and minimal risk. Training requirements are more demanding for high-risk systems, including those that affect hiring decisions, performance evaluation, access to services, or critical infrastructure.
What you should have: a basic risk classification for each system in your inventory. For high-risk systems, the requirement for documented competency is higher, and so is the depth of training required.
"Sufficient AI literacy" doesn't mean the same thing for everyone. Article 4 explicitly recognizes that the required competency level must be adapted to the role: the engineer fine-tuning a model needs a different kind of understanding than the sales rep using a customer analytics tool, or the manager making decisions based on automated recommendations.
Training the entire workforce with the same generic module doesn't fulfill the obligation: it covers it on paper, but not in substance.
What you should have: a role-and-competency matrix that defines, for each profile, which aspects of the AI systems in use they need to understand and at what level of depth.
This is where many organizations fall short without realizing it. Article 4 requires employees to understand three dimensions of the systems they use: what the system can do, what it cannot do, and what risks its use entails.
A tool onboarding module that explains "how to log in, how to run a query, how to read the output" doesn't meet this requirement. The critical dimension is missing: when the system can be wrong, what biases it may carry, what the consequences are of trusting its output blindly.
What you should have: training content that includes, for each system, at least one block on known limitations and one on the risks of misuse or over-reliance.
Here's a distinction many teams overlook: having a training system is not the same as having audit-ready evidence.
An LMS with published modules is a system. Evidence is something else: individualized records showing that each specific employee completed the training, on what date, and with what result if there was an assessment. The difference matters because an inspection doesn't audit the platform, it audits the person. "María García, from the operations department, completed the AI literacy module on May 15 with an 85% score on the final assessment" is evidence. "We have a course in the LMS that all employees have access to" is not.
A PDF sent by email doesn't generate that record. An in-person session without a signed attendance list and outcome, either.
What you should have: individualized completion records per employee, module, date, and assessment result, automatically generated by the system and exportable in a format that supports an audit (SCORM, xAPI, or another recognized traceability standard).
The Regulation treats AI literacy as an ongoing competency, not a one-time certificate. AI systems get updated, the Regulation's application guidelines are published progressively, and the catalog of tools in use at your company will change.
Training designed once to meet a deadline in August 2026 may be obsolete before the year is out.
What you should have: a periodic review mechanism for training content (at minimum, annual) and a clear process for updating modules when a new AI system is introduced or an existing one changes significantly.
Not in three months. Today.
This is the closing question because it reveals whether compliance work is done or merely planned. The inventory, the risk classification, the role matrix, the training content, the records, the update plan: if any of these exists only as intention, the compliance is not complete.
AESIA doesn't evaluate plans. It evaluates evidence.
The AI literacy obligation didn't start in August 2026, it started on February 2, 2025. What changed in August 2026 is that someone can now come and check.
It's the most widespread confusion in compliance teams, and it carries an uncomfortable practical consequence: if your organisation planned AI training as a 2026 project, the evidence for 2025 doesn't exist. That isn't a theoretical problem, because an inspection can ask about the period in which the obligation was already enforceable.
| Date | What applies | Status as of September 2026 |
|---|---|---|
| August 1, 2024 | Regulation enters into force | Done |
| February 2, 2025 | AI literacy (Article 4) and prohibited practices | Enforceable for over a year |
| August 2, 2025 | General-purpose AI models and governance | In application |
| August 2, 2026 | General application of the Regulation, transparency obligations and effective supervision | In application: inspection window open |
| December 2, 2027 | Obligations for Annex III high-risk systems | Pending |
| August 2, 2028 | High-risk embedded in already regulated products | Pending |
With that calendar in front of you, three gaps show up again and again, and almost no organisation has them covered.
The training may have happened informally, in an internal session or a memo, but without named records it isn't evidence. Documenting retroactively what actually took place, with real dates and nothing invented, is more defensible than leaving the period blank.
Most AI system inventories were drawn up in the first wave of compliance. Since then new tools have come in through the back door, adopted by one team without passing through procurement or IT.
A module recorded eighteen months ago describes capabilities and limits that no longer match the current tools. It's the same underlying problem as in any regulatory training: content ages faster than the annual review cycle, and here the lag is measured in months.
Seven questions. In most organizations, two or three don't have a solid answer. That's not a failure, it's a useful diagnosis.
The path forward is practical: inventory first (nothing else is possible without it), then risk classification by system, then the role matrix, and from there the design of training with traceability built in from the first module. The order matters because each step enables the next.
What doesn't work is treating all of this as a project for "after the summer." The deadline is before the summer.
Since February 2, 2025. That's a different date from August 2, 2026, which is when the Regulation became generally applicable and national authorities could exercise supervision. The obligation to train predates the ability to inspect it.
No. The obligation to ensure "sufficient AI literacy" applies to any organization that deploys AI systems, meaning it uses them in its operations. If your company uses an AI tool for hiring, customer analysis, or operational management, Article 4 applies to you.
Since August 2, 2026 AESIA can open supervisory proceedings, and the obligation has been enforceable since February 2025. Penalties under the Regulation for breaches of operator requirements (which include Article 4) can reach up to 15 million euros or 3% of global annual turnover. For less serious breaches, penalties are lower, but reputational risk and exposure in internal audits also count.
It depends on the content, but in most cases it's not enough. Article 4 requires training to be proportionate to the role and to the specific systems the employee uses. A general introductory module can be a starting point, but not the end point.
Article 4 establishes the general AI literacy obligation for all employees who work with AI systems, regardless of risk level. High-risk systems (Annex III of the Regulation) have additional specific requirements: technical documentation, human oversight, audits, activity logging. These are two separate layers: Article 4 applies in every case; the high-risk requirements are added on top when the system falls into that category.
¹ Regulation (EU) 2024/1689 of the European Parliament and of the Council, EU Artificial Intelligence Act - EUR-Lex ² AI regulatory framework: implementation timeline - European Commission ³ AESIA, Spanish Agency for the Supervision of Artificial Intelligence
Program wspierania zatrudnienia na czas nieokreślony wykwalifikowanych osób młodych w ramach Krajowego Systemu Gwarancji dla Młodzieży. Vidext otrzymał dotację w wysokości 25.401€ przyznaną przez LABORA (Walencka Służba Zatrudnienia i Szkoleń) na zatrudnienie na czas nieokreślony w 2024 r. wykwalifikowanych osób młodych zarejestrowanych w Krajowym Systemie Gwarancji dla Młodzieży; działanie kwalifikuje się do współfinansowania z Europejskiego Funduszu Społecznego Plus (EFS+) 2021-2027 lub innego funduszu Unii Europejskiej. Expediente ECOGJU/2024/550/46. Niniejsza publikacja jest dokonywana w wypełnieniu obowiązków przejrzystości określonych w ustawie 19/2013 z dnia 9 grudnia.



