Call · 15 min
AI ActMattia Esposito9 September 20268-minute read

AI training is mandatory. And the obligation kicked in before the one everyone's watching.

While Italian businesses were watching Article 50 and transparency, Article 4 of the same regulation had already been in force for eighteen months. It asks for one thing only: if you use an AI system, look after the skills of the people using it.

In brief

The obligation has applied since 2 February 2025. Article 4 sits in Chapter I of Regulation (EU) 2024/1689, and Chapter I started to apply on that date, a year and a half before Article 50 on transparency.

It also covers businesses that simply use other people's tools. The regulation names the provider and the deployer in the same sentence, and an SME using a third-party assistant or generative model is a deployer in every sense.

You don't need a course with a certificate. The European Commission says no certificate is required, and an internal record of what you've done is enough, as long as it fits the systems actually in use.

Since July 2026 the article has been written more lightly. The digital omnibus on AI replaced the text and dropped the requirement to guarantee a set level of competence for every single person.

This piece goes deep on a point the guide on AI Act obligations for businesses and SMEs only touches on. It's about businesses, not state schools, and it stops where a lawyer's work begins.

Who has the obligation, and since when

Article 4 of Regulation (EU) 2024/1689 is addressed to providers and deployers of AI systems. It has applied since 2 February 2025, because Article 113 says Chapter I applies from that date, and Article 4 is the last article in Chapter I.

The regulation defines a deployer as anyone using an AI system under their own authority, except in the course of a personal, non-professional activity. A business using an assistant on its website, a model that writes copy or a system that transcribes calls fits that definition without any stretch.

The obligation doesn't stop at employees. The text refers to staff and any other persons dealing with the operation and use of the systems on behalf of the business, and the European Commission makes clear that this includes contractors, service providers and, in some cases, customers.

What Article 4 actually says, after July 2026

Regulation (EU) 2026/1744, the digital omnibus on AI published on 24 July 2026 and in force from the third day after, replaced Article 4 in full. The obligation to ensure a sufficient level became an obligation to take measures to support the development of AI literacy.

“This obligation does not require providers or deployers to ensure a specific level of AI literacy for any person.”
Regulation (EU) 2026/1744, new text of Article 4 of the AI Act (our translation of the Italian text)

Recital 8 of the omnibus gives the reason plainly: rigid obligations didn't suit every type of provider and deployer, and created an extra compliance burden, particularly for smaller businesses. The date of application, on the other hand, wasn't touched.

Anyone looking up Article 4 today in a source that hasn't been updated will still find the old wording, with a sufficient level to be ensured. The difference between the two versions changes how you show compliance, so read the consolidated version rather than a commentary.

Whether you need a certified course, and what you need to be able to show

No certificate is needed, and no body issues one that counts for Article 4. The European Commission's published answers on AI literacy say so directly: organisations can keep an internal record of training and other guidance initiatives, and no specific governance structure is imposed.

The same source rules out two other things that get repeated a lot. There's no obligation to measure employees' knowledge of AI, and no need to appoint an AI officer along the lines of a data protection officer.

There is one warning, though, and it's about the most common shortcut. The Commission says that relying on the system's instructions for use, or asking staff to read them, is in many cases not enough: you need training and guidance tailored to the group of people and the context of use.

A useful internal record holds four things: which AI systems run in the business, who uses them, what those people have been told, and when. The first two match the list you need for the regulation's other obligations too, so the work only gets done once.

There's one case where that record counts for a lot more. The Commission notes that enforcement action becomes more likely when there's evidence of an incident caused by a lack of staff training and guidance, and at that point the date on the record is worth more than any statement of intent.

What adequate means for six people and for two hundred

The regulation sets no hours, content or format. It asks you to take four things into account: people's technical knowledge, experience, education and training, and the context the systems are used in. It follows that two businesses of different sizes can both comply with very different measures.

BusinessProportionate measureHow you show it
Six peoplethird-party generative tools, no high-risk systems

An internal session on the tools actually in use, covering the real risks (made-up answers, confidential data pasted into a prompt), and a written rule on what never gets pasted in.

A one-page note with the date, who attended and the tools covered. That's the internal record the Commission describes as sufficient.

Two hundred peopledepartments with different exposure

Separate tracks for each group, because Article 4 asks you to take education and experience into account. People handling customer data and people writing copy don't face the same risks.

A record for each group, dated materials, and a trail of who received what. No body hands out a seal of approval; the evidence stays internal.

Businesses using high-risk systemsChapter III of the regulation

Here Article 4 isn't the only reference. Article 26 requires deployers of high-risk systems to assign human oversight to people with the necessary competence and training.

A different and heavier matter, which needs a dedicated reading of Chapter III and usually a professional.

It applies even if you only use ChatGPT in the office

Yes, and the question is asked in exactly this form in the European Commission's answers, in the case of employees using ChatGPT to write advertising copy or to translate. The answer is yes, with the advice to make those people aware of the tool's specific risks, starting with made-up answers.

This is the case that applies to the vast majority of small Italian businesses, and it's also the one where nobody feels it concerns them. A generative model open in a browser doesn't look like an AI system the business has adopted, but under the regulation's definition it is one.

If you want to understand which tool you actually have, and how much autonomy it has, the practical distinction is on the page comparing an AI agent and a chatbot, and the terms are explained in the AI and automation glossary.

Who enforces it in Italy, and what happens if you haven't done it

Enforcing Article 4 isn't a job for the Commission's AI Office but for the national market surveillance authorities, and the Commission gives 2 August 2026 as the start of supervision. In Italy, Article 20 of Law 132/2025 designates AgID and ACN as the national authorities for artificial intelligence.

Of the two, real enforcement sits with ACN. The law makes it responsible for supervising AI systems, including inspections and penalties, while AgID handles notification, assessment, accreditation and monitoring of the bodies that check conformity.

On penalties, one detail is almost always missed. The list in Article 99(4) of the regulation, the band that goes up to €15 million or 3% of worldwide annual turnover, names Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50. Article 4 isn't there.

So the consequences come through paragraph 1 of the same article, which leaves Member States to set the penalties. In Italy that step isn't finished yet: Article 24 of Law 132/2025 empowers the Government to give AgID and ACN the enforcement powers the regulation provides for, within twelve months of the law coming into force, by 10 October 2026.

The honest reading is this: the Article 4 obligation has applied in full for eighteen months, and Italy's penalty framework is still being built. That's a reason to prepare calmly now, not a reason to put it off.

The human checkpoint, which training alone doesn't cover

AI literacy under Article 4 works together with human oversight, and each holds the other up. Law 132/2025 requires employers to tell staff when artificial intelligence is used, in the cases set out in Legislative Decree 152 of 1997, and informed staff are also the staff able to notice when the system has got something wrong.

In the systems Itria builds, the rule is written down and applies to every message that commits the business: offers, quotes, prices and confirmations go out only after a person has read and approved them. Replies drawing on information the owner has already approved, such as opening hours and availability, can go out on their own, the owner switches that on and off channel by channel, and the reply says it comes from a system, as Article 50 requires from 2 August 2026.

The full principle, including what we never do, is on our AI principles page, and the list of systems we actually use is on the AI transparency page.

The four questions to start with on Monday

The European Commission sets out four minimum steps for a programme that meets Article 4, and they're four questions before they're four activities. A small business can work through them in a morning, with no consultants and nothing to buy.

One: what runs in here. Which AI systems are in use, how they work, what opportunities and what dangers they bring. Two: what's our role. Do we develop AI systems or use systems developed by others? In other words, are we a provider or a deployer?

Three: how much risk there is. What the people using the system need to know, which risks they must recognise, which mitigations they must be aware of. Four: the measures. Build the literacy actions on that analysis, pitched at people's real level and the sector the system is used in.

The list of systems in use is a document that serves three purposes: Article 4, the traceability Italian law asks for, and deciding which process to automate first. On that last point, the method is in which process to hand to AI first.

Questions and answers

Is AI Act training mandatory for businesses?

Yes, in the form of an obligation to act. Article 4 of Regulation (EU) 2024/1689 requires providers and deployers to take measures to support the development of AI literacy among their staff and anyone dealing with those systems on their behalf.

It has applied since 2 February 2025, when Chapter I started to apply. It also covers businesses that only use tools developed by others, because the regulation calls that role deployer and puts it next to the provider in the same sentence.

Do you need a certified course to comply with Article 4?

No. The European Commission's published answers on AI literacy say no certificate is needed and that an organisation can keep an internal record of training and other guidance initiatives.

The same source says no governance structure is imposed, so there's no need to appoint an AI officer. What matters is that the measures fit the systems actually in use and the people using them.

Does the obligation apply if the business only uses ChatGPT?

Yes. The question is asked in this form in the European Commission's answers, in the case of employees using ChatGPT to write advertising copy or to translate, and the answer is yes: those people must be made aware of the tool's specific risks, starting with made-up answers.

Using a third-party generative model puts the business in the deployer role, and Article 4 is addressed to deployers as much as to providers.

What changed in Article 4 in 2026?

Regulation (EU) 2026/1744, the digital omnibus on AI published in the Official Journal of the European Union on 24 July 2026, replaced Article 4 in full. The obligation to ensure a sufficient level became an obligation to take measures to support its development, adding that no specific level is required for any person.

Recital 8 explains why: rigid obligations created an extra compliance burden, particularly for smaller businesses. The date of application didn't change.

Who enforces it in Italy, and what are the penalties?

Enforcement lies with the national market surveillance authorities, and the Commission gives 2 August 2026 as the start of supervision. In Italy, Article 20 of Law 132/2025 designates AgID and ACN, and gives ACN the supervisory role, including inspections and penalties.

Article 4 isn't on the list in Article 99(4), the band that goes up to €15 million. The consequences come through national rules, and in Italy the power granted by Article 24 of Law 132/2025 runs out on 10 October 2026.

Notes on sources

  1. Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 3 for the definitions of provider and deployer, Article 4, Article 99 for the list of penalties, Article 113 for the date Chapter I applies from.
  2. Regulation (EU) 2026/1744, the digital omnibus on AI, published on 24 July 2026: Article 1, point 5, which replaces Article 4, and recital 8 on the reason for the change.
  3. AI Literacy, Questions & Answers, European Commission: no certificate needed, the internal record, the ChatGPT case, the four minimum steps, supervision by national authorities from 2 August 2026. Page accessed on 9 September 2026.
  4. Law no. 132 of 23 September 2025, Gazzetta Ufficiale no. 223 of 25 September 2025 (in Italian), in force from 10 October 2025: Article 11 on informing workers, Article 20 on the national authorities, Article 24 on the delegated power and enforcement powers.
  5. Repository of AI literacy practices, AI Office: a collection of practices adopted by other organisations. The Commission warns that copying them doesn't automatically give a presumption of compliance.
  6. This page doesn't publish a penalty figure for Article 4, because the regulation contains no such figure: Article 4 is left off the list in Article 99(4), and the amount will depend on national implementing rules.

This article is a practical overview, not legal advice. For specific situations, and in particular on employment relationships and organisational models, the answer has to come from a professional who looks at your business.

·The next step

The law says what people need to know. The system can be built compliant from the start.

The list of systems in use and the record of what you've done take a morning, and you can do them yourselves. What that morning doesn't cover is the system itself: if people need to be able to say what it does and where they step in, it's worth building it to be explained. It's fifteen minutes on a call, with the Cruscotto open.