Back to blog
AI Act

AI literacy for staff: the obligation nobody knows about

No exam, no certificate, and it applies to agency workers too. Since July it is an obligation of effort rather than result, and you already run the process for something else.

Radical AI Team11 August 20269 min read
Colleagues in a working session. Article 4 asks for effort, not for an exam.

Since 2 February 2025 there has been an obligation in the EU AI Act that almost no Dutch director knows about. It is not about high-risk systems, not about registration and not about technical files. It is about your own people, it applies to every company regardless of size, and it is by far the cheapest obligation in the entire regulation to meet.

Article 4 covers AI literacy. Put briefly, it says that as a provider or deployer you take measures so that the people working with AI know what they are doing. No certificate, no exam, no mandatory one-day course. But: demonstrably doing something.

In July 2026 that obligation was relaxed, while the enforcement around it got sharper. That combination is easy to misread, so we walk through it precisely below.

What exactly changed in July

The original text of Article 4 required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other people operating AI systems on their behalf.

The Digital Omnibus, in force since 27 July 2026, softened that. Where you had to ensure a level, you now have to support the development of AI literacy. That sounds like a detail and it is not one. The difference is between an obligation of result and an obligation of effort. You do not have to show that every employee reaches a given level. You have to show that you are doing something about it.

What did not change: the duty was not postponed and not deleted, it still applies to every company regardless of size, and from 2 August 2026 the supervisory machinery around it is operational.

Why almost nobody knows about this obligation

It is worth pausing on how this happened, because it also explains why you hear little about it from your advisers.

In the communication around it, the AI Act has been almost entirely captured by the subject of high risk. That is understandable: that is where the technical files, the conformity assessments and the headline numbers live. The result is that the provision which actually applies to most companies, and which entered into force first, stayed in the shadow of the provisions that apply to almost nobody.

On top of that, Article 4 is short, names no penalty of its own and carries no deadline that fits on a timeline. Anything without a date drops off the agenda. That is exactly what happened: the duty took effect on 2 February 2025 and many companies only got their first question touching it a year and a half later, when supervision got going in August 2026.

The third reason is less charming. There is little money in an obligation you can cover with two half-days a quarter. There is money in certification programmes, which explains why the little attention it does get often comes from the wrong direction.

What it is not

Three misconceptions that get expensive if you act on them.

It is not an exam. No employee has to demonstrate competence. There is no standard, no level and no test. Any party selling you a certification programme by appealing to Article 4 is selling you something the law does not ask for.

It is not a one-off course. An e-learning everyone ticks off in January and that then disappears into a folder is not supporting development. It is evidence without content, and it will not help you at the moment it matters.

It is not only about your permanent staff. The text names staff and other persons operating AI systems on your behalf. Agency workers, freelancers and an external agency working with your systems all fall under it. In practice that is the part most often skipped.

A session with the team. Most companies this size already run this process for IT security.A session with the team. Most companies this size already run this process for IT security.

You already have the machinery for this

Here is the most useful observation in this piece, and the Statistics Netherlands figures back it up.

Of Dutch companies with 50 to 250 employees, 66 per cent offer voluntary training on IT security and 46 per cent make that training mandatory. Seventy-one per cent have documents setting out IT security policy. In other words: most companies this size already have a process for teaching people about a risk, recording it and repeating it periodically.

That is exactly what Article 4 asks for, only on a different subject. You do not need to build a new programme. You need to add a subject to the existing one, and that is a half-day conversation with whoever runs that process today.

Anyone who sees this is done with the obligation before most competitors know it exists.

What demonstrable means in practice

You do not need a dossier, you need an overview you can produce within the hour. Four things are enough.

What you recordWhat it containsHow often to update
Who works with which AI systemName, department, system, since whenOn every change
What those people receivedSubject, format, date, who attendedPer session
Which rules applyWhat may and may not go into a tool, who decidesAnnually
Who maintains the overviewOne nameWhen they leave

The last row matters most and is forgotten most often. An overview without an owner is out of date within two quarters. These four items belong in your AI policy, not in a separate document nobody opens.

Why this is the cheapest way to build capability

Now the part that goes beyond the law.

The Statistics Netherlands ICT survey shows that companies with 50 to 250 people which considered AI but did not adopt it name one reason far more often than any other: lack of relevant experience inside the company, at 11 per cent. Cost is named by 3 per cent. So the bottleneck is not the budget, it is the people you already have.

Article 4 forces you to address precisely that bottleneck, which is a happy coincidence. In a company of a hundred and fifty people the obligation costs you maybe two half-days a quarter. Those same two half-days are the cheapest investment in your own capability you can make, because they are about your own processes and your own systems.

The difference is in how you fill them. A generic session on what a language model is satisfies the law and returns nothing. A session where five people take apart a real case from that week, why did this output appear and what should you have checked, satisfies the law just as well and does return something. The cost is identical.

Half an hour a quarter on a real case is worth more than one day a year on theory.Half an hour a quarter on a real case is worth more than one day a year on theory.

What a half-hour session looks like

To make it concrete, because this is where most companies get stuck.

Take a real output from that month. A quote prepared by a model, a candidate a system ranked higher, a forecast that was wrong. Not an example from a course, something from your own company.

Then walk three questions through with the people who work with it. What exactly happened here, in plain language. What should you have checked before this went out. And what would you have done if it had been wrong, who would you have called and what would you have reversed.

Write down the date, the subject and who attended. That is it. You have met the law, and more importantly you have five people who will ask the question themselves next time. That second part is the point, and it is exactly what an e-learning does not do.

What you avoid is the urge to turn it into a presentation. The moment there are slides it becomes one-directional and nobody learns anything about their own work.

Not everyone needs to know the same thing

The law speaks of a level appropriate to the role and the context. In practice that is four groups, and each needs something different.

The board does not need to know how a model works. It needs to know which decisions in the company are partly made by AI, who is accountable for them, and what happens when it goes wrong.

Daily users need the most concrete package: what may and may not go into a tool, how to recognise an output that is wrong, and who to report it to.

The buyers, more often someone from administration or the management team than from IT, need to know which questions to ask a vendor and when you become a provider in the sense of the law.

Whoever builds or adapts something, even if that amounts to configuring a tool, needs the most and usually gets the least, because everyone assumes they already know.

What it costs if you skip it

Article 4 carries no penalty of its own, which leads many boards to conclude that nothing will happen. That conclusion is wrong, for three reasons.

The first is that regulators ask about it in the context of every other question. If a report comes in about an AI system, the first question is rarely legal and almost always factual: who worked with this and what did they know. Without an answer you start the conversation on the back foot, whatever the conversation was about.

The second is that the fines in Article 99 do exist for the provisions around it. For most obligations the ceiling is 15 million euro or 3 per cent of worldwide annual turnover, with SMEs facing the lower of the two rather than the higher. Demonstrable policy and demonstrable effort are exactly what separates a breach that gets talked through from one that gets fined.

The third needs no law at all. An employee who does not know what may and may not go into a tool will at some point put in something that does not belong there. Customer data, a draft acquisition, a payroll file. That is not a theoretical scenario, and it is the only category on this page where the damage is irreversible.

Where it goes wrong

The training is about tools instead of judgement. A session on the buttons of a package is obsolete the moment the vendor changes something. A session on how to check an output stays valid.

Nothing is recorded. The most common and the most foolish. It happens, it gets discussed, and nobody writes down who was there. At the moment you have to show it, you have nothing.

Agency workers and externals are forgotten. See above; the text names them explicitly.

It happens once. Supporting development is repetitive by nature. Half an hour once a quarter is worth more than one day a year, and it costs less.

What to do this month

Find out who handles IT security awareness in your company and ask how that process runs. In three quarters of companies this size that process exists, recording included.

Add AI to it as a subject. Make the list of who works with which system, and include agency workers and externals. Schedule one half-hour session per quarter, and use a real case from that quarter instead of a general introduction.

Record who maintains the overview. That is the whole job. Anyone who does this is not only done with Article 4 but has also built exactly the habit that, according to Statistics Netherlands, most companies this size are missing.

About this page

The figures on IT security training and policy and on reasons for not using AI come from the Statistics Netherlands ICT survey covering 2025, and concern companies with 50 to 250 employed persons. A warning when checking Article 4: many sources still show the original text from before the Digital Omnibus of July 2026. The regulation itself is linked below. This is the state of play on 11 August 2026 and it is not legal advice.

Frequently asked questions

Article 4 requires providers and deployers to take measures supporting AI literacy among staff and others operating AI systems on their behalf. Since the Digital Omnibus of July 2026 it is an obligation of effort, not of result: no exam, no certificate and no set level per person.

Sources

  1. AI Act artikel 4: AI-geletterdheid, met de oorspronkelijke tekst van voor de Omnibusartificialintelligenceact.eu
  2. Verordening (EU) 2026/1744, de Digital Omnibus, volledige tekst op EUR-Lexeur-lex.europa.eu
  3. Lewis Silkin: de Digital Omnibus treedt in werking, met de verzachting van artikel 4lewissilkin.com
  4. CBS 86119NED: ICT-gebruik bij bedrijven, training over ICT-veiligheid en redenen om geen AI te gebruikencbs.nl
  5. AI Act artikel 99: de boetes, met de eigen regel voor kleine en middelgrote ondernemingenartificialintelligenceact.eu
Looking for AI talent?

Tell us what you need.

We respond within 24 hours, from a real human.

Get in touch

Related reads

EU flags outside the European Commission's Berlaymont building in Brussels
AI Act

The EU AI Act for mid-sized companies: what you need in place now

One part of the AI Act starts to bite on 2 August 2026. The part most companies feared was postponed by seventeen months, one week ago. Here is the difference.

31 July 20269 min read
Colleagues around a conference table. How many of them there are makes no difference to the AI Act.
AI Act

From how many employees does the EU AI Act apply?

No article says you are exempt below fifty or two hundred and fifty people. Size counts in exactly three places, and none of them is an exemption.

5 August 20269 min read
A stack of papers. A working policy is two pages, not twenty.
AI Act

Drafting an AI policy: a framework you can use today

Two pages get read. Twenty get filed. A fill-in template for what is allowed, what needs a human, and who to call in doubt.

18 August 20266 min read