How many people in your business used an AI tool this week?
Updated: Aug 28

Now the harder question: how many are trained to, in a way you could actually prove if someone asked?
That second question isn't hypothetical.
It's Article 4 of the EU AI Act, and it has applied to almost every business using AI since 2 February 2025. Most still don't know it exists.
Article 4 requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and anyone else operating AI on their behalf, including contractors and service providers.
Two things make it easy to miss.
It applies if you use AI and supply the European union markets.
Article 4 isn't limited to high-risk systems or to companies building AI. If your team uses an AI tool at work, whether a CRM with predictive features, a writing assistant or a chatbot, you are a "deployer," and the obligation applies. It sits in Chapter I of the Act, which means the Digital Omnibus delay that pushed high-risk deadlines to December 2027 does not touch it. Article 4 has been enforceable for over a year.
"Sufficient" cuts both ways.
The obligation is outcome-based. There's no mandated course, no certificate, no official curriculum. Sufficiency is calibrated to each person's role, existing knowledge, and the context in which they use AI.
That sounds flexible, and it is. But it also means the burden of defining "sufficient," and showing you met it, sits with you. "We sent a memo round" is not obviously sufficient. Neither is a one-off webinar with no record of who attended or why it matched their role. We've signed off on plenty of "we've handled it" trainings in past operational roles that would not have survived a single follow-up question.
The real test: can you demonstrate it?
Picture a mid-sized marketing agency using an AI copywriting tool across its client work. Nobody there builds AI. They just use it. A client complaint triggers a look from the regulator, and the question that lands is simple: what did you do to make sure your staff understood the tool's limitations and risks?
The honest answer is "we assumed it was fine." No record, no role mapping, no rationale. The tool itself was never the problem. The absence of any evidence that they'd taken Article 4 seriously became the aggravating factor that shaped everything that followed.
That's the trap. Article 4 doesn't spell out a records-keeping clause, but "take measures" with no evidence is, from the outside, indistinguishable from having done nothing. A lack of AI literacy is likely to be treated as an aggravating factor in wider enforcement, so the ability to evidence a proportionate, role-appropriate programme is your defence, not a nice-to-have.
A defensible position usually looks like this: a map of who in your organisation touches AI, a baseline level of literacy for everyone, deeper role-specific training where it's warranted, and a dated record of what was delivered to whom and why. Not more than the obligation requires. Not less than you'd want to hand a regulator.
Where most team we talk to actually stand:
Most organisations have done something. Far fewer can prove it holds together. The gap between "we ran some AI training" and "we can demonstrate a sufficient, proportionate literacy programme" is exactly where the risk lives.
veritas_fox was built by operators, not just advisors: people who've sat in the seat where compliance actually lands and been asked to prove it.
Want to know whether yours would hold up?
→ Book a consultation with us: Free Consultation - veritas_fox



Comments