Call · 15 min
AI ActMattia Esposito9 September 20268 min read

AI training is mandatory. And the obligation kicked in before the one everyone is watching.

While Italian businesses were watching Article 50 and transparency, Article 4 of the same regulation had already been in force for eighteen months. It asks one thing only, namely that whoever uses an artificial intelligence system takes care of the skills of those who use it.

In short

The obligation has applied since 2 February 2025. Article 4 is in Chapter I of Regulation (EU) 2024/1689, and Chapter I became applicable on that date, a year and a half before Article 50 on transparency.

It also concerns those who merely use other people's tools. The regulation names the provider and the deployer in the same line, and an SME using a third-party assistant or generative model is a deployer in every respect.

You don't need a course with a certificate. The European Commission writes that no certificate is required and that an internal record of the initiatives carried out is enough, calibrated to the systems actually in use.

Since July 2026 the article is written more lightly. The digital omnibus on AI replaced the text and removed the requirement to ensure a set level of competence for every single person.

This piece goes into depth on a point the guide to the AI Act obligations for companies and SMEs only touches on. It is about businesses, not state schools, and it ends where a lawyer's work begins.

Who has the obligation, and from when

Article 4 of Regulation (EU) 2024/1689 addresses providers and deployers of AI systems. It has applied since 2 February 2025, because Article 113 establishes that Chapter I applies from that date, and Article 4 is the last article of Chapter I.

The regulation defines as deployer whoever uses an AI system under their own authority, except in the course of a personal non-professional activity. A business using an assistant on its website, a model that writes texts or a system that transcribes calls falls within that definition without any interpretive effort.

The obligation doesn't stop at employees. The text speaks of staff and any other persons dealing with the operation and use of the systems on behalf of the business, and the European Commission clarifies that contractors, service providers and in certain cases customers fall within this.

What exactly Article 4 says, after July 2026

Regulation (EU) 2026/1744, the digital omnibus on AI published on 24 July 2026 and in force from the third day after, replaced Article 4 in full. The obligation to ensure a sufficient level became the obligation to take measures to support the development of literacy.

«This obligation does not require providers or deployers to ensure a specific level of AI literacy for any person.»
Regulation (EU) 2026/1744, new text of Article 4 of the AI Act (our translation of the Italian text)

Recital 8 of the omnibus explains the reason bluntly: rigid obligations weren't suited to all types of providers and deployers, and created an additional compliance burden especially for smaller businesses. The date of application, on the other hand, wasn't touched.

Whoever looks up the text of Article 4 today in a source that hasn't been updated still finds the old wording, with the sufficient level to be ensured. The difference between the two versions changes how the obligation is demonstrated, so it pays to read the consolidated version instead of a commentary article.

Whether you need a certified course, and what you must be able to show

No certificate is needed, and no body issues one valid for the purposes of Article 4. The answers published by the European Commission on AI literacy say it directly: organisations can keep an internal record of training and other guidance initiatives, and no specific governance structure is imposed.

The same source rules out two other things that circulate widely. There is no obligation to measure employees' knowledge of AI, and there is no need to appoint an AI officer on the model of the data protection officer.

There is one warning, though, and it concerns the most common shortcut. The Commission writes that relying on the system's instructions for use, or asking staff to read them, is in many cases not enough: training and guidance tailored to the group of people and the context of use are needed.

A useful internal record contains four elements: which AI systems run in the company, who uses them, what has been explained to those people and when. The first two items coincide with the list also needed for the regulation's other obligations, so the work is done only once.

There is one case where that record weighs much more. The Commission notes that enforcement becomes more likely when there is evidence of an incident caused by a lack of staff training and guidance, and at that moment the date on the record is worth more than any statement of intent.

What adequate means for six people and for two hundred

The regulation doesn't set hours, content or formats. It asks you to take four things into account: the technical knowledge, experience, education and training of the people, and the context in which the systems are used. It follows that two companies of different size can both be compliant with very different measures.

BusinessProportionate measureHow to prove it
Six peoplethird-party generative tools, no high-risk system

An internal session on the tools actually in use, with the concrete risks (made-up answers, confidential data pasted into a prompt) and a written rule on what is never pasted.

A one-page note with date, attendees and tools covered. It is the internal record the Commission indicates as sufficient.

Two hundred peopledepartments with different exposures

Differentiated paths by group, because Article 4 asks you to take education and experience into account. Those handling customer data and those writing texts don't face the same risks.

A record per group, dated materials, and a trace of who received what. No body issues a seal, the proof stays internal.

Whoever uses high-risk systemsChapter III of the regulation

Here Article 4 isn't the only reference. Article 26 requires the deployer of high-risk systems to assign human oversight to people with the necessary competence and training.

A different and heavier matter, which requires a dedicated reading of Chapter III and usually a professional.

It also applies to those who only use ChatGPT in the office

Yes, and the question is asked in exactly this form in the European Commission's answers, in the case of employees using ChatGPT to write advertising copy or to translate. The answer is yes, with the indication to inform those people of the specific risks of the tool, starting with made-up answers.

It is the case that concerns the great majority of small Italian businesses, and it is also the one where nobody feels involved. A generative model open in a browser doesn't look like an artificial intelligence system adopted by the company, and under the regulation's definition it is one.

Whoever wants to understand which tool they really have in-house, and with how much autonomy, will find the operational distinction on the page comparing an AI agent and a chatbot and the terms explained in the glossary of AI and automation.

Who supervises in Italy, and what not having done it entails

Supervision of Article 4 doesn't lie with the Commission's AI Office, but with the national market surveillance authorities, and the Commission gives 2 August 2026 as the start of supervision. In Italy, Article 20 of Law 132/2025 designates AgID and ACN as the national authorities for artificial intelligence.

Of the two, real supervision lies with ACN. The law gives it responsibility for supervising artificial intelligence systems, including inspection and penalty activities, while AgID keeps notification, assessment, accreditation and monitoring of the bodies that check conformity.

On penalties a precision is needed that almost nobody makes. The list in Article 99(4) of the regulation, the one for the band up to €15 million or 3% of worldwide annual turnover, names Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50. Article 4 isn't there.

The consequences therefore go through paragraph 1 of the same article, which leaves Member States to lay down the penalties. In Italy that step isn't yet complete: Article 24 of Law 132/2025 delegates to the Government the task of giving AgID and ACN the penalty powers provided for by the regulation, within twelve months of the law's entry into force, that is, by 10 October 2026.

The honest reading of the picture is this: the Article 4 obligation has been in full force for eighteen months, the Italian penalty framework is still under construction. It is a reason to prepare calmly now, not a reason to put it off.

The human step, which training alone doesn't cover

The literacy of Article 4 works together with human oversight, and the two hold each other up. Law 132/2025 requires the employer to inform workers of the use of artificial intelligence in the cases provided by Legislative Decree 152 of 1997, and informed staff are also staff able to notice that the system has made a mistake.

In the systems Itria builds the rule is written and applies to every message that commits the company: offers, quotes, prices and confirmations go out only after a person has read and approved them. Replies on information already approved by the owner, such as opening hours and availability, can go out on their own, the owner switches the function on and off channel by channel, and the reply states that it is a system as Article 50 requires, applicable from 2 August 2026.

The extended principle, with the scope of what we never do, is on the AI principles page, and the list of systems we actually use on the AI transparency page.

The four questions to start from on Monday

The European Commission indicates four minimum steps for a programme that complies with Article 4, and they are four questions before they are four activities. A small business goes through them in a morning, without consultants and without purchases.

One, what runs in here. Which AI systems are in use, how they work, what opportunities and what dangers they bring. Two, what role we have. Do we develop AI systems or use systems developed by others, that is, are we providers or deployers.

Three, how much risk there is. What whoever uses that system needs to know, what risks they must recognise, what mitigations they must know. Four, the measures. Build the literacy actions on the previous analysis, calibrated to the people's real level and to the sector in which the system is used.

The list of systems in use is the document that serves three times: for Article 4, for the traceability the Italian law requires, and for deciding which process to automate first. On this last point the method is in which process it pays to hand to AI first.

Questions and answers

Is AI Act training mandatory for companies?

Yes, in the form of an obligation to take action. Article 4 of Regulation (EU) 2024/1689 asks providers and deployers to take measures to support the development of AI literacy among their staff and anyone dealing with those systems on their behalf.

It has applied since 2 February 2025, the date Chapter I became applicable. It also concerns the business that only uses tools developed by others, because the regulation calls that role deployer and places it next to the provider in the same line.

Do you need a certified course to comply with Article 4?

No. The answers published by the European Commission on AI literacy say that no certificate is needed and that an organisation can keep an internal record of training and other guidance initiatives.

The same source specifies that no governance structure is imposed, so there is no need to appoint an AI officer. What matters is that the measures are calibrated to the systems actually in use and to the people who use them.

Does the obligation apply even if the company only uses ChatGPT?

Yes. The question is asked in this form in the European Commission's answers, in the case of employees using ChatGPT to write advertising copy or to translate, and the answer is yes: those people must be informed of the specific risks of the tool, starting with made-up answers.

Using a third-party generative model places the business in the role of deployer, and Article 4 addresses deployers as much as providers.

What changed in Article 4 in 2026?

Regulation (EU) 2026/1744, the digital omnibus on AI published in the Official Journal of the European Union on 24 July 2026, replaced Article 4 in full. The obligation to ensure a sufficient level became the obligation to take measures to support its development, with the addition that no specific level is required for any person.

Recital 8 explains the reason: rigid obligations created an additional compliance burden, especially for smaller businesses. The date of application hasn't changed.

Who checks in Italy, and what are the penalties?

Supervision lies with the national market surveillance authorities, and the Commission gives 2 August 2026 as the start of supervision. In Italy, Article 20 of Law 132/2025 designates AgID and ACN, and gives ACN supervision, including inspection and penalty activities.

Article 4 doesn't appear in the list of Article 99(4), the one for the band up to €15 million. The consequences go through national rules, and in Italy the delegation in Article 24 of Law 132/2025 expires on 10 October 2026.

Notes on sources

  1. Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 3 for the definitions of provider and deployer, Article 4, Article 99 for the list of penalties, Article 113 for the date of application of Chapter I.
  2. Regulation (EU) 2026/1744, the digital omnibus on AI, published on 24 July 2026: Article 1, point 5, which replaces Article 4, and recital 8 on the reason for the change.
  3. AI Literacy, Questions & Answers, European Commission: no certificate, internal record, the ChatGPT case, the four minimum steps, supervision by national authorities from 2 August 2026. Page opened on 9 September 2026.
  4. Law No 132 of 23 September 2025, Italian Official Gazette No 223 of 25 September 2025, in force since 10 October 2025: Article 11 on informing workers, Article 20 on the national authorities, Article 24 on the delegation and penalty powers.
  5. Repository of AI literacy practices, AI Office: a collection of practices adopted by other organisations. The Commission warns that replicating them doesn't automatically give a presumption of conformity.
  6. This page doesn't publish a penalty figure for Article 4, because that figure doesn't exist in the regulation: Article 4 stays out of the list in Article 99(4), and the amount will depend on the national implementing rules.

This article is an operational overview, not a legal opinion. On specific situations, and in particular on employment relationships and organisational models, the answer comes from a professional who looks at your company.

·The next step

The law says what you need to know. The system can be built compliant from the start.

The list of systems in use and the record of initiatives are a morning's work, and you can do them yourselves. What stays outside that morning is the system itself: if people have to be able to say what it does and where they step in, it pays for it to be built to be explained. It is fifteen minutes on a call, with the Cruscotto open.