EU AI Act training requirements: what you actually have to do

If your staff use AI at work, you are a deployer under the EU AI Act and Article 4 obliges you to take measures supporting their AI literacy. It has applied since 2 February 2025, and national authorities began supervising and enforcing it in early August 2026.

This is not something that organizations should treat as a tick-the-box exercise. AI competence is becoming a core operating capability, and training decides whether your people use AI well or use it badly: capturing the productivity upside, or leaking data into a public model, trusting a hallucinated answer, or spreading shadow AI tools nobody approved.

Your obligations, in one screen

Required

Train everyone who uses AI on your behalf

Employees, and also contractors and service providers operating AI systems for you. There is no minimum-sophistication threshold: a team using a chatbot to draft copy is in scope and needs to understand risks such as hallucination.

Required

Match the training to the systems you actually use

Cover what AI is and how it works, whether you are a provider or a deployer, the risks of your specific systems and their mitigations — including the legal and ethical dimension, not just the technical one.

Required

Differentiate by role and prior knowledge

Technical knowledge, experience and education differ across your workforce, and so should the depth of training. Even staff with AI qualifications still need to know your systems, your policies and the legal aspects.

Required — and stricter

High-risk systems: train for human oversight

If you deploy a high-risk AI system, the people overseeing it must be trained to actually exercise that oversight. This duty is separate from Article 4 and did not change in July 2026.

Required

Keep a record you can produce later

An internal record of trainings and guidance is needed. The exposure is rarely a spontaneous audit; it is an incident, followed by the question of whether the people involved had been trained.

What happens if you do nothing

Who enforces: national authorities — practice will vary by country
Penalties: set by national law, which member states were due to adopt by 2 August 2025 
How it is applied: proportionately, case by case, weighing gravity and whether the failure was intentional or negligent
The realistic trigger: an incident traced to missing training or guidance — which makes your training records the thing that matters

There is also a quieter reason not to wait. Staff are already using AI at work, with or without a program telling them how — and the gap between organizations that are getting real value from it and organizations that are absorbing risk from it usually comes down to whether anyone taught people how. Article 4 gives you the mandate to make that deliberate: a workforce that knows which tasks to hand to AI, how to check what comes back, and where the actual boundaries are. The same training that satisfies the requirement is what actually makes a difference for your organization.

How CyberCoach covers it

Two things distinguish this from generic AI awareness content, and both matter more for capability than for compliance.

Role-based, not one course for everyone

A developer using a coding assistant, a teacher using AI in a classroom, and a salesperson, all use AI differently. In CyberCoach, each gets its own path. Skilled users can demonstrate their skills and skip trainings, as well as complete more challenging versions of trainings. Both support the Article 4 requirement to differentiate by role and prior knowledge.

Updated continuously as the technology moves

AI capability that was current a year ago is not current now, and annual training cannot track that. Content is updated as tools, threats and guidance change, and delivered in short recurring sessions — so your people stay current and your compliance record stays current with them, rather than pointing at a campaign from last spring.

Underneath that, each obligation maps to something you can run in Microsoft Teams or a browser, with no new portal and no new login.

Everyone who uses AI — practical AI use training: what to use AI for, what to verify before trusting output, what must never go into an AI system. Scenario-based, in their own words, so it holds up better than a policy acknowledgement.
Your systems, not generic ones — any text-based material you already have, an AI policy, an acceptable-use rule, a system's instructions for use, becomes an interactive scenario in minutes. That is how training gets specific to the AI you actually deploy.
Human oversight for high-risk systems — scenarios where the learner has to decide when to override, escalate or stop, which is the capability the oversight duty is about. Build them from your own procedures.
Training and policy acknowledgement records— successful completions are recorded per person, which is what an authority or auditor would ask for. 
Beyond the minimum — the same platform that satisfies Article 4 covers modern AI-related phishing and social engineering training, secure coding for developers, and role-based programs for the rest of the organization, so AI literacy is not a separate compliance training. Your users will be more motivated to learn about AI Risks, when the same trainings also train them practical AIskills. 
No training product grants AI Act compliance, ours included. Compliance depends on your systems, your risk analysis and your records. What a platform can do is deliver the role-differentiated training and produce the evidence.
 

Frequently asked questions

Does the EU AI Act require AI training for employees?

Yes. Article 4 requires providers and deployers of AI systems to take measures supporting the AI literacy of their staff and of others using AI on their behalf, and it has applied since 2 February 2025. 

Does using ChatGPT at work put my company in scope?

Yes. A company whose employees use a general-purpose AI tool to draft copy or translate text is a deployer, and those employees should be informed about the specific risks involved, such as hallucination. There is no size or sophistication threshold below which Article 4 stops applying.

Is it enough to send staff the AI tool's instructions for use?

Generally no. Relying on instructions for use, or asking staff to read them, may well be ineffective, and for deployers of high-risk AI systems it is not sufficient on its own — further measures are necessary so that the people involved can genuinely exercise human oversight.

Who enforces Article 4, and what are the penalties?

National authorities supervise and enforce, since early August 2026, and penalties come from national law rather than from the AI Act itself. Sanctions are applied proportionately, case by case, and are more likely where an incident can be traced to a lack of appropriate training and guidance.

Do we need an AI officer or an AI governance board?

Not for Article 4. No specific governance structure is mandated, and there are no sector-specific requirements, including for financial services and healthcare. 

Are small organizations exempt from the AI literacy requirement?

No. Article 4 applies to providers and deployers of AI systems regardless of headcount or turnover — there is no small-business exemption and no threshold below which it stops applying. What scales with your size is the effort, not the duty: the measures have to be appropriate to your systems, your risks and your people, so a ten-person company using one AI tool has a far smaller job than a bank. 

Does the AI Act apply to public sector organizations?

Yes. Public authorities and public bodies are deployers when they use AI systems, and Article 4 applies to them on the same terms as to private employers.

Sources and disclaimer

Based on the European Commission's AI literacy questions and answers (last updated 27 July 2026), Regulation (EU) 2024/1689 (AI Act, Articles 4, 14 and 26) and the Digital Omnibus on AI, Regulation (EU) 2026/1744. The Commission's Q&A is non-binding guidance and is updated periodically.

Published by CyberCoach, which sells AI and security training and therefore has a commercial interest in these conclusions. This is general information, not legal advice, and no lawyer–client relationship arises from reading it. It does not address your jurisdiction, sector or facts. Obtain qualified local counsel before acting.

Reviewed 28 August 2026
Corrections: info@cybercoach.com

Start with one team

Run practical AI training in your own Microsoft Teams tenant or the browser, see the completion records it produces, and decide from there.

Get notified of what's going on in AI and security awareness and compliance

Expert Tips: Stay informed with curated content, expert opinions, and case studies that are relevant to your organization's security awareness strategy.

Special Offers:
Access to CyberCoach promotions and campaigns. 


Stay Informed:
Get the latest insights and updates on security and AI compliance trends, threats, and best practices delivered directly to your inbox.