EU AI Act training requirements: what you actually have to do
If your staff use AI at work, you are a deployer under the EU AI Act and Article 4 obliges you to take measures supporting their AI literacy. It has applied since 2 February 2025, and national authorities began supervising and enforcing it in early August 2026.
This is not something that organizations should treat as a tick-the-box exercise. AI competence is becoming a core operating capability, and training decides whether your people use AI well or use it badly: capturing the productivity upside, or leaking data into a public model, trusting a hallucinated answer, or spreading shadow AI tools nobody approved.
Your obligations, in one screen
Train everyone who uses AI on your behalf
Employees, and also contractors and service providers operating AI systems for you. There is no minimum-sophistication threshold: a team using a chatbot to draft copy is in scope and needs to understand risks such as hallucination.
Match the training to the systems you actually use
Cover what AI is and how it works, whether you are a provider or a deployer, the risks of your specific systems and their mitigations — including the legal and ethical dimension, not just the technical one.
Differentiate by role and prior knowledge
Technical knowledge, experience and education differ across your workforce, and so should the depth of training. Even staff with AI qualifications still need to know your systems, your policies and the legal aspects.
High-risk systems: train for human oversight
If you deploy a high-risk AI system, the people overseeing it must be trained to actually exercise that oversight. This duty is separate from Article 4 and did not change in July 2026.
Keep a record you can produce later
An internal record of trainings and guidance is needed. The exposure is rarely a spontaneous audit; it is an incident, followed by the question of whether the people involved had been trained.
What happens if you do nothing
There is also a quieter reason not to wait. Staff are already using AI at work, with or without a program telling them how — and the gap between organizations that are getting real value from it and organizations that are absorbing risk from it usually comes down to whether anyone taught people how. Article 4 gives you the mandate to make that deliberate: a workforce that knows which tasks to hand to AI, how to check what comes back, and where the actual boundaries are. The same training that satisfies the requirement is what actually makes a difference for your organization.
How CyberCoach covers it
Two things distinguish this from generic AI awareness content, and both matter more for capability than for compliance.
Role-based, not one course for everyone
A developer using a coding assistant, a teacher using AI in a classroom, and a salesperson, all use AI differently. In CyberCoach, each gets its own path. Skilled users can demonstrate their skills and skip trainings, as well as complete more challenging versions of trainings. Both support the Article 4 requirement to differentiate by role and prior knowledge.
Updated continuously as the technology moves
AI capability that was current a year ago is not current now, and annual training cannot track that. Content is updated as tools, threats and guidance change, and delivered in short recurring sessions — so your people stay current and your compliance record stays current with them, rather than pointing at a campaign from last spring.
Underneath that, each obligation maps to something you can run in Microsoft Teams or a browser, with no new portal and no new login.
Frequently asked questions
Does the EU AI Act require AI training for employees?
Yes. Article 4 requires providers and deployers of AI systems to take measures supporting the AI literacy of their staff and of others using AI on their behalf, and it has applied since 2 February 2025.
Does using ChatGPT at work put my company in scope?
Yes. A company whose employees use a general-purpose AI tool to draft copy or translate text is a deployer, and those employees should be informed about the specific risks involved, such as hallucination. There is no size or sophistication threshold below which Article 4 stops applying.
Is it enough to send staff the AI tool's instructions for use?
Generally no. Relying on instructions for use, or asking staff to read them, may well be ineffective, and for deployers of high-risk AI systems it is not sufficient on its own — further measures are necessary so that the people involved can genuinely exercise human oversight.
Who enforces Article 4, and what are the penalties?
National authorities supervise and enforce, since early August 2026, and penalties come from national law rather than from the AI Act itself. Sanctions are applied proportionately, case by case, and are more likely where an incident can be traced to a lack of appropriate training and guidance.
Do we need an AI officer or an AI governance board?
Not for Article 4. No specific governance structure is mandated, and there are no sector-specific requirements, including for financial services and healthcare.
Are small organizations exempt from the AI literacy requirement?
No. Article 4 applies to providers and deployers of AI systems regardless of headcount or turnover — there is no small-business exemption and no threshold below which it stops applying. What scales with your size is the effort, not the duty: the measures have to be appropriate to your systems, your risks and your people, so a ten-person company using one AI tool has a far smaller job than a bank.
Does the AI Act apply to public sector organizations?
Yes. Public authorities and public bodies are deployers when they use AI systems, and Article 4 applies to them on the same terms as to private employers.
Based on the European Commission's AI literacy questions and answers (last updated 27 July 2026), Regulation (EU) 2024/1689 (AI Act, Articles 4, 14 and 26) and the Digital Omnibus on AI, Regulation (EU) 2026/1744. The Commission's Q&A is non-binding guidance and is updated periodically.
Published by CyberCoach, which sells AI and security training and therefore has a commercial interest in these conclusions. This is general information, not legal advice, and no lawyer–client relationship arises from reading it. It does not address your jurisdiction, sector or facts. Obtain qualified local counsel before acting.
Start with one team
Run practical AI training in your own Microsoft Teams tenant or the browser, see the completion records it produces, and decide from there.
Get notified of what's going on in AI and security awareness and compliance
Expert Tips: Stay informed with curated content, expert opinions, and case studies that are relevant to your organization's security awareness strategy.Special Offers: Access to CyberCoach promotions and campaigns.
Stay Informed: Get the latest insights and updates on security and AI compliance trends, threats, and best practices delivered directly to your inbox.