Since 2 February 2025, using AI has carried a training obligation — not only building it. Most organisations in scope have not noticed, because the obligation sits in one short article with no penalty attached to it directly.
Article 4 of the EU AI Act (Regulation (EU) 2024/1689) requires providers and deployers of AI systems to take measures ensuring, as far as they can, a sufficient level of AI literacy among their staff and any other person dealing with the operation and use of AI systems on their behalf.
Two words carry most of the weight. Deployer means the organisation that simply uses an AI system in its work — not the company that built it. If your programme officers use a chatbot to draft donor reports, you are a deployer. On their behalf reaches past your payroll to contractors, consultants and outsourced operators.
The obligation is outcome-based. It does not prescribe a course, a certificate or a number of hours. It asks whether the people using AI in your organisation are competent to do so — and leaves you to demonstrate that they are.
| Organisation | Why it is in scope | Usual reaction |
|---|---|---|
| An NGO with EU operations or EU funding | Deploys AI systems in the Union, or places their output there | “We don't build AI, so this isn't about us.” The article is about deployers |
| A Geneva-based international body with EU activity | Same, wherever the headquarters sits | Assumes privileges and immunities settle the question. Donor and partner contracts often do not |
| Any organisation using contractors | The duty covers persons operating AI on your behalf | Training covers employees only. Consultants and field partners are missed |
| Organisations whose staff use free AI tools informally | Unsanctioned use is still use, and the organisation still carries it | “We have no AI systems.” Two-thirds of professionals report using AI at work believing it was not permitted |
No regulator will ask to see your enthusiasm. Five artefacts do the work, and an organisation that has them is also, incidentally, one where AI is used well.
| Artefact | What it shows | Where it comes from |
|---|---|---|
| An AI use policy | That the organisation has decided what is permitted, by whom, with which data | Written once, approved by the board, reviewed twice a year |
| A tool inventory | Which AI systems are actually in use, for what purpose, on what data | Falls out of the readiness assessment |
| Role-mapped training | That training was proportionate to role, not one generic session for everyone | One organisation-wide session plus a lab per department |
| An attendance record | Who received which training, and when | Kept at delivery. Trivial to produce, impossible to reconstruct later |
| A re-assessment | That literacy is maintained as tools and roles change, not asserted once | Re-score at 90 days, then at six or twelve months |
Ask, without consequences attached, which AI tools people already use and what they put into them. You cannot govern what you have not counted.
Run a readiness assessment across the organisation. It produces the tool inventory, the gap list and the number you will be measured against later.
A prohibition list drives use underground and leaves you carrying the risk blind. Say what is allowed, with which data, by whom.
One session on the shared rules, then one per department on that department's real tasks. Keep the attendance record.
Repeat the assessment. Keep the policy, the inventory, the records and both scores together. That folder is the demonstration.
Every one of these five is something you would want anyway. Article 4 does not add work — it removes the argument for postponing it.
The readiness assessment produces your baseline score, your gap list and the beginning of your tool inventory in about twelve minutes.