Module 3 of the AI Act Compliance certification: what the July 2026 rewrite of Art. 4 changed, why evidence shifted from levels to measures, and the register that satisfies it.
Art. 4 is the obligation most organisations meet first, most often misdescribe, and most cheaply evidence. It is also the one that changed in July 2026, which means most existing positions and most published advice describe a text that no longer applies.
What changed
Before, Art. 4 required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf.
After Regulation (EU) 2026/1744, in force since 27 July 2026, they shall take measures to support the development of AI literacy, and the text adds expressly that this does not require providers or deployers to guarantee any specific level of AI literacy of any individual. A second paragraph tasks the Commission and Member States with supporting and facilitating those efforts, with particular regard to SMEs.
An obligation of result became an obligation of means.
Why that is good news for the programme, not bad
The instinct is to read a softened obligation as a reduced priority. That is the wrong conclusion for two reasons.
What must be proved got easier and more concrete. Under the old text a defensible position tended toward assessment of attainment — testing people, and being able to say they reached a level. Under the new text the artefact is the measure: what you provided, to whom, when, and why it fitted their role. That is something an organisation can actually produce.
The commercial consequence for anyone selling training is the opposite of what it looks like. If the obligation is to take measures, then a dated, nominative record of measures taken is precisely the evidence. The value of a training register went up, not down.
Who is in scope
"Staff and other persons dealing with the operation and use of AI systems on their behalf" is broader than employees. It reaches contractors, temporary staff, and outsourced operators who run systems for you. It does not reach your customers.
The obligation is calibrated: measures shall take into account technical knowledge, experience, education and training, the context in which the systems are used, and the persons or groups on whom they are to be used. That is an instruction to differentiate. A single all-staff module is a measure; it is a weak one, and it is visibly not calibrated to anything.
A programme that matches the text
Four tiers, mapped to how people actually touch AI:
Tier 0 — everyone. What an AI system is, what the organisation uses, what is prohibited, how to report a concern, and the rule that new use cases go through the gate. Thirty to sixty minutes.
Tier 1 — people who use AI in their work. The systems they touch, what those can and cannot do, the limits stated in the instructions for use, and what to escalate. Role-specific by function.
Tier 2 — human overseers of high-risk systems. This is not Art. 4 territory any more; it is Art. 26(2), which requires competence, training, authority and support tied to the specific system. Deeper, narrower, and enforceable.
Tier 3 — the compliance, legal and product people running the programme. The Regulation itself.
The distinction between tiers 1 and 2 is the one that matters most and is most often missed. A general awareness course answers Art. 4, which carries no fine. System-specific overseer training answers Art. 26(2), which carries the Art. 99(4) band. Do not let the first stand in for the second.
The register
One row per person, per measure:
| Field | Note |
|---|---|
| Name and role | Role is what justifies the calibration |
| Measure provided | Course, workshop, briefing, written guidance |
| Date and duration | The dating is what makes it evidence |
| Systems it relates to | Links the measure to the inventory |
| Why this measure for this person | The Art. 4 calibration, in one line |
| Evidence | Attendance, completion, or a certificate with a verifiable id |
| Review trigger | Role change, new system, legal change |
The last row matters because Art. 4 is continuous. A register with a single 2025 cohort and nothing since documents a measure taken once, which is not what an ongoing duty looks like.
What a good record looks like in practice
"J. Okafor, procurement lead. Completed AI Act Fundamentals (5 modules, ~3 hours) and passed the examination on 14 September 2026 — certificate AI-2026-XXXXXXXX, verifiable publicly. Provided because procurement now operates the classification gate for new AI systems. Next review: on any change to the gate procedure or on a material change to the Regulation."
That reads as a measure, calibrated, dated, evidenced and connected to a business reason. It is also two sentences.
The trap to avoid
Do not claim that a course "satisfies" or "meets" Art. 4.
Art. 4 binds the organisation, not the individual, and since the rewrite it asks for measures rather than for a guaranteed level. A training provider cannot satisfy an obligation that is not theirs, and claiming otherwise is the kind of statement that reads badly in a supervisory conversation and worse in a consumer-protection one.
The accurate formulation is that a course is one measure the organisation can record against its Art. 4 obligation. That is both true and sufficient.
Check yourself
- We test everyone and record their score, to prove a sufficient level. — The amended text expressly does not require guaranteeing a level for any individual. Testing is fine; it is no longer what the obligation asks for.
- Art. 4 has a 3% fine, so it is our biggest exposure. — Art. 4 appears in no Art. 99 band. The 3% band applies to Art. 26 and the other operator obligations.
- Our annual all-staff AI module covers our overseers. — It answers Art. 4, not Art. 26(2), which needs competence, training, authority and support tied to the specific system.
- Our training vendor says its course satisfies Art. 4. — A course cannot satisfy an obligation that binds your organisation. It is one measure you record.
Previous: Module 2 — The inventory and classification register Next: Module 4 — Governance gates →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Providers and deployers shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, the context of use, and the persons or groups on whom the systems are to be used. The amended text states expressly that it does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
None directly. Art. 4 appears in no paragraph of Art. 99. The exposure is indirect: a literacy failure feeds a finding under Art. 26(2), which requires oversight persons to have the necessary competence, training, authority and support, and which does carry the Art. 99(4) band of 15 million euro or 3%.
A certificate is evidence of one measure taken for one person. Art. 4 asks the organisation to take measures appropriate to role and context, so what satisfies it is a programme with a register behind it. A verifiable certificate is a good record within that register; it is not the programme.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.