When executives ask me about the AI Act, they usually mean the parts that make headlines: prohibited practices, high-risk classification, conformity assessments. Those matter, but for most small and mid-sized companies they are either distant or simply not applicable. Meanwhile the one provision that already binds nearly everyone gets almost no attention. Article 4 has been in force since 2 February 2025. It is two sentences long, it is deliberately broad, and if your people use AI to do their jobs, it applies to you today.
The obligation is not about the AI you build. It is about the people who use it.
Article 4 requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff and among anyone operating those systems on their behalf. The word that catches most companies out is "deployer." You do not have to build anything. If your marketing team drafts with a language model, if finance runs an AI forecasting tool, if HR uses software that screens applications, you are a deployer, and the obligation is yours.
What counts as "sufficient" is not fixed. The text ties it to the technical knowledge, experience, education and training of the people involved, the context the system is used in, and the people the system is used on. That last clause does real work. A junior drafting social copy needs one level of understanding. Someone whose AI-assisted decision affects a candidate's job application needs a considerably higher one, because a third party carries the consequences of a mistake they cannot see or contest.
Just as important is what Article 4 does not say. It prescribes no curriculum, mandates no certificate, and creates no registry to file with. Companies get this wrong in both directions. Some read the absence of a checklist as evidence there is nothing to do. Others panic and buy a generic e-learning package for the whole company, which satisfies a procurement box and changes no one's behavior.
What you actually gain by treating this seriously
The risk Article 4 addresses is not theoretical, and it is not really a legal risk. It is the employee who pastes customer records into a free public tool because nobody explained where that data goes. It is the analyst who forwards a confidently invented figure into a board pack because nobody explained that fluency is not accuracy. Your AI literacy obligation and your GDPR exposure are, in practice, the same problem wearing different labels. Fixing one fixes much of the other.
There is a commercial return too, and it arrives sooner than most people expect. Enterprise procurement questionnaires have started asking suppliers how they meet Article 4. If you can answer that question with specifics, you stay in the process. If you cannot, you are explaining yourself at exactly the moment you wanted to be talking about price. For smaller suppliers this has quietly become a qualifier.

Where this gets harder than it looks
The first difficulty is evidence. "To their best extent" is an outcome standard, not a task you complete, which means the question is never whether you did something but whether you can show what you did and why it was proportionate. Most companies I see have genuinely trained people and kept no record of it whatsoever. If a national market surveillance authority or, far more likely, a large customer asks, good intentions with no documentation look identical to having done nothing.
The second is shadow AI. Your staff are already using tools you never approved, on accounts you cannot see, often with company data. A literacy program that ignores this describes a fictional organization. Start by finding out what is actually in use, without hunting for someone to blame, because people conceal tools when they expect punishment and then you have lost your only view of the real exposure.
This is also the sharpest test of a prospective AI partner, and it costs you nothing to run. Ask three questions: which of our specific processes count as deployment under Article 4, what level of literacy does each role need and why, and how will we evidence that in twelve months. A partner who answers with a course catalog is selling you training. A partner who starts by asking how your business actually works is doing the job. The difference shows up in the first ten minutes.
My honest read is that Article 4 is the most useful part of the AI Act for a company your size, precisely because it is unglamorous. It does not ask you to classify systems or commission audits. It asks whether the people using AI in your name understand what it does, where it fails, and when to stop and involve a human. That is a question worth answering even if Brussels had never raised it. The regulation simply means you now have to answer it out loud, and be able to show your work.
Not sure where your Article 4 exposure sits?
We map which of your processes count as deployment, what each role actually needs to understand, and how to evidence it. Practical, proportionate, and built around how your business really works.
Start the Conversation