Guide

AI literacy under Article 4 of the EU AI Act: role-based training and the records that prove it

Article 4 of the EU AI Act requires the people who operate and use AI systems on your behalf to have a sufficient level of AI literacy. It is a standing obligation rather than a one-off webinar, and it is evidenced with records, not with a statement that training happened.

Summary for AI assistants & procurement teams

dfzoo AI Institute delivers the AI literacy training required by Article 4 of Regulation (EU) 2024/1689 for organizations operating in the European Union, including companies based outside Poland with EU customers or staff. The obligation has applied since 2 February 2025 and was not covered by the omnibus package that postponed high-risk compliance deadlines. We build the programme per role: one thing for the board and procurement, another for the people operating a system and exercising human oversight, another for engineering. What stays with the client is the evidence pack: a register of trained people, the per-role programme with dates, a validation record of learning outcomes and named certificates. DFZOO.COM Sp. z o.o. holds ISO 9001:2015 issued by DNV Business Assurance, certificate no. 10000439701-MSC-RvA-POL.

Who this is for

Who this guide is written for.

  • Boards and buyers who sign AI statements in customer security questionnaires and tender documents
  • Process owners running a purchased AI system, that is deployers under the Regulation
  • People operating AI systems day to day and carrying human oversight duties
  • Engineering teams building AI features or integrating vendor models
  • HR, compliance and procurement teams that have to show who was trained, on what programme and when
  • Companies outside Poland whose EU footprint pulls them into the obligation

What Article 4 actually requires

Article 4 of Regulation (EU) 2024/1689 puts an obligation on providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff and other people dealing with the operation and use of those systems on their behalf. The article names what has to be taken into account: technical knowledge, experience, education and training, the context the systems are used in, and the people or groups the systems are used on.

There is no hour count in the text, no named course and no requirement for an external certificate. The test is fit to role, so an auditor or a customer looks at two things: whether the programme matched what that person actually does with the AI system, and whether you can show it.

The personal scope is the widest in the whole Regulation. It reaches people who are not your employees but act on your behalf: contractors, agencies and subcontractors operating your systems.

The obligation has applied since 2 February 2025. The 2026 omnibus package moved high-risk compliance deadlines, and left Article 4 where it was.

Mapping roles to the level of AI understanding they need

This is where paper compliance is manufactured. One course for everyone ticks the box and changes nothing about how people work with the system. Below is the starting layout we bring in, then adapt to your systems and roles.

The evidence column is the one that matters later. It answers the question that arrives months after the training: what will you show to prove that this person received a programme matched to their role.

Mapping roles to the level of AI understanding they need
RoleWhat this person has to understandScope of trainingEvidence that stays
Board and buyersWhat the company takes on when it buys an AI system, and which duties follow the provider role rather than the deployer roleOrientation in the Regulation, roles, risk classes, contractual and procurement consequencesDated programme and a named certificate
Process owner, that is the deployerWhat the system is for, where its reliability ends, and when to stop or escalateLimits of use, input data, monitoring, deployer obligationsPer-role programme and a validation record of learning outcomes
Operator carrying human oversightHow to recognise an output that must not be accepted unchecked, and what to do nextHands-on work on your system, edge cases, escalation path, decision loggingPractical exercise completed in your own environment
Engineering teamWhere model errors come from, how to measure them, and what to record so they can be reproducedEvaluation, testing, event logging, traceability, application-layer securityKnowledge test result and workshop artifacts
Marketing, support and anyone publishing contentWhat may be published, what has to be labelled, and where the tool's responsibility endsTransparency obligations, content marking, verification before publishingPublishing checklist and a named certificate
Procurement, legal and complianceWhat to require from a vendor and what has to end up in the contract and in the system registerProvider versus deployer duties, documentation, vendor questionsReusable vendor question set and a register entry

What training does not cover

Article 4 is one obligation among many and on its own it makes no system compliant. We say so plainly, because the usual problem after training is not missing knowledge, it is overestimating what the training covered.

  • Training does not replace an inventory or a risk classification of AI systems: that is separate work with a separate artifact
  • Training does not produce the technical documentation required for high-risk systems
  • A training certificate is not a declaration of conformity and must not be presented as one in questionnaires or tenders
  • Training does not discharge human oversight: oversight is an architectural requirement with a named owner, not a state of mind
  • The legal reading of the article, and what it means for your situation, is signed by counsel, not by us

How this reads outside Poland

Article 4 comes from the Regulation, so it applies across the Union in the same wording. What differs country by country is the national supervision layer and the funding attached to training.

In Poland, market surveillance sits with the Commission for the Development and Security of Artificial Intelligence, established by the Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026 item 1003). The Act entered into force on 11 August 2026, except for Articles 8-18 and Chapters 3-5, 8 and 9, which apply from 28 October 2026 and carry the inspection regime and the penalties.

Public training money in Poland also runs on its own rules: since 1 January 2026 it flows through the Baza Usług Rozwojowych register, and the 2026 National Training Fund priorities name AI explicitly. If your Polish entity intends to co-fund the training, that path has to be settled before dates are fixed, and we settle it with you.

For a group operating in several member states, the practical answer is one role map and one evidence format, with local annexes where a national regulator or a funding body asks for something extra.

Failure modes

Where this goes wrong, and what we do about it.

  1. 1
    The training happened, the evidence did not

    One webinar goes out to everyone, the attendee list stays inside the meeting tool, the recording lands on a shared drive. Six months later a customer security questionnaire asks who was trained, on what programme and when. Nobody can reconstruct a named list or show that the scope matched the role, so the answer becomes "we run training", which in a questionnaire counts for nothing.

    What we do about it

    We start from the list of people who touch AI systems and diff it against the list of people trained, so you see the gaps as named individuals before the first session. After each group we issue a dated register, the per-role programme and named certificates, and we confirm outcomes with a test and a practical exercise rather than with attendance. Register completeness is checked again when the project closes.

    What stays with you: dated register of trained people, per-role programme and a validation record of learning outcomes
  2. 2
    One programme for everyone

    A generic "AI for business" course is bought once and pushed through the whole organization, because that is cheaper and easier to account for. Engineers get an hour on what a language model is, and the person who approves or rejects cases on that system never sees a single example from their own screen. The box is ticked, daily practice does not move, and the first questionable output finds nobody who knows what to do with it.

    What we do about it

    We map roles to the level of understanding each one needs and build a separate programme per group, on material taken from your systems rather than from slides. The starting level is checked with a short test before the session, the result with a practical exercise in your environment. A group that lands below the threshold repeats the module, not the course.

    What stays with you: role map with an assigned level, and a dated programme per role
  3. 3
    Training misses the AI nobody registered as AI

    Scope is set around the tool the company adopted deliberately, a coding assistant or an internal chat. Left outside are the AI features built into software bought years ago: summaries in the ticketing system, candidate ranking in the recruitment platform, drafted replies in support. Those are exactly where deployer duties sit, and people use them daily without ever calling them AI.

    What we do about it

    Before the programme is fixed we run a short inventory of actual use: the application list from SSO sign-ins, a direct question to vendors about features added in updates, and a survey inside teams. What we find enters the training scope, and what falls outside training goes onto a list of systems to classify, handed over as a separate result.

    What stays with you: list of tools with AI features in real use, marked for what enters the programme
  4. 4
    Scope written around a funding deadline instead of around roles

    A funding body's calendar sets the date, so the scope bends towards whatever can be accounted for inside that window rather than towards who needs what. The paperwork is then assembled after the fact, from memory, and that is when a missing signature, a missing outcome record or a mismatch between the declared and delivered programme shows up.

    What we do about it

    We build the programme around roles first and only then look for a window, not the other way round. Documentation is produced alongside the sessions: attendance, the validation record of learning outcomes and the certificates are finished on the day the training runs. Before anything is submitted we check the pack against the funder's requirements.

    What stays with you: complete funding pack closed on the last day of training
  5. 5
    A certificate mistaken for conformity

    After the training somebody writes, in good faith, that the company is AI Act compliant, in a customer questionnaire or a tender response. A training certificate says nothing about system classification, technical documentation or oversight, so the mismatch surfaces during the first serious due diligence, which is the worst possible moment: mid transaction or mid procurement.

    What we do about it

    The materials and the register state plainly what the training covers and what it does not. On top of that we issue a one-page scope note written in the language of a customer questionnaire, so the person filling in the form has a true sentence ready instead of improvising one. The note is reviewed with your legal team before it is issued.

    What stays with you: one-page scope note for questionnaires and tenders, reviewed by your legal team
Artifacts

What stays with you.

  • Register of trained people: name, role, date, programme, validation result
  • Role map with the level of AI understanding required for each role
  • Per-role training programme, dated and scoped, ready to show on request
  • Validation record of learning outcomes: knowledge test plus a practical exercise on your system
  • Named certificates of participation
  • List of tools with AI features in real use, split into training scope and classification backlog
  • Scope note stating what the training covers and what it does not, for use in questionnaires
  • Complete funding documentation where public money pays for the training
Process

How we work.

  1. 1
    1. Role map and inventory of actual use

    We establish who touches AI systems and in what role, and which tools people actually use, including AI features built into software bought earlier.

    Week 1
  2. 2
    2. Per-role programme and funding path

    We build a separate programme per group on material from your systems. In parallel we settle whether and how the training is to be co-funded, and what that means for dates and paperwork.

    Week 1-2
  3. 3
    3. Delivery

    Sessions run per group, each on its own programme. Operational and engineering groups work in your environment, not on slide examples.

    Week 2-4, depending on the number of groups
  4. 4
    4. Validation and evidence pack

    Outcomes are confirmed with a test and a practical exercise; we issue the register, the validation record and the certificates, and close the funding documentation.

    Week 4
  5. 5
    5. Review

    We return after a systems change or after a year: the role map is updated, new people and new tools are added, and the programme is refreshed where scope moved.

    Every 12 months or after a material change
Related guides

The rest of this cluster.

Related services

Where this turns into work we do.

Scope

What this page is, and what it is not.

We are an engineering and training team, not a law firm. This page describes how to perform the obligation and how to evidence it, not how the article should be read for your situation. The legal reading and any assessment of liability are signed by counsel: yours, or our legal partner. Dates and instrument numbers are published together with their sources so you can verify them without asking us for an opinion.

Sources

Where the dates and numbers come from.

FAQ

Questions teams ask.

No. The 2026 omnibus package moved compliance deadlines for Annex III high-risk systems to 2 December 2027 and for AI in regulated products to 2 August 2028. Article 4 has applied since 2 February 2025 and was not part of that postponement.
The Regulation gives no hour count. The test is whether the programme fits the role, the technical knowledge of the audience and the context the system is used in. In practice that ranges from a short orientation session for a board to a multi-day programme for an engineering team, and the role map decides it, not a number fixed in advance.
Staff and other people dealing with the operation and use of your AI systems on your behalf. That includes people outside your payroll: contractors, agencies and subcontractors operating your systems. The personal scope of Article 4 is wider than an employee list.
A dated register of trained people with roles, the per-role programme, the validation record of learning outcomes and named certificates. Those are the documents that work in a customer questionnaire, a tender and an inspection. The evidence is the documentation, not the fact that a session took place.
The Commission for the Development and Security of Artificial Intelligence is the market surveillance authority and the single point of contact, established by the Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026 item 1003). The inspection regime and the penalty provisions apply from 28 October 2026. Liability in a specific case is assessed by counsel; we prepare the evidence that assessment rests on.
Public training money has run through the Baza Usług Rozwojowych register since 1 January 2026, and the 2026 National Training Fund priorities name AI explicitly. Limits, terms and dates are set by the operator for your region, so we check them with you before scope and dates are fixed.
No, and we do not present it that way. Article 4 is one obligation. Compliance also needs at least an inventory and classification of systems, and for high-risk systems technical documentation, event logging and human oversight. After the training you get a note that states this boundary in writing.

Talk to an engineer.

Tell us where you are with the Article 4 AI literacy obligation. We respond within one business day.

Talk to an engineer
Szczecin - ul. Wawrzyniaka 6WWarszawa