Most companies think the EU AI Act does not apply to them yet. They are waiting for August 2026, or December 2027, or some future date when the “real” rules arrive.
Article 4 has been in force since 2 February 2025.
That means if you have employees who use AI tools — ChatGPT, Copilot, Gemini, any AI assistant — you already had a legal obligation more than a year ago. Whether you knew about it or not.
—
## What Article 4 actually says
Article 4 of the EU AI Act requires that providers and deployers of AI systems ensure their staff have a sufficient level of *AI literacy*.
“AI literacy” means the skills, knowledge, and understanding that allow people to:
– Use AI tools appropriately and effectively
– Understand the limitations and risks of AI systems they work with
– Apply critical thinking when evaluating AI outputs
The regulation is deliberately flexible. It does not require a formal certification or a specific number of training hours. What it requires is that you take *reasonably practicable measures* appropriate to your context — the size of your company, the AI tools you use, and how much those tools affect your operations or your customers.
A five-person consulting firm that uses ChatGPT for drafting emails has a different obligation than a 200-person logistics company that uses AI for automated sorting decisions. The obligation scales. But it does not disappear.
—
## Why “I am not the provider” is not an escape
Many SME owners read Article 4 and assume it only applies to companies that *build* AI — the Microsofts, the OpenAIs, the enterprise software vendors.
This is wrong.
Article 4 explicitly covers **deployers** — businesses that use AI systems in the course of their professional activities. If you subscribe to Copilot for Microsoft 365, deploy a chatbot from a third-party vendor, or use AI screening in your recruitment process, you are a deployer. The literacy obligation applies to you.
The distinction matters: you do not need to understand how a large language model is trained at the technical level. You need to ensure the people using AI in your business understand *how to use it responsibly* — what it gets wrong, when not to trust it, and what decisions should not be delegated to it.
—
## What “sufficient AI literacy” looks like in practice
There is no official checklist. But regulators and compliance advisors have converged on a practical interpretation that covers three areas:
**1. Understanding what the AI system actually does**
Your staff should know — in broad terms — how the AI tools they use work, and what those tools are and are not designed to do. Using GPT-4 to summarise a legal contract is fine; using it as a substitute for legal advice is not. Your team needs to know the difference.
**2. Knowing the failure modes**
AI systems hallucinate. They reflect biases in their training data. They can sound confident while being factually wrong. Employees who use AI outputs without any critical review are a compliance risk. Training should address this directly.
**3. Document that training happened**
This is where most SMEs fail. The obligation exists; the training might even happen informally. But without documentation — a record that training occurred, what it covered, and who attended — you have nothing to show an auditor or regulator.
—
## The documentation question
The EU AI Act does not specify the format of literacy documentation. What it expects is that you can demonstrate, if asked, that you have taken Article 4 seriously.
A minimal approach for an SME:
– A written internal policy describing your AI use and the literacy standard you have adopted
– Evidence that staff were briefed (meeting notes, email confirmation, a signed acknowledgement)
– A record of what tools your business uses and in what contexts
This does not need to be elaborate. A two-page policy document and a signed team briefing record is sufficient for most small businesses. The key is that it exists.
If you operate in a regulated sector — financial services, healthcare, education, law — expect higher expectations. The tools you use and the decisions they influence carry more risk, and the documentation should reflect that.
—
## What the fine structure looks like
Article 4 violations are not in the same penalty category as the highest-risk AI failures. But they are not trivial.
Under the EU AI Act, non-compliance with obligations for deployers can attract fines up to **EUR 15 million or 3% of global annual turnover** — whichever is higher. For SMEs, 3% of turnover is usually the binding constraint, and it can be significant even for a company with modest revenue.
More immediately: if you are in any kind of B2B context where clients, auditors, or partners ask about your AI governance practices, having no answer to “how do you ensure your team uses AI responsibly?” is a competitive and reputational risk, not just a legal one.
—
## What to do now
The short version: document what you already do, formalise it slightly, and make sure your team knows it exists.
**Step 1:** List the AI tools your business uses. Be honest — this includes free tools, personal subscriptions, and anything embedded in software you already pay for (Copilot in Office 365, AI features in your CRM, AI writing tools in your email platform).
**Step 2:** Write a short internal policy. It should describe what AI tools you use, what they are and are not used for, and what your expectations are for staff when using them.
**Step 3:** Brief your team. A 30-minute session covering the tools you use, their limitations, and your internal policy is sufficient for most SMEs. Document that it happened.
**Step 4:** Store the records somewhere you can retrieve them. Your internal drive, a folder in your email system, or a dedicated compliance file.
That is it. Article 4 does not require a compliance department. It requires that you take it seriously enough to write it down.
—
## The free resource
I have put together a short compliance checklist specifically for Article 4 — covering the documentation structure, the policy template, and the staff briefing framework.
It is free, in German (EU regulation compliance in the DACH market makes this the priority), and covers everything in about eight pages.
**[→ Download the free Article 4 checklist (German)](https://frelih.gumroad.com/l/slwzch)**
If you are working in French:
**[→ Télécharger la checklist gratuite (Français)](https://frelih.gumroad.com/l/bghydm)**
For the full compliance kit — including policy templates, staff briefing scripts, and a documentation register you can submit to auditors — the complete German kit is available here:
**[→ EU KI-Verordnung Compliance Kit 2026 — Vollständiges Paket (€149)](https://frelih.gumroad.com/l/mjsaqg)**
**[→ Kit Conformité Loi IA — Complet (€149)](https://frelih.gumroad.com/l/xdyenu)**

Leave a comment