Since 2 February 2025, the European AI Act has enforced an article most companies haven't read: Article 4, on "AI literacy". The idea behind it is simple. If people in your company use AI tools in their daily work, you have to make sure they know what they're doing with them — and you have to be able to show it, not just claim it in a meeting.

The text isn't dramatic, which is exactly why it slips past everyone. It doesn't require a specific course or a certificate with an official letterhead. It asks for "a sufficient level of AI literacy" among the staff working with these systems, proportional to each person's role and the context they operate in. An engineer training a model and a salesperson writing proposals with ChatGPT need entirely different things. The law acknowledges that and leaves the interpretation to the company.

That's where the trap is. Interpretive freedom feels comfortable right up until someone — an auditor, a large public-sector client, a partner running due diligence — asks the question: "So how do you know your people use AI correctly?" If the only answer is "they manage", you have nothing to put on the table.

What "sufficient" means, in practice

The regulation leans on a word that scares lawyers and annoys managers: proportional. In practice it means the bar rises with the stakes. Someone summarizing internal notes with an AI assistant needs to know enough not to paste confidential data into a public chat and to check what comes out. Someone using AI to make decisions about clients or candidates sits in a completely different category of responsibility.

What you'd expect from an ordinary employee, in terms a lawyer would sign off on:

  • understands the model can be confidently wrong, and verifies output before using it;
  • knows which types of data must never go into an external tool;
  • recognizes when a task is too sensitive to hand to AI at all.

In plain terms, this is judgment applied to real work: knowing what you can hand to AI and what you can't. No one expects the finance team to become prompt engineers.

What the law doesn't say (and why it matters)

Article 4 doesn't tell you to buy a training. It gives you no checklist. And despite the sales messages you have probably already received, it sets no separate, fixed fine for a lack of "AI literacy" on its own. The large penalties in the regulation attach to other things — prohibited practices, high-risk systems.

What Article 4 does is shift the burden of proof onto you. In any compliance conversation, the question won't be "have you broken a law", it will be "what measures did you take". And "measures" means something you can show: who was trained, on what, when, and what they walked away with — a guide, a procedure, evidence that people went through something structured rather than a forgotten webinar.

Companies that treat this as paperwork for a folder miss the useful part. An employee who understands the limits of AI makes fewer expensive mistakes. The compliance requirement and that improvement come from the same work.

Where to start

You don't need a year-long program. Start with an honest map of who uses AI and for what — usually more than management thinks, because half of it happens unofficially, in personal accounts.

Then, a shared way of working: how to write a good instruction, what to check, what never goes into a chat. A one-page guide people actually use beats a fifty-page manual nobody opens.

Finally, a documented trail. Not for the auditor, but for you: so you know where the team stands and what you will need to cover next year, when the systems change again.

We built the TVL Academy program around exactly this logic — we start from the company's real processes and leave the team with a shared way of working and the documentation that proves the training happened. But whether you do it on your own or with someone else, the order stays the same: first you understand how AI is used in your company, then you make it consistent, then you document it.

The deadline has already passed, back in February 2025, and the longer you wait, the more habits the team builds that you will have to correct later anyway.