Few AI Act obligations attract as many sales myths as Article 4. So first, what is NOT in it: no certified course, no external provider, no annual refresher requirement, no formal documentation rule. What has been required since February 2025 is that people who work with AI have sufficient AI competence — they should be able to judge what the tool can do, where it fails and which data they may trust it with. How you get there is your call. For a typical business it’s one afternoon.
The duty remains in force, Digital Omnibus or not — only the high-risk rules moved. And it applies broadly: you’re a deployer the moment a ChatGPT account is tolerated in sales.
Why the duty is still serious
Article 4 has no fine schedule of its own, and that tempts people to file it away. The flaw in that thinking shows up at the first incident: an employee pastes a client contract into a public AI service, the client finds out, the supervisory authority asks about your safeguards. If you can produce a documented training session with clear rules, you have an isolated incident. If you can produce nothing, you have an organisational failure — the same logic cyber insurers use to cut their payouts.
There’s also the practical benefit that has nothing to do with compliance: most AI mishaps in a company aren’t technology failures; they come from wrong expectations of the tool. People who know a language model can be convincingly wrong double-check numbers before they end up in a quote.
The outline: one session, four blocks
This is the afternoon that satisfies the duty — adapting it is allowed and encouraged:
Block 1 — What the tool is (30 min). How a language model works, in everyday words: it says the statistically likely thing, not the true thing. What follows: hallucinations look like facts, citations can be invented, arithmetic is not its strength. Two or three real examples from your own work beat any slide.
Block 2 — Which data may go in (45 min). The centrepiece, and it’s the same data-class matrix that carries your GDPR work: public material may go into any serious AI, pseudonymisable internal data only into services with a processing agreement, and client data, contracts and personnel records never into open services. Put the matrix on the wall, then walk through examples.
Block 3 — Your rules (30 min). Which services are approved, which are off-limits — and for the off-limits cases, is a model running in-house an option? Who approves new ones? How is AI output marked or reviewed before it reaches a client? Three to five rules suffice — nobody reads more.
Block 4 — Questions and record (15 min). Collect open cases (they will come), keep an attendance list, file the slides and the rules. That is all the documentation it takes.
Repeating it — yes, but for the right reason
Article 4 contains no refresher requirement. A short update still pays off when something changes: newly approved services, new use cases, new people. The trigger is practical, not legal — stale rules nobody remembers are more dangerous than none. If you’d rather not build the first edition yourself, get help setting it up once and repeat it internally afterwards.
Want the training and the data-class matrix tailored to your business? Get in touch — it’s half a day of work, not a training subscription.