Most debates about the EU AI Act revolve around high-risk systems and fines. For those entering the workforce, an inconspicuous article matters more: Article 4 turns AI competence into a legal requirement — and this course is exactly the kind of measure it has in mind.

Why this regulation exists

The AI Act (Regulation (EU) 2024/1689) answers a simple question: how do you ensure that systems whose output is probabilistic and partly hard to trace cause no unacceptable harm — to fundamental rights, safety, and consumer protection? The European answer is risk-based: not the technology is regulated but its use case. The same model architecture can face minimal obligations as a writing assistant and the full high-risk catalog as a credit-scoring system.

When which part of the AI Act applies

Tap a date. Struck-through dates were moved by the 2026 AI Omnibus.

Primary sources: Regulation (EU) 2024/1689 (eur-lex.europa.eu) and the 2026 AI-Omnibus amending regulation — dates for the amended deadlines follow the adopted compromise text; verify against the Official Journal once published.

The timeline — and an important correction

A widespread misunderstanding first: the AI Act did not "launch" in the summer of 2026. It entered into force on 1 August 2024 and has applied in stages since. Since 2 February 2025, the prohibitions of unacceptable practices (Article 5) and the AI-competence obligation (Article 4) already apply. Since 2 August 2025, the obligations for providers of general-purpose AI models apply. On 2 August 2026, the national market-surveillance authorities take up enforcement — including for Article 4 — and the general transparency obligations (Article 50) become applicable. The obligations for high-risk systems under Annex III were originally scheduled for the same date but have been postponed by the AI Omnibus (see below) to 2 December 2027; for high-risk systems embedded in products under Annex I, the date is now 2 August 2028. For the competence obligation, this means precisely: the duty has applied since February 2025; from August 2026 it becomes supervisable by authorities.

A note on currency: with the Digital Omnibus on AI (AI Omnibus), the EU amended the regulation for the first time in June 2026 — the European Parliament approved the compromise on 16 June, the Council adopted it finally on 29 June 2026. Core points: the postponement of the high-risk deadlines (Annex III to 2 December 2027, Annex I to 2 August 2028), two new prohibitions (tools for sexualized deepfakes and abuse imagery, applicable from December 2026), and a rewording of Article 4: the duty to "ensure" AI competence becomes a duty to take measures to promote it. The core idea remains untouched — whoever uses AI professionally must be able to use it competently. Before publishing this chapter, check: has the amending regulation already been published in the EU Official Journal?

The four risk tiers at a glance

The regulation sorts AI systems into four tiers:

  • Unacceptable risk (prohibited, Art. 5): for example, social scoring by public authorities or manipulative systems capable of causing significant harm.
  • High risk (Art. 6 ff.): systems in sensitive areas under Annex III — in finance, most prominently the creditworthiness assessment of natural persons, plus systems in recruiting and critical infrastructure. Here the full catalog applies: risk management, data governance, documentation, human oversight, conformity assessment.
  • Limited risk: transparency obligations (Art. 50) — users must be able to recognize that they are interacting with an AI, and certain AI-generated content must be labeled.
  • Minimal risk: the large remainder, without specific obligations.

Cutting across these tiers are the obligations for general-purpose AI models — the base models behind tools such as Claude or ChatGPT — whose providers must, among other things, supply technical documentation and information on training data.

Why this course starts at the competence layer

The logic of the course mirrors the logic of the regulation. Before anyone operates high-risk systems, reads conformity assessments, or builds AI governance, the base must stand: understanding how the systems work, where they fail, and how to handle them responsibly. Exactly this base is what Article 4 addresses — and exactly this base is what Chapters 1.1 through 1.4 cover. Everything beyond (working with high-risk systems, for instance) presupposes this ground layer and belongs to advanced course levels.

What Article 4 concretely demands

The legal text is short: providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI competence among their staff — taking into account prior knowledge, training, and the context of use. Three points make the norm tangible. First, the broad deployer concept: merely using ChatGPT or Claude productively in a work context makes a company a deployer — Article 4 therefore affects practically every company that uses AI tools. Second, the best-efforts standard: what is required are appropriate, documented measures — no certificates, no exams, no AI officer; the European Commission clarified this in its AI-literacy FAQ. The AI Omnibus lowers this standard once more in 2026 (a promotion duty instead of an ensuring duty); the practical recommendation — run training and document it — is unaffected. Third, context dependence: a marketing department drafting texts needs different knowledge than a team operating credit models.

For you as future employees, this translates as: you may use AI tools at work for the tasks for which you have demonstrably been enabled — and your employer must organize and document that enablement. A completed foundations course like this one is a building block of such evidence.

How enforcement works

Responsibility for Article 4 lies not with the European AI Office but with the national market-surveillance authorities; they take up supervision on 2 August 2026. Article 4 carries no fine provision of its own — its effect is indirect but tangible: through the civil duty of care (an employer letting untrained staff work with AI carries elevated liability risk when AI-related damage occurs) and as a checkpoint in other proceedings, for instance after data-protection incidents caused by faulty AI use. For comparison: violations of the Article 5 prohibitions can draw fines of up to €35 million or 7% of global annual turnover — the regulation is serious, just at a different point.

[CONCLUSION] Article 4 is the quiet clause of the AI Act: no fine of its own, but the norm that turns AI competence from a career advantage into a compliance foundation. Whoever completes this course does not merely satisfy a requirement — they understand why it exists.