Open blank evidence binder with unused purple wax seal and pen — Motto x Beyond Chiefs

AI Act Article 4: What Management Must Be Able to Prove About AI Literacy

# AI Act Article 4: What Management Must Be Able to Prove About AI Literacy

The useful Article 4 question is not “which certificate did people get?” It is: can we reconstruct, from contemporaneous records, why the right people received a fitting measure for the AI they actually use — what was reviewed, what changed, and who owns the next update?

Christian Pobbig and Beyond Chiefs work from Hamburg on AI Executive Search in DACH. This piece is not a training catalogue and not a statute dump. It turns Article 4 into a reviewable evidence chain for management as the internal owner of the proof trail.

Article 4 after the Omnibus: support literacy — do not guarantee a personal score

The Commission is clear: providers and deployers take measures that support the development of AI literacy among staff and other persons dealing with the operation or use of AI systems on their behalf. Measures must be tailored to knowledge, experience, education, training, and context. Article 4 does not require guaranteeing any specific or “sufficient” individual level (European Commission, AI literacy Q&A, last update 27 July 2026).

Germany’s Bundesnetzagentur mirrors the same live position: measures support literacy; they do not guarantee a particular individual level (BNetzA, AI literacy EN; DE).

What is not required

Per the Commission FAQ and BNetzA guidance, Article 4 does not prescribe:

- a certificate or a fixed format
- a guaranteed individual competence level
- an AI officer or a specific governance structure (not a GDPR-style DPO equivalent)
- an obligation to measure employee knowledge levels

Formats stay flexible: self-learning, workshops, training, multi-stage programmes — internal or external. Manuals and instructions alone are often ineffective, the FAQ notes; they do not replace a programme fitted to actual use.

Who is in scope

In scope are staff and other persons acting on the organisation’s behalf — including contractors and service providers where they operate or use the systems. Everyday GPAI / chatbot use (for example ads or translation) is not an exemption: the FAQ explicitly says relevant risks such as hallucination should be addressed (Commission FAQ).

“Management” here means the internal owner of the evidence trail — not a claim that Article 4 separately addresses directors beyond provider/deployer duties.

BNetzA’s three cornerstones → evidence chain

BNetzA names three orientation pillars: identify needs, design measures, keep records / evaluate / update (BNetzA EN; DE).

For management, that becomes a reviewable chain (BC practice frame — not a statutory folder mandate):

  1. Scope — which systems, which uses, which groups of people
  2. Role / context fit — why this measure matches this role and this risk
  3. Measure — type and substance
  4. Participation / completion record — who attended or completed
  5. Evaluation — what was reviewed or fed back (practice, not a legal exam)
  6. Refresh / change log — what changed in the system or use, and what was updated
  7. Accountable sign-off — who knows the current state and owns the next update (practice, not a director certificate)

As documentation fields, BNetzA names among others the type of measures, their content and time scope, and the participating persons. The same fields appear in the June 2025 guidance PDF — still carrying pre-Omnibus Article 4 wording there; use the live page for the current duty, the PDF only for field orientation (Hinweispapier PDF).

Proof that a measure happened ≠ proof that it fitted

An attendance list or a participation certificate can show that a measure took place. It does not by itself show that the measure fitted role, system, risk, and context. That difference is the executive test: does the content match actual use — or was it a generic workshop for everyone?

Evaluation and sign-off are defensible practice here, not a statutory knowledge test and not a certificate duty.

What a management review can ask in one sitting

Compact, aligned to official fields — without invented hours, scores, or retention periods as “Article 4 rules”:

  1. Which AI use is in scope — and which groups of people (including contractors where relevant)?
  2. What need was identified, and how is the measure tailored to role and context?
  3. Type of measure, content and time scope, participating persons — where is the record?
  4. What was evaluated or fed back — and what changed as a result?
  5. When and why is literacy refreshed (system change, new use, new risks)?
  6. Who owns the next update — a name, not a function alone?

BNetzA recommends documenting well so measures can be shown; a lack of literacy may be treated as a duty-of-care issue especially if harm results — that is authority guidance, not a Beyond Chiefs legal opinion (BNetzA).

Boundary: high-risk oversight and board accountability

High-risk systems carry separate oversight-training duties (including Article 26) — adjacent, not this page’s hub. Whom the Vorstand names as owner of an AI decision belongs on the board-accountability spoke — not here. Article 4 does not create a director certificate.

National market surveillance authorities enforce Article 4; the Commission FAQ points to enforcement from August 2026. Recheck that date wording against the FAQ before publish — no invented fine theatre.

FAQ

### Do we need a certificate?

No. Article 4 does not prescribe a certificate or a fixed format, per the Commission and BNetzA. Internal records of trainings and guiding initiatives can suffice.

### Does ChatGPT for ads or translation exempt us?

No. The FAQ treats exactly those cases as literacy scope and expects relevant risks (such as hallucination) to be addressed.

### Must we appoint an AI officer?

No. Article 4 does not require an AI officer, per the Commission FAQ and BNetzA.

### Must we measure knowledge levels?

No. There is no general duty to test employee knowledge. Evaluation as practice can be useful — it is not a legal minimum.

---

Draft inventory. Not live. No service CTA.

Recent Blog Posts

Empty board table, blank minutes, unused violet stop ring

Agentic AI: five questions the board must ask

Team Beyond Chiefs
Read More
Open blank evidence binder with unused purple wax seal and pen — Motto x Beyond Chiefs

AI Act Article 4: What Management Must Be Able to Prove About AI Literacy

Team Beyond Chiefs
Read More

AI Agents: Transforming Global Business in 2025 | Complete Guide

AI as CEO? 6 Costly Misconceptions About AI Leadership That Companies Must Avoid

CONTACT Us

Leading the Future with AI-Driven Leadership

contact us