Article 4 requires organisations to take measures supporting the AI literacy of staff who use AI systems. It applies to providers and deployers alike, which in practice means any company whose employees use ChatGPT, Copilot, Claude, or the AI features now embedded in ordinary business software.
It has been in force since 2 February 2025, with no transition period and no exemption for small companies, and national market surveillance authorities have been enforcing it since August 2026. The July 2026 amendments made the standard easier rather than harder: you no longer have to guarantee any particular level of competence, only show that you took measures.
Which turns the whole thing into a question of evidence, and evidence is inexpensive: a written policy, short role-appropriate training, and retained acknowledgements. That is precisely why having none of it is difficult to justify when an authority asks.