Since 2 February 2025, any organisation using artificial intelligence in its work has had a specific obligation: to make sure the people operating it understand what they are operating. That is article 4 of the Regulation (EU) 2024/1689, and it draws no line by size. It applies to a team of three exactly as it applies to a multinational.
Most boards I talk to have read that article as a job for the training department. Buy a course, take attendance, file the certificate. It is a reasonable reading and it is not enough.
What the rule actually asks for
Article 4 asks for a sufficient level of competence, and adds a condition that tends to go unnoticed: sufficient in relation to the context of use and to the people the system will affect. In other words, it does not ask the same of someone drafting emails with an assistant as of someone letting a model rank a list of candidates.
That gradation is the useful part of the rule. It forces you to look at each use on its own and ask what happens when the system gets it wrong. If the answer is «somebody checks it», the risk is low. If the answer is «nobody would know», you have a problem no amount of training will fix.
The question almost nobody asks
In practice, the place where things break is not knowledge. It is authorship. When a tool drafts a proposal, prices a deal or rejects an application, whose decision is that?
I have seen organisations with twelve-page AI policies that cannot answer. And I have seen small teams settle it in one sentence: «Marta signs that one off». The difference is not technical maturity. It is whether somebody sat down to hand out responsibilities before handing out licences.
Three decisions worth writing down
You do not need a corporate governance framework to start. You need three answers, and they fit on one page:
- Which uses are allowed and which are not. Named processes, not categories. «Drafting proposals» is a use; «improving productivity» is not.
- Who reviews each one before it leaves the building. A person with a name, not a department. Departments do not sign things.
- What gets recorded. If in six months you have to explain why a decision was made, somebody must be able to reconstruct it.
All three are management decisions, not technical ones. None requires understanding how a model works inside. All require being willing to say who carries the consequences.
The calendar is tight, but it is not the point
The bulk of the European Regulation applies from 2 August 2026, and that date is absorbing all the attention. I understand the urgency, but I think it frames the problem badly. An organisation that arrives in August with its training documented and no idea who answers for what will have completed the paperwork and will be exactly as exposed as before.
The real exposure is not regulatory. It is operational. A system that proposes prices with nobody validating them will eventually propose a bad one, and the problem will not be the fine. It will be the client.
Literacy means teaching people to distrust
Training that works does not explain what a transformer is. It explains the specific cases where this tool, in this company, produced answers that looked right and were not. It teaches people to recognise the moment when a response sounds convincing and has to be checked anyway.
That is not learned on a generic course. It is learned from your own cases, reviewed as a team, including the ones that went badly. It is more uncomfortable, and it is the only thing that changes how people behave.
AI governance does not start with a policy. It starts when somebody writes a list of names next to a list of decisions, and accepts what that means.