Axura Logo
Axura Blog

SPUNTI E CONVERSAZIONI DI UN’AGENZIA
SPECIALIZZATA IN INTERAZIONI DIGITALI

SPUNTI E CONVERSAZIONI

AI Act training under Article 4: why AI literacy matters, beyond any course

Stella Fumagalli

Tempo di lettura: 8′

Four people in a meeting room watch the opening slide of the Axura course "Fundamentals of AI and the AI Act", presented by the Axura mascot.
Four people in a meeting room watch the opening slide of the Axura course “Fundamentals of AI and the AI Act”, presented by the Axura mascot.

At Axura we started using generative artificial intelligence tools practically as soon as they became available.

We did it by experimenting, but above all by talking to each other: with many (many!) structured training sessions in which we stopped to share ideas and news, to look at what worked and what didn’t, to think through opportunities and risks.

We pooled good practices, doubts and ideas so we could use artificial intelligence at its best, to our benefit and to that of the clients we work with.

Now that AI has become part of everyday life for so many people, both personally and professionally, we realise one thing: our experience at Axura is probably more the exception than the rule.

In how many organisations is artificial intelligence used every single day without anyone really knowing it? You open ChatGPT (or Claude, or Gemini, or Copilot), you ask it something and you stop there, without wondering what it does well and what it does badly, where you can trust it and where you can’t, what happens to the data you feed it.

Then there’s the opposite reaction: the company decides AI is dangerous and bans it. The result, almost always, is that people go on using it anyway, with their personal accounts, on their own devices, outside any rule.

It’s called shadow AI, that is artificial intelligence used inside a company without the company knowing, and today it is one of the most widespread and least supervised risks in SMEs. A ban doesn’t eliminate the use of artificial intelligence: it eliminates any chance of knowing how it is being used.

Two different attitudes with the same cause: nobody in the company has ever had the chance to really understand what they are dealing with when they use AI. In other words: nobody has ever had any training on artificial intelligence.

The numbers tell the same story: the latest Istat report on Enterprises and ICT shows that in 2025, 16.4% of Italian companies with at least 10 employees used at least one AI technology, compared with 8.2% in 2024 and 5.0% in 2023 (the share has more than tripled in two years!).

"Enterprises and ICT, year 2025": AI use doubles in a year and now involves more than half of large companies.
“Enterprises and ICT, year 2025”: AI use doubles in a year and now involves more than half of large companies.

Large companies went from 32.5% to 53.1%; SMEs, although they doubled, stop at 15.7%. Among the companies that do not use AI, 11.5% did consider adopting it and then decided not to go ahead. When Istat asks them what held them back, the most frequent answer is a lack of skills, cited by 58.6%, followed by insufficient legislative clarity (47.3%) and the unavailability or poor quality of the necessary data (45.2%).

Put differently: the first obstacle to artificial intelligence in Italian SMEs is that people don’t really know how to use it, and the second is that they don’t really know what happens if they use it the wrong way.

This is precisely what Article 4 of the AI Act is about — the European rule on AI literacy — which has had a new wording since 27 July 2026.

Article 4 of the AI Act: the current wording

The AI Act (Regulation (EU) 2024/1689) devotes an entire article to something that concerns virtually every business: the skills of the people who work with artificial intelligence.

That’s Article 4, and it was rewritten recently: on 24 July 2026 Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, was published in the Official Journal of the European Union, and it entered into force on 27 July.

Here is what the rule says today: those who build AI systems and those who use them in their business must take measures to support the development of AI literacy among their people. Not for everyone in the same way, though: account must be taken of each person’s existing skills, of the context in which those systems are used, and of the people they are used on (the obligation does not require proof that a given level has been reached, nor must the company guarantee it for individuals).

From “ensure” to “support”: what actually changed

The previous wording required those who build AI systems (providers) and those who use them in their own activity (deployers) to “take measures to ensure, to their best extent, a sufficient level of AI literacy”.

The current one requires them to “take measures to support the development of AI literacy”.

The difference looks subtle and is in fact substantial. “Ensure, to their best extent” could be read as a promise about the outcome: the company had to make sure its people had reached a certain level. But which level? And measured how? It was a requirement that was hard to translate into practice.

Graphic comparison: before, "ensure", illustrated by a finish line; after, "support", illustrated by a rising staircase.
Graphic comparison: before, “ensure”, illustrated by a finish line; after, “support”, illustrated by a rising staircase.

“Support the development” shifts the weight elsewhere: what counts is what the organisation puts in place, not the end point reached by the individual.

In practice, the company must be able to show that it offered training to its employees.

Why this is not a free-for-all

The training obligation remains, and since 2 August the AI Act has entered its phase of full application, with national supervisory authorities now operational.

Which means that if someone asks a company to account for the training it has offered its employees, the company must be able to document it.

But is an AI Act course mandatory? No, and this needs saying clearly, because in recent weeks plenty of “mandatory AI Act courses” have been on offer, promising a compliance that no course can deliver. The rule does not prescribe courses, it does not prescribe certificates or certifications, it does not set a minimum number of hours. What is needed is the ability to reconstruct the process: what was done, with what programme, what content, addressed to whom and when.

There is a second, very important point: training must be calibrated to people’s existing skills, to how the company uses AI, and to those affected by it. A course that is identical for everyone and delivered without looking at what actually happens inside that company is unlikely to meet this requirement.

To see how other organisations are approaching this, the European Commission maintains a free, publicly available repository of AI literacy practices: it collects more than forty concrete experiences from businesses and public administrations, from classroom courses to e-learning platforms.

Laptop open on the European Commission page "Repository of AI literacy practices".
Laptop open on the European Commission page “Repository of AI literacy practices”.

The repository can be an excellent source of ideas, but there is an important caveat: adopting one of the practices described does not automatically make you compliant with Article 4 (the Commission says so itself). The point is not to copy what another organisation has done, but to build training that fits your own reality, the people involved, and the way AI is actually used in your company.

The rest of the calendar: what already applies and what is coming

Timeline of AI Act deadlines from 2025 to 2028, listed in the text below.
Timeline of AI Act deadlines from 2025 to 2028, listed in the text below.

The Digital Omnibus postponed specific sections of the AI Act, leaving the rest in place.

Let’s try to clear things up.

Already applicable today:

  • the AI literacy obligation (Art. 4) and the original prohibitions of Art. 5, since 2 February 2025;
  • the general application of the Regulation and the transparency obligations of Art. 50, since 2 August 2026, with national supervisory authorities operational.

Coming up:

  • from 2 December 2026 the AI Act adds two express prohibitions, concerning AI systems used to generate non-consensual realistic intimate material and child sexual abuse material. These are acts already unlawful on other grounds; what’s new is that they also become a direct breach of the Regulation. By 2 December 2026, generative AI systems must mark the content they produce so that a machine can recognise it as artificially generated (this is Art. 50(2)). This is an obligation for those who build and sell such systems, not for those who use them in their business. Providers who placed them on the market before 2 August 2026 have until December to comply; for systems placed on the market from 2 August 2026 onwards, the obligation already applies in full.One thing not to get confused about: this extension covers only the technical marking. All other transparency obligations have applied since 2 August 2026, with no exceptions, including those affecting companies that merely use AI: disclosing deepfakes, disclosing AI-generated text when it informs the public on matters of public interest, and notifying people exposed to emotion recognition systems.

  • from 2 December 2027, the obligations for high-risk systems under Annex III (including recruitment and staff assessment, credit, health);
  • from 2 August 2028, the same obligations for high-risk systems embedded in products (Annex I).

The application dates are set out in Article 113 of the AI Act, as amended by the Digital Omnibus.

Beyond the rule: AI training is a business issue

The reason it’s worth investing in AI training is not Article 4: really knowing artificial intelligence is what makes the difference between those who simply “use it” and those who manage to turn it into a concrete advantage.

People who know these tools well can spot the tasks where they are genuinely useful, can tell a good result from a mediocre one and, above all, understand when it’s better not to use them at all. Those who know them only superficially tend to settle for the first output they get, often without realising how much more they could be getting.

It’s the same difference there is between a company that uses AI to improve a few activities and one that, thanks to AI, rethinks the way it works.

It’s no coincidence that, in the Istat report, a lack of skills is the number one barrier: SMEs don’t give up on AI because they don’t see its value, but because they don’t feel equipped to govern it.

And note: generative AI has made its way everywhere — marketing and sales, of course, but also administration, production, purchasing, customer service, HR. An email to write, a quote to put together, a product description to translate, a pile of CVs to sift through: any of these is enough for someone to reach for a generative AI tool.

Before the training: understanding how AI is already being used in your company

Out of all this — the rule, our own experience and above all what we see inside companies — at Axura we have put together a training path designed for SMEs.

It starts with a question: how does this company use artificial intelligence today?

This is the initial assessment phase, and it serves to line up which tools are actually in use, in which processes, on which data, with what effects on people, with which rules already in place and which not.

In our experience it is also the moment when a few “surprises” tend to surface: tools activated by individual departments, personal licences used for work, AI features built into company software that nobody had noticed.

The training itself follows from that picture: our path begins with a first module we’ve called “The AI Decalogue”. It lasts an hour and a half, is delivered as asynchronous e-learning and is aimed at all staff (because it’s the groundwork anyone in the company who opens an AI tool needs).

By the end of the module, participants can recognise an AI system and its risk category, know what they may and may not enter into generative tools, can spot an unreliable output and know who to turn to.

Monitor showing the slide of the Axura course "Fundamentals of AI and the AI Act", module C0: 1.5 hours, asynchronous e-learning, aimed at all staff.
Monitor showing the slide of the Axura course “Fundamentals of AI and the AI Act”, module C0: 1.5 hours, asynchronous e-learning, aimed at all staff.

Those who pass the final test receive a certificate of attendance and the decalogue card to keep at hand; from there, depending on roles and on how the company uses AI, the path can continue with dedicated in-depth modules.

(A word of precision about the certificate: it documents that the person completed the path, and for the company it counts as documentary evidence of the training measures adopted. It is not, and cannot be, a certification of compliance with the AI Act — no course is.)

Where to start: Axura’s AI training path

Be careful about treating training as a mere formality: if people sense that the company is just ticking a box, they will behave accordingly.

A company that trains its people on artificial intelligence cannot do it just to be compliant: it should do it because trained people get better results, make fewer mistakes and know when to stop.

That this also produces the documentary evidence required by Article 4 is – how shall we put it? – a welcome side effect.

At Axura we help companies tell their story and use technology well: we have built an AI training path designed for SMEs, starting from an assessment of how the company already uses artificial intelligence and leading to training calibrated on real roles and real risks.

Want to know more? Get in touch: we’ll tell you how it works.