EU AI ACT · ARTICLE 4
Your AI literacy obligation
is already in force.
Article 4 has applied since 2 February 2025. It is an obligation of effort, not result — which means your documented, proportionate effort is the compliance artefact. The Scan produces that record in five business days.
There was no phase-in.
There is no grace period.
Most organisations treat Article 4 as something to prepare for. It isn’t. The obligation has been live since February 2025, and an organisation without AI literacy measures in place is not preparing for a deadline — it is already outside the requirement.
Because it is an obligation of effort rather than result, the record is the compliance position. The Regulation does not ask you to prove a literacy level — it asks what measures you took, for which roles, and when. Organisations that have documented nothing have nothing to show.
That record cannot be built retrospectively. Whatever you can evidence today is what you had. The Scan produces that record — and tells you honestly where the gaps are before someone else finds them.
And “we ran AI training last year” is not automatically an answer. The requirement is proportionate to role and context — a single all-staff module treats a procurement lead and a developer as the same person, and the Regulation does not.
What Article 4 asks of you
In plain terms — not a legal reading. Interpretation belongs to your counsel; we build what the obligation requires you to have.
Requirement 01
Support the development of AI literacy
Providers and deployers must take measures to support the development of AI literacy among staff and others dealing with the operation and use of AI systems on their behalf. The Regulation states expressly that this does not require you to guarantee any specific level of literacy in any individual. It is an obligation of effort — which makes documented, proportionate effort the compliance artefact.
- Can you say what level of AI literacy each of your role-groups currently has?
- Is that based on evidence, or on assumption?
Requirement 02
Proportionate to role and context
The Regulation ties the measures to technical knowledge, experience, education and training, the context the systems are used in, and the persons or groups on whom they are used. A procurement lead, a clinician, and a developer do not need the same thing — and a single all-staff module does not reflect that.
- Have you distinguished between role-groups, or trained everyone the same way?
- Does your provision reflect what each group actually does with AI?
Requirement 03
Across your whole AI footprint
Not just the systems you built or bought deliberately. Most organisations underestimate their AI footprint by a wide margin once embedded features in existing tools are counted.
- Do you have a current inventory of every AI system in use?
- Does it include AI features embedded in tools you already licence?
Requirement 04
Beyond your own staff
Recital 20 frames AI literacy as equipping providers, deployers and affected persons to make informed decisions — including the knowledge affected persons need to understand how AI-assisted decisions will impact them. If your systems make or support decisions about customers, patients, or citizens, that widens what literacy has to reach.
- Do AI-assisted decisions in your organisation affect people outside it?
- Could you explain one of those decisions to the person it affected?
Requirement 05
Demonstrable, not assumed
The practical question is not whether your people are competent. It is whether you can show what you did, for whom, and when — in a form that holds up to someone asking.
- If a regulator or client asked tomorrow, what would you send them?
- Would it show what was in place, and from when?
Requirement 06
Maintained, not one-off
Literacy is tied to the systems in use and the context they’re used in — both of which change. A new tool, a new use case, or a new team shifts what “sufficient” means. Provision documented once and never revisited describes an organisation as it was, not as it is.
- When did you last review AI literacy provision against your current systems?
- What happens when a new AI tool is adopted — does anything trigger?
Scope, price, and terms
Fixed fee, fixed scope, fixed turnaround. You know the number before anything starts.
The fee
€2,800
Fixed fee, invoiced in full on signature for first engagements. Five business days from a complete kickoff pack — the clock starts when we have what we need, not at signature.
You know the number before anything starts. No hourly billing, no scope creep.
The scope
What’s included
Up to 10 AI systems and 5 role-groups. Up to 6 remote interviews. One revision round included. Everything in the deliverables above.
Larger footprints are quoted on scope — we’ll tell you on the call if you’re outside this.
The terms
How it runs
A three business day turnaround applies to information requests on your side. Misses move the delivery date day for day — we won’t absorb delay silently and then miss the deadline.
Clear on both sides. That’s what makes five days deliverable.
The credit
It credits back in full
If you contract a follow-on engagement of €10,000 or more within 90 days of the Scan readout, the full €2,800 credits against it.
The Scan tells you whether you need more work. If you do, you don’t pay twice for the diagnosis.
What the Scan delivers
A working record your leadership can act on and your counsel can rely on. Not a training course, and not a certificate.
AI systems inventory
Every AI system in use or planned across the scoped perimeter — including the embedded features most inventories miss.
Role-group mapping
Who interacts with which systems, in what capacity, and what level of literacy each group’s role actually requires.
Literacy gap assessment
Where current provision meets the requirement, where it doesn’t, and how far apart those two things are.
Documented measures record
The evidentiary artefact — what measures exist, for which role-groups, effective from when. The thing you send if someone asks.
Remediation roadmap
Training, policy, and documentation, sequenced by exposure and by what you can actually execute. Every item with an owner and a timeline.
Board-ready summary
A short, plain-language read for people who need to know where the organisation stands without reading the full record.
Update triggers
What constitutes a change requiring the record to be revisited — a new system, a new use case, a new team — so provision does not silently fall out of date.
Who this is for
- Organisations deploying AI in the EU — whether purpose-built, procured, or embedded in tools already licensed
- Deployers who need a defensible record of AI literacy provision and don’t currently have one
- Organisations that have run all-staff AI training and aren’t sure it satisfies a role-proportionate requirement
- Law firms advising on the AI Act who need implementation delivered without it sitting on associate time
- Organisations facing client or counterparty due diligence on AI governance
- Teams who don’t know how many AI systems they actually have
Why Connext
LL.M. in Innovation, Law, and Technology, University of Toronto Faculty of Law (2026) — AI, privacy, cybersecurity, and technology regulation.
Cross-jurisdictional practice across the EU AI Act and GDPR, Canadian privacy legislation, CCPA/CPRA, and Asia Pacific regimes.
Implementation and governance only. Legal interpretation stays with your counsel — the boundary is written into every engagement.
What follows the Scan: where it identifies high-risk systems, the High-Risk AI Readiness Assessment covers classification and Articles 6 and 26. Where Article 27 applies, a Fundamental Rights Impact Assessment follows.
Scope of engagement — please read
Connext does not provide legal advice. Nothing in our deliverables constitutes a legal opinion or a determination of regulatory status.
Classification and applicability are legal determinations. Whether an AI system falls within a given obligation, and whether any measure is sufficient to satisfy it, remain the responsibility of the client and its legal counsel. Our analysis is prepared to support that determination — it does not replace it.
Deliverables should be reviewed by qualified counsel in the relevant jurisdiction before you rely on them. Connext accepts no liability for any consequence arising from a decision not to obtain that review, or from reliance on our deliverables without it.
START THE CONVERSATION
Find out whether the Scan fits.
A 45-minute scoping call. We’ll map your AI footprint, confirm which obligations apply, and tell you whether the Scan is the right instrument. If it isn’t, we’ll say so — and tell you what is.
BOOK A 45-MINUTE CALLOr email hello@connextbusinesssolutions.com — a short question doesn’t need a meeting. Remote-first across Canada, the United States, Europe, and Asia Pacific.