Mandatory AI training at work: compliance obligation or competitive advantage?
AIStrategy

Mandatory AI training at work: compliance obligation or competitive advantage?

Since 2 February 2025, every company using AI tools has had to provide adequate training. Treat it as a compliance box to tick and it's a cost. Treat it as an investment and it's the first step towards adopting AI with real results.

QMates· Software Advisory25 March 202611 min read

Mandatory AI training is now a reality. Since 2 February 2025, Article 4 of the European Regulation on artificial intelligence (the AI Act) has required every company using AI systems to ensure an adequate level of "AI literacy" among its staff.

The most common reaction? "Another regulatory box to tick." A course to get through, a certificate to file away, one more line in the compliance register.

Anyone running a company knows that regulatory obligations fall into two categories: ones that stay a cost, and ones that become an investment. The difference isn't in the rule itself, but in how you approach it.

This article is for anyone running a company — CEOs, managing directors and heads of operations — who wants to understand what the AI training obligation actually requires, what it means in practice, and how to turn it into a real competitive advantage. If you're working out how to adopt AI in your business with real results, training your team is the first step.

What does the AI training obligation require (Art. 4 AI Act)?

The essential facts, without the legalese.

Article 4 of Regulation (EU) 2024/1689 (the AI Act) requires providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy — the Regulation's own term — among the staff who operate those systems.

The obligation has been in force since 2 February 2025. Enforcement — meaning the possibility of penalties — applies from 2 August 2026.

In Italy, Law 132/2025 transposed the European framework, giving the ACN (National Cybersecurity Agency) and AgID responsibility for supervision and coordination.

The definition of "AI literacy" appears in Article 3, point 56 of the Regulation: the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, taking into account the applicable rights and obligations.

In practice: anyone using AI tools at work needs to understand what they're using, with what limitations, and with what responsibilities.

That's the law. Now for the part that matters: what it means in practice.

Who needs to take AI training at work?

This is the question that causes the most confusion. The AI Act uses the term "deployer": who counts as one?

A deployer is any organisation that uses an AI system under its own authority. You don't need to develop it or sell it: using it is enough. If your company uses ChatGPT to generate content, Copilot to write code, a chatbot for customer service, or any other AI-based tool, you're a deployer.

AI training in the workplace doesn't mean training everyone the same way. It means making sure each person has the skills appropriate to their role and to how much they interact with AI systems.

Here's a concrete example — a manufacturing company with 60 people:

  • Leadership (5 people): the CEO, the CFO and the heads of function. They don't use AI directly, but they make strategic decisions about where and how to adopt it. They need to understand what AI can and can't do, the regulatory risks, and how to evaluate vendor proposals
  • Operational managers (12 people): the heads of production, sales and procurement. They decide how AI is used in their processes. They need to understand how to govern AI use in their team, what to check, and when to step in
  • Front-line teams (43 people): the people using AI tools day to day. Sales drafting proposals with AI, customer service running the chatbot, marketing generating content. They need to understand how to use the tools effectively and responsibly

Three groups, three different training needs, a single regulatory obligation. The difference lies in the depth of training, not in who's exempt.

The three levels of risk from inadequate AI training: legal, operational and competitive
The three levels of risk from inadequate AI training: legal, operational and competitive

What are the risks of not complying?

The risks of skipping AI training operate on three levels, from the most immediate to the most strategic.

Legal risk

Article 4 doesn't set out a specific penalty of its own, but a lack of AI training counts as an aggravating factor in AI Act infringements. Fines can reach €35 million or 7% of global annual turnover, whichever is higher.

In practice: if something goes wrong with how AI is used and staff weren't properly trained, the company is in a far more exposed position.

Operational risk

Untrained people make decisions based on output they don't understand. A sales team generating proposals with AI without knowing how the model handles confidential data. A manager signing off an automated workflow without knowing where the system can get it wrong. A legal team using AI for contract analysis without checking for the model's hallucinations.

This isn't theoretical: it's already happening in companies that have rolled out AI tools without training.

Competitive risk

According to 2025 Eurostat data, only 16% of Italian companies use AI technologies, compared with 26% in Germany and 42% in Denmark. The gap isn't in the technology available: it's in organisations' ability to adopt it.

A company with an untrained team adopts AI more slowly, makes more mistakes and has less to show for it. Meanwhile, competitors who have invested in training pull ahead.

What should AI training actually cover?

The AI Act, through Article 4 and Recital 29, identifies three dimensions that training needs to cover. Here they are in operational terms.

1. How AI works: capabilities and limitations

Nobody needs to become a data scientist. What matters is that people using AI understand what it can and can't do. That a language model doesn't "know" things; it generates statistically likely responses. That it can produce output that sounds convincing but is completely wrong (the so-called hallucinations). That the quality of the result depends on the quality of the input and the context.

A real-world example: a sales team using AI to generate proposals needs to know that the model can invent references, cite data that doesn't exist, or underestimate costs. Checking the output isn't optional: it's part of the process.

2. Rights and accountability: who's responsible when the output is wrong?

AI has no legal liability. Responsibility always sits with the company and the people using the output. If a commercial proposal contains incorrect data generated by AI, the client takes it up with the company, not the model.

Training needs to spell out the chain of accountability: who validates the output, who decides whether to use it, who answers for it if something goes wrong. Without that clarity, AI becomes a way of dodging responsibility for decisions.

3. Impact on people: bias and human oversight

AI models reflect the biases present in their training data. A CV-screening system can systematically penalise certain profiles. A customer service chatbot can treat requests differently depending on how they're phrased.

Training needs to build awareness of these risks and the principle of human oversight: AI supports decisions, it doesn't replace them. Especially decisions that affect people.

Why isn't a generic course enough?

The AI Act calls for training that is "adequate" to the context. The key word is "adequate".

When we work alongside companies that have already rolled out AI tools without any specific training, we see almost the same pattern every time: AI gets used like a faster search engine. People ask, the model answers, and nobody systematically checks the output. Not because people are careless — it's that nobody has ever set out when to trust the model and when to check it. That's not a technical problem: it's a training gap. And a generic course on "what is AI" doesn't close it, because it never touches the specific tools that team uses every day, in the specific processes where they use them.

A standardised online course on "what is artificial intelligence" can be a starting point, but on its own it doesn't meet the requirement, because it isn't tailored to how the company actually works.

Mandatory AI training needs to be tailored to context. The team using AI for commercial proposals needs to understand how the model handles pricing data. Customer service staff using a chatbot need to know when the bot can answer on its own and when it needs human intervention. Leadership needs to know how to evaluate the ROI of an AI project and what questions to ask vendors.

Standardised training produces generic competence. Generic competence produces slow adoption. Slow adoption produces mediocre results.

The approach that works is different: start from how AI is actually used in that specific company, identify the skills gaps by role, and build a training programme that closes those specific gaps.

What does it cost not to train your team on AI?

Flip the question. The right one isn't "how much does training cost?" but "how much does skipping it cost?"

According to the 2024 McKinsey report on the state of AI, most companies struggle to move AI projects from pilot to production. The pattern is always the same: a brilliant prototype, a convincing demo, then it stalls. The main reason isn't technical: it's organisational. Teams that don't understand the technology, managers who don't know how to govern it, leadership that doesn't know how to evaluate it.

Here's what happens when a company rolls out AI without adequate training:

  • The sales team generates proposals with AI without understanding how the model handles clients' confidential data. A proposal containing one client's confidential information ends up in a bid for a competitor. The reputational damage is incalculable
  • A manager approves a €200,000 AI project without the tools to assess the vendor, the technical feasibility, or the operational risks. The project stalls after six months with nothing to show for it. Budget burned
  • Customer service uses an AI chatbot that gives clients incorrect information. Nobody on the team can tell when the bot is "hallucinating". Complaints rise, customer satisfaction falls

Training isn't an extra cost: it's an investment that prevents far higher costs down the line.

What's the link between AI training and effective adoption?

AI training isn't a standalone obligation. It's the prerequisite for adopting AI with real results.

An organisation with a trained team:

  • Spots high-value processes more accurately: people who understand what AI can do identify where it can generate real impact, not just where it's most fashionable
  • Evaluates vendor proposals: a trained manager can tell a solid AI project apart from an impressive demo that will never make it to production
  • Governs with less risk: the chain of accountability is clear, controls are in place, bias is monitored
  • Adopts faster: competent teams overcome resistance to change and start using AI productively within weeks, not months

In other words: training isn't the end goal, it's the means. The end goal is an organisation capable of adopting AI where it genuinely matters, with measurable results and managed risk.

Treat training as a box-ticking exercise and you get slide decks and certificates. Treat it as an investment and you get an organisation that's ready.

Where to start: next steps for your company

You don't need a multi-year plan. You need three concrete steps.

1. Map who's already using AI tools

Before you train anyone, you need to know who to train and on what. In many companies, AI has already come in through the back door: teams using ChatGPT, Copilot or other tools without any company policy. The first step is a snapshot of where things stand: who's using what, for what, and with what data.

2. Define training levels by role

Not everyone needs the same training. Leadership, operational managers and front-line teams have different needs. Defining the levels means setting out what each group needs to know to operate competently and responsibly.

3. Link training to the AI adoption roadmap

Training isn't a one-off event: it's the first step in a longer journey. A trained team is ready to identify the processes where AI generates the most value, evaluate the solutions available, and govern the rollout. Linking training to the adoption roadmap turns a regulatory obligation into a strategic accelerator.

If you want to work out how to structure an AI training programme tailored to your company, or you're weighing up how to move from training to real adoption, let's talk.

Frequently asked questions

Does mandatory AI training apply to SMEs too?

Yes. Article 4 of Regulation (EU) 2024/1689 applies regardless of company size. The difference lies in how deep the required training needs to be, not in whether the obligation applies. Even an SME using ChatGPT to draft commercial proposals must ensure its staff have adequate skills.

By when do companies need to comply with the AI training obligation?

The obligation has been in force since 2 February 2025. Enforcement, with the possibility of penalties, applies from 2 August 2026. Companies that start early build real capability and an operational advantage; those that leave it to the last minute risk a rushed exercise that satisfies the letter of the law but not its spirit.

What are the penalties for failing to provide AI training?

Article 4 doesn't set out a specific penalty of its own, but a failure to train staff counts as an aggravating factor in AI Act infringements, with fines that can reach €35 million or 7% of global turnover. The bigger risk, though, isn't the fine: it's using AI without understanding it, which exposes the company to bad decisions and unprotected data.

Is an online course enough to meet the AI training obligation?

The Regulation calls for training that is "adequate" to the role and to the company's specific context. A generic online course can be a starting point, but on its own it doesn't meet the requirement unless it's tailored to the processes, the AI tools actually in use, and the risks specific to the sector.

Sources

  1. Regulation (EU) 2024/1689 (the AI Act): full text on EUR-Lex. Article 4 (the AI literacy obligation), Article 3, point 56 (definition of AI literacy), Recital 29 (grounds for the obligation)
  2. European Commission FAQ: AI Literacy Questions & Answers. AI Office, 2025
  3. Law No. 132 of 23 September 2025. Italy's law on artificial intelligence (Gazzetta Ufficiale)
  4. McKinsey Global Survey on AI, 2024. The state of AI: data on the adoption and scaling of AI projects
  5. Eurostat: Use of artificial intelligence in enterprises, 2025. AI adoption by country across the European Union

Want to organise AI training for your team?

Tell us about your business: together we'll design a training programme built around your processes and tools

We use your data to respond to your request. Read our Privacy Policy.