EU AI Act — Article 4 is enforceable as of 2 August 2026

Your buyer now has to prove their people are capable. So do you.

If you sell into the EU, the AI Act reaches you through your customer's procurement process. They must evidence a sufficient level of AI literacy across everyone operating AI on their behalf — and that phrase includes your people, on their contracts.

Cognistry captures the operating context, builds the capability, and produces the evidence. Not a completion certificate. A record that survives review.

A compliance lead describes an AI Act procurement demand and Cognistry Signal ingests the regulation and the company's own operating evidence, identifies which roles are exposed, and seals a dated evidence snapshot.

Evidence, not attendance
Traceable to source
Calibrated per role
Survives procurement review

The clock that actually matters

The compliance deadline moved. The capability deadline did not.

2 Aug 2026

Article 4 AI literacy — enforceable now

2 Dec 2027

Article 26(2) oversight competence required

€15M / 3%

Article 99 exposure tier for deployer breaches

How Cognistry works

Ten steps from “we cannot answer this” to a record your customer accepts.

No theory. This is the actual sequence — capture, build, practise, evidence — and what you are looking at in the product at each stage.

A procurement questionnaire where every security question is answered and the AI literacy question is blank

01 — The question you cannot currently answer

You have the security answers. You have the data-protection answers. Then comes a question about the AI literacy of the people delivering the contract, and there is nothing to put in the box.

This is how the AI Act reaches companies that are not based in the EU. Not through a regulator. Through your customer. They carry the Article 4 obligation, that obligation covers “other persons dealing with the operation and use of AI systems on their behalf,” and on their contracts that is your team.

A generic AI-awareness certificate does not close this. The Act asks for a sufficient level — calibrated to the person and the context. A certificate evidences neither.

Documents, procedures and expert interviews converging into a structured skill demand register

02 — Signal starts from your operations, not a template

Article 4 requires literacy calibrated to “the context the AI systems are to be used in.” A bought-in course cannot satisfy that, because it does not know your context.

Signal ingests what you already have — standard operating procedures, incident and escalation logs, expert frameworks, decision scenarios, SME interviews — and derives which capabilities your people actually need to demonstrate.

The output is a Skill Demand Register: a defensible statement of what good judgment looks like in your operation, sourced from evidence rather than assumed from a syllabus.

A sealed, dated Signal Snapshot with an unbroken trace back to the source evidence

03 — The evidence gets sealed, dated and made traceable

Two years from now, someone will ask why you trained these people on these things. “It seemed sensible” is not an answer that survives a review.

Signal seals its findings into an immutable, dated Snapshot. Every capability requirement traces back to the specific document, interview or incident that produced it — so the reasoning is inspectable long after the people who did the reasoning have moved on.

This is the difference between having done training and being able to show why that training was the right training.

04 — Inside Forge: the programme gets architected, not assembled

This is the actual authoring surface. You describe the gap in plain language; Forge argues back about what would genuinely close it.

It does not start writing slides. It establishes the capability, the audience, the evidence that would prove it, and the real constraint — then structures the programme against that.

What you are watching: a compliance lead and Cognistry agreeing what an Article 4 programme has to contain before a single word of content exists.

A compliance lead and Cognistry Forge agree the capability an Article 4 programme must build, structure it into role-specific moments, and specify what gets built for the highest-exposure tier.

One capability requirement splitting into four role-specific programmes of different depth

05 — One programme, four depths — because the Act says so

Read the operative wording: literacy sufficient “taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.”

That is a specification for differentiation. An organisation that puts 900 people through one identical module has not read it — and has produced a record that reads, to a reviewer, as exactly what it is.

Forge builds the tiers separately. The person who can override an AI output goes deep. The person who supplies inputs to it does not. Both are covered, and the difference is on the record with the reasoning attached.

A capability architecture from programme down to individual decision moments

06 — Structured down to the individual decision

Programme → module → section → interaction → decision practice. Every branch of the structure terminates in a moment where a person has to decide something.

That matters for evidence. A module you can only report on at programme level tells a reviewer that someone finished it. A structure that resolves to individual decisions lets you say which judgments were practised, by whom, and how they went.

It also makes the programme maintainable. When the regulation shifts — and it has already shifted once via the Omnibus — you amend the affected moments rather than rebuilding the course.

Cognistry Sim runs a decision simulation in which the AI recommendation is confidently wrong, scores whether each person overrode it, and reports which cohorts deferred.

07 — Inside Sim: the competence nobody else can train

Article 14(4)(b) requires overseers who “remain aware of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias).”

You cannot train that by explaining it. Telling people about automation bias does not stop them deferring — that is precisely why the regulation names it.

The only thing that works is putting a person in front of a confident, plausible, wrong recommendation while the clock runs, and letting them find out what they do.

What you are watching: the measurement running, the baseline coming back uncomfortable, and the re-test proving the programme worked.

A confident AI recommendation that is wrong, and a person choosing to override it rather than defer

08 — Overriding a machine is a skill. It has to be rehearsed.

Article 14(4)(d) requires that an overseer be able to “decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output.”

Think about what that asks of a person. Contradicting a system that is right most of the time, in front of colleagues, under time pressure, with no certainty they are correct. Someone who has never done it once has not demonstrated they can.

A simulation is the only place they can practise it before it counts — and the only place you can capture proof that they did.

09 — Inside the evidence layer: what procurement actually receives

Most training platforms can export a completion report. A completion report answers a question nobody asked.

Cognistry exports the chain: the regulation, the operating evidence behind your scope decision, the calibration reasoning per tier, the decisions people practised, and how they performed.

What you are watching: the pack being assembled, the gap being caught before the customer catches it, and the export going out.

Cognistry assembles the customer-facing evidence pack, flags a contractor cohort with no evidence before the customer finds it, and exports the completed pack.

A completed evidence pack of capability records being handed to a procurement reviewer and accepted

10 — Build it once. Answer every EU buyer with it.

The work in steps 1 to 9 is not per-deal work. It is a capability system you build once and maintain.

The next EU customer sends their annex and the answer already exists — current, sourced, and specific to how your people actually operate. The deal stops stalling in review.

Companies treating this as a form-filling exercise will do it again for every customer, badly, forever. The ones that build the capability once turn a procurement blocker into something closer to a reason to pick them.

Every sector selling into the EU

The obligation does not care what you make.

Article 4 attaches to anyone providing or deploying AI systems — with no sector carve-out and no risk threshold. What changes by industry is which judgment your people have to demonstrate.

Manufacturing & industrial

Operators overriding AI-driven quality and maintenance calls

The system flags a batch as within tolerance. The operator has seen this pattern fail before. Who wins, and can you show they were trained for it?

Financial services

Analysts acting on model output in regulated decisions

Model risk governance already demanded challenge. Article 4 now demands evidence that the challengers are capable of challenging.

Healthcare & life sciences

Clinicians and reviewers interpreting AI-assisted findings

Automation bias in diagnostic support is the most-studied failure mode there is. It is also the one Article 14(4)(b) names explicitly.

Technology & SaaS

Teams shipping AI features into EU customers

Your customers inherit obligations from your product. Their procurement pushes it straight back to you, in writing.

Professional services

Consultants using AI on client work

You are the textbook case of 'persons dealing with the operation and use of AI systems on their behalf.' Your client's obligation is your problem.

Logistics & supply chain

Planners overriding AI routing and allocation

Optimisation output looks authoritative. Local knowledge that contradicts it needs practised confidence to be voiced.

Energy & utilities

Control-room judgment alongside AI monitoring

Safety-critical operations where deferring to a confident system has consequences that do not stay inside the organisation.

Public sector suppliers

Contractors delivering into EU public bodies

Public-authority deployers face a hard 2 August 2030 compliance date under Article 111(2) — and they will pass the requirement down the chain.

The four things people say before they start

“We are not in the EU.”
Neither is the obligation, directly. But your EU customer holds it, it explicitly covers people acting on their behalf, and their procurement team will ask you in writing. The AI Act reaches exporters through contracts, not through regulators.

“The deadline moved to 2027.”
The high-risk rules moved. Article 4 did not — it has been binding since February 2025 and became enforceable on 2 August 2026. The one obligation that got harder this year is the one about your people.

“We already ran AI training.”
Then you can evidence attendance. Article 4 asks for a sufficient level, calibrated to each person's experience and context. A completion record does not evidence a level of anything, and a reviewer knows it.

“We will handle it with policy.”
Policy tells people what to do. Article 14(4) requires that they be able to — interpret output, recognise their own automation bias, override a confident system under pressure. No document has ever produced that.

What we do not do

The AI Act's obligations about training data, model documentation, conformity assessment and general-purpose AI models — Articles 10, 15, 53 and 55, and Annexes IV and XI — belong to whoever builds the model. We have no role in any of them, and we will not pretend otherwise.

Cognistry addresses the half of the Act that is about your people: Article 4 literacy, Article 26(2) oversight competence, and the Article 14(4) capabilities an overseer has to actually possess. Even there, Article 26(2) asks for competence, training, authority and support — and the last two are organisational design, not a learning problem. We will tell you that in the first meeting.

No product makes you AI Act compliant. Ours makes the people half evidenceable.

Article 4 exposure assessment

Find out what you would have to send if they asked tomorrow

A working session against your actual operations. We map which roles are in scope, what evidence you already hold, and where the gaps are that a procurement reviewer would find.

You leave with the exposure map whether or not you buy anything.