Your evidence-of-effort checklist for Article 4
4 June 2026 · 6 min read

Article 4 of the EU AI Act asks you to ensure a sufficient level of AI literacy among the people who use AI on your behalf. What it does not ask for is a certificate, a licence, or a specific accredited course. There is no official Article 4 stamp to collect. That sounds relaxing until you realise what it means in practice: the obligation is to make a reasonable, role-appropriate effort, and then to be able to show it. The practical standard, in other words, is evidence of effort.
This matters because a verbal "we talked about it in a team meeting" is not something you can hand to anyone. When a client, an insurer, a partner or eventually a supervisor asks how you meet Article 4, they are not looking for a feeling. They are looking for artefacts: things with dates, names, and version numbers that show a deliberate, proportionate effort rather than a vague intention. This article walks the four artefacts that turn "we tried" into "here, look". For each, you get what it is, what good looks like, and how to produce it quickly.
Article 4 applies from 2 February 2025. It applies regardless of your company size and regardless of which risk tier your tools sit in. A two-person studio using ChatGPT for copy has the same basic duty as a fifty-person agency running AI in hiring, even if the depth of effort differs. The duty is proportionate: it takes into account the technical knowledge and training of your people, the context in which the AI is used, and the people it is used on. A small deployer of minimal-risk tools does not need the same programme as a company touching high-risk uses under Annex III.
The catch is that proportionality is judged after the fact, and it is judged on what you can show. A calm, dated record of a modest but genuine effort is far stronger than an ambitious story with nothing behind it. Memory fades, staff leave, and "we definitely covered that" does not survive contact with a due-diligence questionnaire. Dated, ID-stamped evidence does. So the goal is not to over-engineer a compliance programme. It is to leave a trail.
The one rule that ties this together: date everything. Every artefact below should carry a clear date and, where people are involved, a name or an ID. An undated policy or an unsigned training note is close to worthless as evidence. A dated one is proof. When in doubt, add the date.
What it is. A simple list of every AI tool your business actually uses, each one tagged with its risk tier under the Act. It is the foundation for everything else, because you cannot train people on, or write policy for, tools you have not named.
What good looks like. A short table or document that captures, for each tool: its name, what you use it for, who uses it, and its risk classification. The four tiers to sort into are unacceptable or prohibited under Article 5 (banned uses such as social scoring or emotion recognition in the workplace), high-risk under Annex III (for example AI in hiring, worker evaluation, or access to essential services), limited or transparency risk under Article 50 (chatbots and AI-generated content that must be disclosed), and minimal risk (most everyday tools, which carry no specific obligations beyond good practice and the literacy duty). Good inventories are honest about shadow AI, the tools people use without asking, and they carry a "last reviewed" date.
How to produce it fast. Ask each team what AI tools they touch in a normal week, including the ones baked into software they already pay for. List them. For each, ask one question: does this touch hiring, workers, essential services, or anything on the prohibited list? If yes, flag it for a closer look. If no, it is very likely minimal or limited risk. Put a date on it and set a reminder to review it every few months.
What it is. Evidence that the specific people using AI have received training appropriate to how they use it. Article 4 is explicit that literacy is role-dependent, so this is not one generic slide deck for everyone. A developer wiring an AI feature into a product needs more than a marketer drafting captions.
What good looks like. Training that is matched to roles, and a record showing who completed what and when. The record is the load-bearing part. A dated certificate or completion log with the person's name turns "our team is trained" into "these named people completed this training on these dates". Good training covers what the tool does, where it fails, when a human must check the output, and what people must never put into it. It is refreshed as tools and roles change, not treated as a one-time event.
How to produce it fast. Group your people by how they use AI, perhaps into everyday users, heavy or specialist users, and anyone touching high-risk uses. Run a short, honest session for each group rather than a marathon for all. Capture attendance with dates and names, and issue a simple completion record. The content does not have to be elaborate to count; it has to be relevant to the role and documented.
What it is. A written statement of how your business uses AI and what the rules are. It is the document that shows your effort is a standing practice rather than a one-off conversation, and it gives your team something to point to when they are unsure.
What good looks like. A short, readable policy that a non-lawyer can follow. It should say which tools are approved, what data must never be entered into them, where human review is required, how the transparency duties under Article 50 are met (for example telling people when they are dealing with a chatbot or labelling AI-generated content), and who to ask when something is unclear. It names an owner and carries a version number and a date. A policy nobody can find or understand is not much of a policy, so it lives somewhere your team actually looks.
How to produce it fast. Start from your tool inventory, since it already tells you what you are governing. Write plainly. Two pages that people read beat twenty that they ignore. Cover the approved tools, the hard "never do this" rules, the review points, and the transparency commitments. Date it, version it, and circulate it so there is a record that people received it.
What it is. The bundle. It gathers the inventory, the training records, and the policy into one dated package that you can hand, as a coherent whole, to a client, an insurer, a partner, or a supervisor. It is the artefact that answers the question "show me" in a single move.
What good looks like. A single, dated record that pulls the other three together and tells a short story: here is what we use, here is how our people are trained, here are our rules, and here is when we last reviewed all of it. It is current, internally consistent, and presentable to an outsider without a scramble. The best version is one you can produce on the day it is asked for, not one you have to assemble under pressure.
How to produce it fast. Keep the three earlier artefacts in one place and add a short cover summary with an overall date. Review the whole bundle on a regular cadence, quarterly is a sensible default for a small team, and update the date each time. This is exactly the kind of ongoing, low-effort record-keeping that Klaar is built to hold together, so that the bundle is always one click from being handed over rather than a project you dread.
It is worth being clear-eyed about who comes knocking, because it is rarely a regulator first. In practice the order tends to be: clients running due diligence before they sign, who increasingly include AI questions in their vendor checks; insurers pricing or renewing cover; partners you integrate with who need to know your side is sound; and, further down the line, supervisors. Enforcement is national. In the Netherlands the Autoriteit Persoonsgegevens has taken a coordinating role for algorithm and AI supervision alongside the RDI, and in Germany the Bundesnetzagentur is widely expected to take a central role, with data protection authorities involved. The date most small businesses hear about is 2 August 2026, but it is worth being precise about what it brings: that is when the transparency duties under Article 50 apply, for example telling people they are dealing with a chatbot and labelling AI-generated content. The heavier high-risk obligations under Annex III do not land then. The 2026 Digital Omnibus moved those from 2 August 2026 to 2 December 2027, for both deployers and providers, so there is more runway than the old headline date suggested. The point is not to panic about supervisors. It is that the same evidence satisfies all four audiences, so you build it once.
Here is the checklist. If you can tick these, your Article 4 effort is provable.
None of this is heavy. It is a list, a few short training sessions, a two-page policy, and the discipline to keep them dated and together. That modest bundle is the difference between "we talked about it" and evidence you can put on the table. Article 4 does not ask for a certificate. It asks you to make the effort and be ready to show it, and the four artefacts above are how you show it.
Klaar walks you through inventory, training, policy and the dated evidence.