Something happened in July that let half of Italian industry breathe out. Regulation (EU) 2026/1744 — the one everyone calls the Digital Omnibus — pushed back the most feared deadlines in the AI Act: obligations for standalone high-risk systems now start on 2 December 2027, and those for systems embedded in products on 2 August 2028.
The message that reached companies was a single one, and it was wrong: there is time.
Not for everything. One obligation was not postponed. It has applied since 2 February 2025, it covers just about anyone who uses artificial intelligence at work, and since August of this year somebody is watching it. It is Article 4, AI literacy.
And there is a second thing that the training market has no interest in telling you right now: you do not need a certificate to comply with it.
What actually changed on 27 July
The Digital Omnibus did not repeal Article 4. It rewrote it, and the rewrite is more interesting than the postponement.
The new wording asks providers and deployers to adopt effective and proportionate measures, calibrated on people's tasks, on their technical knowledge, and on the context in which the systems are used. It has applied since 27 July 2026.
Translated: the obligation becomes more explicitly bespoke. There is no package that fits everyone — which cuts the ground from under both the companies doing nothing and the ones buying a generic two-hour course for the whole workforce and filing the PDF.
Since August somebody is watching, and in Italy it has a name
Until recently Article 4 was an obligation without a supervisor: the rule existed, nobody enforced it. That is over.
The European Commission, in its official questions and answers on AI literacy, states that the supervision and enforcement rules apply from 3 August 2026, and that enforcement sits with national market surveillance authorities — not with the European AI Office. The same answers make clear that those authorities could impose penalties and other enforcement measures for infringements of Article 4, following a proportionate approach that weighs the nature and gravity of the infringement and whether it was intentional or negligent.
In Italy those authorities have a precise name, set by law 132/2025. Article 20 designates the National Cybersecurity Agency (ACN) as the market surveillance authority, with competence over inspections and penalties, and AgID as the notifying authority. For financial matters, the Bank of Italy, CONSOB and IVASS remain competent.
This is not an imminent threat: nobody expects blanket inspections of small manufacturers in September. But the difference between "an obligation with no enforcer" and "an obligation with an agency that can inspect and fine" is the difference between a theoretical risk and a real one.
It covers you too, almost certainly
This is where most companies get it wrong, because Article 4 does not speak only to the people who build artificial intelligence.
It binds providers and deployers of AI systems. A deployer is anyone using an AI system in the course of their professional activity. If someone in your company uses a conversational assistant to write emails to customers, a tool that summarises documents, a copilot inside the office suite, or a system that does a first pass over CVs, you are a deployer.
One detail that almost always gets missed: the Commission specifies that the obligation covers people dealing with the operation and use of the systems on behalf of the provider or deployer. So not only employees: contractors, consultants and service providers using those systems for you are in scope as well.
If you have outsourced customer care and the people answering use an AI assistant on your data, that responsibility did not leave the company along with the service.
The part nobody will tell you: no certificate
This is the paragraph worth reading twice, because right now you are receiving a lot of proposals that say the opposite.
The European Commission, again in its official answers, is explicit on two points. First: there is no need for a certificate, and organisations can simply keep an internal record of trainings and other initiatives taken. Second: there is no one-size-fits-all when it comes to AI literacy, and no strict requirements or mandatory trainings are imposed — it depends on the organisation's context and level of risk.
Anyone selling you a certificate of compliance with Article 4 is selling you an object the rule does not ask for. The course may well be excellent and worth its price for what it teaches — but do not buy it for the piece of paper, because the piece of paper is not what is being asked of you.
What is being asked is that the people using these systems know what they are using: what it can do, where it fails, what data may and may not go into it, and when a machine's answer has to be checked by a person before it becomes a decision.
What I would keep in an internal record
If compliance is demonstrated through an internal record, it is worth knowing what to put in it. This is the minimum I would keep, and it holds for a company of fifteen people:
- the list of AI systems actually in use, including the ones nobody ever formalised — a personal subscription used for work counts, and it is usually the most exposed item on the list;
- who uses them and what for, split by role: who generates text, who analyses data, who uses them in a process that touches people (recruitment, assessment, credit);
- what was done for each group: an internal session, an external course, a written operating note, side-by-side coaching. With dates and attendees;
- the usage rules, in writing: which data never leaves the company, what never goes into a prompt, which decisions are never taken without a person checking;
- what happens when something goes wrong: who gets told if a system produces an error that reaches a customer;
- when it gets reviewed: people change, tools change faster. An annual review is already something.
It is one page of document, not a project. And it has a benefit beyond compliance: for most companies it is the first time they find out how many AI tools they are actually running.
If you do decide to train properly, who pays
The record covers the obligation. But for some roles serious training genuinely helps — and at that point it is worth knowing you are probably already paying for it.
In Italy every company with employees pays a contribution to the social security institute equal to 0.30% of wages, under law 388/2000. That contribution can be directed to a joint interprofessional training fund by signing up, at no additional cost: it is not an incentive to apply for, it is a choice about where money that leaves your payroll anyway ends up. If you join no fund, that share stays with the social security institute and you pay for training separately.
The funds work through two channels, which carry different names from fund to fund but share the same logic:
- a company account, fed by what your business has accrued over time, usable with more freedom and generally whenever you want;
- calls for proposals, periodic tenders distributing collective resources to assessed projects, often through pooled formats designed for small businesses.
The first channel is faster and depends on how much you have accumulated; the second can fund larger projects but follows deadlines and rankings.
What a training provider will ask you
If you call a training body, this is the profile they will ask for in order to work out which channels are open to you. Having it ready saves a fortnight of back-and-forth:
- the region the company is based in, because several calls are regional;
- which fund you belong to and, where the fund distinguishes them, which channel you can count on — company account or calls;
- the last call you took part in, which often conditions access to the next one;
- the type of courses you are interested in;
- the number of people to be involved.
One warning worth putting in writing: fund-financed training comes with its own constraints — attendance registers, minimum hours, reporting — which do not line up with what Article 4 asks. They are two separate tracks. The fund tells you how to pay for the course; the AI Act tells you what people need to know. A funded course that never touches the tools you actually use satisfies the first and not the second.
The mistake we are about to watch a lot of people make
The likeliest script for the coming months is this: a generic two-hour course on "what artificial intelligence is", identical for the warehouse and for the finance team, a certificate for everyone, folder filed, obligation considered closed.
It does not hold, for two reasons. The first is formal: the new wording asks for measures proportionate to tasks and context of use, and identical content for different roles is the definition of a measure that is not proportionate. The second is substantive, and matters more: that course does not reduce the risk companies are actually running, which is not the fine. It is the quote pasted into a public chatbot, the customer list dropped into a prompt, the assistant's wrong answer sent on to a client with nobody rereading it.
Useful training starts there: from the tools your people already have open on their desktop, and from the three or four things that must never be done with them.
A note on sources
The postponed deadlines and the rewording of Article 4 come from Regulation (EU) 2026/1744, in force since 27 July 2026, as reconstructed from consistent specialist legal sources.
The statements on certificates not being required, on the absence of mandatory courses, on who falls in scope, and on the supervision and enforcement dates come from the European Commission's official questions and answers on AI literacy.
The designation of ACN as market surveillance authority and AgID as notifying authority comes from Article 20 of Italian law no. 132 of 23 September 2025.
The 0.30% contribution and the interprofessional funds mechanism sit under Italian law 388/2000. Channel names and access conditions vary by fund: check them against the rules of the fund you belong to.
This article describes a picture current as at August 2026 and does not constitute legal advice. Assessing a specific organisation's compliance is a job for a qualified professional.