Finland switched on AI Act supervision in January
A lot of EU countries spent 2025 arguing about who should police the AI Act. Finland put its answer on the statute book. The Act on the Supervision of Certain Artificial Intelligence Systems (1377/2025) was approved by the President on 22 December 2025 and took effect on 1 January 2026. That was late against the government's own plan (Government Proposal 46/2025 had aimed for 2 August 2025), and still well ahead of Norway, which is only now heading back to consultation.
The model is decentralised. Supervision is spread across 15 authorities: nine market surveillance authorities and eight fundamental-rights supervisors, with some, like the Data Protection Ombudsman, wearing both hats. Traficom, the transport and communications agency, is the single point of contact and does the coordinating. Fines, though, are centralised. The government's bill would have let each authority impose fines of up to €100,000 itself, but Parliament's Constitutional Law Committee worried about uneven practice. So the final Act sends every fine, whatever the amount, to a new Sanctions Board that sits alongside Traficom and acts on the supervising authority's proposal.
Why should a training buyer care about the plumbing? Because it hints at who might one day ask about your AI literacy records. Probably not one central AI regulator reading training logs. More likely a supervisor that already knows your sector: the Act puts high-risk recruitment tools under the Data Protection Ombudsman and life and health insurance pricing under FIN-FSA. And the tone so far is advisory. When the Article 50 transparency duties started applying on 2 August 2026, Traficom published guidance and said its first aim is to guide, advise and let companies put things right. As of mid-August, no AI Act fines or formal investigations had been reported in Finland.
There's plenty to supervise, though. Eurostat's 2025 survey found 37.8% of Finnish enterprises with ten or more staff using AI, close to double the EU figure of 20.0%.
Related reading: Continuous Learning Funding in Finland 2026: JOTPA After the Allowance Cut · Norway Public Sector AI Training in 2026: A Vendor's Guide to the Money · How to Choose an EdTech Vendor for Nordic Enterprise Upskilling in 2026
What the Omnibus did to Article 4
Then Brussels moved the goalposts, mostly in the buyer's favour. Regulation (EU) 2026/1744, the Digital Omnibus on AI, cleared the European Parliament on 16 June and the Council on 29 June, was published in the Official Journal on 24 July and entered into force on 27 July 2026. Most coverage went to the delayed high-risk dates: Annex III systems now apply from 2 December 2027, and Annex I systems (AI built into already-regulated products) from 2 August 2028. The Article 4 rewrite got less airtime. For anyone who sells or buys training, it's the bigger story.
The original text, applicable since 2 February 2025, told providers and deployers to take measures to "ensure, to their best extent, a sufficient level of AI literacy". The new text asks them to "take measures to support the development of AI literacy" among staff and other people who operate and use the systems. Then it adds the sentence lawyers will be quoting for years: the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual".
| Element | Article 4 from February 2025 | Article 4 after Regulation (EU) 2026/1744 |
|---|---|---|
| Core wording | Ensure, to their best extent, a sufficient level of AI literacy | Take measures to support the development of AI literacy |
| Type of duty | Obligation of result | Obligation of means |
| Guarantee for each individual | Arguably implied by 'sufficient level' | Expressly not required |
| Role of the Commission and Member States | Not mentioned in the article | Support providers and deployers, with particular regard to SMEs |
| Reference points | None named | AI Board recommendations setting common objectives, taking European competence frameworks into account |
| Dedicated fine in the AI Act | None | None |
Lawyers call it a move from an obligation of result to an obligation of means. In plain terms, you're now judged on what you did, not on what your people know.
Effort, not outcome: what 'support the development' means in practice
Here's our opinion, stated plainly. The Omnibus did Finnish training buyers a favour. It ended the certify-everyone-by-Friday panic market that ran through 2025, when a lot of generic AI literacy content was sold on fear of a legal standard nobody could define. If your AI literacy programme only exists because of Article 4, retire it at renewal. The programmes worth keeping are the ones tied to how specific roles use specific systems.
Article 4 hasn't gone away. You still have to take measures, and a regulator can still ask what they were. The Commission's AI literacy Q&A, updated after the Omnibus, promises continuity, so its original checklist is still the best guide to what a proportionate measure covers:
- a general understanding of AI inside the organisation
- clarity on whether you're the provider or the deployer of each system
- a view of the risks of the systems you actually run
- actions matched to your staff's knowledge, experience and working context
The same Q&A is blunt about paperwork. There's no need for a certificate, and an internal record of training and other initiatives will do. That line alone should change how you procure. Certificates were always a vendor's product feature, never a legal requirement.
Two things haven't changed. First, enforcement. The AI Act never attached a dedicated fine to Article 4 and still doesn't, and Finland's Act leaves Article 4 off its list of breaches that can draw a sanction fee. Still, the Commission's Q&A notes that national authorities could sanction infringements, case by case and proportionately. Second, the high-risk track. Article 26(2) still requires deployers of high-risk systems to assign human oversight to people with "the necessary competence, training and authority", and the Commission's updated guidance says that duty stands. Annex III (recruitment screening, credit scoring, life and health insurance pricing, among others) applies from 2 December 2027. About fourteen months.
That's where the durable training budget sits. Not in teaching 4,000 people what a language model is, but in making sure the 40 who approve or override an AI-assisted pricing decision know when they should.
Is a 60-minute course still enough?
For most of your staff, probably yes, as long as it's paired with a record and a usage policy. MinnaLearn, which built Elements of AI with the University of Helsinki, now offers Get AI Ready, a 60-minute AI literacy programme mapped to the EU AI Act, both as an individual certification and as an organisational programme. Under the old wording you could argue about whether an hour gets anyone to a sufficient level. Under the new wording most of that argument disappears, because nobody has to prove a level.
What an hour can't do is the specifics. A claims handler with a fraud-scoring tool, a recruiter reading rankings from a screening model, a developer shipping a chatbot: each needs something different, and a generic module speaks to none of them. So the sensible structure is a thin, cheap baseline for everyone and a thicker, system-specific layer for roles that touch consequential outputs.
If you sell training, the pitch changes more than the product. The compliance-fear angle is gone. What's left to sell is evidence (buyers still need a clean record) and relevance (nobody will pay for a second generic hour). Vendors who can take a client's system inventory and build role paths from it will win the renewals. Vendors selling seats on a universal course are up against a free Finnish one that two million people have already signed up for.
EdTech vendors and universities have one more thing to check. Education and vocational training is itself an Annex III area, so if your platform decides admission, evaluates learning outcomes or monitors students during tests, you may be a high-risk provider from December 2027. Expect it in procurement questionnaires well before then.