The deadline you already missed, and the one that just landed
Two dates matter here, and most compliance teams in Warsaw, Budapest and Sofia have only one of them written down. Article 4 of the EU AI Act, the AI literacy obligation, has applied since 2 February 2025. It has been binding law for a year and a half. What changed on 3 August 2026 is that the enforcement architecture came into force: national market surveillance authorities with real powers, and a penalty framework sitting behind them.
If your working assumption has been that AI literacy is a 2027 problem, that assumption expired this month.
Here is the part people find irritating. Article 4 carries no headline fine of its own. The large numbers in the Act (up to 35 million euros or 7% of global turnover for prohibited practices, up to 15 million or 3% for most other breaches) attach to other articles. Article 4 gets enforced through supervisory attention, through what you can document when a regulator opens a file on something adjacent, and through your customers' procurement questionnaires. That third channel is the one that will cost you revenue this financial year, and it is already happening: if you sell software or services into a German or Dutch enterprise from a Polish or Bulgarian delivery centre, the AI literacy question is now in the vendor security review.
Related reading: Poland's Capability Centres in 2026: Hiring After the GBS Growth Slowdown · Bulgaria IT Outsourcing in 2026: A Buyer's Guide to Sofia's Software Sector · Budapest as Hungary's AI R&D Hub in 2026 · CEE Corporate Training and AI Upskilling in 2026.
What Article 4 actually asks for
Stripped of legal phrasing, the obligation is this. If your organisation provides or deploys AI systems, you have to take measures to give the people operating those systems on your behalf a sufficient level of AI literacy, calibrated to their technical background, their role, and the context in which the system is used. That is the whole requirement.
Notice what is absent. No prescribed curriculum. No certification body. No mandatory exam, no minimum hours, no approved provider list. Regulators left the definition of "sufficient" to you.
Every compliance lead I have spoken to in the region reads this as good news for about a week, then realises it is the harder version. A prescribed curriculum would let you buy a course, tick a box, and file the certificate. Instead you have to decide what sufficient means for your workforce, in writing, and defend that reasoning later. The obligation is not really "train your people". It is "have a defensible position on what your people need to know, and evidence you acted on it".
Your org chart is wrong about who the deployer is
Most CEE organisations start this exercise by listing their data scientists. That list is almost never the risk.
A deployer, under the Act, is any organisation using an AI system under its own authority in a professional context. That covers the recruiter running CV screening through a vendor tool. The credit team using a scoring model. The customer support manager who put a large language model in front of tier-one tickets. The marketing coordinator who uses an image generator on client work. None of them think of themselves as operating an AI system, and every one of them is inside scope.
A compliance lead at a Kraków shared-services centre described their first gap analysis to me. The data science team scored fine, no surprises. The failure was in accounts payable, where somebody had wired an invoice-extraction model into the approvals workflow eleven months earlier, through a low-code platform, with no review, no documentation, and no idea that the tool was in scope for anything. It had processed roughly 40,000 invoices by the time anyone looked at it.
That is the shape of the typical CEE finding. The exposure sits in operations, not in the AI team.
Three tiers, and what evidence each one produces
The structure that survives contact with a regulator is tiered by role rather than uniform across headcount. Here is a workable model, with rough delivery time and the artefact each tier should leave behind.
| Tier | Who | Content | Time | Evidence produced |
|---|---|---|---|---|
| Baseline | All staff, including non-technical functions | What AI systems are, what your internal policy permits, how to escalate, what data must never go into a public tool | 60 to 90 minutes | Completion log with dates, policy acknowledgement |
| Operator | Anyone whose workflow includes an AI output: recruiters, credit, support, procurement, marketing | Limits of the specific tools in use, failure modes, bias in the relevant domain, when human review is mandatory, record-keeping | 4 to 8 hours, tool-specific | Role mapping, per-tool sign-off, escalation logs |
| Builder and owner | Engineers, data scientists, product owners, procurement leads signing AI contracts | Risk classification, Annex III triggers, documentation duties, human oversight design, vendor due diligence | 2 to 4 days, refreshed annually | Risk register entries, oversight design docs, vendor assessments |
The middle tier is where organisations underinvest and where the actual exposure lives. Baseline training is cheap and everybody does it. Builder training is expensive and the engineers usually want it. Operator training requires knowing which tools are deployed in which workflow, which means somebody has to do a real inventory first, and inventories are unglamorous work that nobody volunteers for.