Short answer: if your organisation uses artificial intelligence, you are obliged to ensure that the staff using those tools have enough competence to use them responsibly. That includes ChatGPT, Copilot and the AI features already sitting inside Microsoft 365. The requirement comes from Article 4 of the EU AI Act, it applies regardless of sector or organisation size, and since 2 August 2026 supervisory authorities have had formal power to enforce it.

What changed on 2 August 2026

Article 4 is not new. The provision has applied in the EU since 2 February 2025, alongside the regulation's opening chapters. What changed on 2 August 2026 is that national supervisory authorities gained formal enforcement powers.

The difference matters in practice. Until this summer the requirement existed without machinery to follow it up. Now the machinery exists.

What Article 4 requires

The provision obliges both providers and organisations deploying AI systems to ensure a sufficient level of AI literacy among staff and others handling the systems on their behalf.

It is short, but broad. It does not distinguish by risk level, by sector or by organisation size. Where the rest of the regulation targets those who develop or deploy high-risk systems, Article 4 in practice reaches everyone who uses AI at work. Including the small council with twelve employees.

Who it applies to

If anyone in the organisation uses an AI tool for work, you are covered. That includes a good deal that does not feel like an "AI system":

  • Staff using ChatGPT, Claude, Copilot or Gemini for text, summarising or research
  • AI features built into tools you already pay for: Microsoft 365, Google Workspace, Teams meeting notes, CRM systems
  • Automated sorting, prioritisation or recommendation in casework
  • AI-based recruitment or screening tools

That last point deserves its own warning: AI in recruitment is classified as high risk under the regulation, and triggers considerably stricter requirements than competence alone. If you use such tools, Article 4 is the least of your concerns.

Status in Norway

The AI Act is EEA-relevant, but has not yet been formally incorporated into the EEA Agreement. Implementation in Norwegian law has been expected during 2026.

Two things make waiting a poor strategy. Norwegian organisations with activity in the EU are already directly covered, regardless of Norwegian implementation. And the Norwegian Data Protection Authority (Datatilsynet) has advised organisations to prepare now rather than wait for formal incorporation.

Competence is not something you acquire in an afternoon when the regulator calls. It is documentation that has to be built over time.

What "sufficient competence" means in practice

The regulation does not set a fixed level or number of hours, and that is deliberate. The requirement is contextual: competence must be proportionate to the systems you use, who uses them, and what the consequences of misuse could be.

In practice, staff should understand four things:

  • What the tool actually does. That a language model generates probable text patterns, not verified facts.
  • Where the limits are. What should never be pasted into an AI tool: personal data, confidential information, sensitive case details.
  • How errors arise. Hallucinations, bias in training data, and why an answer can be confidently phrased and still wrong.
  • When a human has to step in. Which judgements should never be made by AI alone.

A council caseworker handling information about individuals needs a different level from a communications adviser using AI to draft copy. That is precisely why the requirement is framed contextually rather than as a syllabus.

What doing nothing costs

Article 4 sits at a mid-level in the regulation's penalty regime, not in the top tier reserved for prohibited forms of AI use.

But the level of fines is probably not the most relevant risk for a Norwegian council or a mid-sized organisation. Two other things matter more in practice:

  1. Missing competence is an aggravating factor. If an AI system causes harm and it turns out staff never received training, the primary breach is judged more harshly.
  2. Procurement asks for it. Public buyers have begun requesting documentation of AI competence and internal policies in tender documents. Missing documentation becomes a commercial problem before it becomes a regulatory one.

How to document compliance

The requirement is about actually ensuring competence, not merely having offered a course once. Four things should be available to show:

  1. An inventory of AI systems in use. Most organisations badly underestimate this. Start with a survey, and expect to find tools nobody declared.
  2. An internal policy for AI use. What is permitted, what is not, who approves new tools.
  3. An attendance record from completed training. Date, content, who took part.
  4. A routine for new staff. The requirement applies continuously, not only to those present when the course was held.

Three steps you can take this month

If you have not started, this order gives the most effect fastest:

  1. Survey. Ask departments which AI tools are actually in use. This takes a week and gives you the basis for everything else.
  2. Write a provisional ground rule. One page. It can be improved later. The point is that it exists and has been communicated.
  3. Run shared foundational training. Half a day that gives everyone the same understanding of what the tools are and where the limits sit.

This is not a compliance project that has to take six months. It is a foundation that needs to be in place, and then maintained.

Frequently asked questions

Does the EU AI Act apply in Norway?

The AI Act is EEA-relevant and is expected to be incorporated into Norwegian law. Norwegian organisations with activity in the EU are already directly covered regardless of Norwegian implementation, and the Norwegian Data Protection Authority (Datatilsynet) has advised organisations to prepare now rather than wait.

Does it count as AI use if we only use ChatGPT?

Yes. Article 4 applies to everyone deploying AI systems, and generative tools such as ChatGPT, Copilot, Claude and Gemini are covered. The same goes for AI features built into tools you already use, such as Microsoft 365 or Google Workspace.

How much training is enough?

The regulation sets no fixed number of hours. The requirement is contextual: competence must be proportionate to the systems you use, who uses them, and what the consequences of misuse could be. A caseworker handling personal data needs more than someone using AI to draft text.

What are the penalties for breaching Article 4?

Article 4 sits at a mid-level in the regulation's penalty regime. Just as important in practice is that a lack of AI competence can be an aggravating factor in breaches of other provisions: if an AI system causes harm and staff had received no training, the primary breach is judged more harshly.

Do we have to document the training?

Yes. You should be able to show an inventory of AI systems in use, an internal policy for AI use, an attendance record from completed training with dates and content, and a routine ensuring new staff receive the same training.

One last thing

The competence requirement is often read as a burden. Our experience is the opposite: organisations that actually run the training get more out of their tools, not less. People who understand what a language model is use it both better and more safely than people who guess.

The regulation demands a minimum. Nothing stops you from using the occasion for something more useful than that.

Sources: Regulation (EU) 2024/1689 of the European Parliament and of the Council (the AI Act), Article 4 and Chapter XII on penalties · Guidance on artificial intelligence from the Norwegian Data Protection Authority (Datatilsynet) · Lov&Data: "The AI Act's requirement to ensure competence in artificial intelligence" (June 2025).

Last updated 27 July 2026. This is a general account, not legal advice. The status of Norwegian implementation may change. Check the Datatilsynet website for current information.