Skip to main content
government-room

EU AI Act, Article 4, Won’t Be Solved with More AI Training

For the last year, the EU AI Act conversation has been dominated by models, data, suppliers and risk frameworks. Organisations have been busy writing AI policies, forming governance boards and building inventories of AI systems. But Gartner’s recent analysis of Article 4 puts the spotlight somewhere much more uncomfortable: people.

That matters because Article 4 moves AI literacy out of the learning and development box and into the world of business risk, assurance and market access. Gartner’s interpretation is clear: organisations need to show that the people using AI systems understand how to use them appropriately in the context of their role. A sales user, HR decision-maker and software engineer do not need the same generic AI awareness course. They need different guidance, different oversight and different evidence.

Reading Gartner’s paper, I kept coming back to one thought: the industry may be looking at this through the wrong lens.

Most organisations will interpret Article 4 as a training problem. I believe it is actually an identity governance problem.

The issue is not whether someone sat through an AI course. It is whether the right guidance reached the right person, at the right moment, for the right AI-enabled activity, and whether the organisation can evidence that when challenged by regulators, customers, insurers or investors.

AI literacy is not about teaching everyone to “use AI.” It is about ensuring specific people have the specific understanding they need to make safe, accountable decisions in AI-influenced business processes.

That is where the IAM and IGA lens becomes powerful.

Identity Has Never Been About Technology

There is a persistent misconception that Identity and Access Management is primarily about technology. It is not. Technology is usually the smaller part of the problem.

Access decisions are rarely technical decisions. They are business decisions, shaped by people, process, accountability, risk and desired outcomes.

When an organisation asks who should approve a payment, access customer records, onboard a supplier, make a hiring decision or access privileged systems, the answer is not found in technology first. It is found by understanding the business process, the risks involved and the outcome the organisation is trying to achieve.

In my experience, 80% of a successful IAM or Identity Governance programme is understanding the organisation: how people work, how decisions are made, where accountability sits and what outcome the business is trying to protect. The technology only becomes useful once that is clear. The same is now true for AI. Article 4 is not simply asking whether people have completed training. It is asking whether the organisation understands which business processes are being influenced by AI, who is using AI within those processes, what outcomes they affect and what support they need to make good decisions.

What Article 4 Looks Like in Real Business Decisions

Example 1: Recruitment and Hiring

Traditionally the IAM discussion is:

Should a recruiter have access to the recruitment platform?

But with AI:

The recruiter uses AI to shortlist candidates, generate interview questions and recommend hiring decisions.

Article 4 now raises additional questions:

  • Does the recruiter understand how the AI reaches those recommendations?
  • Does the recruiter understand potential bias or limitations?
  • Does the recruiter know when to challenge the output?
  • Does the recruiter know when escalation is required?

The governance challenge is no longer simply whether access was granted.

It becomes: have we identified that this role uses AI, provided role-specific guidance and captured evidence that the individual received it?

Those are governance questions, not training questions.

Example 2: Finance Approvals

Historically, the question was simple:

Should a Finance Manager approve payments over £100,000?

Now the question is harder:

Finance Manager uses AI-generated spend analysis and risk recommendations before approving payments.

The risk is no longer just whether the person can access the system.

The risk becomes:

  • Does the approver understand where the AI recommendation came from?
  • Do they know what data influenced the recommendation?
  • Do they understand when the output may be unreliable?
  • Are they aware that they remain accountable for the final decision?

Article 4 asks whether that individual is equipped to exercise meaningful human oversight, not just whether they were authorised to click approve.

Example 3: HR Performance and Employee Decisions

Consider an HR professional using AI to:

  • recommend internal candidates
  • identify flight risk
  • suggest performance actions
  • generate redundancy scenarios

The IAM question is:

Should this person have access to the HR system?

The Article 4 question is:

Does this individual understand the limitations, risks and escalation requirements associated with the AI-driven recommendations they are receiving?

Access permission and literacy obligation start to become connected.

Just because someone can access an AI-enabled system does not mean they are competent to use it safely in the context of their role.

Example 4: Customer Service

The desired outcome is to resolve customer enquiries accurately and consistently.

The IAM question is whether the advisor should have access to the customer service platform or other systems within the organisation.

The AI governance question is whether they understand when to trust the AI response, when to override it and when to escalate.

Across these examples, Article 4 introduces a new governance relationship:

Identity – Access – AI capability – Literacy requirement – Business outcome

AI changes the IAM equation. Access alone is no longer enough. Organisations must understand how AI is influencing business processes, which roles are interacting with AI, what decisions those roles shape and whether those individuals have the right knowledge to provide effective oversight.

These are questions identity and access management (IAM) and identity governance and administration (IGA) have been solving for years.

We already know how to answer:

  • Who has access?
  • Why do they have access?
  • Who approved it?
  • Is it still appropriate?
  • Can we prove it?

Article 4 introduces a parallel set of questions:

  • Who is using AI?
  • What decisions are they influencing?
  • What guidance applies to them?
  • Who owns the risk?
  • Can we prove appropriate oversight exists?

The underlying governance challenge is strikingly familiar.

This is the opportunity for the identity profession: to become central to enterprise AI governance, not adjacent to it.

Organisations need more than visibility of the AI tools they deploy. They need visibility of the people, roles, responsibilities, approvals, ownership, attestations and evidence that sit around those tools. That is identity governance territory.

The next dimension is not only AI tooling and agents. It is the deeper integration of AI into the organisation itself.

The real power of AI will come when systems can draw on richer organisational context: business data, identity signals, collaboration patterns, operational workflows, customer records, risk indicators and process history. That integration will make AI outputs more relevant and more valuable. But it also raises the stakes.

The governance question is no longer only whether someone is trained to use an AI tool. It is whether the organisation understands what information the AI can access, which signals shape its recommendations, what decisions it supports and who remains accountable for the outcome.

Some are beginning to describe this as intelligence governance. But intelligence governance will depend on identity governance. Without clear control over people, roles, permissions, responsibilities, approvals and evidence, organisations will struggle to unlock the benefits of AI transformation safely.

AI systems are no longer only assisting users. Increasingly, they are acting on behalf of users: accessing systems, retrieving information, making recommendations and initiating action. So when Gartner refers to providers, deployers, employees, contractors, partners and service providers operating AI on behalf of an organisation, it raises the next obvious question: how will organisations govern AI agents alongside human identities?

For me, this is where Article 4 becomes particularly interesting.

The next generation of AI governance will not simply be about models and policies. It will be about proving which humans and which AI agents participated in a business decision, what permissions they had, what guidance was provided, who owned the outcome and whether meaningful oversight existed.

That is not a training conversation.

That is an identity conversation.

Organisations that recognise this early will be better positioned to demonstrate AI trustworthiness, accelerate customer assurance and reduce governance risk. Those that treat Article 4 as a compliance training exercise may find themselves with completed courses, but very little evidence that operational controls exist.

For years, IAM and IGA have helped organisations prove who can participate in a business process and under what conditions. Article 4 extends that challenge into AI. The question is no longer just who has access. It is who is using AI, what outcome they influence, what guidance they received and whether the organisation can prove appropriate oversight. That is why Article 4 is far more than an AI literacy requirement. It is the point where AI governance and identity governance begin to converge.

And if Gartner is right, the organisations that can demonstrate this convincingly will not simply reduce risk. They will create competitive advantage.

Let's talk.

Start your journey with a free briefing

Sense-check your identity approach, discuss challenges, and get practical guidance on governance, security, and modern identity, with a dedicated Condatis specialist.

Get started

Stay Ahead of Identity, Security & AI Governance

Practical insights, real-world experiences, new research, and exclusive event invitations from the identity specialists helping organisations navigate transformation with confidence.

Privacy Preference Center

Condatis
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.