A certificate answers a single question: did this person sit through it. That is a real question, and for a long time it was the one that mattered.
The questions that matter under an AI-literacy obligation are different. Does this person know what the rule requires of their role? Could they show it against a source a stranger can open? And could an auditor confirm that later without asking the organisation that trained them?
What the law asks for
Article 4 of the EU AI Act, as replaced by Regulation (EU) 2026/1744 on 27 July 2026, asks providers and deployers of AI systems to take measures to support the development of AI literacy of their staff and of other people who operate AI systems on their behalf, taking account of their knowledge, experience, education and training, and the context the systems are used in. The same Article 4 states that it does not require any specific level of AI literacy of any individual. The obligation has applied since 2 February 2025; national market surveillance authorities enforce it from 2 August 2026, under Article 113 of the Regulation and the Commission's published guidance.
The European Commission's own questions and answers on Article 4, updated on 27 July 2026, say three things worth quoting. There is no need for a certificate. An organisation can keep an internal record of trainings. And the article does not entail an obligation to measure the knowledge of employees.
So nothing in Article 4 requires a certificate, a test, or a verifiable record. Anyone who tells you otherwise is selling one.
Why a record anyway
The obligation is to take measures, by role and context. The thing an organisation will be asked to show is that it took them: what was done, for whom, on what date, and how it fitted the person's role. An internal spreadsheet can hold that. What a spreadsheet cannot do is let a customer, an insurer or an auditor confirm a line on it without taking the organisation's word.
That is the property a certificate lacks too. It is issued by the organisation that ran the training, it sits in the hands of the person who attended, and the person checking it has to trust both. A record that a third party can open on its own changes who has to be trusted.
A knowledge test is a separate choice. The law does not ask for one. An organisation that chooses to test is saying something more than "this person was there": it is saying "this person answered these questions, drawn from this source, on this date, and here is the result". That is a stronger sentence, and it is worth making sure the record can carry it.
What the record has to contain
Here is how the Academy's record works, described as it ships. Open this one before you read the description of it. It needs no account.
When a learner passes, the Academy stores a record of the track, the result band, the issue and expiry dates and the content version, fingerprints that record with SHA-256, and signs the fingerprint with a key held on the server. Anyone with the link can open the record without an account and see the status, the result band, the dates, the content version and the fingerprint, and the name when the holder has chosen to show it, but not the score, the questions, or the person's email. The record cannot prove who was at the keyboard, or that the person understood rather than answered.
Three things about that description are deliberate.
It names what the record does not show. The score is not on it, because a percentage invites comparison between people and the record is about one person. The questions are not on it, because the bank would not survive being published one credential at a time.
It names what the record cannot prove. The exam is not proctored and the holder's name is not identity-checked; the page says so in the same paragraph as the result. A record that claimed more would be worth less.
It says "signed", and it says what that means: a fingerprint of the record, and a signature over the fingerprint with a key the server holds. The page shows the fingerprint. It does not yet give a stranger enough to recompute it, which is a shortfall we list in the standard rather than paper over.
The record you just opened was issued in July, before signing was added in August, so its page shows the transport and domain checks and the screening date but not the signed mark. A record issued today shows all four.
Two habits for the buyer
Ask to verify a sample record yourself before you buy. Not a screenshot, not a PDF, the live page. If the vendor cannot produce one, there is nothing to verify.
Ask what the record does not contain. A vendor who has thought about the record will answer at once. A vendor who has not will offer to add whatever you like, which is the wrong answer.
The question the standard raises
When an employee gets a question wrong, what does the program do with that? A certificate has no view on it. A record of a result has a partial one. A program that can tell a manager which topic to go back to has the whole answer, and that is the question we put to ourselves in the standard, where the Academy's own gap on it is stated in bold.
