There is a provision of the EU AI Act that most companies have not actioned, and it is not waiting for some future deadline. Article 4 has been in force since February 2, 2025. It applies to essentially every organization that uses AI — not just the ones building high-risk systems — and it says something simple: if your people operate AI systems on your behalf, you must ensure they have a sufficient level of AI literacy, and you should be able to show your work. (Read Article 4 itself — it is four sentences — and the full EU AI Act on EUR-Lex.)
That last part is the one that matters. Article 4 does not mandate a specific course, a specific certificate, or a specific vendor. What regulators, auditors, insurers, and — increasingly — your own enterprise customers ask for is evidence: documented training, appropriate to each person’s role, with dates, content, and names attached. “We talked about AI at an all-hands once” is not a record. A record is a record.

Why this is showing up in your sales pipeline, not just your legal review
Enforcement machinery for the AI Act ramps through August 2026. Article 4 itself carries no fixed EU-level fine — enforcement falls to national market-surveillance authorities — but it is exactly the kind of obligation that is trivially easy for an authority to check: show me your AI literacy measures.
But the nearer-term pressure isn’t regulators. It’s procurement. Enterprise security questionnaires and vendor evaluations have started asking directly about AI governance and staff training. HR teams now evaluate AI-training providers with formal scoring tables and Article 4 evidence checklists. If you sell to enterprises, the question “how is your staff trained on AI?” is arriving in your deal cycle whether or not a regulator ever calls. A documented AI-literacy program is one of the highest-return, lowest-cost answers on the whole compliance list.
What the market currently offers — and what it costs
Today’s options cluster at two extremes. At one end: exam-based certificates from established European certification bodies, typically running a four-figure cost per person — rigorous, but at that price, “certify the whole staff” is a six-figure line item for a 100-person company, so organizations certify three people and call it a program. At the other end: free awareness courses and internal lunch-and-learns — genuinely useful, but frequently undocumented, not role-differentiated, and invisible to an auditor.

Article 4’s own language points at the gap between these extremes. It asks for training proportionate to role and context — your board needs different literacy than your engineers, who need different literacy than your sales team — and it asks for documentation. What most organizations need is role-appropriate training for everyone, with a verifiable record for each person, at a price that makes “everyone” realistic.
How the Academy approach works, in plain English
SanctumShield Academy is an AI-governance training and certification platform built around exactly that gap. The design maps directly onto what Article 4 asks for (see the full curriculum):
Role-proportionate by construction. One curriculum, five persona tracks. Employee Essentials runs 25–35 minutes — shadow AI, browser agents, the artifacts that matter, effective human oversight. Board & CEO runs about an hour on oversight duties and the artifact you sign. Legal, CTO, and CISO tracks go progressively deeper, up to the full 19-module program. Everyone gets literacy sufficient to their role — which is Article 4’s own standard, expressed as a curriculum.
A real exam, scored deterministically. Certification is a timed, randomized examination graded by exact-match logic — no AI grades it, and no participation trophy is issued. Pass at 80% and the credential means the person actually demonstrated the knowledge.
A verifiable record for every person. Each passing learner receives a credential with a public verification URL, tamper-evident via a SHA-256 hash, valid for three years. Anyone you hand the link to — an auditor, a customer’s security team, an insurer — can confirm it independently, without contacting us and without trusting a screenshot. Employee-track completions produce dated, individually attributed Training & Acknowledgment Records: the evidence layer for an Article 4 program, accumulated person by person.
Content that stays current. The curriculum covers the EU AI Act, Colorado’s AI law, DORA, HIPAA, GDPR, NIST AI RMF, and ISO/IEC 42001, clause by clause in plain English — and credentials carry a content version. When the regulatory ground shifts materially, recertification is triggered by the change, not by the calendar alone.
The whole-staff math
Here is the part that changes the decision. A Team plan is $199 per month for 10 seats. Seats are access; credentials belong to people. When an employee completes their track and earns their credential, that credential is theirs — bound to their identity, verifiable for its full three-year term — and their seat can be reassigned to the next employee.

A 100-person organization can rotate its entire staff through the Employee Essentials track — a 25–35 minute commitment per person — across a couple of billing cycles, and end with one hundred individually named, independently verifiable training records. Total cost: a few hundred dollars. The same coverage at per-person certificate pricing would run well into six figures.

And the organization gains a number it can actually use: percentage of workforce credentialed in AI governance. That figure goes into security-questionnaire responses, customer trust pages, and board reporting — each individual claim behind it independently checkable by anyone with the link. That is what turning shadow-AI anxiety into demonstrable posture looks like: not an assertion of culture, but a stack of records.
What this does not do — said plainly
Honesty is the product here, so three limits, stated the way we’d want any vendor to state them. Completing the Academy does not automatically make an organization Article 4 compliant — “sufficient” is a judgment about your specific context, and scoping it is a question for your counsel; what the Academy produces is the training itself and the evidence a compliance case is built from. The credential is a knowledge certification via randomized, timed, deterministic examination — it is not an identity-proofed, proctored credential, and we say so on the credential itself. And training is one pillar of a governance program, not the whole of it — it sits alongside your acceptable-use policy, your risk assessments, and your operating records. (Generating those artifacts is what SanctumShield itself does; the Academy is where your people learn what they mean.)
Where to start
The full syllabus is published openly — every module title, every track outline — before you spend anything. Most organizations start in one of two places: an individual leader takes their own track first (Board, CISO, or Legal, depending on who’s reading this), or a team lead puts ten seats to work on Employee Essentials and watches the credential count climb.
The requirement is already in effect. The evidence is the point. And the gap between “we should train people on AI” and “here are one hundred verifiable records that we did” turns out to be about thirty-five minutes per person.
Judgment is not evidence. Train accordingly.