What Article 4 enforcement changed on 2 August 2026, and the questions every life sciences leader should be able to answer.
By Siobhán O'Leary | The Institute of Applied AI | Building AI Capability series | August 2026
For many organisations, AI still lives in the productivity conversation. Which tool should we buy? Where can we save time? Which use case should we pilot?
Those are reasonable questions. In life sciences, they are no longer the first questions. The first question is now this: can we demonstrate that we know where AI is being used, who is using it, what decisions it influences, and what controls are in place?
That is the shift from productivity to compliance, and it is already underway.
Article 4 of the EU AI Act requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff. It is not new. It has applied since 2 February 2025.
What changed on 2 August 2026 is enforcement. National market surveillance authorities are now supervising the Act, which moves Article 4 from a policy discussion to an enforceable expectation. The 18-month grace period, whether organisations used it or not, is over.
The obligation is deliberately proportionate. Literacy is assessed against the technical knowledge, experience and training of the people involved, how the systems are used, and who they are used on. For a regulated organisation, that should not be read as putting everyone through the same AI 101 course. It means being able to answer, with confidence, questions like these:
If those answers come easily, the compliance question largely takes care of itself. If they do not, that is where the readiness gap sits.
Most companies are not starting from zero. Employees are already experimenting. Teams are using generative AI to draft, summarise, analyse and automate. Suppliers are embedding AI into platforms. In many cases this activity is helpful and entirely understandable.
The risk is not that employees are using AI. The risk is that the organisation cannot see, assess or govern how it is being used. When adoption is invisible, or disconnected from existing quality, cybersecurity, data integrity and change control processes, it becomes shadow AI. Treating it as a discipline problem drives it further underground. Treating it as a visibility problem brings it into processes you already run well.
Readiness does not begin with a tool audit or a training procurement. It begins with 3 questions, asked honestly, at every level from the boardroom to the bench:
Ask them of leadership, of quality, of IT, of operations. Where the answers agree, you have readiness. Where they differ, you have found the work.
The obligation is already in force. The enforcement is already live. The organisations best placed are simply the ones who can answer these questions before someone else asks them.
About the author: Siobhán O'Leary, AIGP, is an Applied AI Advisor and founder of The Institute of Applied AI, helping organisations build AI capability that is grounded in literacy, governance, and practical adoption. She publishes AI in Motion, a weekly newsletter for leaders navigating AI beyond the headlines.
Subscribe to AI in Motion on LinkedIn →