Les DPO de la Santé
All articles
Artificial Intelligence

AI training: the Article 4 obligation of the AI Act for occupational health services and social care providers

Les DPO de la SantéPublished 5 min
AI training: the Article 4 obligation of the AI Act for occupational health services and social care providers

Since February 2025, Article 4 of the AI Act requires organizations to train every team that uses AI. Occupational health services and social care providers: what the obligation covers, who to train, and how to go about it.

An occupational physician using an AI tool to prepare case summaries, a medical secretary triaging appointment requests with an intelligent assistant, a care home piloting a reception chatbot: in each of these cases, Article 4 of the European Artificial Intelligence Regulation already applies. It requires organizations that provide or use AI systems to ensure a “sufficient level of AI literacy” among their staff — and it has been in force since 2 February 2025.

Occupational health services and social and medico-social care providers are doubly concerned: because their teams are adopting these tools quickly, and because they use them on the most protected data there is — health data covered by professional secrecy.

What Article 4 actually says

The text requires providers and deployers of AI systems to take “measures to ensure, to their best extent, a sufficient level of AI literacy” of their staff and of other persons using AI systems on their behalf — taking into account their technical knowledge, experience, education and training, and the context in which the systems are used.

Three points structure the obligation. First, it is an obligation of means: proportionate, documented measures are expected — not an engineering degree for every nurse. Second, it is graduated: the expected level depends on actual use — someone drafting an email with generative AI and someone relying on a clinical decision-support tool do not need the same training. Third, it already applies: the postponement of the “high-risk” obligations enacted by Regulation (EU) 2026/1744 does not concern Article 4, which has applied since February 2025 regardless of the risk category of the tools used.

Why occupational health services are on the front line

An occupational health service concentrates everything that makes the question sensitive: occupational health data covered by medical secrecy, significant volumes (thousands of monitored employees), multidisciplinary teams with very different profiles — occupational physicians, nurses, assistants, prevention specialists, support functions — and rapid adoption of AI-enabled tools: drafting assistance for reports, pre-analysis of questionnaires, prioritisation of medical visits, consultation transcription.

Each use raises the same questions: what data leaves the organization when a consumer-grade tool is used? Who checks the machine's output before it enters the occupational health record? What is the monitored employee told? The training required by Article 4 is precisely where these reflexes are built — and it dovetails with the GDPR, which continues to govern every underlying processing of health data.

And social care providers: same tools, more vulnerable people

In social and medico-social care — care homes, home-care services, disability services, child protection — AI arrives through user records, schedules, handovers, and sometimes monitoring or assistance devices. The people concerned are often vulnerable, which raises the ethical and legal bar another notch.

The timetable should not lull anyone: while certain “high-risk” obligations under Annex III will only apply from 2 December 2027, the AI literacy of Article 4 is due today — and supervisory authorities and funders are starting to ask the question. For a care-facility director, training the teams now also means preparing calmly for the 2027 deadlines.

What a serious “Article 4” training programme must cover

A one-hour generic awareness session on “AI in general” does not meet the objective of the text. A training programme adapted to an occupational health service or a care provider covers at minimum:

  1. 1The useful basics: what an AI system can do, cannot do, and why it gets things wrong (bias, hallucinations, limits of training data);
  2. 2The legal framework applied to the job: the AI Act (risk categories, human oversight), the GDPR and professional secrecy — what may be entered into which tool, and what must never be;
  3. 3The team's real use cases, reviewed one by one: which are allowed, under what conditions, with what human verification;
  4. 4Governance reflexes: who to notify about a new tool, how to escalate a doubt or an incident, where to find the internal AI-use policy.

And it must be documented: programme, participants, dates, materials. That record is what demonstrates, when the day comes, that the obligation of means has been met.

Getting compliant: four steps

Step 1 — map actual uses, including “unofficial” uses of consumer tools: that is often where the risk sleeps. Step 2 — write a short, workable AI-use policy: authorised tools, prohibited data, human verification, reporting. Step 3 — train by profile: a common foundation for everyone, a reinforced module for healthcare professionals and roles handling sensitive data. Step 4 — document and update: a register of uses, proof of training, an annual review — tools change fast, and the training must keep up.

This is precisely the format of our “Mastering AI (Article 4)” training, designed for healthcare organizations and adapted to each structure — with your real use cases as the raw material.

The questions we are asked

“Is it really mandatory, even if we do not use ‘high-risk’ AI?” Yes: Article 4 applies as soon as an AI system is used, whatever its risk category. “Is there a specific penalty?” Article 4 has no dedicated fine in the Regulation, but the obligation is a legal one: it weighs in the overall assessment of compliance, engages the organization's liability in the event of an incident, and training requirements already appear in standards and in calls for tenders. “Who must be trained?” Anyone who uses an AI system in a professional capacity — not just the IT team, and not just the physicians. “How often?” The text does not say; the logic of an obligation of means argues for regular refreshers, all the more so when new tools enter the organization.

This article is provided for general information purposes and does not constitute personalized legal advice.

Turn your obligations into opportunities.

A free, no-obligation first conversation to review your compliance posture and identify your priorities — in English.

Response within 24 business hours · No obligation