A trigger decides, not a date on the calendar
Asking how often to repeat AI training assumes there is a correct answer in months. That answer has no support in law, and no support in how AI tools and roles actually change inside a company. A more workable rule is to watch for specific events and match each one to a response: a short refresher, a targeted retrain for part of the team, or a full repeat of the whole programme.
Companies that pick a fixed interval, once a year for example, are not doing anything wrong; that is a legitimate internal choice, and it can sit alongside the triggers below as a safety net for periods when none of them fires. The mistake is assuming a fixed interval alone is sufficient, regardless of what has actually changed inside the company in the meantime.
What Article 4 of the AI Act currently requires
Article 4 of the AI Act was amended by Regulation (EU) 2026/1744, published in the Official Journal in July 2026. The current duty is to take measures supporting the development of AI literacy among staff and other people who deal with AI systems. The European Commission’s own Q&A on this duty states clearly that there is no obligation to measure employees’ knowledge, no mandated single format, no strictly mandatory training, and no required certificate; an internal record of training is enough if a company wants to keep one.
The direct consequence for repeat frequency follows from that: the law does not say how often training should repeat, or that it must repeat in any particular form at all. A company cannot ground a claim about repeat intervals in a legal requirement. It can only ground it in its own judgement, and that judgement is best informed by what has actually changed in day-to-day operations.
Five triggers worth tracking
Five situations recur across industries in practice, and each one typically signals that the team’s trained state no longer matches the reality of the work.
A substantial tool change happens when a vendor swaps the underlying model, materially reworks the interface, or adds a feature that changes how people work with the output. A cosmetic interface tweak does not count as a trigger.
A role or process change happens when what AI is used for inside the company shifts, for instance when a tool moves from a supporting task into a process with a direct effect on a customer or on a decision with legal weight.
A new person joining the workflow is a trigger for anyone joining a process that uses AI, regardless of how long the rest of the team has already been trained.
A recurring error pattern in checked output is a trigger when a review repeatedly catches the same type of mistake across multiple people or tasks, not just once from one person.
A change to internal rules happens when the company revises what may be entered into AI tools, which tool is approved, or which review step is mandatory.
Artefact: triggers and the matching response
| Trigger | What has actually happened | Recommended response | Who the response is for |
|---|---|---|---|
| Substantial tool change | New model version, interface change or new feature affecting output | Short refresher on the change; a targeted retrain for whoever checks output, if the review method itself changes | All users of the tool, or just the reviewers |
| Role or process change | AI moves into a step or role where it was not previously used | Targeted retrain focused on the new context of use | People in the affected role or process |
| New person joining the workflow | An employee starts on a process where AI is already routinely used | Onboarding equivalent to the original training, individually or in a small group | The new person specifically, not the whole team |
| Recurring error pattern in output | Review repeatedly catches the same type of mistake across people or tasks | Targeted retrain on that specific error type; consider a full repeat if it spreads across the team | People showing the pattern, or the whole team if it is widespread |
| Change to internal usage rules | What may go into AI tools changes, the approved tool changes, or a review step becomes mandatory | Short refresher on the new rules, without repeating the full training content | Everyone the rule affects |
The table does not assume every trigger appears in the same year, or that they carry equal weight. When more than one fires together, for instance a tool change alongside a rule change, it usually makes sense to combine the response into one longer refresher rather than run two short ones back to back.
Making triggers part of normal operations
Triggers only work if someone is watching for them. In practice that means connecting them to three sources of information the company likely already has: the vendor’s change log for each tool, the record of staffing changes in teams that use AI, and the output of regular quality checks on AI-assisted work. If a company already samples output for quality, a recurring error pattern will surface naturally as one of the inputs to the retraining decision.
The compliance backdrop behind Article 4 is covered in more depth in the AI Act’s compliance deadlines from February 2025 to August 2027. A rule change about what may be entered into a tool is easiest to picture against whether it is safe to put company data into ChatGPT, a common source of the internal-rules trigger described above. Wider questions about keeping AI use across a company under control connect to securing AI use in the enterprise. A concrete example of what a substantial tool change looks like in practice is set out in Microsoft Copilot’s free chat versus the Microsoft 365 business add-on, where moving a team between the two counts as exactly this kind of trigger.
Sources and limits
This article relies on two direct sources for Article 4: the current wording after amendment by Regulation (EU) 2026/1744, and the European Commission’s Q&A, which explicitly rules out mandatory knowledge testing, a single format, and a certificate requirement. The exact day the amendment took effect is deliberately not stated here, because it has not been independently confirmed; only the month and year of publication are given. The DigComp 3.0 European framework is cited only as evidence that digital competence is described in professional practice as a set of skill levels, not as a repeat interval; it is not an AI-specific framework and it does not measure forgetting over time. The five triggers in the table above are a CIAD recommendation based on what, in practice, changes whether a team’s trained state is still current; they are not an empirically measured set or an exhaustive list, and a company may have its own additional triggers specific to its operations.
Frequently asked questions
Does the law require AI training once a year?
No. Since Regulation (EU) 2026/1744 amended Article 4 of the AI Act, employers and deployers must take measures supporting AI literacy, but the article sets no interval, no format and no duration, and does not require a certificate. A company can still choose an annual cycle as its own internal rule; the statute itself sets no such cycle as a requirement.
What if only one feature of a tool the team uses daily changes?
Usually a short refresher covering exactly what changed, and how to check the new output after the update, is enough. A full repeat only makes sense when the change affects how the team works with the tool across the whole process, not just one feature a minority of the team relies on.
Does a new team member need the same training as everyone else?
In content, yes; in format, usually not. A new person needs to cover the same material as the rest of the team, most often through individual onboarding rather than waiting for the next scheduled group session. Putting someone into an AI-using workflow without that onboarding raises the error risk from day one, and colleagues typically end up carrying the cost of checking the extra mistakes.
How do you tell a training gap from a tool problem when the same mistake keeps happening?
If several people make the same mistake across different tasks, that points to a training or rule gap. If one person repeats the same mistake on the same type of task, it may be an individual gap worth addressing directly. If the mistake tracks a specific quirk of the tool itself, the tool is what needs checking, not the people.
Is an email enough after a rule change, instead of a refresher?
For a small change, it can be, provided the rule is written clearly and the company can show people actually read it. For a change to what staff may input into AI tools, or one that adds a new approval step, a short refresher works better, since it gives people a chance to ask questions on the spot.
SOURCES AND VERIFICATION
reviewed Lukáš Dlouhý ·