Dispatches
Essays··6 min read

The Certificate That Does Not Exist Yet

Article 4 AI literacy obligations have applied since 2 February 2025, so every university in the Union employing staff to operate AI systems has been out of compliance for more than seven months, or it has already certified that its people meet a sufficient level of AI literacy for the work they do. The …

Article 4 AI literacy obligations have applied since 2 February 2025, so every university in the Union employing staff to operate AI systems has been out of compliance for more than seven months, or it has already certified that its people meet a sufficient level of AI literacy for the work they do. The auditor's question is not whether the university met the obligation. The Act imposes a "sufficient level of AI literacy" requirement on providers and deployers, considering technical knowledge, experience, education, training, and the context in which the systems are used. The question is what the auditor writes when the institution produces evidence that it met that standard and the auditor cannot find a line in the regulation telling them what sufficient actually means.

High-risk AI requirements entered force 2 August 2026, covering admissions, grading, and exam monitoring. That is the deadline most institutions have been watching. The literacy rule came earlier and applies more broadly, to anyone operating any AI system. A dean running a student allocation algorithm needs literacy. A communications lead generating web copy with Claude needs literacy. A PhD supervisor who pastes abstracts into ChatGPT to draft feedback needs literacy. Informal use, such as a lecturer pasting student work into a free AI chatbot, likely violates transparency requirements about training data and decision logic, making it potentially illegal post-August, but determining whether that lecturer possessed sufficient literacy to avoid that violation is the prior question, and it has been the applicable question since February.

Nobody disagrees that proof matters. Companies have significant flexibility in devising the content and format of their AI training for staff, but defending against a regulator who argues that the training was inadequate requires something more than a sign-in sheet from a seminar last autumn. PANORAIMA launched in late January 2025 and began programme development in late 2025 through 2026, with pilot runs of specialisation tracks starting September 2026. That puts the first cohorts finishing in 2027 or 2028. HCAIM, its predecessor, graduated 16 students across 2022 through mid-2024, with a dropout rate around 50%. If you add the 30 more expected, you are still south of 50 credentialed graduates across four countries since 2022. PANORAIMA extends responsible AI training to professionals in healthcare, media, law, management, and finance. Even if every one of those tracks runs at capacity and retention improves, the EU has several thousand universities and tens of thousands of staff in scope.

The market has responded. CertiProf has partnered with over 1,500 institutions globally, certifying more than 2 million individuals, with a portfolio of over 70 proprietary certification programmes including AI. Stanford offers a graduate certificate accredited by WSCUC, delivered as a blockchain-verified digital credential. MIT, Wharton, Chicago Booth, and Penn all run executive programmes marketed as leadership-ready. The credentials exist. What does not exist is a register of which ones the auditor should accept as proof of sufficient literacy under Article 4, or a test the auditor can apply to determine whether the in-house training the university built itself meets the threshold.

The default position is that the institution documents what it did, maps it to the roles and systems in question, and the auditor decides whether it was reasonable. Countering allegations of non-compliance will be challenging if companies fail to implement any form of AI training, but defending against claims that the training was inadequate will be much easier. That sentence assumes the institution has done something and that the adequacy judgement lands in its favour. It does not tell the auditor what test to use when the institution produces a three-hour workshop, a vendor certificate from a platform the auditor has never heard of, or a self-declared completion record from an internal LMS with no exam component. The Act built compliance around a principle, not a checklist, which is defensible regulatory design until the moment the auditor has to sign a report.

Two paths out. One is that a European standards body or an accreditation consortium publishes a reference curriculum and assessment framework, and institutions align to it. The European University Association opened participation for a 2026-2027 thematic peer group on AI in doctoral education, but peer groups produce guidance, not binding standards. The other is that national regulators publish interpretive notes clarifying what they will accept, institution by institution, and the auditor becomes a document-matching exercise rather than a judgement call. Neither has happened yet. The AI Act now sits alongside GDPR, and procurement teams must document both data residency and the specific AI processing steps applied, but that is vendor diligence, not staff competence.

The gap is not theoretical. In the United States, 134 bills related to AI in education were introduced across 31 states in 2026, many requiring teacher training. Maryland enacted SB 720, requiring professional development on AI, local AI coordinators in every district, and a statewide AI Education Collaborative. Virginia and others followed. But several states signed AI training mandates into law in 2026, and more are moving bills through committee, with no settled definition of what the training must contain. The US is five years behind the EU on this file, and it is already running into the same wall: legislators can mandate training, but somebody still has to write down what counts.

An institution that ran a vendor workshop in March 2025 can claim it met the February obligation. One that ran nothing until July can claim the flexibility language in Article 4 allowed time to tailor the programme. One that waited until September and is now scrambling is out of time but can argue it interpreted the high-risk deadline as the effective date for everything. All three will land on the auditor's desk with a declaration of compliance, and the auditor has to issue a finding. If the auditor marks the March workshop sufficient and the July bespoke programme insufficient, the institution will ask for the standard. If the auditor cannot produce one, the finding is arbitrary. If the auditor marks all three sufficient because none of them can be disproven, Article 4 has no teeth.

What I would accept, if I were sitting on that side of the table: documentation that the training covered the system's risk classification, the transparency obligations that apply to it, the data it processes and where that data came from, the decisions it influences and who remains accountable for them, and a record that the person operating it demonstrated understanding of those four points before being granted access. That is not a credential, it is a control. If the institution can produce that record for everyone in scope and tie it to the systems they touch, I would sign. If it produces a bulk attendance list and a course outline that mentions ethics twice, I would not. Neither answer is in the regulation.

The universities that already built this are the ones that saw GDPR enforcement coming in 2018 and did not wait for the first penalty to ship training. They are not waiting now. Everyone else is deciding whether to spend money on an expensive external certificate whose relevance nobody has confirmed, or to build something in-house and hope it holds up when the file is opened. The Article 4 obligation is real, the deadline has passed, and the standard does not exist yet.


Tarry Singh is the founder and CEO of Real AI (realai.eu), an enterprise AI advisory and deployment firm working with global enterprises on production agent systems, model risk, and AI sovereignty strategy. He also leads Earthscan (earthscan.io) for Energy AI, and is a founding contributor to the EU-funded HCAIM and PANORAIMA programmes for responsible AI education across European universities. He writes at tarrysingh.com.

Cartouche
The Certificate That Does Not Exist Yet · Dispatches, 21 September 2026 · T. Singh