TWINLADDER
TwinLadder logoTwinLadder
Back to Insights

EU AI Act

Building an AI Governance Framework: From US Rules to Article 4 Readiness

Effective AI governance requires more than a policy document. We map the US rules-based approach against Article 4's competence mandate, then outline the committee structures, policy components, and implementation phases that European firms need — with templates adapted for different organisation sizes.

2025. gada 5. novembrisLīga Pauliņa, Līdzdibinātāja un TwinLadder Akadēmijas direktore14 min read
Building an AI Governance Framework: From US Rules to Article 4 Readiness

Building an AI Governance Framework: From US Rules to Article 4 Readiness

Article 4 of the EU AI Act requires organisations deploying AI to ensure "sufficient AI literacy" among their staff. That single sentence changes what governance means for European firms — and the US enforcement record shows exactly why you cannot afford to get it wrong.


Article 4 became applicable on 2 February 2025. It applies to all deployers of AI systems — not just high-risk ones — and requires that staff possess AI literacy "taking into account their technical knowledge, experience, education and training... as well as the context in which the AI systems are to be used." There is no exemption for firm size, practice area, or level of AI adoption.

If you are a European professional services firm using any AI tool — from a contract review platform to a general-purpose large language model — you are a deployer. And you need a governance framework that goes beyond policy documents to build genuine competence.

The good news: you do not need to start from zero. The United States has spent the past two years generating enforcement data, ethics opinions, and cautionary tales that map directly onto the governance challenges you face. The question is how to translate rules-based US guidance into the competence-based framework that Article 4 demands.


Two Approaches to the Same Problem

The American Bar Association issued Formal Opinion 512 in July 2024, establishing six duties governing AI use: competence (Model Rule 1.1), confidentiality (Model Rule 1.6), communication with clients (Model Rule 1.4), candor toward the tribunal (Model Rules 3.1 and 3.3), supervisory responsibilities (Model Rules 5.1 and 5.3), and reasonable fees. At the state level, over 1,000 AI-related bills have been introduced across nearly every US state.

This is a rules-based approach. It tells you precisely what you must do and what you must not do. It works — but it is designed for a common-law litigation culture where enforcement comes through individual sanctions.

Article 4 takes a fundamentally different path. It does not prescribe specific duties or verification steps. It requires that your people are competent enough to use AI responsibly, and it leaves the definition of "sufficient" to context. The penalty for failure sits in Article 99, Tier 2: up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.

Think about that for a moment. The US approach says: "Follow these six rules." The EU approach says: "Make sure your people actually understand what they are doing." Both are valid. But the governance frameworks they require look quite different.


What US Enforcement Teaches European Firms

You do not need to repeat the mistakes that American practitioners have already made for you. Three cases illustrate what inadequate governance produces — and each maps directly to an Article 4 obligation.

Mata v. Avianca (2023): Attorney Steven Schwartz submitted a brief containing six fabricated case citations generated by ChatGPT. He did not verify them. He did not understand that large language models generate plausible text, not accurate legal research. The court imposed sanctions. Under Article 4, this is a textbook literacy failure — a professional deploying an AI system without sufficient understanding of its capabilities and limitations.

Morgan & Morgan (2025): A paralegal used AI to generate citations that were not verified before filing. Supervising attorney T. Michael Morgan was fined $1,000 despite not being involved in creating the problematic filing, because his signature appeared on the document. This case demonstrates that governance is not just about the person using the tool. It is about everyone in the supervision chain. Article 4 requires literacy across the organisation, not just among individual users.

Ko v. Li (2024): The lawyer avoided contempt sanctions only because the court exercised discretion, but the substantive violations were clear. AI-generated content was submitted without adequate review. The case illustrates that even when formal penalties are limited, reputational damage and professional exposure are real.

These are not edge cases. 79% of law firms have adopted AI tools, but only 10% have implemented formal governance. That gap — between adoption and governance — is precisely what Article 4 targets.


Governance Structure Options

Your governance framework must match your organisation's size and complexity. The structure differs, but the Article 4 obligation does not.

Enterprise Model: Dedicated AI Governance Board

For organisations with 200+ professionals, a dedicated governance board provides centralised oversight. This model works where AI deployment spans multiple practice areas, significant technology investment requires coordinated assessment, and regulatory exposure across jurisdictions demands a unified response.

The board typically includes representatives from technology leadership, risk management and compliance, ethics and professional responsibility, practice group leaders from high-utilisation areas, and information security. The critical addition for Article 4: a competence lead responsible for ensuring literacy requirements are met across the organisation, not just documented.

Mid-Market Model: Distributed Responsibility

Organisations with 50–200 professionals often lack resources for dedicated governance infrastructure. A distributed model assigns governance to existing roles: managing partner or executive committee for policy approval, IT director for tool evaluation and vendor management, ethics partner for compliance monitoring, and practice group leaders for implementation oversight.

Success depends on clear accountability. Under Article 4, "we assumed someone else was handling training" is not a defence. Each role must have explicit literacy obligations documented and monitored.

Small Firm Model: Partner-Led Governance

For organisations under 50 professionals, governance often falls to a single partner or small committee. Your essential elements are: a written AI acceptable use policy, a defined approval process for new tools, mandatory training before access is granted, an incident reporting mechanism, and periodic policy review.

The focus should be on preventing the most common failures: confidentiality breaches, unverified outputs, and the use of AI systems without understanding their limitations. Small firms have one advantage here — you can achieve genuine literacy across your entire team, not just compliance documentation.


Essential Policy Components

Data Classification and Handling

Any effective AI policy must address what information can and cannot be input into AI systems. Your categories should include:

Prohibited inputs:

  • Client confidential information in public AI tools
  • Privileged communications
  • Personally identifiable information (GDPR obligations compound here)
  • Information subject to protective orders or NDAs

Conditional inputs (with appropriate enterprise tools):

  • Anonymised case facts
  • General research queries
  • Document drafts for internal review

Under both GDPR Article 5 and the AI Act, you must specify which tools are approved for which data categories. Using public AI tools for client work without human verification is an ethical violation under Opinion 512 — and a potential data protection breach under GDPR.

Verification Requirements

Every governance framework needs explicit verification obligations:

  • All AI-generated legal citations must be verified against primary sources
  • AI-drafted content requires review before submission to courts or clients
  • Factual assertions generated by AI require independent confirmation

This is where US enforcement data is directly useful. The Mata, Morgan & Morgan, and Ko v. Li cases provide concrete examples of what happens when verification fails. Use them in your training materials. Your people need to understand that AI systems generate plausible text, not verified facts.

Disclosure Obligations

In the US, over 200 federal judges have issued standing orders requiring AI disclosure in court submissions. European jurisdictions are beginning to follow. Your policy should address jurisdictions where disclosure is mandatory, internal standards for voluntary disclosure, client communication about AI use in their matters, and documentation requirements for AI assistance.

Even where disclosure is not yet mandatory in your jurisdiction, consider this: transparency about AI use builds client trust. Concealment destroys it.

Training and Competency — The Article 4 Core

This is where European governance diverges most sharply from the US model. Opinion 512 requires lawyers to have "a reasonable understanding of the capabilities and limitations of AI tools they use." Article 4 requires something broader: sufficient AI literacy across the entire organisation, proportionate to context.

The TwinLadder methodology — published as an open-source framework under CC-BY-SA 4.0 — operationalises Article 4 through four phases:

  1. Assess: Evaluate current AI literacy levels across roles. You cannot build a training programme without knowing where your people stand. Standardised assessment maps each professional's comfort and competence with AI tools they actually use.

  2. Learn: Deliver workflow-based training that prioritises practical competence over technical knowledge. Your professionals do not need to understand transformer architectures. They need to know which tasks benefit from AI, how to verify outputs, and where the boundaries of responsible use lie.

  3. Apply: Supervised practice with AI tools in real professional contexts. Competence is not built in classrooms — it is built through guided application with feedback loops.

  4. Certify: Document competence outcomes that demonstrate Article 4 compliance. This is not a checkbox exercise. Certification must reflect genuine capability, not merely attendance.

This four-phase approach produces what compliance-check modules cannot: professionals who actually understand the tools they are using, with documentation that demonstrates it to regulators.

Supervision and Accountability

Under US Model Rules 5.1 and 5.3, supervisory obligations apply to partners and managers. Under Article 4, the obligation extends further: the organisation itself must ensure literacy. This means:

  • Ensuring all staff understand AI policies and their rationale
  • Monitoring compliance with verification requirements
  • Addressing violations promptly and documenting responses
  • Maintaining records that demonstrate ongoing competence, not just initial training

The Morgan & Morgan case illustrates supervisory exposure clearly: the supervising attorney was sanctioned despite having no involvement in the AI use itself. Your governance framework must ensure that every person in the review chain understands their obligations.


Implementation: A Phased Approach

Phase 1: Policy Development (4–6 weeks)

Draft policies, conduct a baseline literacy assessment, gather stakeholder input, and obtain approval. Use the TwinLadder assessment framework to establish where your organisation stands before designing training.

Phase 2: Training Development (4–8 weeks)

Build workflow-based training materials mapped to your specific practice areas and tools. Identify trainers — they need both AI competence and domain credibility. Generic training programmes fail because they do not connect to the work your people actually do.

Phase 3: Pilot Deployment (4–8 weeks)

Limited rollout with enhanced monitoring. Select practice groups or teams with the highest AI utilisation and test your governance framework in practice. Collect feedback, measure competence outcomes, and refine before wider deployment.

Phase 4: Organisation-Wide Rollout (ongoing)

Broader access with standard oversight. By this point, your training programme should produce measurable competence, your policies should reflect practical experience, and your documentation should demonstrate Article 4 compliance.

Phase 5: Continuous Improvement (ongoing)

Policy updates based on experience, regulatory developments, and evolving AI capabilities. Article 4 requires literacy "taking into account" context — and the context changes with every new tool and every regulatory clarification.


Technology Controls

Policies work best when supported by technical measures:

  • Approved tool lists enforced through IT systems
  • Access controls limiting AI tool availability to trained users
  • Logging and monitoring of AI tool usage
  • Data loss prevention controls for sensitive information (particularly important under GDPR)

Vendor assessment is equally critical. Third-party AI tools require due diligence on data handling and retention practices, security certifications, compliance with applicable regulations — including the AI Act's transparency obligations — contract terms on confidentiality and data use, and the vendor's own AI governance maturity.


Key Takeaways

  • Article 4 of the EU AI Act requires sufficient AI literacy for all deployers — applicable since 2 February 2025, with penalties up to EUR 15 million or 3% of worldwide turnover
  • US enforcement cases (Mata, Morgan & Morgan, Ko v. Li) provide concrete evidence of what governance failures produce — use them as training material, not just cautionary tales
  • The US rules-based approach (Opinion 512's six duties) and the EU competence-based approach (Article 4) address the same problem differently — your governance framework should draw from both
  • Governance structures scale from dedicated boards to partner-led models, but Article 4 obligations apply regardless of organisation size
  • The TwinLadder four-phase methodology (Assess, Learn, Apply, Certify) operationalises Article 4 through workflow-based competence building, available as an open-source framework under CC-BY-SA 4.0

Sources

  1. EU AI Act, Article 4 — "AI Literacy": The legal basis requiring providers and deployers to ensure staff AI literacy, applicable since 2 February 2025. artificialintelligenceact.eu

  2. EU AI Act, Article 99 — "Fines": Penalty framework establishing three tiers of administrative fines, with Article 4 violations classified under Tier 2 (EUR 15 million or 3% of worldwide annual turnover). artificialintelligenceact.eu

  3. American Bar Association — "ABA Formal Opinion 512" (2024): The ABA's ethics framework for generative AI use, covering competence, confidentiality, communication, candor, supervision, and fees. americanbar.org

  4. Thomson Reuters — "Just 10% of Law Firms Have a GenAI Policy" (2024): Report revealing the gap between AI adoption (79%) and governance implementation (10%) in law firms. legaltechnology.com

  5. ABA Litigation Section — "Court-Mandated Disclosure of Artificial Intelligence in Court Submissions" (2024): Documentation of 200+ federal standing orders requiring AI disclosure. americanbar.org

  6. American Bar Association — "ABA Tech Report: Artificial Intelligence" (2024): Tracker documenting over 1,000 AI-related bills introduced across US states. americanbar.org

  7. TwinLadder — "Comfort Over Code: A Workflow-Based Framework for AI Literacy in Professional Practice" (2026): Open-source methodology for operationalising Article 4 through four-phase competence building, released under CC-BY-SA 4.0. twinladder.ai

  8. GDPR, Article 5 — "Principles relating to processing of personal data": Data protection principles that intersect with AI governance obligations, particularly data minimisation and purpose limitation. gdpr-info.eu

  9. Baker Donelson — "2026 AI Legal Forecast: From Innovation to Compliance" (2026): Assessment of legal AI governance trajectories. bakerdonelson.com