The TwinLadder Standard
A Board-Grade Reading of Judgment
Judgment is the capital your organisation runs on. As AI enters daily work, the question is where judgment lives, how it was formed until now, and how it will be formed from here. The TwinLadder Standard reads exactly that — across seven pillars, with evidence.
Where the EU AI Act fits in
The EU AI Act is Europe’s landmark regulation for artificial intelligence. Most of the Act concerns high-risk AI systems — medical devices, recruitment tools, credit scoring. Article 4 is broader: it touches every organisation that provides or deploys AI. It is a supporting fact here, not the reason to act.
What Article 4 asks today
- Since Regulation (EU) 2026/1744, in force since 27 July 2026, Article 4 is a best-efforts duty: organisations that provide or deploy AI take measures that support the development of AI literacy in their staff.
- AI literacy means understanding what AI can and cannot do, being aware of the risks, and knowing how to use AI tools responsibly.
- The measures are proportionate — they take into account the technical knowledge, experience, and role of each person. A software engineer and a marketing manager need different levels of understanding.
- It is an obligation of means, not of result. No specific literacy level has to be guaranteed — the duty is discharged by showing the measures you have taken.
Who does it cover?
- Not just regulated industries — every European organisation that uses AI in any capacity.
- Not just IT departments — every person who interacts with AI tools in their work.
- Not just high-risk applications — all AI use, from drafting emails with ChatGPT to screening CVs with automated software.
- If your team uses ChatGPT, Copilot, AI-powered recruitment tools, contract review software, or any product with AI embedded — Article 4 applies to your organisation.
Why this matters to a board
Article 4 today is a best-efforts duty — discharged by showing your measures. A comparable, evidenced method is exactly that evidence. The deeper question belongs to the board: where does the organisation’s judgment live, and how is it being formed now that AI sits in daily work? That is what the TwinLadder Standard reads.
What solutions exist — and what is missing
Dozens of AI frameworks exist. Most of them solve a different problem.
The governance layer is well served
ISO 42001 covers AI management systems. The NIST AI Risk Management Framework addresses risk identification and mitigation. EU AI Act compliance checklists help organisations map their obligations. These frameworks are valuable — they tell you whether you have the right policies, processes, and documentation.
The judgment layer is not
- Governance tells you whether you have an AI policy. It does not tell you whether your people understand it.
- You can pass an ISO 42001 audit and still have a workforce that cannot explain what a hallucination is.
- You can have a perfect AI acceptable use policy and no idea whether the people applying it can tell sound output from confident nonsense.
- What a board needs to read is judgment — who exercises it, how it was formed, and how it holds when AI is in the loop. No governance audit measures that.
How TwinLadder is different
We measure competence, not just governance
Our seven pillars read where judgment is formed and exercised: deployment competence, training, evidence of capability — not just policies on paper. They double as evidence of Article 4 measures.
A clear evidence line
Score 52 or above and your measures are visible and defensible. Below that, you have measurable gaps to close. No ambiguity.
Open methodology, proprietary platform
The standard is published under CC BY-SA 4.0 — free to use, adapt, and redistribute. Think TCP/IP: the protocol is open, the services built on it are commercial. Anyone can adopt the methodology; TwinLadder provides the best implementation.
Risk-calibrated and evidence-gated
A pharmaceutical company and a design studio face proportionate standards. And you show where you stand with evidence, not self-declarations.
Seven pillars of AI competence
Each pillar answers a specific question about where judgment lives in your organisation. Together, they give a board-grade reading — and stand as evidence of the measures Article 4 asks for.
Swipe horizontally to browse all pillars
Maturity Levels
Exploring
0–25
Staff have heard of AI but cannot articulate capabilities or risks. No formal awareness activities.
Developing
26–50
Leadership aware of AI obligations. Most staff have vague understanding of AI but cannot name specific risks.
Implementing
51–75
Organisation-wide AI briefings completed. Staff can identify AI systems they use and describe key risks.
Optimising
76–100
Continuous awareness programme. Staff proactively identify emerging AI risks. Context-specific understanding for all roles.
Maturity Levels
Exploring
0–25
No AI use policy exists. Data protection in AI contexts not addressed.
Developing
26–50
AI use policy drafted but not enforced. Informal guidance on acceptable use. GDPR acknowledged but not integrated.
Implementing
51–75
Active AI use policy with defined acceptable and prohibited uses. GDPR compliance integrated into AI governance. DPIAs conducted for high-risk tools.
Optimising
76–100
Comprehensive, regularly reviewed AI policy. Privacy-by-design principles embedded. Cross-regulatory compliance framework (AI Act + GDPR) fully operational.
Maturity Levels
Exploring
0–25
No structured AI training. Staff learn informally or not at all.
Developing
26–50
Generic AI training available. Self-directed learning. No role differentiation or completion tracking.
Implementing
51–75
Role-specific training programme delivered to all AI-interacting staff including contractors. Completion tracked. Refresh cycles in place.
Optimising
76–100
Personalised learning paths. Competence verified through scenario-based assessments. Continuous development culture. Third-party literacy verified contractually.
Maturity Levels
Exploring
0–25
AI tools used ad hoc. No inventory of AI systems. Shadow AI prevalent.
Developing
26–50
Partial AI inventory. Some tools assessed. Human review optional. Access controls informal.
Implementing
51–75
Complete AI systems inventory with risk classification. Human oversight for consequential decisions. Verification protocols in place.
Optimising
76–100
Automated AI systems monitoring. Continuous verification. Tool governance integrated into procurement. Shadow AI effectively eliminated.
Maturity Levels
Exploring
0–25
No documentation of AI competence efforts. No audit trail.
Developing
26–50
Some records exist. Informal documentation. Could not survive regulatory audit.
Implementing
51–75
Centralised training records and evidence portfolio. Needs assessment documented. Can demonstrate effort under audit.
Optimising
76–100
Comprehensive evidence framework. Automated compliance dashboards. Proportionality reasoning documented. Benchmark-ready data.
Maturity Levels
Exploring
0–25
No AI governance structure. No designated responsible person.
Developing
26–50
Informal responsibility. No dedicated oversight. Ad-hoc reviews when issues arise.
Implementing
51–75
Named AI governance owner. Periodic review cycle. Ethics considerations documented. Incident response procedures exist.
Optimising
76–100
Board-level AI oversight. Cross-functional governance committee. Continuous regulatory monitoring. Proactive risk anticipation.
Maturity Levels
Exploring
0–25
No decision inventory. AI makes decisions with no defined boundaries or oversight.
Developing
26–50
Some awareness of AI decision boundaries. Ad-hoc escalation. No formal delegation framework.
Implementing
51–75
Decision inventory exists. Authority boundaries documented per system. Escalation paths and human override capability in place.
Optimising
76–100
Full authority delegation framework. Continuous monitoring for authority creep. Clear accountability chains. Regular boundary audits.
Four maturity levels
Every organisation starts somewhere. The four levels describe a progression from no formal AI awareness to embedded, continuously renewed judgment. The evidence line — where an organisation can show the measures Article 4 asks for — sits at the boundary between Level 1 and Level 2.
Exploring
Score: 0–25
No formal AI awareness programme. AI tools adopted ad hoc by individuals. No usage policy exists. Staff cannot articulate what AI tools they use or the risks involved. No measures to show — and no reading of judgment.
Developing
Score: 26–50
Some awareness training delivered. An AI acceptable use policy drafted but not yet consistently enforced. A tool inventory started but incomplete. Governance gaps remain. Measures under way, but not yet evidenced.
Implementing
Score: 51–75
Structured training programme in place, tailored to roles. AI policy enforced organisation-wide. Evidence of competence documented and auditable. This is the evidence line — the measures Article 4 asks for, visibly in place.
Optimising
Score: 76–100
Continuous improvement embedded. External benchmarking against industry peers. AI governance integrated into business processes. Judgment treated as capital — formed deliberately, measured, and renewed.
Evidenced measures are the floor. Formed judgment is the advantage.
© TwinLadder 2026 · CC-BY-SA 4.0
Article 4 — Mapped to the Seven Pillars
Article 4 is a duty of means. This interactive mapping shows how each of its elements is evidenced by one or more of the seven pillars — how the standard turns regulatory language into a measurable method.
| Article 4 Element | Deployment Competence | Policy & Data Protection | Training | Tools | Evidence | Governance | Authority Delegation |
|---|---|---|---|---|---|---|---|
“Providers and deployers of AI systems” | P | S | |||||
“shall take measures” | S | P | |||||
“to ensure, to their best extent” | S | P | S | ||||
“a sufficient level of AI literacy” | P | S | |||||
“of their staff and other persons dealing with the operation and use of AI systems on their behalf” | S | P | S | ||||
“taking into account their technical knowledge, experience, education and training” | S | P | |||||
“the context in which the AI systems are to be used, and considering the persons or groups of persons on whom the AI systems are to be used” | P | S | S | S |
“Providers and deployers of AI systems”
“shall take measures”
“to ensure, to their best extent”
“a sufficient level of AI literacy”
“of their staff and other persons dealing with the operation and use of AI systems on their behalf”
“taking into account their technical knowledge, experience, education and training”
“the context in which the AI systems are to be used, and considering the persons or groups of persons on whom the AI systems are to be used”
The evidence line: score 52
Based on a line-by-line mapping of Article 4 to our seven pillars, the minimum score for an evidenced, defensible position is approximately 52 — the transition point from Developing to Implementing. Scoring 52 means you can show the measures your organisation has taken. Scoring below it means you have identifiable, measurable gaps.
- All seven pillars must score above zero — a single zero-score pillar means a blind spot in how judgment is formed
- Policy & Data Protection and Training carry the highest evidential weight — they are where measures are most visible
- The line is not a ceiling — organisations scoring 52 are evidenced but fragile. A single staff change or new tool deployment could drop you below
- Article 4 is a best-efforts duty — the score is not a pass mark, it is the evidence of measures a board can stand behind
How to use the standard
The TwinLadder Standard supports a complete journey from measuring where you are to proving where you need to be.
Assess
Take the AI-powered conversational assessment to get your baseline scores across all seven pillars. The free Quick Scan takes 15 minutes. The Executive Report is a board-grade reading of where the organisation’s judgment stands, with prioritised recommendations.
Start assessmentLearn
Enrol in TwinLadder Academy courses mapped to your weakest pillars. Foundation, Leadership, and Mastery pathways cover everything from Article 4 basics to cross-functional AI governance.
Explore coursesCertify
Reassess to measure your progress. Build an evidence portfolio that documents training completed, policies adopted, and competence achieved. Work toward TwinLadder Certified status.
View pricingOpen Methodology
The TwinLadder Standard is published under Creative Commons Attribution-ShareAlike 4.0 International. The methodology is open — anyone can use, adapt, and redistribute it with attribution. The platform, assessment tools, and certification programme are proprietary. The standard is free. The implementation is ours.
