Article 4 EU AI Act: Your Plain-English Guide to the AI Literacy Obligation

One EU AI Act deadline has already passed - and most organisations missed it.
Article 4 of the EU AI Act entered into application on 2 February 2025. That is the date by which providers and deployers of AI systems were required to start taking measures to ensure a "sufficient level of AI literacy" among their staff. Not August 2026. Not some future date. February 2025.
If your organisation uses AI tools at work - and almost every organisation does - this obligation almost certainly applies to you right now. This guide explains what Article 4 actually says, who it covers, what "sufficient" means in practice, and how to build a programme that will hold up when enforcement machinery switches on.
This article is for information only and does not constitute legal advice. Consult qualified counsel for advice specific to your organisation.
What Article 4 Actually Says
The text of Article 4 is deceptively short. In full, it reads:
"Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used."
Three things stand out. First, the obligation falls on both providers and deployers - not just the companies building AI, but every organisation using it professionally. Second, it extends beyond direct employees to "other persons dealing with the operation and use of AI systems on their behalf" - which the European Commission's Q&A guidance interprets broadly to include contractors and service providers. Third, the phrase "to their best extent" introduces a reasonableness standard: providers and deployers are not required to take every conceivable step to ensure a sufficient level of AI literacy - the formulation implies a criterion of reasonableness that considers individual circumstances.
What "AI literacy" means
Article 3(56) of the AI Act defines "AI literacy" as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause.
This is broader than technical training. It covers understanding what AI systems can and cannot do, recognising bias and error, knowing when to escalate or override, and understanding the legal and ethical context of the tools being used.
Who Is Covered?
Providers vs. deployers
The AI Act draws a sharp distinction between these two roles:
- Providers develop or place AI systems on the market - software vendors, model developers, companies that build AI-powered products.
- Deployers use AI systems in a professional context - a bank using an AI credit-scoring tool, an HR team using an AI CV-screening platform, a hospital using an AI diagnostic assistant.
Article 4 applies to any organisation that is a provider or deployer using AI systems, regardless of size or sector. There is no carve-out by headcount. The Act applies to the smallest sole-proprietor consultancy and to the largest multinational. What changes with size is what "sufficient" looks like in practice - a 6-person team is not expected to run the same programme as a 6,000-person enterprise. But the obligation itself is the same.
What about purely personal use?
The obligation is scoped to professional contexts. Purely personal or non-professional use of AI falls outside Article 4. The practical test: if someone is using an AI tool as part of their job, on behalf of the organisation, the obligation applies.
The "other persons" question
The Commission regards "other persons" as those broadly under the organisational remit, and the Q&As provide examples of contractors, service providers and clients. This is a wider net than many organisations initially assumed. If you rely on a third-party contractor who operates AI systems on your behalf, their AI literacy is part of your compliance picture.
The Two Dates You Need to Know

2 February 2025 - the obligation is already live
Article 4 of the AI Act entered into application on 2 February 2025, therefore the obligation to take measures to ensure AI literacy of their staff already applies. This is confirmed directly by the European Commission's own Q&A guidance. If you have not yet started, you are not "preparing to comply" - you are already in breach of a live legal obligation.
3 August 2026 - enforcement begins
The supervision and enforcement rules apply from 3 August 2026 onwards. The supervision and enforcement of Article 4 of the AI Act is not with the AI Office, but it is under the remit of national market surveillance authorities. Different Member States are designating different bodies: France has positioned the CNIL as the candidate lead authority; Italy has split the work between AgID for AI policy and the Garante for privacy-related AI supervision; Germany has signalled the BNetzA as a likely lead; the Netherlands has assigned the Autoriteit Persoonsgegevens (AP) a coordinating role on AI supervision.
What about the Digital Omnibus?
You may have heard that the EU's Digital Omnibus package proposed changes to Article 4. Here is the accurate picture as of June 2026.
The Article 4 AI literacy obligation, which has applied since 2 February 2025, is proposed to be softened: providers and deployers would be required to support the development of AI literacy among their staff, rather than to guarantee a specific level of literacy. On 7 May 2026, the Council and the European Parliament reached a provisional political agreement on a set of targeted amendments aimed at streamlining certain aspects of the AI Act. However, these amendments have not yet been formally adopted. The text remains subject to approval by both the European Parliament and the Council, with adoption envisaged before 2 August 2026.
The practical upshot: the current Article 4 obligation - as written in Regulation (EU) 2024/1689 - remains in force today. Even if the Omnibus softening is adopted, the legislator emphasises that AI literacy should remain a strategic priority, irrespective of regulatory pressure or potential sanctions. And critically, for those who deploy high-risk AI systems, the obligation to ensure that their staff is trained to ensure human oversight remains in place.
The Digital Omnibus did not delay the Article 4 obligation. The enforcement date of 3 August 2026 remains active. The Omnibus proposes to soften how the obligation is framed — not to remove it or push back the enforcement date. Plan against the current law, not a proposed amendment that is not yet formally adopted.
What Does "Sufficient" and "Proportionate" Mean in Practice?
This is where most organisations get stuck. The Act deliberately avoids prescribing a curriculum, a number of training hours, or a list of approved programmes. The EU AI Act does not provide a prescriptive curriculum. Instead, it establishes a principles-based standard informed by Recital 20, the AI Office's guidance, and broader policy frameworks.
What the Act does require is that the level of literacy be calibrated to three factors:
- The people involved - their existing technical knowledge, experience, education and training
- The context - what the AI system is used for, in what sector, under what conditions
- The affected persons - who the AI system is used on, and what the consequences of error might be
Companies are required to assess and build the necessary literacy in a differentiated and needs-based way, rather than relying on a generic one-size-fits-all solution. A customer service agent using an AI chatbot assistant needs different training from a data scientist building a recommendation model - and both need different training from a procurement manager evaluating AI vendors.
The Commission's Q&A is explicit on one point: in many cases, simply asking staff to read an AI system's instructions for use may be ineffective and insufficient. Handing someone a product manual does not satisfy Article 4.
A practical tiering approach
Most organisations find it useful to think in three tiers:
| Tier | Who | What they need |
|---|---|---|
| Foundation | All staff who use any AI tool at work | What AI is, how it can fail, when to flag concerns, basic data protection overlap |
| Operational | Staff who regularly operate AI systems as part of their role | System-specific risks, bias recognition, human oversight duties, escalation procedures |
| Advanced | Those procuring, building, configuring or governing AI | Technical architecture, risk assessment, regulatory obligations, vendor due diligence |
An AI system used for credit scoring requires literacy about financial inclusion risks and algorithmic bias. An AI system used for employee scheduling requires literacy about labour rights and fairness. The content of training must reflect the actual systems in use.
Building a Defensible AI Literacy Programme
Inventory every AI system your organisation uses or provides. For each system, identify which staff interact with it and in what capacity. This mapping drives everything else — you cannot calibrate training without knowing what systems are in scope and who touches them.
You are not required to formally test employees, but you do need to understand where gaps exist. A short self-assessment survey, manager review, or structured conversation with team leads is usually sufficient to identify where baseline knowledge is weakest.
Build or source training that matches each tier. Foundation content can be e-learning or short video modules. Operational and advanced tiers benefit from scenario-based learning tied to the actual systems people use. Generic AI awareness courses alone will not satisfy the proportionality requirement for high-touch roles.
At minimum, a compliant programme should address: what AI systems are and how they work at a conceptual level; risks including bias, hallucination, and over-reliance; human oversight — when and how to intervene; data protection overlap (GDPR intersects heavily with AI use); and the organisation's own AI governance policies.
Record who received what training, when, in which version of the material, and (optionally) what assessment or acknowledgement was completed. This documentation is your evidence of compliance. Without it, you cannot demonstrate to a market surveillance authority that you have met the obligation.
AI systems change. New tools get adopted. Regulatory guidance evolves. A one-time training event is not sufficient. Build annual reviews at minimum, with more frequent updates when new systems are deployed or significant guidance is published.
What the Commission's Living Repository tells us
Following the entry into application of Article 4 on 2 February 2025, the AI Office launched a repository of AI literacy practices to support learning and exchange among providers and deployers, as well as the wider public. The repository provides examples of more than 40 AI literacy initiatives implemented by companies and the public sector - from e-learning platforms and in-person trainings to bootcamps and collaboration activities between industry and academia.
The signatories who provided case studies for the repository consistently cited the use of training or e-learning programmes for staff, often split between different learning levels or topics, such as foundations or basics of AI, advanced AI, AI regulation or AI in the context of the business. Some businesses have created separate, tailored programmes for technical and non-technical staff.
One important caveat: replicating the practices collected in the living repository does not automatically grant presumption of compliance with Article 4 of the AI Act. The repository is a source of inspiration, not a compliance checklist.
Documentation: Your Evidence of Compliance
There is no obligation to measure employees' AI literacy levels, although it is important to record what training has been undertaken. This is a critical distinction. You do not need to run exams or certify staff. You do need a paper trail.
At minimum, your records should capture:
- Who completed training (by name and role)
- What they completed (module title, version, content scope)
- When they completed it (date)
- How it was delivered (e-learning, workshop, self-study)
- For which AI systems the training was relevant
Regulators will likely criticise obvious non-compliance with AI literacy requirements in any later inquiries and investigations. A useful first step is to analyse what trainings or other resources to achieve AI literacy the company has provided to its workforce in the past - and to document these measures to evidence compliance and defend against future enquiries from regulators or claims from third parties.
There is also a liability angle beyond regulatory enforcement. From 2 August 2025, providers and deployers of AI systems may face civil liability, for instance if the use of AI systems by staff who have not been adequately trained causes harm to consumers, business partners, or other third parties.
Common Myths, Debunked
We're a small company — does Article 4 really apply to us?
Yes. There is no size threshold or SME exemption for the Article 4 obligation itself. What changes is what 'sufficient' looks like in practice — a small team is not expected to run an enterprise-scale programme. A written AI use policy, a short induction covering the basics, and a simple log of who completed what is a proportionate and defensible starting point for a small organisation.
Do we need to pass employees through a formal exam or certification?
No. The AI Act does not require formal testing, certification, or any specific qualification. The obligation is to take measures to ensure a sufficient level of literacy — not to prove it through an exam. That said, some form of acknowledgement or completion record is strongly advisable as evidence of compliance.
We only use off-the-shelf AI tools like Microsoft Copilot or ChatGPT — are we really a 'deployer'?
Almost certainly yes, if you use those tools in a professional context. A deployer is any natural or legal person that uses an AI system in a professional capacity. Using a third-party AI tool at work makes you a deployer. The obligation to ensure your staff have sufficient AI literacy applies regardless of whether you built the system yourself.
The Digital Omnibus is going to remove the Article 4 obligation — can we wait?
No. The Omnibus proposes to soften the obligation (shifting from 'ensure a sufficient level' to 'support the development of AI literacy'), but it has not been formally adopted as of June 2026. The current law still applies. Even under the proposed softened version, the obligation does not disappear — and for deployers of high-risk AI systems, the training obligation for human oversight remains fully in place.
We already have GDPR training — does that count?
Partially, but not fully. GDPR training covers data protection principles, which overlap with some AI literacy topics (lawful basis for processing, data subject rights, automated decision-making under Article 22 GDPR). But AI literacy under Article 4 is broader — it must also cover how AI systems work, their specific failure modes, bias risks, and human oversight duties. GDPR training is a useful foundation, not a substitute.
What are the actual fines for breaching Article 4?
Article 4 breaches do not carry a separately specified fine tier. They fall under the general operator-obligation provisions of the AI Act. Enforcement is via national market surveillance authorities from August 2026, applying national penalty laws that Member States were required to adopt by August 2025. More practically: a lack of AI literacy training is likely to be treated as an aggravating factor in any wider AI Act enforcement action, and could ground civil liability claims if untrained staff cause harm through AI use.
An Interactive Self-Assessment: Where Does Your Organisation Stand?
Use this quick tool to identify where your AI literacy programme has gaps and what to prioritise next.
The Window Between Now and August 2026
The obligation is live now. The penalty machinery activates from August 2026. The window between is the time to build a programme that is real, role-appropriate, refreshed, and documented - so that when the supervision regime arrives, you are not building from scratch.
A lack of AI staff training and guidance will likely be seen by regulators as an aggravating factor in wider enforcement for other breaches of the EU AI Act. In other words, even if standalone enforcement of Article 4 is rare, poor AI literacy will make every other AI Act investigation harder to defend.
The organisations that are best positioned are not those that ran a single e-learning module and declared compliance. AI literacy is moving from a compliance checkbox to a core institutional capability. Organisations that treat it as a one-time training event will find themselves returning to the question repeatedly as AI systems evolve and regulatory expectations sharpen.
Start with an inventory. Build role-appropriate content. Document everything. Refresh as tools change. That is what a defensible Article 4 programme looks like.
Free tools on AI Act Navigator:
- Risk-Tier Classifier — answer a short questionnaire and get a provisional tier assessment for your AI systems, with a plain-English rationale you can share with stakeholders.
- Obligations Checker — once you know your risk tier, this page maps every relevant obligation to practical compliance steps for both providers and deployers.
- The AI Act Brief — our free newsletter covering regulatory updates, enforcement news, and plain-English explainers as the AI Act rolls out. No spam, unsubscribe any time.
Related reading

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.

Article 22 EU AI Act: The Plain-English Guide to Authorised Representatives for Non-EU Providers
If you build high-risk AI outside the EU and want to sell into the EU market, Article 22 requires you to appoint an EU authorised representative by written mandate - before you go live. Here's exactly what that means.