AI Literacy Under the EU AI Act: What Article 4 Now Requires

Key takeaways

  • AI literacy is a binding obligation under Article 4 of the EU AI Act. It applies to every provider and deployer, at every risk tier, and has done since 2 February 2025.
  • The Digital Omnibus rewrote Article 4 with effect from 27 July 2026. The duty is now to take measures that support the development of AI literacy, not to guarantee a particular level in any individual.
  • National market surveillance authorities began supervising and enforcing Article 4 on 2 August 2026. The AI Office does not enforce it.
  • The Commission requires no certificates and no testing of employee knowledge. It does expect an internal record of what you did.
  • The practical exposure is not an untrained workforce. It is a trained workforce you cannot evidence.
AI literacy under EU AI Act Article 4, illustration of an open book

What AI literacy means under the EU AI Act

Most of what is written about AI literacy describes a personal capability: knowing what a model is, writing better prompts, spotting a hallucination. The EU AI Act means something narrower and more consequential.

Article 3(56) of Regulation (EU) 2024/1689 defines AI literacy as the “skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause”.

Three things follow from that wording. The measure of AI literacy is informed deployment, not tool proficiency. Someone can be fluent with a chatbot and illiterate in the Act’s sense, because they cannot tell you what the system does to the people it is used on. The definition is explicitly relative to “respective rights and obligations”, so the literacy a procurement lead needs is not the literacy a data scientist needs. And the definition reaches “affected persons”, not only the people operating the system.

This is why AI literacy sits closer to your compliance programme than to your learning and development budget. It is one of the foundational duties in the EU AI Act operator’s guide, and it attaches to the organisation rather than to a specific system.

Article 4 changed in July 2026

The version of Article 4 that applied from 2 February 2025 told providers and deployers to “ensure, to their best extent, a sufficient level of AI literacy” among their staff. That wording created two years of argument about what “sufficient” meant and how anyone would prove it.

The Digital Omnibus settled the argument by removing the word. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Article 4 now requires providers and deployers to “take measures to support the development of AI literacy”, and states that the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”.

Read carefully, this is a change of legal nature, not a repeal. Article 4 has moved from an obligation of result to an obligation of effort. You are no longer answerable for how literate any given employee turns out to be. You are answerable for the measures you took. That is a lower substantive bar and a higher documentary one, because effort is only visible if it leaves a trace.

What did not change

The scope did not move. Article 4 still binds both providers and deployers, and it is still ungated by risk tier: it applies to a spam filter as much as to a system listed in Annex III. Nothing in the rewrite narrows the audience or excuses smaller organisations. Article 4(2) still obliges the Commission and Member States to support compliance, with particular attention to SMEs, and Article 4(3) still tasks the Board with recommendations that draw on European competence frameworks. If you built an AI literacy programme against the old text, none of it is wasted. What changed is what you are defending when someone asks.

Who is covered, and who counts as staff

Article 4 reaches “staff and other persons dealing with the operation and use of AI systems on their behalf”. The second half of that phrase does most of the work, and it is where organisations underscope.

The Commission AI Office Q&A reads “other persons” to include contractors, service providers and clients. Anyone acting on your behalf in the operation or use of an AI system is inside the perimeter, whether or not they are on your payroll.

The Centre for Information Policy Leadership, in its May 2025 paper on Article 4, recommends casting the net wider still: the workforce across all business units including sales and marketing, contractors, third-party vendors, clients and customers, users, and individuals affected by the organisation’s use of the system. The reasoning is practical rather than legalistic. The people who create Article 4 exposure are rarely the model builders. They are the account manager who promises a capability the system does not have, and the operations team quietly running a tool nobody registered.

That second failure mode is worth naming, because AI literacy and shadow AI are the same problem seen from two directions. Staff cannot be literate about systems the organisation has not admitted it uses.

Enforcement started on 2 August 2026

Here is the fact missing from almost every article on AI literacy: the obligation is now enforceable.

National market surveillance authorities began supervising and enforcing Article 4 on 2 August 2026. The AI Office does not enforce it. Enforcement sits with the designated authority in each Member State, which means the posture, appetite and procedure differ by country.

The penalties come from national law. Under Article 99, Member States were required to lay down their own rules on penalties and other enforcement measures by 2 August 2025, within a tiered ceiling: up to EUR 35 million or 7% of global annual turnover for prohibited practices, up to EUR 15 million or 3% of global annual turnover for most other operator obligations, and up to EUR 7.5 million or 1.5% for supplying misleading information to authorities. Article 4 falls in the middle band. Penalties must be proportionate, taking into account the nature and gravity of the infringement and whether it was intentional or negligent.

Notice the sequence. The substantive bar was lowered on 27 July 2026. The enforcement powers switched on six days later. An organisation reading only the Omnibus headline would conclude that Article 4 got easier, and would be right about the standard and wrong about the risk. Before 2 August 2026 a weak AI literacy programme was a paper problem. After it, the same programme is something an authority can ask about, and the proportionality test rewards organisations that can show deliberate effort rather than none. This is the same enforcement architecture described in the AI regulatory landscape: the obligations arrive first, the supervisory machinery follows, and the gap between the two is where unprepared operators sit.

What regulators will actually ask to see

The Commission has been unusually direct about what Article 4 does not require. From the AI Office Q&A: “There is no need for a certificate.” And: “Article 4 of the AI Act does not entail an obligation to measure the knowledge of AI of employees.”

So there is no mandated curriculum, no accreditation, no exam, and no obligation to score your staff. What the Commission recommends instead is that organisations keep “an internal record of trainings and/or other guiding initiatives”. No format is prescribed.

That sounds permissive until you pair it with the high-risk documentation duties. CIPL makes the point precisely: there is no explicit technical obligation under Article 4 to document a workforce’s literacy for most systems, but “providers and deployers of high-risk AI systems are required to document and demonstrate compliance with certain AI Act obligations, and AI literacy practices may be treated as within scope of that obligation”. If you operate anything high-risk, your AI literacy evidence can be pulled into the Article 11(1) and Annex IV technical file, which is covered in more detail in our guide to AI system documentation requirements.

The minimum defensible file

An obligation of effort is defended with artefacts. Six of them cover most of the ground:

  1. A role-to-competence matrix saying which roles need which understanding, and why.
  2. A training register recording who received what, on what date, in what format.
  3. Policy acknowledgements tying staff to the organisation’s rules on acceptable AI use.
  4. A common AI taxonomy, so that “AI system” means the same thing in procurement, legal and engineering.
  5. An inventory of assessed use cases, which is what makes the taxonomy operational rather than decorative.
  6. A review cadence with a named owner and a signature, showing the programme is maintained rather than filed.

None of that requires certificates. All of it survives a question.

Building a programme that produces evidence

CIPL’s paper sets out eight best practices for Article 4. Reframed as controls rather than advice, they collapse into a shorter operating model.

Start with sponsorship. AI literacy programmes that live inside a training function stall; the ones that work are visibly owned above it. Then integrate rather than isolate: organisations subject to Article 4 are almost always subject to data protection, cybersecurity, consumer protection and sectoral rules at the same time, and running AI literacy as a standalone module duplicates effort and fragments the evidence. It belongs inside the existing AI governance framework.

Role-tiered, not one-size-fits-all

A single company-wide module is the most common design and the weakest one. It satisfies nobody’s actual need and produces a register that shows uniform treatment of very different exposures.

The alternative is a baseline for everyone, then targeted modules keyed to role, expertise and how much the person actually touches the system. Where resources are limited, CIPL suggests scaling first to the stakeholders who create the most impact or interact most with the technology. In practice that usually means procurement, sales, and whoever operates customer-facing automation, well before the data science team that already understands the risks.

Beyond training

Training alone decays faster than the technology changes. The mechanisms that hold are structural: a responsible AI board with representation from each business unit, named AI champions who can judge when an issue needs escalating, a decision tree that tells a team whether what they are building meets the organisation’s own definition of an AI system and what to do next, an anonymous channel for flagging risky use, and a feedback loop with tracked indicators so the programme adjusts as the rules and the tools move.

Each of those produces a record as a by-product. That is the point. A control that generates evidence while running is worth more than a control that has to be reconstructed for an inspection.

How AI literacy maps to ISO 42001 and NIST AI RMF

If you are already working toward a management system, most of the Article 4 work is done.

ISO/IEC 42001:2023 clause 7.2 requires an organisation to determine the competence necessary for people whose work affects the performance of the AI management system, to ensure they are competent, and to retain documented information as evidence of that competence. Clause 7.3 requires those same people to be aware of the AI policy and of their contribution to it. That is Article 4’s substance, expressed as an auditable clause with a retention requirement attached.

The NIST AI Risk Management Framework covers the same ground under GOVERN, particularly GOVERN 4 on cultivating a culture of risk management and GOVERN 5 on engagement with relevant AI actors.

The leverage is in not building three programmes. One role-to-module competence matrix, maintained on a documented review schedule signed by the governance owner, can satisfy EU AI Act Article 4, ISO 42001 clause 7.2 and NIST AI RMF GOVERN 4 from a single audit trail. Our cross-mapping of NIST AI RMF, ISO 42001 and the EU AI Act sets out where the rest of the obligations overlap, and the standards stack analysis explains why certification alone does not close the gap.

FAQ

What is the meaning of AI literacy?

Under Article 3(56) of the EU AI Act, AI literacy is the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems and to be aware of the opportunities, risks and possible harms involved. It is defined relative to a person’s rights and obligations, so the standard differs by role. This is narrower than the general-purpose meaning of AI literacy used in education, which usually describes personal capability with AI tools.

What is an example of AI literacy?

A recruiter who can explain what an automated screening tool scores candidates on, knows it must not be the sole basis for a rejection, recognises when an output looks anomalous, and knows who to escalate to. Note what is absent: no ability to build the model, and no technical vocabulary. The recruiter can make an informed decision about a system they do not personally operate at a technical level, which is what the Act asks for.

What is needed for AI literacy?

At organisational level: a shared definition of what counts as an AI system, an inventory of where those systems are used, a baseline of understanding across the workforce, targeted depth for roles with real exposure, and a record of the measures taken. At individual level, the requirement scales to the person’s role, technical knowledge, experience, and the context in which the system is used.

Is AI literacy training mandatory under the EU AI Act?

Training is the usual method, but it is not itself mandated. Article 4 requires measures that support the development of AI literacy. Formal courses count, and so do guidance documents, internal briefings, decision trees and practical support. The Commission has confirmed there is no need for a certificate and no obligation to measure employees’ AI knowledge.

What happens if we do not comply with Article 4?

Since 2 August 2026, national market surveillance authorities can supervise and enforce Article 4. Penalties are set by national law within the Article 99 ceilings, and obligations of this class sit in the band capped at EUR 15 million or 3% of global annual turnover. Penalties must be proportionate to the nature and gravity of the infringement and to whether it was intentional or negligent, which is why documented effort matters even where the outcome is imperfect.

Does AI literacy apply to companies outside the EU?

Yes, where the AI Act applies to you. The Regulation reaches providers placing systems on the EU market and deployers established in the Union, as well as certain non-EU operators whose system output is used in the Union. A US or UK company that deploys AI affecting people in the EU carries the same Article 4 duty as a company headquartered in the Union.

Conclusion

AI literacy has quietly become one of the few AI Act obligations that touches every organisation, at every risk tier, right now. The Digital Omnibus made the standard easier to meet and, by arriving days before enforcement began, made it harder to ignore.

The organisations that will struggle in an inspection are not the ones with untrained staff. They are the ones whose training happened but left no trace: no matrix, no register, no owner, no review date. Treat AI literacy as a foundational control that produces evidence as it runs, map it once to ISO 42001 and NIST AI RMF, and the Article 4 question answers itself.

If you want to see how AI literacy fits alongside the rest of your obligations as a managed, evidenced control, explore how AI Sigil operationalises AI governance.

Data Governance Framework: From Pillars to Proof

A data governance framework that satisfies auditors, not just committees: the four pillars re-scoped to EU AI Act Article 10, ISO 42001 A.7 and NIST AI RMF.

Conformity Assessment Under the EU AI Act: 2027 Guide

Conformity assessment is how a high-risk AI system proves it complies. The Article 43 routes, the Annex IV evidence, and the December 2027 deadline.

AI Red Teaming: From Security Test to Audit Evidence

AI red teaming is now an enforceable EU AI Act duty for GPAI providers. What Article 55 requires, who is bound, and the evidence auditors ask for.

AI Literacy Under the EU AI Act: What Article 4 Now Requires

AI literacy is now enforceable under EU AI Act Article 4. What the Digital Omnibus changed, who is covered, and the evidence regulators expect.

AI Assurance: How to Prove an AI System Is Trustworthy

AI assurance is how you measure, evaluate and communicate that an AI system works. See the mechanisms, the standards and the EU AI Act evidence chain.

AI Impact Assessment: Which Regime Actually Applies to You

An AI impact assessment is not one duty but six. Map the EU AI Act Article 27 FRIA, ISO 42005 and GDPR DPIA to what your organisation owes.