← Back to Klariq Check my obligations →

AI literacy policy requirements under Article 4 of the EU AI Act

If your company uses AI at all and has people operating it, the answer under EU law has been yes since 2 February 2025. What changed in 2026 is how demanding the duty is, not whether it exists.

Article 4 of the EU AI Act, Regulation (EU) 2024/1689, is the shortest obligation in the Regulation and the one that reaches the most companies. It applies to providers and deployers alike, at every risk level, and it has been in force since 2 February 2025, when Chapters I and II became applicable. The Digital Omnibus, Regulation (EU) 2026/1744, replaced its text in July 2026. It did not remove the obligation and it did not move the date.

What Article 4 says now

Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.

Article 4(1), as replaced by Regulation (EU) 2026/1744.

Two further paragraphs were added. Article 4(2) requires the Commission and Member States to support providers and deployers, in particular SMEs, in meeting the duty, and obliges the Commission to publish practical examples of how to comply on the single information platform referred to in Article 62(3)(b). Article 4(3) tasks the European Artificial Intelligence Board with adopting recommendations, taking into account European competence frameworks, to support the promotion of AI literacy, including by setting common objectives.

What changed in the 2026 rewrite

ElementOriginal Article 4 (2024)Article 4 after the omnibus
The core verbTake measures to ensure, to their best extent, a sufficient level of AI literacyTake measures to support the development of AI literacy
Outcome guaranteeImplied by "sufficient level"Expressly excluded: no specific level must be guaranteed for any individual
Who is coveredStaff and other persons dealing with operation and use on your behalfUnchanged
Factors to weighTechnical knowledge, experience, education and training, context of use, people affectedUnchanged
Institutional supportNone in the ArticleCommission practical examples, Board recommendations
Applies from2 February 20252 February 2025

The practical effect is a shift from an outcome duty to an effort duty. Before the rewrite, a regulator could in principle ask whether an individual employee's AI literacy was in fact sufficient. After it, the question is whether you took measures, appropriate to the roles and the context, to support literacy developing. In practice the measures themselves are what a regulator will ask to see, so they need to be documented. The recitals to the omnibus give the reason for the change directly, noting that stringent obligations to ensure a sufficient level of AI literacy were not suitable for all providers and deployers and created an additional compliance burden, particularly for smaller enterprises.

Who this applies to

Unlike the high-risk rules, Article 4 is not limited to one risk category. It applies to:

In practice this covers almost every company with people who touch AI in any way. It does not cover your customers, who are not operating the system on your behalf, and it does not cover an employee's private use of a consumer tool outside work.

What the obligation actually requires

The Regulation sets no curriculum, no minimum hours and no certification standard. It gives you four calibration factors and expects the measures to scale with them:

  1. Technical knowledge, experience, education and training of the people involved. A data team and a sales team do not need the same session.
  2. The context the systems are used in. An internal note-taking tool and a customer-facing decision aid carry different consequences for the same mistake.
  3. The persons or groups the systems are used on. When outputs affect job applicants, patients, borrowers or children, the bar moves up.
  4. The measures being measures, not outcomes. Article 4(1) now says outright that no specific level must be guaranteed for any individual.

What Article 4 does not require

What a policy should contain

  1. Scope. Which AI systems and tools the organisation uses, and who operates each one. This doubles as the start of an AI system register, which you will want anyway once a customer's procurement questionnaire asks.
  2. Roles and risk. Group people by what they do with AI rather than by department, because the calibration factors in Article 4 are about the use, not the org chart.
  3. Training content per role. Capabilities and limitations of the tools in use, foreseeable risks such as hallucination, bias and data leakage, what must never be entered into a prompt, and when a human decision is required.
  4. Delivery and refresh. How the instruction is given, whether onboarding session, e-learning module or written guidance, and what triggers a refresh, such as a new tool, a new use case or a material change in the law.
  5. Ownership. A named person responsible for keeping the policy current, and a review date.
  6. Evidence. A record that the training happened: attendance logs, quiz scores or completion certificates per person. This is the piece most companies skip, and the piece a regulator, auditor or enterprise customer will ask for.

Training by role: a worked matrix

RoleTypical AI useWhat the measures should coverDepth
Marketing and contentGenerative drafting, image generationHallucination and source-checking, Art. 50(4) deep fake and public-interest text disclosure, no confidential inputs, brand and copyright limitsLight, refreshed on new tools
Customer supportChatbot, reply suggestionsArt. 50(1) disclosure at first contact, escalation to a human, no promises the bot invents, handling of personal data in transcriptsLight to medium
HR and recruitingCV screening, candidate rankingBias and adverse impact, why a human decision is required, deployer duties under Art. 26 ahead of 2 December 2027, worker information dutiesDeep
EngineeringCoding assistants, retrieval systemsCode provenance and licence risk, secret leakage into prompts, evaluation before shipping a model-backed feature, loggingMedium to deep
Finance and creditScoring, fraud checksAnnex III area 5(b) boundary, the fraud-detection carve-out, explainability to the customer, record keepingDeep
LeadershipProcurement and approval decisionsRisk categories and which duties attach, the timeline of dates, vendor questions to ask before signingMedium

Three worked examples

Nine-person e-commerce firm, Prague. Uses a support chatbot and a generative writing tool. Two roles touch AI: two support agents and one marketer. A one-page policy naming both tools, a 45-minute onboarding session covering disclosure duties and prompt hygiene, a five-question quiz, and a signed attendance sheet satisfy Article 4 comfortably. Total effort is an afternoon, and the same document answers the AI question in the next enterprise customer's security review.

Sixty-person staffing agency, Warsaw. Uses a candidate ranking tool. Article 4 measures for recruiters must be deeper, because the systems are used on job applicants, which is the third calibration factor at its strongest. The same session should carry the Article 26 deployer duties that start on 2 December 2027, so that the people who will have to exercise human oversight learn what that means before the obligation binds.

Machinery manufacturer, Bavaria. Uses AI for quality control on the line and a copilot in the engineering team. The quality-control use is probably not a safety component after the omnibus added Article 6(1a), so the company is not on the high-risk path it feared. Article 4 still applies to both uses. The measures for engineers should cover when a model-backed feature would change the product's safety profile, because that is the judgment that decides whether the 2 August 2028 regime ever applies to them.

How Klariq's document pack covers this: the one-time EUR 249 pack includes an Article 4 AI-literacy policy template and a staff training module with a short quiz and a completion certificate per employee, so you have both the measures and the evidence in one place. See the free classifier to check which other documents apply to you.

What happens if you skip it

Article 4 is not listed in the Article 99(4) catalogue of provisions that carry the EUR 15 million or 3 percent ceiling. There is no AI Act fine attached specifically to failing the literacy duty. That is not the same as no exposure. Article 99(1), as amended by the omnibus, requires Member States to lay down rules on penalties and other enforcement measures, which may include administrative fines, warnings and non-monetary measures, applicable to any infringement of the Regulation, so national implementing law can attach consequences to Article 4 that the Regulation itself does not spell out.

The larger exposure is evidential. Every other AI Act duty assumes the people operating a system understand what they are operating. If you cannot show literacy measures, you weaken your position on the Article 50 disclosures, on human oversight, and on any argument that an incident was not negligent. Article 99(7)(g) tells the authority to weigh the degree of responsibility of the operator taking into account the technical and organisational measures it implemented, which is precisely what a documented literacy programme is. And where a fine does land, an SME benefits from the Article 99(6) lower-of cap, which is worth understanding before the conversation starts, not after.

Outside enforcement, the practical trigger is commercial: customer procurement questionnaires increasingly ask how AI use is governed, and a written policy with training records is the answer they expect.

A 30-day implementation plan

Week 1: inventory

  • List every AI tool in use, including the ones nobody approved. Ask each team, do not guess from the software budget.
  • Note for each: who operates it, what decisions its output feeds, and whose data goes in.

Week 2: classify and group

  • Check each tool against the risk categories, so the training reflects real obligations rather than generic caution.
  • Group people into three or four role bands by what they actually do with AI.

Week 3: write and deliver

  • Write the policy: scope, roles, content per role, delivery, ownership, review date. Two pages is enough for most SMEs.
  • Run the sessions. Keep them role-specific rather than one generic all-hands.

Week 4: evidence and calendar

  • Collect attendance, quiz results or certificates, and store them where they can be produced on request.
  • Put the review date and the onboarding trigger in a calendar, so a new hire in month seven is covered without anyone remembering.

Common mistakes

Common questions

Who has to comply with the Article 4 AI literacy requirement?

Both providers and deployers of AI systems, at every risk level. Article 4 is not limited to high-risk systems. If your company uses AI in any capacity and has staff or contractors operating it on your behalf, Article 4 applies to you.

When did the AI literacy obligation start?

2 February 2025, when Chapters I and II of the AI Act became applicable. It is already in force. The Digital Omnibus, Regulation (EU) 2026/1744, replaced the text of Article 4 rather than removing it, and did not change the date it applies from.

What did the Digital Omnibus change about Article 4?

The original Article 4 required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff. The replacement requires them to take measures to support the development of AI literacy, and states that the obligation does not require guaranteeing any specific level of AI literacy of any individual. The factors to weigh, meaning technical knowledge, experience, education and training, the context of use and the people affected, survived unchanged. New paragraphs 2 and 3 task the Commission with publishing practical compliance examples and the AI Board with adopting recommendations.

What does an AI literacy policy need to contain?

A short written policy naming which AI systems the organisation uses and who operates them, what each role is taught about capabilities, limitations and foreseeable risks, how that instruction is delivered and refreshed, who owns the policy, and a record that the training actually happened. Article 4 prescribes no format, so the record is what turns the policy into evidence.

Is there a fine for not having an AI literacy policy?

Article 4 is not listed in the Article 99(4) catalogue of provisions carrying the EUR 15 million or 3 percent ceiling, so there is no AI Act fine attached specifically to it. Article 99(1) still requires Member States to lay down rules on penalties and other enforcement measures applicable to any infringement of the Regulation, so national law can attach consequences. The practical exposure is that without documented literacy measures you cannot demonstrate compliance when a regulator, customer or insurer asks.

How much AI training is enough under Article 4?

The Regulation sets no curriculum and no hours. It asks you to scale the measures to the technical knowledge, experience, education and training of the people involved, the context the systems are used in, and the people the systems are used on. Someone occasionally drafting copy with a writing assistant needs less than someone configuring a system that screens job applicants.

Does Article 4 apply to contractors and freelancers?

Yes, where they operate the AI system on your behalf. Article 4 covers staff and other persons dealing with the operation and use of AI systems on the provider's or deployer's behalf, which reaches contractors, agency staff and outsourced support teams.

This page is general information about Regulation (EU) 2024/1689, Article 4, as replaced by Regulation (EU) 2026/1744, not legal advice, and does not replace a case-by-case legal assessment. Article text was checked against the consolidated Official Journal texts. Last verified: 27 August 2026.