AI literacy policy requirements under Article 4 of the EU AI Act
If your company uses AI at all and has people operating it, the answer under EU law has been yes since 2 February 2025. What changed in 2026 is how demanding the duty is, not whether it exists.
Article 4 of the EU AI Act, Regulation (EU) 2024/1689, is the shortest obligation in the Regulation and the one that reaches the most companies. It applies to providers and deployers alike, at every risk level, and it has been in force since 2 February 2025, when Chapters I and II became applicable. The Digital Omnibus, Regulation (EU) 2026/1744, replaced its text in July 2026. It did not remove the obligation and it did not move the date.
What Article 4 says now
Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
Article 4(1), as replaced by Regulation (EU) 2026/1744.
Two further paragraphs were added. Article 4(2) requires the Commission and Member States to support providers and deployers, in particular SMEs, in meeting the duty, and obliges the Commission to publish practical examples of how to comply on the single information platform referred to in Article 62(3)(b). Article 4(3) tasks the European Artificial Intelligence Board with adopting recommendations, taking into account European competence frameworks, to support the promotion of AI literacy, including by setting common objectives.
What changed in the 2026 rewrite
| Element | Original Article 4 (2024) | Article 4 after the omnibus |
|---|---|---|
| The core verb | Take measures to ensure, to their best extent, a sufficient level of AI literacy | Take measures to support the development of AI literacy |
| Outcome guarantee | Implied by "sufficient level" | Expressly excluded: no specific level must be guaranteed for any individual |
| Who is covered | Staff and other persons dealing with operation and use on your behalf | Unchanged |
| Factors to weigh | Technical knowledge, experience, education and training, context of use, people affected | Unchanged |
| Institutional support | None in the Article | Commission practical examples, Board recommendations |
| Applies from | 2 February 2025 | 2 February 2025 |
The practical effect is a shift from an outcome duty to an effort duty. Before the rewrite, a regulator could in principle ask whether an individual employee's AI literacy was in fact sufficient. After it, the question is whether you took measures, appropriate to the roles and the context, to support literacy developing. In practice the measures themselves are what a regulator will ask to see, so they need to be documented. The recitals to the omnibus give the reason for the change directly, noting that stringent obligations to ensure a sufficient level of AI literacy were not suitable for all providers and deployers and created an additional compliance burden, particularly for smaller enterprises.
Who this applies to
Unlike the high-risk rules, Article 4 is not limited to one risk category. It applies to:
- Providers: companies that develop an AI system, or have one developed, and place it on the market or put it into service under their own name or trade mark. Substantially modifying a third-party system, or putting your own brand on it, can make you a provider of it.
- Deployers: companies using an AI system under their own authority. That includes using third-party tools: a chatbot platform, a generative writing assistant, an AI coding copilot, a meeting transcriber, a CV-screening add-on inside your applicant tracking system.
- Other persons operating on your behalf: the wording reaches beyond employees, so contractors, agency staff and an outsourced support team using your AI tooling are inside the scope.
In practice this covers almost every company with people who touch AI in any way. It does not cover your customers, who are not operating the system on your behalf, and it does not cover an employee's private use of a consumer tool outside work.
What the obligation actually requires
The Regulation sets no curriculum, no minimum hours and no certification standard. It gives you four calibration factors and expects the measures to scale with them:
- Technical knowledge, experience, education and training of the people involved. A data team and a sales team do not need the same session.
- The context the systems are used in. An internal note-taking tool and a customer-facing decision aid carry different consequences for the same mistake.
- The persons or groups the systems are used on. When outputs affect job applicants, patients, borrowers or children, the bar moves up.
- The measures being measures, not outcomes. Article 4(1) now says outright that no specific level must be guaranteed for any individual.
What Article 4 does not require
- No external certification, accreditation or approved training provider.
- No mandated number of training hours or renewal interval.
- No guarantee that any individual reaches any given standard.
- No registration or filing with an authority.
- No separate policy document, strictly speaking. A policy is simply the most economical way to show the measures exist and to keep them consistent as staff turn over.
What a policy should contain
- Scope. Which AI systems and tools the organisation uses, and who operates each one. This doubles as the start of an AI system register, which you will want anyway once a customer's procurement questionnaire asks.
- Roles and risk. Group people by what they do with AI rather than by department, because the calibration factors in Article 4 are about the use, not the org chart.
- Training content per role. Capabilities and limitations of the tools in use, foreseeable risks such as hallucination, bias and data leakage, what must never be entered into a prompt, and when a human decision is required.
- Delivery and refresh. How the instruction is given, whether onboarding session, e-learning module or written guidance, and what triggers a refresh, such as a new tool, a new use case or a material change in the law.
- Ownership. A named person responsible for keeping the policy current, and a review date.
- Evidence. A record that the training happened: attendance logs, quiz scores or completion certificates per person. This is the piece most companies skip, and the piece a regulator, auditor or enterprise customer will ask for.
Training by role: a worked matrix
| Role | Typical AI use | What the measures should cover | Depth |
|---|---|---|---|
| Marketing and content | Generative drafting, image generation | Hallucination and source-checking, Art. 50(4) deep fake and public-interest text disclosure, no confidential inputs, brand and copyright limits | Light, refreshed on new tools |
| Customer support | Chatbot, reply suggestions | Art. 50(1) disclosure at first contact, escalation to a human, no promises the bot invents, handling of personal data in transcripts | Light to medium |
| HR and recruiting | CV screening, candidate ranking | Bias and adverse impact, why a human decision is required, deployer duties under Art. 26 ahead of 2 December 2027, worker information duties | Deep |
| Engineering | Coding assistants, retrieval systems | Code provenance and licence risk, secret leakage into prompts, evaluation before shipping a model-backed feature, logging | Medium to deep |
| Finance and credit | Scoring, fraud checks | Annex III area 5(b) boundary, the fraud-detection carve-out, explainability to the customer, record keeping | Deep |
| Leadership | Procurement and approval decisions | Risk categories and which duties attach, the timeline of dates, vendor questions to ask before signing | Medium |
Three worked examples
Nine-person e-commerce firm, Prague. Uses a support chatbot and a generative writing tool. Two roles touch AI: two support agents and one marketer. A one-page policy naming both tools, a 45-minute onboarding session covering disclosure duties and prompt hygiene, a five-question quiz, and a signed attendance sheet satisfy Article 4 comfortably. Total effort is an afternoon, and the same document answers the AI question in the next enterprise customer's security review.
Sixty-person staffing agency, Warsaw. Uses a candidate ranking tool. Article 4 measures for recruiters must be deeper, because the systems are used on job applicants, which is the third calibration factor at its strongest. The same session should carry the Article 26 deployer duties that start on 2 December 2027, so that the people who will have to exercise human oversight learn what that means before the obligation binds.
Machinery manufacturer, Bavaria. Uses AI for quality control on the line and a copilot in the engineering team. The quality-control use is probably not a safety component after the omnibus added Article 6(1a), so the company is not on the high-risk path it feared. Article 4 still applies to both uses. The measures for engineers should cover when a model-backed feature would change the product's safety profile, because that is the judgment that decides whether the 2 August 2028 regime ever applies to them.
How Klariq's document pack covers this: the one-time EUR 249 pack includes an Article 4 AI-literacy policy template and a staff training module with a short quiz and a completion certificate per employee, so you have both the measures and the evidence in one place. See the free classifier to check which other documents apply to you.
What happens if you skip it
Article 4 is not listed in the Article 99(4) catalogue of provisions that carry the EUR 15 million or 3 percent ceiling. There is no AI Act fine attached specifically to failing the literacy duty. That is not the same as no exposure. Article 99(1), as amended by the omnibus, requires Member States to lay down rules on penalties and other enforcement measures, which may include administrative fines, warnings and non-monetary measures, applicable to any infringement of the Regulation, so national implementing law can attach consequences to Article 4 that the Regulation itself does not spell out.
The larger exposure is evidential. Every other AI Act duty assumes the people operating a system understand what they are operating. If you cannot show literacy measures, you weaken your position on the Article 50 disclosures, on human oversight, and on any argument that an incident was not negligent. Article 99(7)(g) tells the authority to weigh the degree of responsibility of the operator taking into account the technical and organisational measures it implemented, which is precisely what a documented literacy programme is. And where a fine does land, an SME benefits from the Article 99(6) lower-of cap, which is worth understanding before the conversation starts, not after.
Outside enforcement, the practical trigger is commercial: customer procurement questionnaires increasingly ask how AI use is governed, and a written policy with training records is the answer they expect.
A 30-day implementation plan
Week 1: inventory
- List every AI tool in use, including the ones nobody approved. Ask each team, do not guess from the software budget.
- Note for each: who operates it, what decisions its output feeds, and whose data goes in.
Week 2: classify and group
- Check each tool against the risk categories, so the training reflects real obligations rather than generic caution.
- Group people into three or four role bands by what they actually do with AI.
Week 3: write and deliver
- Write the policy: scope, roles, content per role, delivery, ownership, review date. Two pages is enough for most SMEs.
- Run the sessions. Keep them role-specific rather than one generic all-hands.
Week 4: evidence and calendar
- Collect attendance, quiz results or certificates, and store them where they can be produced on request.
- Put the review date and the onboarding trigger in a calendar, so a new hire in month seven is covered without anyone remembering.
Common mistakes
- Treating it as an IT policy. Article 4 is about the people operating the systems, so a tool-permissions document does not discharge it.
- One generic all-hands session. The Regulation asks you to calibrate to role and context; a single undifferentiated session shows the opposite.
- Policy with no record. Without a record, you cannot show the measure was taken.
- Assuming it only applies to high-risk systems. It applies at every risk level, including minimal-risk tools.
- Forgetting contractors. The wording covers other persons operating the systems on your behalf.
- Citing the old "sufficient level" wording. Guidance and templates written before July 2026 test against a standard that the omnibus removed.
Common questions
Who has to comply with the Article 4 AI literacy requirement?
Both providers and deployers of AI systems, at every risk level. Article 4 is not limited to high-risk systems. If your company uses AI in any capacity and has staff or contractors operating it on your behalf, Article 4 applies to you.
When did the AI literacy obligation start?
2 February 2025, when Chapters I and II of the AI Act became applicable. It is already in force. The Digital Omnibus, Regulation (EU) 2026/1744, replaced the text of Article 4 rather than removing it, and did not change the date it applies from.
What did the Digital Omnibus change about Article 4?
The original Article 4 required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff. The replacement requires them to take measures to support the development of AI literacy, and states that the obligation does not require guaranteeing any specific level of AI literacy of any individual. The factors to weigh, meaning technical knowledge, experience, education and training, the context of use and the people affected, survived unchanged. New paragraphs 2 and 3 task the Commission with publishing practical compliance examples and the AI Board with adopting recommendations.
What does an AI literacy policy need to contain?
A short written policy naming which AI systems the organisation uses and who operates them, what each role is taught about capabilities, limitations and foreseeable risks, how that instruction is delivered and refreshed, who owns the policy, and a record that the training actually happened. Article 4 prescribes no format, so the record is what turns the policy into evidence.
Is there a fine for not having an AI literacy policy?
Article 4 is not listed in the Article 99(4) catalogue of provisions carrying the EUR 15 million or 3 percent ceiling, so there is no AI Act fine attached specifically to it. Article 99(1) still requires Member States to lay down rules on penalties and other enforcement measures applicable to any infringement of the Regulation, so national law can attach consequences. The practical exposure is that without documented literacy measures you cannot demonstrate compliance when a regulator, customer or insurer asks.
How much AI training is enough under Article 4?
The Regulation sets no curriculum and no hours. It asks you to scale the measures to the technical knowledge, experience, education and training of the people involved, the context the systems are used in, and the people the systems are used on. Someone occasionally drafting copy with a writing assistant needs less than someone configuring a system that screens job applicants.
Does Article 4 apply to contractors and freelancers?
Yes, where they operate the AI system on your behalf. Article 4 covers staff and other persons dealing with the operation and use of AI systems on the provider's or deployer's behalf, which reaches contractors, agency staff and outsourced support teams.