Posted in

EU AI Act Article 4 AI Literacy: Requirements, Role-Based Training & Compliance Checklist

EU AI Act Article 4 AI literacy compliance guide

EU AI Act Article 4 AI literacy is the obligation most organizations have prepared for least. It has applied since 2 February 2025, national market surveillance authorities began supervising it from early August 2026 (the Commission’s own materials have cited both 2 and 3 August 2026), and the Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026 — amended its wording. Much of the published guidance still reflects text that no longer exists in the Regulation. What follows maps the current obligation, a role-based training architecture, and the documentation an authority would request.

What Article 4 Requires Under the Amended Text

Diagram of EU AI Act Article 4 obligation of means for AI literacy

The current Article 4 as amended by the Digital Omnibus provides that providers and deployers of AI systems “shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf.” Two elements govern how those measures must be shaped: the technical knowledge, experience, education and training of the persons concerned, and the context in which the AI systems are used, including the persons or groups of persons on whom the systems are used.

The amended paragraph adds a sentence with no counterpart in the original text: the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual.” The Commission’s own reading of the change is that AI literacy remains an obligation for providers and deployers, but no specific — or “sufficient” — level is mandated. Read together, the amended duty operates as an obligation of means: an organization must take measures, shape them to its systems and people, and be able to show that it did. What the amendment removes is outcome liability for any individual’s level of literacy. What it leaves intact is everything else — the duty to act, the calibration factors, and the need for evidence.

Two further paragraphs complete the provision. Under Article 4(2), the Commission and Member States are tasked with supporting and facilitating providers’ and deployers’ efforts — in particular those of SMEs — including through practical examples of compliance published by the Commission on the Single Information Platform. Under Article 4(3), the AI Board is to adopt recommendations, taking account of European competence frameworks, to support the Commission and Member States in the promotion of AI literacy, including by setting out common objectives. Those recommendations and examples do not yet exist as binding standards. They are reference points a programme should be built to absorb, and the measure of compliance today remains the amended text itself.

The substance those measures must serve is fixed elsewhere in the Regulation. Article 3(56) defines AI literacy as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems and to gain awareness of the opportunities, risks and possible harm AI can cause. Analytical emphasis belongs on the word “informed”: the obligation calls for the capacity to recognize what a system is doing, where it can fail, and when human judgement should override an output — informed deployment, not mastery of every tool.

Official guidance fills the deliberate flexibility in the text. The European Commission’s official AI literacy questions and answers set out a four-step analytical sequence for any programme: establish what AI is used in the organization and why; establish whether the organization acts as provider or deployer; assess the risk profile of the systems in use, since higher-risk systems call for more thorough measures; and build the resulting actions around the differences in staff knowledge and the context of use. Guidance of this kind shapes supervisory expectations without being law — that distinction is preserved throughout what follows.

Who Is Covered — and Who Enforces

Diagram showing who the EU AI Act Article 4 AI literacy duty covers and who enforces it

Two groups carry the duty: providers, meaning organizations that develop AI systems or place them on the market under their own name, and deployers, meaning organizations that use AI systems in a professional context. Importers and distributors have no direct Article 4 obligation of their own. Because the duty attaches to the act of providing or deploying, it reaches organizations regardless of size and regardless of whether their systems fall into any risk category under the Regulation. A company whose employees use a general-purpose chatbot for advertising copy and translation sits inside Article 4, and Commission guidance states expressly that such users should be informed about the specific risks of those tools, including hallucinated output.

The phrase “staff and other persons dealing with the operation and use of AI systems on their behalf” extends the obligation beyond the payroll. Contractors, agency personnel and service providers operating the organization’s systems carry the same need for calibrated measures as employees, and Commission guidance applies this on the same footing. Training employees while leaving the contingent workforce outside the programme is a scope error the text itself invites — the kind an authority testing the breadth of measures would probe first.

Enforcement sits with the market surveillance authorities designated by each Member State under Regulation (EU) 2019/1020, with supervision of Article 4 live since early August 2026. On penalties, a genuine interpretive wrinkle deserves attention: Article 99(4) is an enumerated list of specific provisions carrying the €15 million or 3% tier — provider and deployer duties, Article 25, Article 50 transparency, among named others — and Article 4 does not appear on it. A bare Article 4 failure standing alone has no named EU-level fine tier; exposure for that gap alone runs through whatever penalty regime the relevant Member State has attached under its own transposing law, which varies by jurisdiction. Where an Article 4 gap surfaces alongside a breach of a provision that is enumerated in Article 99(4) — a high-risk deployer’s failure to train named overseers under Article 26, for instance — the documented literacy gap functions as an aggravating factor within that EU-level fine, not as a separate exposure of its own.
No public enforcement decision on Article 4 had been issued at the time of writing. The posture of supervisors is not yet observable; the rational response to that asymmetry is a documented programme.

One distinction belongs here because it is the most consequential misreading of the provision. Deployers of high-risk AI systems carry a separate, stricter training duty: they must ensure that persons assigned to implement the instructions for use and to exercise human oversight have the necessary competence, training, authority and support. That duty survived the Digital Omnibus and is cumulative with Article 4 — baseline literacy for everyone who touches AI, oversight-grade training for the named individuals responsible for high-risk systems. Treating one as a substitute for the other understates both.

AI Literacy Training for Employees: A Role-Based Architecture

Five-tier AI literacy role-based training pyramid for EU AI Act Article 4

Article 4 does not prescribe a curriculum. The calibration factors in Article 4(1) supply the design logic: the same organization will need materially different measures for a data scientist tuning models than for a facilities manager approving AI-generated invoices. The architecture below builds on the Commission’s own internal approach, which the European Commission’s official AI literacy questions and answers describe as tiered learning packages — essential modules for all staff, with highly recommended and recommended packages layered on top. A private organization can adapt that structure without inheriting the Commission’s scale.

The baseline module: everyone who touches an AI tool

Every person who operates or uses an AI system on the organization’s behalf receives the same foundational unit, whether they hold a permanent contract or sit on a vendor’s payroll. Its content is deliberately narrow: what the specific AI tools used in the organization are and what they are for; where those tools characteristically fail; awareness of the practices prohibited under Article 5; safe handling of data entered into general-purpose systems; and a named escalation path for outputs that look wrong. The calibration factor that matters most at this layer is the context of use. An administrator pasting customer correspondence into a chatbot faces a different failure mode than a designer using image generation, and the baseline module should reflect the organization’s actual toolset rather than a generic catalogue of AI.

Technical roles: developers, ML engineers and data teams

The depth difference for technical staff is substantial because their decisions shape the systems everyone else relies on. Content at this layer extends to model behavior and known limitations, data quality and provenance, bias detection and correction techniques, and the interface between the training programme and the organization’s broader AI risk management. One regulatory change from the Digital Omnibus belongs in this module: a dedicated legal basis, now codified as Article 4a and applicable from 2 August 2026, permits providers and deployers to process special categories of personal data for the sole purpose of detecting and correcting bias in AI systems, subject to safeguards — extending a privilege previously confined to high-risk development. A module that teaches technical staff how to use that authority responsibly, and where its limits sit, now serves a concrete compliance function.

Deployer-side operators

Between the builders and the occasional users sit the employees who run AI systems as part of a defined workflow: analysts working with predictive outputs, recruiters using screening tools, claims handlers assisted by classification systems. This layer needs operational depth. The module should cover working strictly within the provider’s instructions for use, recognizing output anomalies and drift, the operator’s role in monitoring duties, and the specific conditions under which use must be suspended and a human decision substituted. Where the system is high-risk, this group overlaps most often with the named overseers discussed below, and the training records of that overlap deserve particular care.

Named human overseers of high-risk systems

Where an organization deploys a high-risk AI system, it must assign human oversight to specific persons and ensure those persons can assess input data relevance, remain aware of automation bias, and intervene or interrupt the system. Article 4 requires those individuals to hold a deeper level of AI literacy than other staff, and the deployer must ensure the persons assigned to oversight — and those implementing the instructions for use — have the necessary competence, training, authority and support. The training records for this group are the documents an inspector will request first, because this is the only Article 4-related duty that names individuals rather than the workforce as a whole. Per-person records should capture role, module version, completion date and assessment results attached to the named individual instead of filed at cohort level. Baseline literacy measures “support the development” across the organization; oversight training under Articles 14 and 26 attaches to identifiable people performing a statutory function, and the records must show that difference.

Executives, legal counsel, risk and procurement

The final layer is the smallest in headcount and the widest in consequence. Executives and board members need enough literacy to discharge oversight duties over the organization’s AI governance: what the systems do in aggregate, where the regulatory exposure concentrates, and what the accountability chain looks like when something fails. Legal and risk functions need literacy pitched at interpretation — reading provider documentation and conformity assessments, mapping system changes to regulatory triggers, judging when a deployment shifts risk categories. Procurement staff occupy a frequently missed position, because vendor claims about a system’s capabilities and compliance status enter the organization through their decisions. A module covering how to read and challenge AI vendor documentation closes a gap that technical training elsewhere cannot reach.

Each layer answers the same test — more knowledge where technical decisions are made, more context where outputs touch people, more authority where intervention carries consequences — and the calibration rationale linking each role to those factors is itself part of the evidence plan the next section specifies.

AI Literacy Documentation and Evidence: What to Retain

Five-component evidence pack for EU AI Act Article 4 AI literacy

A literacy programme that cannot be produced on request is, from a supervisory standpoint, indistinguishable from no programme. Commission guidance states that no certificate is needed and that organizations may keep an internal record of trainings and initiatives; the Regulation itself mandates no particular governance structure for Article 4. That flexibility is a documentation problem wearing a compliance costume. The measures must exist, must be calibrated, and must leave a trail an authority can inspect — and the trail, not the training, is where most organizations are exposed.

The evidence pack has five components. The first is a written AI literacy policy or programme document carrying a named owner, the scope of covered persons, and the calibration logic that connects each role to the Article 4(1) factors. The second is per-individual training records for the roles where individuals matter — named human overseers first — capturing person, role, module, version, date and assessment result. The third is per-cohort completion summaries for the wider workforce, sufficient to demonstrate coverage without building a personal file on every employee. The fourth is the calibration rationale: the documented reasoning that says why developers receive one curriculum and executives another. The fifth is the refresh trigger register described below. An inspector who receives these five artefacts can reconstruct the programme’s design, coverage and currency in a single sitting. One who receives a Learning Management System export and nothing else cannot.

Two cautions govern the surrounding practice. The Commission maintains a Living Repository of AI literacy practices as a learning bench for organizations building programmes; using or replicating those practices confers no presumption of compliance, and guidance states this plainly. The repository is a source of design ideas, not a safe harbor. Separately, the AI Board’s recommendations on common objectives for literacy measures under Article 4(3), together with the practical examples the Commission will publish under Article 4(2), are pending reference points rather than current standards. A well-built programme does not need to anticipate their content; it needs a structure that lets their arrival land as an update within the architecture instead of forcing a rebuild.

The refresh register converts a static programme into a living one. Trigger events fall into three families: regulatory change, system change and personnel change. Regulatory change covers amended obligations, new Board recommendations, new Commission examples and newly designated national supervisory guidance. System change covers the deployment of any new AI system, the material reconfiguration of an existing one, or a shift in risk category that moves a tool into or out of high-risk treatment. Personnel change covers the movement of an employee into a named oversight role, the engagement of a new contractor category, or the arrival of a workforce segment the original calibration did not contemplate. Each trigger maps to a defined action — content update, targeted retraining, or recalibration of the role matrix — so that the register functions as an operational control.

How to Comply With Article 4: The Compliance Checklist

The following checklist consolidates the obligations, the calibration logic and the evidence requirements into a sequence a compliance team can execute and an internal audit function can test. Each item is checkable as written.

  • Approve a written AI literacy policy with a named individual owner, covering providers and deployers in scope, and record the approval date.
  • Inventory every AI system in use and assign each a provider or deployer designation, since the duty attaches differently to each role.
  • Map every covered person to a training layer — baseline, technical, operational, oversight or executive — using the Article 4(1) calibration factors, and document the mapping rationale.
  • Assign the baseline module to all staff and to all contractors, agency personnel and service providers who operate AI systems on the organization’s behalf.
  • Deliver oversight-grade training to every named human overseer of a high-risk system and retain per-individual records instead of cohort summaries for this group.
  • Confirm the programme content reflects the amended Article 4 text and the current obligation to support the development of AI literacy.
  • Assemble the evidence pack: policy document, per-individual oversight records, cohort completion summaries, calibration rationale, refresh register.
  • Verify the evidence pack is retrievable within one business day in exportable form, independent of any single administrator.
  • Define the three trigger families — regulatory, system, personnel — with an owner and a response action for each.
  • Monitor the AI Board’s recommendations under Article 4(3) and the Commission’s practical examples under Article 4(2) as they appear, and log programme updates against them.

Items one through six build the programme; items seven through ten keep it defensible. An organization that completes the first six and neglects the last four has a training initiative. An organization that completes all ten has a programme it can defend in front of a market surveillance authority.

Failure Patterns That Attract Supervisory Attention

Five common Article 4 AI literacy compliance failure patterns

Five failure patterns recur across published guidance, supervisory commentary and the text of the Regulation itself. None requires an enforcement decision to be credible; each follows directly from what Article 4 and the Commission’s questions-and-answers document say.

The single onboarding video. The most common artefact presented as an Article 4 programme is one generic training module assigned at onboarding and never revisited. The Commission has stated that AI literacy is a continuous learning process and that one-off training does not constitute a compliant approach. A video watched once, untailored to the organization’s systems, uncalibrated to any role and unrefreshed since deployment, fails on every calibration factor simultaneously. The failure lies in the absence of everything around it: role differentiation, context specificity and a documented refresh cycle. The medium itself can be legitimate — an e-learning module is a normal component — but alone it satisfies none of the calibration factors.

The belief that the Omnibus repealed the obligation. Coverage of the Digital Omnibus focused on deferred deadlines and softened penalties, and some compliance teams concluded that Article 4 went away with the amendments. It did not. The obligation survives in amended form, in force since February 2025, with supervision live under the original governance track. An organization that stood down its literacy programme on the strength of a headline now holds an undocumented gap in a live obligation — the exact configuration an authority’s first inspection question would expose.

Treating literacy as a substitute for oversight training. Article 4 measures and the training of named human overseers are cumulative duties. An organization that trains its whole workforce to baseline standard has satisfied neither duty fully: the baseline does not confer the competence, authority and support that Articles 14 and 26 attach to named individuals, and oversight training does not reach the contractor pasting data into a chatbot. Programmes that budget for one and present it as both leave the second duty entirely uncovered.

Training employees only. The text obliges organizations to support the development of AI literacy for their staff and other persons dealing with the operation and use of AI systems on their behalf. Guidance applies this to service providers and contractors on the same footing as employees. The failure pattern is structural: Learning Management Systems key on employee ID, procurement contracts rarely embed training clauses, and the contingent workforce drifts outside the programme by default. Closing it requires a scope decision recorded in the policy document.

No documentation. Because Article 4 mandates no certificate, no audit and no prescribed governance structure, organizations default to producing nothing. Supervisory practice under Regulation (EU) 2019/1020 treats documentation as the primary evidence of conformity for any obligation. A literacy programme described orally by a compliance officer demonstrates intention; documentation demonstrates measures. The five-component evidence pack in the preceding section exists precisely because the burden of demonstration sits with the organization, and nothing in the amended text moves it.

How Article 4 Sits on the Post-Omnibus TimelineEU AI Act Article 4 AI literacy compliance timeline from 2025 to 2028

The Digital Omnibus redrew the compliance calendar, and the redraw matters for Article 4 more than the amendment of its wording does. Under the adopted changes made by Regulation (EU) 2026/1744, most obligations attaching to high-risk AI systems listed in Annex III — the systems that drive the largest share of enterprise compliance spend — apply from 2 December 2027 rather than the original date of 2 August 2026, while systems embedded in products covered by Annex I legislation moved to 2 August 2028. Organizations that re-planned their entire AI compliance programme around those deferred dates did so correctly for high-risk obligations.

The deferral does not touch Article 4. Literacy and governance duties for providers and deployers — Article 4 among them — sat on the original governance track and took effect in early August 2026, alongside the transparency duties and alongside the prohibitions in force since February 2025. The practical consequence is a two-speed exposure that many re-planned programmes have missed. An organization with no high-risk systems and a deferred compliance calendar is nonetheless supervised for Article 4 now. An organization with a fully staffed high-risk programme but no workforce literacy measures is exposed on the obligation most likely to be tested first, because verification requires a records request rather than a technical assessment.

The asymmetry resolves in the Regulation’s design. Article 4 is the floor obligation: it applies to every provider and deployer, its evidence is administrative, and its verification is cheap for an authority with limited inspection capacity. As Member States designate their market surveillance authorities and publish supervisory expectations, the organizations positioned earliest for inspection are those whose compliance documentation is thinnest — which, across the published guidance landscape, describes the literacy obligation more often than any other. The two tracks converge in December 2027 when the deferred high-risk obligations activate. By then, literacy measures will have been a supervised obligation for over a year.

Compliance Priorities Before the Next Milestones

The sequence of actions follows from where the exposure sits. Three priorities are immediate, two are design decisions for the near term, and two are watch items that convert pending regulatory outputs into programme updates.

Immediate. First, audit the programme’s documentation against the current text of Article 4: any policy, training content or internal guidance quoting the pre-amendment obligation should be reissued against the amended wording, with the reissuance itself recorded. Second, close the contingent workforce gap by amending procurement and engagement contracts for categories of contractors and service providers who operate the organization’s AI systems, with completion tracked as a named action. Third, assemble the five-component evidence pack — policy document, oversight records, cohort summaries, calibration rationale, refresh register — and test its retrievability with a timed drill. An evidence pack that takes three weeks to compile will not survive a records request.

Near term. Design the programme’s structure so that pending regulatory outputs arrive as updates rather than rebuilds. The AI Board’s recommendations under Article 4(3) and the Commission’s practical examples under Article 4(2) will supply common objectives and worked illustrations; a programme whose calibration rationale is documented can absorb either by adjusting content within an existing architecture, while a fixed course catalogue will need replacement. Aligning the calibration matrix with European competence frameworks referenced in the legislative materials — including DigComp — positions the programme to map cleanly onto whatever the Board recommends, without anticipating content that has not been published.

Watch items. Two developments warrant standing monitoring with assigned owners. The Commission’s practical examples on the Single Information Platform will show how the institution that wrote the obligation interprets its own flexibility, and they will likely become the de facto benchmark in supervisory dialogue. National market surveillance authorities, as they designate and publish supervisory priorities, will convert the abstract obligation into concrete inspection practice; guidance from the authority in each Member State of operation belongs in the refresh register’s regulatory-change family. Neither output exists yet as a compliance standard. Both will function as one the moment they appear, which is why they belong on a watch list with owners attached.

EU AI Act Article 4 AI Literacy: Frequently Asked Questions

Was Article 4 repealed or removed by the Digital Omnibus?

No. Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended Article 4 and entered into force on 27 July 2026. The obligation to take measures supporting the development of AI literacy remains; the calibration factors are unchanged; and the duty has applied since 2 February 2025. The amendment also added that the obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual — in the Commission’s own reading, no specific or “sufficient” level is mandated. What the amendment changed is the operative verb: “ensure” became “support the development of.” What it did not do is remove the duty.

What happens to literacy programmes built under the pre-amendment obligation?

Measures taken under the original text remain valid evidence of compliance; organizations are not required to start over. Two actions are prudent. Reissue policy and training materials so internal documents quote the amended wording, and record the reissuance in the evidence pack — a programme documented against repealed text invites questions an authority would otherwise not ask. Review the programme against the practical examples the Commission will publish under Article 4(2) on the Single Information Platform, since those examples will function as the working benchmark for supervisory dialogue even though they carry no presumption of compliance.

Does the EU AI Act require an AI literacy certificate?

No. Commission guidance states that no certificate is required and that organizations may keep an internal record of trainings and initiatives; the Regulation mandates no particular governance structure for Article 4. The absence of a certificate requirement does not relax the underlying duty. Measures must still exist, be calibrated to the organization’s systems and people, and leave documentation an authority can inspect.