EU AI Act Article 4: the AI literacy obligation, explained

Last updated: 15 August 2026

Article 4 of the EU AI Act is the one obligation in the regulation that reaches almost every organisation using AI at work — and the one most often assumed, wrongly, to have been delayed.

The short answer. Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures aimed at supporting a sufficient level of AI literacy among their staff and anyone else operating AI systems on their behalf. It has applied since 2 February 2025. National authorities gained formal supervisory powers on 2 August 2026. It applies whether or not your AI is high risk, and the high-risk deferrals agreed in the Digital Omnibus did not touch it.

What does Article 4 actually require?

It requires you to take measures aimed at supporting a sufficient level of AI literacy among the people who operate AI systems for you. It does not require a certificate, a specific course, a named qualification or a minimum number of training hours. The regulation deliberately sets no fixed standard.

Following the Digital Omnibus — endorsed by the European Parliament on 16 June 2026 and approved by the Council on 29 June 2026 — the wording shifted from an obligation to ensure a sufficient level of AI literacy to an obligation to support its development. In practice that turns it from an obligation of result into an obligation of effort. The question a regulator asks is no longer “did you guarantee literacy?” but “what did you do about it, and can you show us?”

The European Commission set out a working minimum in its May 2025 FAQs on AI literacy. Organisations should:

  • Ensure general AI understanding — staff should know what AI is, how it works, which AI systems the organisation uses, and the opportunities and risks that come with them.
  • Define organisational roles — be clear about whether you develop AI systems or simply use systems supplied by others, because the obligations differ.
  • Identify risks — explain the risks associated with the specific AI systems in use, and the mitigations that apply.

There is no one-size-fits-all standard. The assessment is flexible and proportionate to what your organisation actually does with AI.

Who does Article 4 apply to?

It applies to providers and deployers of AI systems. A provider develops an AI system or has one developed and places it on the market under its own name. A deployer uses an AI system under its own authority in the course of its work. Most organisations are deployers.

The obligation covers your staff and, in the words of the regulation, “other persons dealing with the operation and use of AI systems on your behalf”. That reaches beyond employees to contractors, temporary staff and agency workers who use your AI systems. It is the broadest single obligation in the regulation for exactly that reason.

Critically, Article 4 is not limited to high-risk AI. If your organisation uses a general-purpose assistant to draft correspondence, it is in scope. The high-risk classification changes what else you must do; it does not decide whether Article 4 applies.

Does my organisation actually use AI systems?

Almost certainly yes, and usually in more places than expected. AI features have been folded into ordinary business software over the past two years, often without any decision being taken to “adopt AI”.

Common examples that bring an organisation into scope as a deployer:

  • Generative assistants in office suites — drafting, summarising, rewriting, meeting notes.
  • CRM and sales tools that score leads, predict churn or suggest next actions.
  • Accounting software that categorises transactions or flags anomalies automatically.
  • Recruitment platforms that rank, screen or match candidates.
  • Marketing tools that generate copy, images or audience segments.
  • Customer service chatbots and automated ticket routing.
  • Translation and transcription services.

There is also the software staff bring in themselves. Where employees use consumer AI tools for work without formal approval, the organisation is still the deployer in practice, and the literacy obligation still attaches to those people.

When did the obligation start, and what changed on 2 August 2026?

The duty itself has applied since 2 February 2025. What changed on 2 August 2026 is that national market surveillance authorities gained formal supervisory and enforcement powers over it.

The staged timetable of Regulation (EU) 2024/1689 runs as follows:

DateWhat applied
1 August 2024The AI Act entered into force.
2 February 2025Prohibited AI practices and the Article 4 AI literacy obligation.
2 August 2025General-purpose AI model rules, the governance chapter, the penalty regime, and the deadline for Member States to designate national competent authorities.
2 August 2026National supervision and enforcement of Article 4 begins.
2 December 2027High-risk obligations for standalone Annex III systems, deferred by the Digital Omnibus from the original August 2026 date.
August 2028High-risk obligations for AI embedded in regulated products under Annex I.

Did the Digital Omnibus delay the AI literacy rules?

No. This is the single most common misreading of the 2026 reforms. The Digital Omnibus deferred the applicability of the high-risk system obligations under Annex III and Annex I. It did not defer Article 4.

What the Omnibus did to Article 4 was soften the standard — from ensuring a sufficient level of literacy to supporting its development — while leaving the duty, the applicability dates and the 2 August 2026 enforcement start untouched. Widespread reporting of a “delay to the AI Act” described the high-risk deferral, not the literacy obligation, and organisations that read those headlines as a general reprieve are now a year and a half into an obligation they believe has not started.

For organisations whose AI systems are not high risk, Article 4 is the only AI Act obligation that is enforceable in the near term.

What are the penalties for failing to meet Article 4?

There is no fine attached to Article 4 itself. This is the most misunderstood point in the whole obligation, and it is worth stating precisely.

Article 99 sets out the AI Act's administrative fines in three tiers: up to €35 million or 7% of total worldwide annual turnover for breaching the prohibited practices in Article 5; up to €15 million or 3% for the operator obligations listed in Article 99(4); and up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities. For SMEs and start-ups the cap inverts — the fine is the lower of the percentage or the absolute figure, not the higher.

Article 99(4) is an enumerated list of specific provisions, and Article 4 is not on it. An organisation therefore cannot be fined under the AI Act for a literacy failure considered in isolation. Many commercial summaries state otherwise and quote the €15 million figure; that is not what the text says.

Three things follow, and they matter more than the headline number:

  • Market surveillance authorities still have enforcement powers that do not involve fines — information requests, corrective measures, and orders to bring practices into compliance.
  • Member States may create their own penalties. Article 99(1) requires them to lay down rules on penalties for infringements of the Regulation, and a Member State may use that power to attach a national sanction to Article 4. Whether one exists depends entirely on your country's implementing law.
  • Absence of training becomes an aggravating factor. The realistic exposure is not a standalone literacy fine but a weaker position when a regulator examines you for something else — a prohibited practice, a transparency breach, or a high-risk obligation. A documented, dated record of what you did is worth considerably more than the training itself.

Which EU institutions oversee the AI Act?

Three EU-level bodies matter, and none of them enforces Article 4 against ordinary organisations.

The European AI Office, within the European Commission, is the centre of AI expertise. It supervises providers of general-purpose AI models directly, coordinates approaches across Member States, and issues guidance. It does not take enforcement action against individual deployers under Article 4.

The European AI Board, established under Article 65, is composed of one representative per Member State. Under Article 66 it coordinates the national competent authorities responsible for applying the AI Act, which is how consistency across 27 different national systems is supposed to be achieved.

The European Data Protection Supervisor is the competent authority for AI systems used by EU institutions, agencies and bodies themselves — not for private organisations in the Member States.

Supervision and enforcement of Article 4 sits with national market surveillance authorities. Member States were required to designate them by 2 August 2025, and many missed that deadline; by early 2026 only around nine of the 27 had formally completed the designation. Which authority supervises you, and how far along its designation is, depends entirely on the country you operate in.

What should an organisation do first?

Start with an inventory, because you cannot train people on systems you have not identified. A proportionate first pass looks like this:

  1. List the AI systems in use. Include AI features inside software you already licence, not just tools bought as “AI”.
  2. Decide whether you are a provider or a deployer for each one. Most organisations are deployers throughout.
  3. Identify who operates each system, including contractors and anyone acting on your behalf.
  4. Give those people a general understanding of what the systems do, where they fail, and what the organisation expects of them.
  5. Write down what you did and when. The obligation is one of effort, so the evidence of effort is the compliance.

Proportionality runs through all of it. A twelve-person firm using an assistant for correspondence is not expected to match a bank deploying credit-scoring models.

Frequently asked questions

Does Article 4 apply to small businesses?

Yes. The AI Act sets no size threshold for Article 4. A sole trader using an AI assistant for client emails is a deployer and the obligation applies. What changes with size is proportionality — a small organisation is expected to do less, not nothing.

Do we need a certificate to prove AI literacy?

No. The regulation names no qualification, certificate or accredited course, and no accreditation scheme exists for Article 4. What matters is that you took measures and can evidence them: what was covered, who received it, on what date, and how that maps to the AI systems your organisation actually uses in practice.

Is Article 4 only about high-risk AI systems?

No. Article 4 applies regardless of risk classification. High-risk status triggers additional obligations, such as the human oversight requirement under Article 26, but the literacy duty attaches to any provider or deployer of any AI system. Using an ordinary generative assistant for everyday work is enough to bring you into scope.

Who enforces Article 4 in my country?

Your national market surveillance authority, not the European Commission or the AI Office. Designations vary widely across the Union: Italy, Spain and Poland have named their authorities in national law, while France and the Netherlands were still completing the legislative process through 2026. Check your own country's position rather than assuming.

Does the obligation cover contractors and freelancers?

Yes. Article 4 covers staff and, in the words of the regulation, other persons dealing with the operation and use of AI systems on your behalf. Contractors, agency staff, temporary workers and freelancers who operate your AI systems all fall inside the obligation, which is why it is the broadest duty in the regulation.

What happens if we do nothing?

Article 4 carries no fine of its own, because it is not listed in Article 99(4). Market surveillance authorities can still require corrective action, Member States may attach national penalties, and the absence of training weakens your position if a regulator examines you for any other AI Act matter.

Has the AI literacy deadline been postponed?

No. The Digital Omnibus deferred the high-risk obligations to December 2027 and August 2028, and that deferral is what most reporting described. Article 4 was not deferred. Its standard was softened, from ensuring a sufficient level of literacy to supporting its development, but neither the applicability date nor the enforcement date moved.

Sources

This article explains the regulation in general terms and is not legal advice. Obligations depend on your specific systems and jurisdiction; take professional advice on your own position.