What Article 4 of the EU AI Act actually requires
Article 4 of the EU AI Act (Regulation (EU) 2024/1689) requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. Those measures must take into account the people's technical knowledge, experience, education, and training, as well as the context in which the AI systems are used and the persons or groups on whom they will be used. The obligation has applied since 2 February 2025.
The Regulation defines AI literacy in Article 3(56) as the skills, knowledge, and understanding that allow providers, deployers, and affected persons to make an informed deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause.
- •Three features make Article 4 unusual among the Act's duties. It is short. It is risk-tier agnostic — it does not say "high-risk". And it is expressed as an obligation of effort ("to their best extent") rather than a fixed standard, which means the assessment of whether an organisation has complied is inseparable from what that organisation actually does with AI.
Who is covered — and why most SMEs already are
Article 4 names two roles: providers and deployers. Under the Act's definitions, a provider develops an AI system or has one developed and places it on the market or puts it into service under its own name or trade mark. A deployer uses an AI system under its own authority, other than in a purely personal, non-professional activity.
For a typical European SME, the deployer role is the one that bites. If your team uses a commercial generative AI assistant to draft customer communications, an AI-assisted CV screening tool, a demand-forecasting model embedded in your ERP, or a customer-service chatbot, you are using AI systems in a professional capacity — and the literacy obligation attaches irrespective of whether any of those systems is high-risk.
Who inside the organisation needs to be covered
The scope is "staff and other persons dealing with the operation and use of AI systems on their behalf". In practice this typically reaches:
- Employees who operate an AI system directly — the people entering prompts, reviewing outputs, or acting on recommendations.
- Employees who configure, tune, or integrate AI systems, including IT and data teams.
- Managers who decide which AI tools are procured or approved for use.
- Contractors, freelancers, and agency staff operating AI systems on the organisation's behalf.
- Anyone with human-oversight responsibilities over a high-risk system, where the Act's oversight requirements impose an additional and more demanding competence expectation.
- •It does not extend to customers or the general public, and it is not a general workforce-wide computer-literacy duty. An employee with no contact with any AI system is not the target of Article 4 — though in most organisations the honest answer to "who touches AI?" is broader than management assumes, because tool adoption tends to run ahead of tool governance.
What proportionate looks like for an SME with a handful of AI systems
Proportionality is written into Article 4 itself. A twelve-person consultancy using one approved AI writing assistant is not expected to run the same programme as a provider of a high-risk recruitment system. The variables the Regulation points to — technical background of the people involved, context of use, and who is affected — give a workable structure for scaling effort.
Layer 1: an organisation-wide baseline
A single short session or e-learning module for everyone who touches AI, covering: what AI is and how these systems produce output; the known failure modes (hallucination, bias, brittleness on edge cases, drift); the organisation's approved tools and its rules on confidential and personal data; and the escalation route when something looks wrong. Many SMEs pitch a general-staff baseline at around 30-60 minutes; the Act sets no minimum and adequacy depends on context.
Layer 2: role-specific depth
Deeper content for the smaller group whose decisions carry more weight. This is where you cover the specific system: its intended purpose, its documented limitations, the provider's instructions for use, what the outputs do and do not mean, and how to exercise meaningful judgement rather than deferring to the machine.
Layer 3: transparency and oversight duties
Where the organisation is subject to the Act's transparency obligations for certain systems — for example informing people they are interacting with an AI system, or marking synthetic content — the staff who operate those systems need to know the disclosure is required and how it is delivered. Where a high-risk system is in use, the people assigned human oversight need training that matches the competence, training, and authority the Act expects of them.
- Anchor every module in a system your people actually use, not in abstract AI theory.
- Use the provider's instructions for use as source material — for high-risk systems the provider is required to supply them, and they describe the real limitations.
- Refresh when the tool changes materially, when a new system is adopted, or on a set annual cycle.
- Include onboarding: new joiners who use AI need the baseline before they start using it, not at the next annual cycle.
Step-by-step guidance on structuring and rolling out a proportionate programme is in the Veritome Help Center (help.veritome.eu).
How to evidence AI literacy compliance
Because Article 4 sets no measurable threshold, evidence has two components: a documented rationale explaining why your chosen level of literacy is sufficient for your context, and records showing that the programme was actually delivered. The rationale is what makes the records meaningful; records alone show activity but not judgement.
The rationale document
- An inventory of AI systems in use, with each one's role (provider or deployer) and its risk classification under the Act.
- A mapping of which roles interact with which systems, and in what way — operating, configuring, overseeing, or acting on output.
- A statement of the literacy level judged sufficient for each group, with the reasoning that ties it to the Article 4 factors: technical background, context of use, and affected persons.
- The date the assessment was made and the trigger for its next review.
The delivery records
- Content: the actual slides, script, or module, versioned and dated, so you can show what was taught and not merely that something was.
- Attendance: who completed what, and when, including contractors.
- Onboarding coverage: evidence that new starters receive the baseline.
- Acknowledgement of the internal AI use policy, where one exists.
- Any comprehension check — a short quiz is not required, but it converts "attended" into "understood", which is a stronger record.
- A change log: what was updated, when, and why.
- •None of this requires a learning management system. Can be a proportionate starting point, depending on the systems in use — no authority has yet specified what evidence is sufficient.
How Article 4 connects to the rest of your compliance work
Article 4 is often the first duty an SME can complete, and it is worth treating as the on-ramp rather than an isolated task. Building the programme forces you to answer questions the rest of the Regulation will ask anyway.
- You cannot train people on systems you have not inventoried, so Article 4 drives the AI system register.
- You cannot pitch training at the right depth without knowing each system's risk classification, so it drives classification work.
- You cannot explain a system's limitations without reading the provider's instructions for use, so it drives supplier documentation collection.
- Where transparency obligations apply, literacy work surfaces whether disclosures are actually being made in practice.
The sequence that tends to work is: discover what AI is in use, classify it, assign roles, then design literacy around the result. Running it in that order means the training rationale writes itself from artefacts you needed regardless.
Member States had to designate authorities and notify penalty rules by 2 August 2025; the market surveillance provisions apply with the main high-risk regime from 2 August 2026. Article 4 itself does not carry a standalone administrative fine in the Act's penalty provisions in the way that, for example, the prohibited-practices rules do — but that is not a reason to leave it undone. Member States set national penalty regimes under Article 99(1), so national law may still attach consequences. Literacy is the foundation the human-oversight, transparency, and risk-management duties all rest on, and its absence tends to show up as failures in those other areas.
Practical guidance on sequencing inventory, classification, and literacy is in the Veritome Help Center (help.veritome.eu).