AI LITERACY9 min

Article 4 AI Literacy: The Obligation Almost Everyone Already Has

What Article 4 of the EU AI Act requires, who it covers, what a proportionate AI-literacy programme looks like for an SME, and how to evidence it without a training department.

V
Veritome Team
03.08.2026

Key Takeaways

  • 1Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures ensuring a sufficient level of AI literacy among their staff and other people operating AI systems on their behalf.
  • 2The obligation has applied since 2 February 2025, ahead of most of the Regulation's other duties.
  • 3Article 4 is not limited to high-risk AI: it attaches to any AI system a provider or deployer places on the market or uses, including everyday generative AI tools.
  • 4Literacy is explicitly proportionate — it must reflect technical knowledge, experience, education, training, the context of use, and the people affected.
  • 5The Regulation prescribes no curriculum, certificate, or minimum hours, so evidence rests on a documented rationale plus records of what was delivered to whom.
  • 6A workable SME programme is typically a short organisation-wide baseline plus role-specific briefings for the few people who configure, monitor, or interpret AI output.

What Article 4 of the EU AI Act actually requires

Article 4 of the EU AI Act (Regulation (EU) 2024/1689) requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. Those measures must take into account the people's technical knowledge, experience, education, and training, as well as the context in which the AI systems are used and the persons or groups on whom they will be used. The obligation has applied since 2 February 2025.

The Regulation defines AI literacy in Article 3(56) as the skills, knowledge, and understanding that allow providers, deployers, and affected persons to make an informed deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause.

  • Three features make Article 4 unusual among the Act's duties. It is short. It is risk-tier agnostic — it does not say "high-risk". And it is expressed as an obligation of effort ("to their best extent") rather than a fixed standard, which means the assessment of whether an organisation has complied is inseparable from what that organisation actually does with AI.

Who is covered — and why most SMEs already are

Article 4 names two roles: providers and deployers. Under the Act's definitions, a provider develops an AI system or has one developed and places it on the market or puts it into service under its own name or trade mark. A deployer uses an AI system under its own authority, other than in a purely personal, non-professional activity.

For a typical European SME, the deployer role is the one that bites. If your team uses a commercial generative AI assistant to draft customer communications, an AI-assisted CV screening tool, a demand-forecasting model embedded in your ERP, or a customer-service chatbot, you are using AI systems in a professional capacity — and the literacy obligation attaches irrespective of whether any of those systems is high-risk.

Who inside the organisation needs to be covered

The scope is "staff and other persons dealing with the operation and use of AI systems on their behalf". In practice this typically reaches:

  • Employees who operate an AI system directly — the people entering prompts, reviewing outputs, or acting on recommendations.
  • Employees who configure, tune, or integrate AI systems, including IT and data teams.
  • Managers who decide which AI tools are procured or approved for use.
  • Contractors, freelancers, and agency staff operating AI systems on the organisation's behalf.
  • Anyone with human-oversight responsibilities over a high-risk system, where the Act's oversight requirements impose an additional and more demanding competence expectation.
  • It does not extend to customers or the general public, and it is not a general workforce-wide computer-literacy duty. An employee with no contact with any AI system is not the target of Article 4 — though in most organisations the honest answer to "who touches AI?" is broader than management assumes, because tool adoption tends to run ahead of tool governance.

What proportionate looks like for an SME with a handful of AI systems

Proportionality is written into Article 4 itself. A twelve-person consultancy using one approved AI writing assistant is not expected to run the same programme as a provider of a high-risk recruitment system. The variables the Regulation points to — technical background of the people involved, context of use, and who is affected — give a workable structure for scaling effort.

Layer 1: an organisation-wide baseline

A single short session or e-learning module for everyone who touches AI, covering: what AI is and how these systems produce output; the known failure modes (hallucination, bias, brittleness on edge cases, drift); the organisation's approved tools and its rules on confidential and personal data; and the escalation route when something looks wrong. Many SMEs pitch a general-staff baseline at around 30-60 minutes; the Act sets no minimum and adequacy depends on context.

Layer 2: role-specific depth

Deeper content for the smaller group whose decisions carry more weight. This is where you cover the specific system: its intended purpose, its documented limitations, the provider's instructions for use, what the outputs do and do not mean, and how to exercise meaningful judgement rather than deferring to the machine.

Layer 3: transparency and oversight duties

Where the organisation is subject to the Act's transparency obligations for certain systems — for example informing people they are interacting with an AI system, or marking synthetic content — the staff who operate those systems need to know the disclosure is required and how it is delivered. Where a high-risk system is in use, the people assigned human oversight need training that matches the competence, training, and authority the Act expects of them.

  • Anchor every module in a system your people actually use, not in abstract AI theory.
  • Use the provider's instructions for use as source material — for high-risk systems the provider is required to supply them, and they describe the real limitations.
  • Refresh when the tool changes materially, when a new system is adopted, or on a set annual cycle.
  • Include onboarding: new joiners who use AI need the baseline before they start using it, not at the next annual cycle.

Step-by-step guidance on structuring and rolling out a proportionate programme is in the Veritome Help Center (help.veritome.eu).

How to evidence AI literacy compliance

Because Article 4 sets no measurable threshold, evidence has two components: a documented rationale explaining why your chosen level of literacy is sufficient for your context, and records showing that the programme was actually delivered. The rationale is what makes the records meaningful; records alone show activity but not judgement.

The rationale document

  • An inventory of AI systems in use, with each one's role (provider or deployer) and its risk classification under the Act.
  • A mapping of which roles interact with which systems, and in what way — operating, configuring, overseeing, or acting on output.
  • A statement of the literacy level judged sufficient for each group, with the reasoning that ties it to the Article 4 factors: technical background, context of use, and affected persons.
  • The date the assessment was made and the trigger for its next review.

The delivery records

  • Content: the actual slides, script, or module, versioned and dated, so you can show what was taught and not merely that something was.
  • Attendance: who completed what, and when, including contractors.
  • Onboarding coverage: evidence that new starters receive the baseline.
  • Acknowledgement of the internal AI use policy, where one exists.
  • Any comprehension check — a short quiz is not required, but it converts "attended" into "understood", which is a stronger record.
  • A change log: what was updated, when, and why.
  • None of this requires a learning management system. Can be a proportionate starting point, depending on the systems in use — no authority has yet specified what evidence is sufficient.

How Article 4 connects to the rest of your compliance work

Article 4 is often the first duty an SME can complete, and it is worth treating as the on-ramp rather than an isolated task. Building the programme forces you to answer questions the rest of the Regulation will ask anyway.

  • You cannot train people on systems you have not inventoried, so Article 4 drives the AI system register.
  • You cannot pitch training at the right depth without knowing each system's risk classification, so it drives classification work.
  • You cannot explain a system's limitations without reading the provider's instructions for use, so it drives supplier documentation collection.
  • Where transparency obligations apply, literacy work surfaces whether disclosures are actually being made in practice.

The sequence that tends to work is: discover what AI is in use, classify it, assign roles, then design literacy around the result. Running it in that order means the training rationale writes itself from artefacts you needed regardless.

Member States had to designate authorities and notify penalty rules by 2 August 2025; the market surveillance provisions apply with the main high-risk regime from 2 August 2026. Article 4 itself does not carry a standalone administrative fine in the Act's penalty provisions in the way that, for example, the prohibited-practices rules do — but that is not a reason to leave it undone. Member States set national penalty regimes under Article 99(1), so national law may still attach consequences. Literacy is the foundation the human-oversight, transparency, and risk-management duties all rest on, and its absence tends to show up as failures in those other areas.

Practical guidance on sequencing inventory, classification, and literacy is in the Veritome Help Center (help.veritome.eu).

Frequently Asked Questions

What is Article 4 of the EU AI Act?

Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. Those measures must account for the people's technical knowledge, experience, education, and training, the context in which the systems are used, and the persons or groups on whom they will be used. It has applied since 2 February 2025 and is not limited to high-risk AI.

Who needs AI literacy training under the EU AI Act?

Article 4 covers staff and other persons who deal with the operation and use of AI systems on behalf of a provider or deployer. In practice this includes employees who operate AI tools directly, those who configure or integrate them, managers who approve their procurement, and contractors or agency staff doing the same work. It applies whatever the system's risk tier, so an SME using a commercial generative AI assistant is in scope. It does not extend to customers or the general public.

How do you evidence AI literacy compliance?

Evidence has two parts. First, a documented rationale: an inventory of AI systems in use, a mapping of which roles interact with each, and a statement of why the chosen literacy level is sufficient given technical background, context of use, and affected persons. Second, delivery records: dated and versioned training content, attendance logs including contractors, onboarding coverage, policy acknowledgements, and a change log. In our experience a slide deck, a spreadsheet and a short rationale is a practical starting point for many SMEs; no authority has yet specified what evidence is sufficient

Since when has Article 4 applied?

The AI literacy obligation in Article 4 has applied since 2 February 2025, alongside the Regulation's general provisions and the prohibitions on certain AI practices. This makes it one of the earliest duties in the Act to take effect, well ahead of most high-risk system obligations. Organisations that have deployed AI tools since before that date are already within scope, so the practical question is usually not whether to start but how to document what has been done so far.

Does Article 4 only apply to high-risk AI systems?

No. Article 4 refers to AI systems generally, without restricting the obligation to those classified as high-risk under the Act. A deployer using a low-risk chatbot or a general-purpose AI assistant in a professional context is within scope. What changes with risk level is depth, not applicability: the Article's proportionality factors mean a high-risk system in a consequential setting warrants substantially more training than a drafting tool, and human-oversight duties for high-risk systems impose their own competence expectations on top.

Is there an official AI literacy curriculum or certificate?

The Regulation prescribes no curriculum, no certificate, and no minimum number of hours. Article 4 is drafted as an obligation of effort — measures taken "to their best extent" and calibrated to the organisation's context. External courses and certifications can form part of a programme and are useful for specialist roles, but no certificate on its own demonstrates compliance. What matters is that the content maps to the AI systems your organisation actually uses and that you can show the reasoning behind the level you chose.

EU AI Act updates, in your inbox

Deadlines, enforcement news and practical compliance guidance. One confirmation email first, then only the updates — one-click unsubscribe in every one.