The Obligation Everyone Skipped Past
The EU AI Act's headline dates are about high-risk systems and general-purpose AI. But the very first substantive obligations bit on 2 February 2025 — and while the prohibited-practices ban got the attention, it arrived alongside a duty that applies to vastly more organisations: Article 4, AI literacy. It is not coming. It is already law, and most companies have not addressed it.
Article 4 is short, which is part of why it is underestimated. It requires providers and deployers of AI systems to 'take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf' — taking into account their technical knowledge, experience, education and training, the context in which the systems are used, and the people the systems affect.
- •In force since 2 February 2025 — one of the earliest binding duties in the Act.
- •Applies to providers AND deployers of AI systems.
- •No risk-tier threshold: it is not limited to high-risk systems.
- •No headcount exemption: a five-person team is as much in scope as a multinational.
Who It Applies To (Almost Everyone)
This is the part that surprises people. Article 4 has none of the gating that limits most of the Act. It does not wait for a system to be high-risk. It does not exempt small companies. If your organisation develops AI (provider) or uses AI in a professional capacity (deployer) — and in 2026 that is almost every organisation — you owe an AI-literacy duty for the people building, operating and relying on those systems.
'Staff and other persons dealing with the operation and use of AI systems on your behalf' is deliberately broad. It reaches employees, but also contractors, agency staff and outsourced operators who touch your AI on your behalf. The scope follows the people, not the org chart.
The obligation is proportionate, not uniform
- A data scientist building a model needs deep technical and legal literacy about its limitations and risks.
- A recruiter using an AI CV-screening tool needs to understand what it does, how it can go wrong, when to override it, and how to interpret its output.
- An executive or board member needs enough literacy to make informed governance decisions and set policy.
- A customer-support agent using an AI assistant needs to know it is AI, its limits, and when to escalate to a human.
What 'Sufficient AI Literacy' Actually Means
There is no certificate you can buy to close Article 4, and that is by design. The Act defines AI literacy as the skills, knowledge and understanding that allow people to make an informed deployment of AI, to gain awareness of its opportunities and risks, and to understand the possible harm it can cause. 'Sufficient' is measured against the specific role, the specific systems, and the specific people affected — so a one-size training video does not discharge it.
In practice, sufficient literacy for a given person covers three things: a general understanding of how AI works and where it fails; the specific risks and limitations of the systems they actually use; and the relevant legal and ethical guardrails — including when a human must stay in the loop. The Commission's AI Office has published guidance and a living repository of practices to help organisations calibrate this, and has been clear that the measure is contextual rather than a fixed syllabus.
- •General AI understanding: how the systems work, and how they fail (bias, drift, hallucination, over-reliance).
- •System-specific risk: the concrete limitations of the tools each person uses.
- •Legal and ethical context: the guardrails, the oversight duties, and when to escalate to a human.
- •Calibrated to the person: role, prior knowledge, and who the AI affects all change what 'sufficient' means.
Why It Has Teeth Even Without Its Own Fine
Article 4 does not carry a dedicated penalty the way the prohibited-practices or high-risk provisions do. That has lulled some organisations into treating it as optional. It is not. Regulators and the Commission have signalled clearly that AI literacy is a baseline expectation, and that inadequate literacy will be treated as an aggravating factor when authorities assess penalties for other breaches of the Act.
The logic is straightforward: when a high-risk system fails because the person operating it did not understand its limits or ignored the oversight design, the deployer's failure to ensure literacy becomes part of the story a supervisory authority tells. An organisation that can produce role-specific, timestamped training records demonstrates diligence; one that cannot looks negligent precisely when it can least afford to. Article 4 is, in effect, the cheapest insurance policy in the Act.
How to Comply — and Prove It
Compliance with Article 4 is less about volume of training and more about fit and evidence. The defensible posture is training that is mapped to roles, tied to the specific systems people use, refreshed as those systems change, and — critically — logged. If you cannot show who was trained, on what, and when, you cannot prove the measure was taken.
A practical Article 4 checklist
- Inventory who operates or relies on AI in your organisation — including contractors and outsourced staff.
- Map roles to literacy needs: general awareness for everyone, deeper technical and legal literacy for builders and overseers.
- Deliver training that covers general AI understanding, the specific risks of the systems in use, and the legal and ethical guardrails.
- Record it: log completion with timestamps, link records to individuals, and retain them as evidence.
- Refresh on change: when you adopt a new system or a system materially changes, update the training and the records.
- Keep a short written AI-literacy policy that states the programme, its scope, its owner, and its review cadence.
This is the rare EU AI Act obligation that is fully in your control, low-cost, and immediately actionable. It is also the one most companies have quietly missed. Closing it now — with auditable records rather than good intentions — removes an aggravating factor before it is ever needed and demonstrates exactly the diligence the Act rewards.