OBLIGATIONS8 min

EU AI Act Article 4: The AI Literacy Deadline Every Company Already Passed

A practical guide to EU AI Act Article 4: who the AI-literacy obligation applies to, what 'sufficient AI literacy' means, why it is already in force, and how to build auditable training that satisfies it.

V
Veritome Team
20.07.2026

Key Takeaways

  • 1Article 4 has applied since 2 February 2025 — the same day as the prohibited-practices ban. It is one of the first binding obligations of the entire Act, not a future deadline.
  • 2It applies to every provider and deployer of AI systems, at any risk tier. There is no high-risk gate and no small-company exemption.
  • 3The duty is to ensure a 'sufficient level of AI literacy' among staff and anyone operating AI on your behalf — proportionate to their role, the systems, and the people affected.
  • 4There is no single certificate that discharges it. Sufficiency is contextual: a data scientist, a recruiter using an AI screening tool, and a board member need different literacy.
  • 5Article 4 has no standalone fine, but the Commission and authorities have been explicit that inadequate literacy is an aggravating factor when penalties for other breaches are assessed.
  • 6Auditable, role-specific, timestamped training records are the defensible way to prove compliance — and the cheapest obligation in the whole Act to get right.

The Obligation Everyone Skipped Past

The EU AI Act's headline dates are about high-risk systems and general-purpose AI. But the very first substantive obligations bit on 2 February 2025 — and while the prohibited-practices ban got the attention, it arrived alongside a duty that applies to vastly more organisations: Article 4, AI literacy. It is not coming. It is already law, and most companies have not addressed it.

Article 4 is short, which is part of why it is underestimated. It requires providers and deployers of AI systems to 'take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf' — taking into account their technical knowledge, experience, education and training, the context in which the systems are used, and the people the systems affect.

  • In force since 2 February 2025 — one of the earliest binding duties in the Act.
  • Applies to providers AND deployers of AI systems.
  • No risk-tier threshold: it is not limited to high-risk systems.
  • No headcount exemption: a five-person team is as much in scope as a multinational.

Who It Applies To (Almost Everyone)

This is the part that surprises people. Article 4 has none of the gating that limits most of the Act. It does not wait for a system to be high-risk. It does not exempt small companies. If your organisation develops AI (provider) or uses AI in a professional capacity (deployer) — and in 2026 that is almost every organisation — you owe an AI-literacy duty for the people building, operating and relying on those systems.

'Staff and other persons dealing with the operation and use of AI systems on your behalf' is deliberately broad. It reaches employees, but also contractors, agency staff and outsourced operators who touch your AI on your behalf. The scope follows the people, not the org chart.

The obligation is proportionate, not uniform

  • A data scientist building a model needs deep technical and legal literacy about its limitations and risks.
  • A recruiter using an AI CV-screening tool needs to understand what it does, how it can go wrong, when to override it, and how to interpret its output.
  • An executive or board member needs enough literacy to make informed governance decisions and set policy.
  • A customer-support agent using an AI assistant needs to know it is AI, its limits, and when to escalate to a human.

What 'Sufficient AI Literacy' Actually Means

There is no certificate you can buy to close Article 4, and that is by design. The Act defines AI literacy as the skills, knowledge and understanding that allow people to make an informed deployment of AI, to gain awareness of its opportunities and risks, and to understand the possible harm it can cause. 'Sufficient' is measured against the specific role, the specific systems, and the specific people affected — so a one-size training video does not discharge it.

In practice, sufficient literacy for a given person covers three things: a general understanding of how AI works and where it fails; the specific risks and limitations of the systems they actually use; and the relevant legal and ethical guardrails — including when a human must stay in the loop. The Commission's AI Office has published guidance and a living repository of practices to help organisations calibrate this, and has been clear that the measure is contextual rather than a fixed syllabus.

  • General AI understanding: how the systems work, and how they fail (bias, drift, hallucination, over-reliance).
  • System-specific risk: the concrete limitations of the tools each person uses.
  • Legal and ethical context: the guardrails, the oversight duties, and when to escalate to a human.
  • Calibrated to the person: role, prior knowledge, and who the AI affects all change what 'sufficient' means.

Why It Has Teeth Even Without Its Own Fine

Article 4 does not carry a dedicated penalty the way the prohibited-practices or high-risk provisions do. That has lulled some organisations into treating it as optional. It is not. Regulators and the Commission have signalled clearly that AI literacy is a baseline expectation, and that inadequate literacy will be treated as an aggravating factor when authorities assess penalties for other breaches of the Act.

The logic is straightforward: when a high-risk system fails because the person operating it did not understand its limits or ignored the oversight design, the deployer's failure to ensure literacy becomes part of the story a supervisory authority tells. An organisation that can produce role-specific, timestamped training records demonstrates diligence; one that cannot looks negligent precisely when it can least afford to. Article 4 is, in effect, the cheapest insurance policy in the Act.

How to Comply — and Prove It

Compliance with Article 4 is less about volume of training and more about fit and evidence. The defensible posture is training that is mapped to roles, tied to the specific systems people use, refreshed as those systems change, and — critically — logged. If you cannot show who was trained, on what, and when, you cannot prove the measure was taken.

A practical Article 4 checklist

  • Inventory who operates or relies on AI in your organisation — including contractors and outsourced staff.
  • Map roles to literacy needs: general awareness for everyone, deeper technical and legal literacy for builders and overseers.
  • Deliver training that covers general AI understanding, the specific risks of the systems in use, and the legal and ethical guardrails.
  • Record it: log completion with timestamps, link records to individuals, and retain them as evidence.
  • Refresh on change: when you adopt a new system or a system materially changes, update the training and the records.
  • Keep a short written AI-literacy policy that states the programme, its scope, its owner, and its review cadence.

This is the rare EU AI Act obligation that is fully in your control, low-cost, and immediately actionable. It is also the one most companies have quietly missed. Closing it now — with auditable records rather than good intentions — removes an aggravating factor before it is ever needed and demonstrates exactly the diligence the Act rewards.

Frequently Asked Questions

When did the EU AI Act AI-literacy obligation come into force?

Article 4 has applied since 2 February 2025 — the same date the prohibited-practices ban took effect. It is one of the first binding obligations of the entire Act, so it is not a future deadline: organisations are already expected to comply.

Who does Article 4 apply to?

Every provider and deployer of AI systems. There is no high-risk threshold and no exemption for small companies. The duty covers your staff and other persons who deal with the operation and use of AI systems on your behalf, which includes contractors, agency staff and outsourced operators.

What counts as 'sufficient' AI literacy?

It is contextual, not a fixed syllabus. Sufficient literacy is proportionate to the person's role and technical background, the specific systems they use, and the people those systems affect. In practice it covers a general understanding of how AI works and fails, the specific risks and limitations of the tools in use, and the relevant legal and ethical guardrails including human-oversight duties. There is no single certificate that discharges the obligation.

Is there a fine for failing Article 4?

Article 4 does not carry its own dedicated penalty the way the prohibited-practices and high-risk provisions do. However, the Commission and supervisory authorities have made clear that inadequate AI literacy is treated as an aggravating factor when penalties for other breaches of the Act are assessed. So it materially affects your exposure even though it is not separately fined.

How do I prove we have complied with the AI-literacy duty?

With auditable records. Deliver role-specific training covering general AI understanding, the risks of the specific systems in use, and the legal and ethical context; then log completion with timestamps linked to individuals, and retain those records. A short written AI-literacy policy stating the programme, its scope, its owner and its review cadence turns 'we did some training' into demonstrable diligence.

Does a generic 'intro to AI' course satisfy Article 4?

Rarely on its own. A generic awareness course can cover the general-understanding component for lower-risk roles, but sufficiency requires the training to reflect the specific systems people use and their role in operating or overseeing them. A recruiter using an AI screening tool and a data scientist building it need materially different training, and the records should show that role-appropriate calibration.

EU AI Act updates, in your inbox

Deadlines, enforcement news and practical compliance guidance. One confirmation email first, then only the updates — one-click unsubscribe in every one.