What is the AI literacy requirement in the EU AI Act?

AI regulation: the EU AI Act

As of 21 July 2026, Article 4 of the EU AI Act requires providers and deployers to take measures so staff and other people using AI on their behalf have a sufficient level of AI literacy. "Sufficient" is context specific: it depends on role, technical knowledge, experience, training, the use case, and who may be affected. The Digital Omnibus on AI has been adopted and signed, but it was still awaiting Official Journal publication, so the current wording still applies for now.

What this means

The legal duty in Article 4 is not a general slogan about "being good at AI". It is a specific compliance obligation in the EU AI Act. If your organisation builds AI systems, you may be a provider. If your organisation uses AI systems in its operations, you may be a deployer. In practice, that reaches most organisations using AI at work.

The rule has applied since 2 February 2025. It says organisations must take measures so the people operating or using AI on their behalf have enough understanding to use it properly in the real context where it is deployed. That includes not just employees, but can also extend to contractors and, depending on the use case and risk, other people acting within the organisation's remit.

This is also a moving target. The law in force on 21 July 2026 still uses the stronger "ensure a sufficient level" wording. But an amending law, the Digital Omnibus on AI, had already been adopted and signed and would soften Article 4 once it enters into force, replacing it with a duty to take measures to support the development of AI literacy and making clear that no organisation has to guarantee a specific level for each individual.

Why it matters

AI literacy matters because many AI failures are not caused only by bad models. They are also caused by bad use: people trusting output they should question, using tools outside an approved context, missing bias or hallucinations, mishandling personal data, or failing to exercise human oversight where the law expects it. Article 4 tries to reduce that gap between buying or building AI and using it competently.

For leaders, this means Article 4 is not just an HR or learning issue. It sits inside governance, risk, procurement, product, security, compliance and operational decision making. A reasonable literacy programme can reduce avoidable incidents and improve evidence that the organisation took proportionate measures. A weak one can become an aggravating fact if something goes wrong, especially where the system affects workers, customers, rights, safety or access to important services.

How it works

Article 4 is already in force

Regulation (EU) 2024/1689 entered into force on 1 August 2024. Under the law currently in force, the AI literacy duty in Article 4 has applied since 2 February 2025. That date did not wait for the wider 2 August 2026 application point that covers most of the remaining AI Act obligations. So organisations have not been waiting lawfully for 2026 to start thinking about literacy. The duty already exists.

Article 4 applies to both providers and deployers. That matters because a deployer is not just a tech company shipping models. It includes ordinary organisations using AI in work processes, from marketing and customer service to recruitment, operations, fraud, procurement or internal productivity tools.

What "sufficient" means under the current law

The AI Act defines AI literacy as the skills, knowledge and understanding needed to make an informed deployment of AI and to understand its opportunities, risks and possible harm. Article 4 then makes that contextual. The relevant benchmark is not a universal syllabus or exam. It is whether the people using or operating the system have enough understanding for their role, with account taken of their technical knowledge, experience, education and training, the context in which the AI is used, and the persons or groups of persons on whom the system is used.

The Commission's AI Office has explained this in practical terms. As a minimum, organisations should build a general understanding of what AI is and what tools are used in the organisation, consider whether they are acting as provider or deployer, assess the risk of the systems involved, and then tailor literacy actions to the knowledge of the target group and the real deployment context. It also makes clear that legal and ethical aspects belong inside this analysis, not outside it.

That is why a sufficient level for one team can be plainly insufficient for another. A senior lawyer using a drafting assistant needs a different form of competence from an HR team using ranking tools, an engineer overseeing a high risk system, or a customer support team using an AI assistant in live conversations. The law is asking for fitness for purpose, not generic enthusiasm.

It is broader than formal training, but not satisfied by wishful thinking

Article 4 does not require a certificate, an exam, an AI officer, or a single mandatory course format. The Commission also says there is no one size fits all model and no obligation to measure every employee's AI knowledge formally. But that flexibility should not be misread as a free pass.

The same Commission guidance says that simply telling staff to read the instructions for use will often be ineffective and insufficient. Literacy actions may include training, guidance, practical notices, role based modules, human oversight instructions, escalation routes, and internal records of what was done. Different levels of detail for different groups are not just allowed, they are often the sensible way to comply.

This also extends beyond payroll employees. The Commission has said "other persons" can include contractors, service providers and clients where that makes sense in context. So if external personnel operate or use your AI system on your behalf, Article 4 may still be part of your compliance design.

How Article 4 is enforced in practice

Article 4 is unusual because it is legally binding, but it does not come with a neat standalone EU fine line that says "breach Article 4, pay X". Instead, enforcement runs through the wider AI Act structure. Member States were required to put national penalty rules in place, and national market surveillance authorities are the public bodies expected to supervise and enforce compliance for AI systems. The AI Office does not directly enforce Article 4 in the way it supervises general purpose AI models.

In practice, that means three things. First, sanctions and corrective measures depend on national law and the facts of the case. Second, lack of literacy is likely to matter most when it is tied to something else: poor human oversight, a harmful incident, misleading use of an AI system, weak risk controls, or failure to follow instructions and safeguards. Third, the proportionality of any response matters. The Commission's own Q&A says authorities can look at factors such as the nature and gravity of the infringement and whether conduct was intentional or negligent.

There is also a timing nuance. Under the AI Act, Member States had to adopt penalty rules by 2 August 2025, but the broader practical enforcement architecture for the rest of the AI Act becomes much more concrete from early August 2026 as market surveillance and other operational pieces come fully into play. So Article 4 is already binding, but its real enforcement weight rises as the wider machinery comes online.

What the Commission has published so far

For Article 4, the Commission has so far relied on soft law and support materials rather than a binding detailed rulebook. The main public resources are the AI Literacy Questions and Answers and the repository of AI literacy practices. The repository contains more than 40 examples drawn from companies and public sector bodies and includes formats such as e learning, in person training, bootcamps and collaboration models. The Commission is explicit that copying one of these practices does not create a presumption of compliance.

That matters because Article 4 currently has no harmonised standard, no official certification path and no safe harbour. The repository is for learning and exchange, not immunity. On the Commission pages checked on 21 July 2026, no newer AI literacy specific interpretive document had replaced the December 2025 Q&A. The newest AI Act guidance published by the Commission on that date was instead the transparency guidance under Article 50, issued on 20 July 2026. That does not change Article 4, but it shows the Commission is still filling out the implementation picture across the Act.

The Omnibus creates a dual track that readers need to separate carefully

As of 21 July 2026, the Digital Omnibus on AI was no longer a political idea or a provisional deal. The legislative procedure had completed. Parliament adopted the text on 16 June 2026, the Council took its decision on 29 June 2026, and the act was signed on 8 July 2026. But the OEIL procedure file still showed it as completed and awaiting publication in the Official Journal. That matters because the current AI Act text still governs until the amending regulation enters into force, which will happen on the third day after publication.

The final adopted text is important because it did not simply copy the Commission's original November 2025 proposal. The Commission proposal would have shifted Article 4 toward a Member State and Commission promotion duty. The text adopted in June and July 2026 took a different route. It keeps an organisational duty on providers and deployers, but softens it. Once in force, Article 4 will say providers and deployers must take measures to support the development of AI literacy of staff and other persons using AI on their behalf, and it will say explicitly that this does not require them to guarantee any specific level of AI literacy for any individual. It also adds duties for the Commission and Member States to support and facilitate those efforts, especially for SMEs, and requires the Commission to publish practical examples on its single information platform.

For this article, the key point is simple. Under the law in force on 21 July 2026, the stronger current Article 4 still applies. The Omnibus, once published and in force, will change the wording and lower the guarantee-like edge of the duty, but it does not erase the need for organisations to take practical literacy measures.

What a proportionate SME programme looks like

A proportionate Article 4 programme for an SME should look more like a focused operating discipline than a corporate university. The Commission's own minimum factors point to a compact model.

Start with a simple inventory: what AI tools are used, by whom, for what purpose, and with what risk. Then give all relevant staff a short baseline on how the organisation uses AI, where it is allowed, what its common failure modes are, when not to trust outputs, what data can and cannot be entered, and when to escalate. Add role based guidance for people with higher impact tasks, such as those making decisions about people, handling regulated content, using customer facing systems, or overseeing systems that may be high risk. Keep short written guidance near the workflow, not buried in a policy portal. Extend the same expectations to contractors or service providers acting on the organisation's behalf where relevant. Record what was delivered and refresh it when tools, risks or uses change.

That is likely to be far more defensible than buying a large off the shelf training package and assuming the problem is solved. Article 4 is about contextual capability in real operations, not about collecting course completion badges.

Examples

A marketing team uses a general purpose AI tool to draft advertising copy or translate text. The Commission has said that this still falls within Article 4's logic. Staff should be informed about the specific risks of the tool, including hallucination. In other words, low stakes use does not mean no literacy duty. It means the literacy response can be lighter and tightly targeted.

A deployer uses a high risk AI system with a human in the loop control. The Commission distinguishes Article 4 from the more specific high risk deployer duties, but it also says relying only on instructions for use is not enough. The people operating the system and performing human oversight need skills targeted to that system and task. That is a useful reminder that general AI awareness does not replace product specific operational competence.

An organisation uses contractors or service providers who operate or use AI systems on its behalf. The Commission says "other persons" under Article 4 can include contractors, service providers and, in some contexts, clients. That means a literacy programme may need to extend beyond direct employees if external users are part of the operational chain or if the affected person context makes that appropriate.

Common misunderstandings

"Article 4 is only for AI developers." No. It applies to providers and deployers, so it covers both organisations building AI and organisations using AI in their operations.

"Only high risk AI triggers the literacy duty." No. Article 4 is general. Risk changes the depth and specificity of the literacy measures, but the duty is not limited to high risk systems.

"If we buy a tool from a major vendor and tell staff to read the manual, that is enough." Usually not. The Commission says that simply relying on instructions for use may be ineffective and insufficient, especially where the system's risks require practical guidance and human oversight.

"There is a fixed EU fine for breaching Article 4." Not in a neat standalone sense. Enforcement sits with national market surveillance authorities and national penalty rules, and lack of literacy is likely to matter as part of the wider facts of a case.

"The Omnibus has already abolished Article 4." No. As of 21 July 2026, the Omnibus had been adopted and signed but was still awaiting Official Journal publication. The current Article 4 therefore still applies. And even once the Omnibus enters into force, the obligation does not disappear. It is reframed into a softer duty to support the development of AI literacy, with no requirement to guarantee a specific level for each individual.

Risks and boundaries

Article 4 is not a complete AI governance framework. It does not replace system specific obligations, high risk controls, human oversight design, transparency duties, incident handling, procurement due diligence or data protection analysis. A staff training deck on its own will not make a risky deployment lawful.

It is also not a command to make every worker an AI specialist. The current law asks for a sufficient level in context. The adopted Omnibus text goes further and makes explicit that providers and deployers do not have to guarantee any specific level for an individual. The boundary is organisational reasonableness, not perfection.

There is also a legal status boundary on 21 July 2026. The available Commission AI literacy Q&A explains the current law and discusses the Commission's November 2025 proposal, but it predates the final June and July 2026 adopted Omnibus text. Because that amending act was still awaiting Official Journal publication on 21 July 2026, the current Article 4 remained the law in force. Readers should therefore keep two tracks separate: current law now, and adopted but not yet in force law next.

What to do next

Treat Article 4 as an operating control, not a communications exercise. Identify where AI is actually used in the business, decide which teams are providers and which are deployers, and rank those uses by risk and impact on people. Put a short baseline literacy module in place for everyone who uses AI at work, then add role specific guidance for higher impact teams. Extend the same expectations to contractors where relevant. Keep evidence of what you did. Review it when tools, workflows or incidents change. And because the Omnibus is pending publication, plan so your programme works under both formulations: strong enough for the current duty, proportionate enough for the softer wording that is likely to follow.

FAQs

Does Article 4 apply if our staff only use a chatbot for drafting, summarising or translation?

Yes. The Commission has expressly said that even staff using a tool like ChatGPT for advertising text or translation should be informed about the relevant risks, such as hallucination.

Do we need to test every employee and issue certificates?

No. The Commission says Article 4 does not require formal measurement of every employee's knowledge and does not require certificates. Internal records of training or guidance are enough as evidence of what you did.

Do contractors count, or only employees?

Contractors can count. The Commission says "other persons" can include contractors, service providers and, depending on the use case, clients. If they operate or use AI on your behalf, they may need to be covered.

Is an AI officer mandatory, like a DPO under data protection law?

No. The Commission says no specific governance structure is mandated just to comply with Article 4. You can assign ownership internally without creating a formal new office.

Who enforces Article 4?

Public enforcement sits with national market surveillance authorities, not with the AI Office directly. The AI Office supports implementation, but Article 4 is enforced through national authorities and national measures.

Does the current Article 4 require us to guarantee that every person is AI literate?

Under the law in force on 21 July 2026, the wording is stronger and speaks in terms of ensuring a sufficient level. But even there, the Commission treats the duty as contextual and flexible, not as a universal exam obligation. The adopted Omnibus text would make this clearer by stating that no specific individual level must be guaranteed.

Has the Omnibus already changed Article 4?

Not yet as of 21 July 2026. It had been adopted and signed, but the procedure file still showed it as awaiting Official Journal publication. Until publication and entry into force, the current Article 4 remains the law in force.

Does Article 4 apply to organisations outside the EU?

It can. The Commission says the AI Act applies to actors inside and outside the EU where the AI system is placed on the Union market, used in the Union, or its use affects people in the EU.

Sources