Article 4

Article 4: the AI literacy obligation most companies are already missing

21 July 2026 · 8 min

Article 4: the AI literacy obligation most companies are already missing

Most of the attention on the EU AI Act has gone to the parts that arrive with a bang: the banned practices, the high-risk classifications, the headline fines of up to 35 million euros or 7 percent of global turnover. Compliance teams have spent two years mapping systems against Annex III and arguing about whether their recruitment tool is high-risk. That work matters. But while they were looking at the top of the pyramid, a much smaller obligation at the base quietly became binding on almost every company operating in Europe, and most have done nothing about it.

That obligation is Article 4. It says, in one sentence, that anyone who builds or uses AI must make sure the people around it know what they are doing. It has been law since 2 February 2025. It applies whether your AI is a bespoke credit-scoring model or a marketing assistant running on ChatGPT. And it is the one requirement in the entire Act that a well-drafted policy document cannot satisfy on its own.

What Article 4 actually says

The text is short enough to read in full:

"Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used."

A few things are worth pulling apart. First, the duty falls on both providers (organisations that develop or supply AI systems) and deployers (organisations that use them under their own authority). If your firm uses AI at all in the course of its work, you are almost certainly a deployer, and Article 4 applies to you.

Second, the standard is not absolute. It asks for a "sufficient" level of literacy, judged against people's existing knowledge, the context of use, and who is affected by the system. This is a proportionate duty, not a demand that every employee become a data scientist. A junior analyst pasting client data into a chatbot and a compliance officer reviewing an automated decision need different things, and the Act expects you to recognise that.

Third, the date. The AI Act entered into force in August 2024, but its provisions switch on in stages. Article 4, together with the ban on prohibited practices in Article 5, became applicable on 2 February 2025. The European Commission has been explicit that there is no grace period specific to AI literacy. The obligation is live now.

Who it actually covers

The common misreading is that this is an IT or data-science concern. It is not. Article 4 reaches "staff and other persons dealing with the operation and use of AI systems on your behalf." Read plainly, that includes the marketing manager drafting campaigns with a generative tool, the recruiter using AI to screen CVs, the customer-service agent working alongside a chatbot, and the analyst who has quietly started using Copilot to summarise contracts.

It also reaches beyond your payroll. "Other persons acting on your behalf" pulls in contractors, agency staff, and outsourced service providers who touch AI in delivering work for you. If you have handed a process to a vendor and they run it through an AI system, their competence is your problem too.

The European Commission's own guidance makes the point concretely, using the example of a company using an off-the-shelf customer-service chatbot or generative AI for marketing. These are not exotic high-risk deployments. They are the ordinary tools that have spread through every department in the last two years, usually faster than any governance function could track. That spread is exactly why so many firms are already non-compliant without knowing it.

The enforcement question, answered honestly

This is where careful reading matters, because there is a great deal of loose commentary suggesting that ignoring Article 4 exposes you to the Act's headline fines. That is not accurate, and overstating it damages your credibility with the people you are trying to persuade.

Here is the real position. The penalty regime sits in Article 99. Its largest tier, up to 35 million euros or 7 percent of worldwide turnover, attaches specifically to breaches of the Article 5 prohibitions, not to AI literacy. A second tier, up to 15 million euros or 3 percent, covers most other operator obligations. Crucially, Article 99 does not set out a dedicated fine for breaching Article 4. There is no standalone AI-literacy penalty written into the Act.

Enforcement is instead indirect, and it is still maturing. Member States were required to designate national market surveillance authorities to police the Act, and those authorities are the bodies that will supervise obligations like Article 4. The Commission's guidance states that supervision and enforcement of the AI literacy duty by these authorities begins on 2 August 2026. In other words, the obligation has been binding since February 2025, but the machinery to enforce it against ordinary deployers becomes fully operational in August 2026, and each Member State sets its own penalty rules within the framework Article 99 provides.

So no, you will not receive an automatic 35-million-euro fine for a thin training programme. What you face is quieter and, for a serious business, arguably more dangerous. A literacy failure rarely arrives as a standalone charge. It surfaces as an aggravating factor when something else goes wrong: a discriminatory automated decision, a data breach caused by staff feeding personal data into a public model, a customer harmed by an output nobody checked. At that point the question from a regulator, a court, or a claimant's lawyer is simple. Did you take reasonable measures to ensure the people operating this system understood it? If the honest answer is no, that gap becomes evidence of negligence, and it can compound liability under the GDPR, under national employment and consumer law, and under the Act itself.

One further point of honesty. In November 2025 the Commission proposed, as part of its Digital Omnibus package, to soften Article 4 from a duty to "ensure" a level of literacy to a duty to "support" its development, an obligation of effort rather than of result. As of mid-2026 that proposal is still moving through the legislative process and is not yet settled law. Even if it passes in full, the practical requirement does not disappear. You would still have to show you took real measures to build competence. The direction of travel changes the wording, not the work.

Why documentation cannot discharge this one

Most of the AI Act can be met with artefacts. Risk assessments, technical documentation, conformity declarations, logs. These are things you produce, file, and can hand to an auditor. A capable legal team and a good template will get you a long way.

Article 4 is different in kind. It does not ask you to produce a document. It asks you to change the state of your workforce. The obligation is discharged only when actual people can actually recognise what a system is doing, when to trust it, when to challenge it, and when to escalate. You cannot write that into existence. A policy that says "all staff shall be AI literate" is not evidence of literacy. It is evidence of a policy.

This is the central trap. Firms that are excellent at compliance-by-documentation tend to treat Article 4 as another paperwork exercise, produce a one-page policy and an intranet page, and consider it closed. But the thing being regulated is capability, and capability lives in people, not in files. The only durable proof that you met the standard is a workforce that behaves differently, supported by a record of how you got them there.

What a real programme looks like

The Commission has been clear that there is no single prescribed curriculum and no mandatory certificate. That freedom is useful, but it means you have to design something defensible. Four principles hold across the good programmes.

Role-based. A blanket e-learning module for the whole company is the classic weak response. Segment instead. Everyone needs a common foundation: what AI is, how these systems fail, the basic rules on what data may go into them. Beyond that, tailor. People making or reviewing consequential decisions with AI need more depth than people using it to tidy up an email.

Risk-based. Concentrate effort where the exposure is. A team using AI in hiring, credit, or anything touching health, safety, or fundamental rights warrants serious, specific training. A team using it to generate internal meeting notes does not need the same intensity. Map your AI uses to their potential harm, and let that drive where you spend.

Ongoing. A single session in 2025 does not make a workforce literate in 2026. The tools change monthly, new systems enter through the side door, and people forget. Build a rhythm: onboarding for new joiners, refreshers when tools or rules change, and a live inventory of what AI is actually in use so training tracks reality rather than last year's assumptions.

Evidenced. Because enforcement is indirect and reactive, your protection is a contemporaneous record. Keep track of who was trained, on what, when, and to what standard. You do not need certificates. You do need to be able to show, on the day a regulator or claimant asks, that you took reasonable and proportionate measures. Undocumented good intentions are worth very little at that moment.

The takeaway

Article 4 is easy to underrate precisely because it is small, unglamorous, and not backed by a scary standalone fine. That is the wrong reading. It is the one obligation in the AI Act that reaches almost every organisation, applies right now, and cannot be closed out with a document. The firms that treat it as a training and culture problem rather than a paperwork problem will be the ones who can answer the only question that ultimately matters: when your people used AI, did they know what they were doing?

If you are starting from a policy page and little else, that is a normal place to be, and it is fixable well before the enforcement machinery matures in August 2026. The work is to turn the obligation into genuine, evidenced capability across the roles that carry the most risk. That is a design problem, and it is one worth getting help with if this is not what your team does every day.

← All insights

Where do you stand?

A short diagnostic tells you exactly where you are on the EU AI Act, and what to do next. No pressure.

Book an intro call →