AI Act Article 4: What the AI Literacy Duty Asks of You
AI Act Article 4 after the 2026 Digital Omnibus: who must support AI literacy, what the Commission expects, how enforcement works, and a plan to follow.
Article 4 of the EU AI Act requires every provider and deployer of AI systems to take measures that support the AI literacy of their staff and of anyone else who operates or uses AI on their behalf. If your team uses ChatGPT, Claude or any other AI tool for work, your company is a deployer and the rule covers you. It has applied since 2 February 2025. The Digital Omnibus on AI rewrote it with effect from 27 July 2026: you no longer have to reach a "sufficient level", and you need no certificate. National authorities supervise it from August 2026.
Everything below comes from the text of Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 on EUR-Lex and from the European Commission's AI literacy Q&A, checked on 6 October 2026. I run AI training for teams, and in Lithuania I do it through my company Retos galimybės (opens in a new tab). Article 4 comes up in almost every first call, so this is the answer I give, with the sources.
AI Act Article 4: the text in force now
The Digital Omnibus on AI, Regulation (EU) 2026/1744 (opens in a new tab), replaced Article 4 in full. It entered into force on 27 July 2026. Paragraph 1 now reads:
Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
Paragraph 2 obliges the Commission and the Member States to support providers and deployers, "in particular SMEs", and tells the Commission to publish practical examples of how to comply. Paragraph 3 asks the European AI Board to adopt recommendations based on European competence frameworks.
| Article 4 until 26 July 2026 | Article 4 from 27 July 2026 | |
|---|---|---|
| Duty | "ensure, to their best extent, a sufficient level of AI literacy" | "take measures to support the development of AI literacy" |
| Who | Providers and deployers: their staff and other persons acting on their behalf | Same |
| Level | A "sufficient level" | No specific level guaranteed for any individual |
| Support from authorities | Not in the article | Commission and Member States must support, in particular SMEs |
Recital 8 of the Omnibus gives the reason: a duty to ensure a sufficient level "would not be suitable for all types of providers and deployers" and "creates an additional compliance burden, particularly for smaller enterprises". The same recital adds that AI literacy "should be a strategic priority, regardless of regulatory obligations and potential sanctions".
So the duty got lighter, and it stayed. Some summaries say the Omnibus deleted Article 4. The text on EUR-Lex shows otherwise.
Who Article 4 covers
The AI Act (Regulation (EU) 2024/1689 (opens in a new tab)) defines two roles that matter here:
- Provider: whoever develops an AI system or model, or has one developed, and places it on the market or puts it into service under its own name, paid or free.
- Deployer: any person, company or public body "using an AI system under its authority", except for personal non-professional use.
Most companies are deployers. Your sales team drafts emails with ChatGPT, your accountant summarises invoices with an AI tool, your HR team screens CVs with software that has AI inside it. Each of those makes you a deployer.
The rule reaches beyond employees. The Commission explains that "other persons" are "persons broadly under the organisational remit", for example "a contractor, a service provider, a client". The Act also covers companies outside the EU when their AI system is placed on the EU market, used in the EU, or affects people in the EU.
What counts as AI literacy
Article 3(56) defines it as the "skills, knowledge and understanding" that let providers, deployers and affected persons "make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause".
For a team, that means your people know what the tool does, where it goes wrong, and what they may and may not feed it. The Commission's own example is the ChatGPT case. Asked whether a company whose employees use ChatGPT to write advertising text or translate must comply, it answers: "Yes, they should be informed about the specific risks, for example hallucination."
What the Commission expects as a minimum
The Commission's AI literacy Q&A (opens in a new tab) lists four steps that an AI literacy programme should consider at least:
- A general understanding of AI. What is AI, how does it work, which AI does the organisation use, and what are its opportunities and dangers?
- Your role. Does the organisation develop AI systems, or use systems built by someone else?
- The risk of your systems. What do employees need to know when they work with each system, and which risks must they be aware of?
- Actions built on that analysis. Fit the training to how much each group already knows, and to the sector and purpose the AI serves.
The Commission adds that "simply relying on the AI systems' instructions for use or asking the staff to read them might be ineffective". It imposes no fixed format: "no strict requirements or mandatory trainings are imposed".
Enforcement, penalties and records
National market surveillance authorities supervise Article 4, not the EU AI Office. The Commission says they start supervising and enforcing the rules in August 2026. The penalties come from national law: Article 99(1) of the AI Act tells each Member State to set rules on penalties and other enforcement measures, "which may also include warnings and non-monetary measures".
The Commission describes enforcement as proportionate, with sanctions based on the individual case, the gravity of the infringement and whether it was intentional or negligent. It also names the scenario that raises the stakes: a sanction "might, however, be more likely if there is proof of an incident due to lack of appropriate training and guidance of employees or other persons".
For records, the Commission's answer is short: "There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives." Keep one anyway. If something goes wrong with an AI output, a dated record of who learned what is your best evidence that you took measures.
What Article 4 does not require
From the Commission's Q&A:
- No certificate for staff or trainers.
- No AI officer or governance board: "no specific governance structure is mandated".
- No knowledge test: Article 4 "does not entail an obligation to measure the knowledge of AI of employees".
- No industry-specific rules from the AI Office. Your sector and the risk of your systems shape the content instead.
One obligation sits outside Article 4 and stays strict. Deployers of high-risk AI systems must make sure their staff are "sufficiently trained to handle the system and ensure human oversight" under Article 26. The Omnibus moved the start of those high-risk rules to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.
How I would meet Article 4 in a small or mid-sized company
This is my working method, built on the four Commission steps.
- List the tools. Ask every team which AI tools they use, including the free accounts nobody approved. You cannot train for tools you do not know about.
- Group the people. Daily users who send AI-assisted work to clients need more than colleagues who open ChatGPT once a month. Include contractors who work in your name.
- Write a one-page rule set. What data may go into which tool, who checks outputs before they reach a client, and which tasks stay with humans.
- Train on real work. People learn hallucination risk best when they catch the tool inventing a fact in their own document. My team workshops run half a day or a full day on the team's own documents and clients.
- Record it. Date, group, topics, trainer, materials. One shared spreadsheet is enough.
- Repeat when tools change. A new tool or a new use case, such as AI in hiring, means a new short session for the people affected.
If you want the curriculum for step 4, I wrote it out in AI training for employees: what a one-day workshop should cover. For the daily habits that stop hallucinations and data leaks, see how to use ChatGPT at work.
Get your team trained
Article 4 asks for measures that fit your people and your tools. A half-day workshop on your own tasks is one such measure, and the attendance list goes straight into your record. I run sessions in Lithuanian or English, on site in Vilnius or remote, with German and Russian on request. In Lithuania, the training runs through Retos galimybės (opens in a new tab), which publishes its prices. To plan a session, book a call and tell me how big the team is and which tools it uses.
Questions and answers
What does Article 4 of the EU AI Act require?
Providers and deployers of AI systems must take measures to support the AI literacy of their staff and of other people who operate or use AI systems on their behalf. The measures should fit those people's technical knowledge, experience, education and training, and the context in which the AI is used. Since the Digital Omnibus took effect on 27 July 2026, the law states that you do not have to guarantee any specific level of AI literacy for any individual.
Does Article 4 apply if my staff only use ChatGPT?
Yes. A company that uses AI systems in its work is a deployer. In its AI literacy Q&A, the European Commission answers that a company whose employees use ChatGPT to write advertising text or translate should inform them about the specific risks, for example hallucination.
Do employees need an AI literacy certificate?
No. The Commission's Q&A says there is no need for a certificate and that organisations can keep an internal record of trainings and other guiding initiatives.
When does Article 4 apply and who enforces it?
Article 4 has applied since 2 February 2025. National market surveillance authorities supervise and enforce it, starting in August 2026. Penalties come from national law, and the Commission says enforcement follows a proportionate approach.
Did the Digital Omnibus remove the AI literacy obligation?
No. Regulation (EU) 2026/1744 rewrote Article 4 but kept a duty on providers and deployers. It replaced the phrase 'to ensure, to their best extent, a sufficient level of AI literacy' with a duty to 'support the development of AI literacy', and it added tasks for the Commission, the Member States and the AI Board.