Guide · Compliance

The AI literacy obligation: what Article 4 actually requires

You have been told the EU AI Act obliges you to train your people. That is true, but not in the terms you are being sold. Here is the text, its scope, what counts as compliance, and what the Regulation really provides if you do nothing.

Zakaria El Asri12 min

The awkward fact

Article 4 appears in none of the fining tiers of Article 99.

In brief

The answer in one paragraph

Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff and among those who operate these systems on their behalf. It has applied since 2 February 2025. It defines no level to reach, requires no certification, sets no number of hours, and carries no fining tier in Article 99. It is a real best-efforts obligation that you should be able to document.

Which page do you need? Our guide to the AI Act timeline and obligations answers "what applies, and when". This one answers "we are told we must train our people, so what do we actually do". If you are looking for the high-risk dates, the other page is the one.

Primary source

The text, word for word

Start with what the Regulation says, because much of what circulates about Article 4 is a paraphrase of a paraphrase. In its current form Article 4 has three paragraphs. The first carries the obligation:

"Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."

The second paragraph puts the Commission and the Member States in a supporting role towards providers and deployers, in particular SMEs, and requires the Commission to publish practical examples of how to comply on the single information platform referred to in Article 62(3), point (b). The third tasks the AI Board with adopting recommendations, taking account of European competence frameworks, including by setting out common objectives.

Two observations before going further. The word "training" does not appear in the obligation itself. It appears only as one of the parameters to take into account, alongside experience and education. And AI literacy is defined, in Article 3, point 56: the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and the harm it can cause. A definition of purpose, not a syllabus.

A note on method. EUR-Lex returns an anti-bot screen to automated tools, which makes a direct machine-verified quotation of the Official Journal impossible. The wording above was taken from the European Commission's AI Act Service Desk and cross-checked against the Commission's AI literacy questions and answers, updated on 27 July 2026. Both are Commission publications. Where there is any doubt, the Official Journal prevails.

What changed

Article 4 was rewritten in July 2026

If you have read a briefing on Article 4 published before the summer of 2026, it describes a heavier obligation than the one in force. Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026, changed the wording.

VersionWhat the text asks forNature of the obligation
Original (2024/1689, applicable 2 February 2025)Take measures to "ensure, to their best extent, a sufficient level of AI literacy"A result to reach, but a result never defined and never measured
In force since 27 July 2026 (2026/1744)Take measures to "support the development of AI literacy", with no individual level to guaranteeA best-efforts obligation, openly framed as one
The two wordings of Article 4, taken from European Commission publications consulted on 29 September 2026.

Three practical consequences. The phrase "sufficient level" has gone from the text, so quoting it today means quoting repealed wording. The clause stating that no individual level has to be guaranteed is new, and it closes the door on the idea of a pass mark for every employee. And paragraphs 2 and 3 create duties for the Commission and the AI Board, not for you: producing examples and competence frameworks is their job.

What the Omnibus did not change is the application date. Article 4 has applied since 2 February 2025 and stayed in force throughout the negotiation. The deadline extensions it granted concern high-risk systems, set out in our AI Act implementation timeline.

Scope

Who is covered, precisely

Article 4 targets two roles and two categories of people. The roles first.

  • The provider (Article 3, point 3) develops an AI system or has one developed, and places it on the market or puts it into service under its own name or trademark.
  • The deployer (Article 3, point 4) uses an AI system under its own authority, except in the course of a personal non-professional activity.

Almost every company reading this page is a deployer. You buy a subscription to a conversational assistant, you switch on an AI feature in your CRM, you have an agent installed to sort your inbox: you are a deployer. There is no headcount threshold, no turnover threshold and no SME exemption in Article 4. A three-person firm is covered as fully as a group.

Then the people. The text refers to "staff" and to "other persons dealing with the operation and use of AI systems" on your behalf. The Commission, in its questions and answers, indicates that this second category can include a contractor, a service provider or a client. The useful test is therefore not the employment contract, it is whether someone operates your system under your authority.

SituationCovered by Article 4?
Employees using an AI assistant in their daily workYes
Executives and managers deciding on deploymentsYes, the text draws no distinction by seniority
A contractor running your AI agent on your behalfYes, on the Commission’s reading
An employee who uses no AI system at allOutside the scope of Article 4
Strictly personal use, outside any professional settingOutside scope, excluded by the definition of deployer
Lumyniq's reading of Article 4 and the definitions in Article 3. Borderline cases are decided one by one.

The sore point

The "sufficient level" was never defined

This is the question everyone asks, and the honest answer is an uncomfortable one: there is no target level, there never was one, and since July 2026 the notion has been removed from the text.

The Commission is explicit in its questions and answers: Article 4 does not entail an obligation to measure employees' knowledge of AI, and does not require guaranteeing any specific level for any individual. There is no score, no threshold and no mandatory assessment.

What the text does impose is proportionality. Measures must take account of four parameters, written into the article: the technical knowledge, experience, education and training of the people concerned; the context in which the systems are to be used; and the persons on whom those systems are used. In other words, the same half-day for everybody is precisely what the text does not ask for. A lawyer having case documents summarised and a salesperson having follow-up emails drafted do not face the same risks.

So the right question is not "what level should we reach" but "can we show our measures fit our actual uses". That is what AI training built around your own processes is for, because it starts from what your teams really do rather than from a common syllabus.

In practice

What counts as compliance, and what to keep

Since no format is imposed, compliance turns on two things: measures that genuinely fit, and the ability to show them. The Commission states that no certificate is needed and that organisations can keep an internal record of trainings and other guiding initiatives. That is the only evidential guidance the regulator gives, and it is deliberately loose.

A defensible file usually holds the following, none of which is required by name:

ItemWhat it demonstrates
A dated inventory of the AI systems in useThat you know what is running, the precondition for any proportionate measure
A map of the roles exposed to those systemsThat the population in scope was thought through, not inherited
The content of each action, by populationThe proportionality the text requires
A dated attendance listThat the action really happened, without having to measure a level
An internal AI usage policyThat understanding is maintained between sessions
A scheduled review dateThat the programme tracks how your uses evolve
Items commonly found in an Article 4 file. None is mandated by the Regulation. Lumyniq, 2026.

The AI Office also publishes a living repository of AI literacy practices, contributed by signatories of the AI Pact. It is a useful and free source of ideas, with one caveat the Commission writes itself: replicating a practice from the repository grants no presumption of compliance with Article 4.

One last word on content. Understanding a tool also means understanding what it does with your data and what happens when it gets things wrong. Our guides on AI agent security and on the transparency obligation for AI agents cover two topics that belong in just about any serious programme.

Sorting it out

What the text requires, and what the market claims it requires

Article 4 has become a sales argument. It is short, it is in force, and its edges are blurred, which makes it convenient marketing material. Here is the sorting.

What circulatesWhat the text says
"You must train 100% of your workforce"The obligation covers those dealing with the operation and use of AI systems, not the entire headcount
"You need a recognised certification"No certification scheme exists. The Commission writes that no certificate is needed
"There is a minimum number of hours"No number of hours appears in the text or in the Commission’s documents
"You must assess every employee’s level"The Commission states that Article 4 entails no obligation to measure employees’ knowledge
"You face EUR 15 million or 3% of turnover"That tier is Article 99(4), which does not cover Article 4. See the next section
"A body can certify your Article 4 compliance"No attestation or presumption-of-conformity mechanism is provided for Article 4
Claims found in commercial material, checked against the text and Commission publications, September 2026.

None of this means the obligation is decorative. It exists, it applies, and a company with nothing to tell an inspector would be in breach. But the bar to clear is a proportionate, documented programme, and not a certification plan.

The real risk

If you do nothing: what is provided, and what is not

Precision matters here, because loose talk is expensive in both directions. Article 99 of the Regulation does not mention Article 4. Its three fining tiers target named breaches:

TierArticles coveredCap
Article 99(3)Article 5, prohibited practicesEUR 35m or 7% of total worldwide annual turnover
Article 99(4)Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50EUR 15m or 3%
Article 99(5)Incorrect or misleading information supplied to authoritiesEUR 7.5m or 1%
Article 99 of Regulation (EU) 2024/1689, taken from the Commission's AI Act Service Desk on 29 September 2026. Article 4 appears in none of these tiers.

What remains is Article 99(1): each Member State lays down the rules on penalties applicable to infringements of the Regulation, which must be effective, proportionate and dissuasive, with regard to the viability of SMEs. A Member State may therefore penalise a breach of Article 4. The Regulation simply does not do so itself, and sets no cap for that case.

The Commission, for its part, indicates that oversight of Article 4 sits with the national market surveillance authorities rather than the AI Office, and that those authorities can in principle impose penalties and other enforcement measures from 2 August 2026, any sanction having to remain proportionate and assessed case by case.

In France, the machinery is not in place yet. The law designating the national competent authorities sits in an EU-adaptation bill adopted by the Senate on 18 February 2026 and passed to the Assemblée nationale; we could not confirm its final adoption as at 29 September 2026. As long as no authority is designated and no national penalty regime is published, nobody can tell you what a breach of Article 4 costs in France. Anyone quoting a figure for that specific case is inventing it.

Two good reasons not to wait remain. The first is that the obligation has been running since 2 February 2025: a penalty regime adopted tomorrow will not apply retroactively, but your own records will show how late you started. The second is that Article 4 is the one part of the AI Act that pays off regardless of enforcement. Teams that understand what they are handling make fewer confidentiality mistakes and are better at spotting a model output that should not be trusted.

Taking action

What an Article 4 programme looks like

The Commission suggests a four-stage progression in its questions and answers: a general understanding of AI, the role of the organisation, the risks specific to the systems in use, then a deeper layer matched to each person's level. Here is that logic turned into six executable steps.

  1. Inventory the AI systems actually in use, including AI features switched on inside software you do not think of as "AI", and tools adopted by teams without going through IT. Without that inventory, no measure can be proportionate.
  2. Identify the exposed populations and what each does with those systems. Someone who drafts, someone who decides on the basis of a model output and someone who configures the tool have three different needs.
  3. Set a common baseline: what an AI system is, what it does with the data it is given, why it can produce a confident wrong answer, and what the company permits or forbids.
  4. Go deeper by function, on your real files. This is where the proportionality the text requires is won or lost, and it is the part a generic catalogue does not cover.
  5. Write a short usage policy people can actually read: approved tools, forbidden data, the habit of verifying, and who to alert when in doubt. It keeps understanding alive between sessions.
  6. Date it, file it, schedule the review. Content, attendees, date, and a point in the calendar to refresh it when your uses change. That is exactly what the Commission describes as an internal record.

These steps overlap with the scoping work we run as AI consulting before any deployment, and step 4 is the heart of our AI training programmes. If your uses touch recruitment, healthcare or legal work, the requirements arriving on 2 December 2027 are worth preparing for now.

Do not confuse them

Article 4 is not Article 26(2)

One frequent confusion is worth clearing up, because it changes the nature of the risk. If your company deploys a high-risk AI system within the meaning of Annex III, screening job applications or assessing creditworthiness for instance, a second requirement applies to you.

Article 4Article 26(2)
WhoEvery provider and every deployerDeployer of a high-risk system
WhatSupport the development of AI literacyAssign human oversight to people with competence, training and authority
Since when2 February 20252 December 2027 for Annex III
Dedicated fining tierNone in Article 99Yes, Article 99(4): EUR 15m or 3%
The two competence obligations in the Regulation, side by side. Lumyniq, 2026.

Put differently: Article 4 is a broad obligation with little attached penalty, Article 26(2) is a narrow one with a clear penalty. A programme that handles the first without checking the second misses the real financial exposure. To work out whether your uses are high-risk, the sector table in our guide to AI Act obligations sets out the most common cases.

FAQ

Frequently asked questions about the AI literacy obligation

Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff and among those who operate these systems on their behalf. It is a best-efforts obligation and it has applied since 2 February 2025. The text never says "training" and imposes no format: a training course is one way to meet it, not the only one.

Related guides

Read next

Sources

Links verified at publication. Regulatory texts change — always defer to the official source.

Let's talk about your project

A question, a project, an idea? We respond within 24h. Free audit, no commitment.

Contact details