Guide · Compliance
You have been told the EU AI Act obliges you to train your people. That is true, but not in the terms you are being sold. Here is the text, its scope, what counts as compliance, and what the Regulation really provides if you do nothing.
The awkward fact
Article 4 appears in none of the fining tiers of Article 99.
In brief
Which page do you need? Our guide to the AI Act timeline and obligations answers "what applies, and when". This one answers "we are told we must train our people, so what do we actually do". If you are looking for the high-risk dates, the other page is the one.
Primary source
Start with what the Regulation says, because much of what circulates about Article 4 is a paraphrase of a paraphrase. In its current form Article 4 has three paragraphs. The first carries the obligation:
"Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."
The second paragraph puts the Commission and the Member States in a supporting role towards providers and deployers, in particular SMEs, and requires the Commission to publish practical examples of how to comply on the single information platform referred to in Article 62(3), point (b). The third tasks the AI Board with adopting recommendations, taking account of European competence frameworks, including by setting out common objectives.
Two observations before going further. The word "training" does not appear in the obligation itself. It appears only as one of the parameters to take into account, alongside experience and education. And AI literacy is defined, in Article 3, point 56: the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and the harm it can cause. A definition of purpose, not a syllabus.
A note on method. EUR-Lex returns an anti-bot screen to automated tools, which makes a direct machine-verified quotation of the Official Journal impossible. The wording above was taken from the European Commission's AI Act Service Desk and cross-checked against the Commission's AI literacy questions and answers, updated on 27 July 2026. Both are Commission publications. Where there is any doubt, the Official Journal prevails.
What changed
If you have read a briefing on Article 4 published before the summer of 2026, it describes a heavier obligation than the one in force. Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026, changed the wording.
| Version | What the text asks for | Nature of the obligation |
|---|---|---|
| Original (2024/1689, applicable 2 February 2025) | Take measures to "ensure, to their best extent, a sufficient level of AI literacy" | A result to reach, but a result never defined and never measured |
| In force since 27 July 2026 (2026/1744) | Take measures to "support the development of AI literacy", with no individual level to guarantee | A best-efforts obligation, openly framed as one |
Three practical consequences. The phrase "sufficient level" has gone from the text, so quoting it today means quoting repealed wording. The clause stating that no individual level has to be guaranteed is new, and it closes the door on the idea of a pass mark for every employee. And paragraphs 2 and 3 create duties for the Commission and the AI Board, not for you: producing examples and competence frameworks is their job.
What the Omnibus did not change is the application date. Article 4 has applied since 2 February 2025 and stayed in force throughout the negotiation. The deadline extensions it granted concern high-risk systems, set out in our AI Act implementation timeline.
Scope
Article 4 targets two roles and two categories of people. The roles first.
Almost every company reading this page is a deployer. You buy a subscription to a conversational assistant, you switch on an AI feature in your CRM, you have an agent installed to sort your inbox: you are a deployer. There is no headcount threshold, no turnover threshold and no SME exemption in Article 4. A three-person firm is covered as fully as a group.
Then the people. The text refers to "staff" and to "other persons dealing with the operation and use of AI systems" on your behalf. The Commission, in its questions and answers, indicates that this second category can include a contractor, a service provider or a client. The useful test is therefore not the employment contract, it is whether someone operates your system under your authority.
| Situation | Covered by Article 4? |
|---|---|
| Employees using an AI assistant in their daily work | Yes |
| Executives and managers deciding on deployments | Yes, the text draws no distinction by seniority |
| A contractor running your AI agent on your behalf | Yes, on the Commission’s reading |
| An employee who uses no AI system at all | Outside the scope of Article 4 |
| Strictly personal use, outside any professional setting | Outside scope, excluded by the definition of deployer |
The sore point
This is the question everyone asks, and the honest answer is an uncomfortable one: there is no target level, there never was one, and since July 2026 the notion has been removed from the text.
The Commission is explicit in its questions and answers: Article 4 does not entail an obligation to measure employees' knowledge of AI, and does not require guaranteeing any specific level for any individual. There is no score, no threshold and no mandatory assessment.
What the text does impose is proportionality. Measures must take account of four parameters, written into the article: the technical knowledge, experience, education and training of the people concerned; the context in which the systems are to be used; and the persons on whom those systems are used. In other words, the same half-day for everybody is precisely what the text does not ask for. A lawyer having case documents summarised and a salesperson having follow-up emails drafted do not face the same risks.
So the right question is not "what level should we reach" but "can we show our measures fit our actual uses". That is what AI training built around your own processes is for, because it starts from what your teams really do rather than from a common syllabus.
In practice
Since no format is imposed, compliance turns on two things: measures that genuinely fit, and the ability to show them. The Commission states that no certificate is needed and that organisations can keep an internal record of trainings and other guiding initiatives. That is the only evidential guidance the regulator gives, and it is deliberately loose.
A defensible file usually holds the following, none of which is required by name:
| Item | What it demonstrates |
|---|---|
| A dated inventory of the AI systems in use | That you know what is running, the precondition for any proportionate measure |
| A map of the roles exposed to those systems | That the population in scope was thought through, not inherited |
| The content of each action, by population | The proportionality the text requires |
| A dated attendance list | That the action really happened, without having to measure a level |
| An internal AI usage policy | That understanding is maintained between sessions |
| A scheduled review date | That the programme tracks how your uses evolve |
The AI Office also publishes a living repository of AI literacy practices, contributed by signatories of the AI Pact. It is a useful and free source of ideas, with one caveat the Commission writes itself: replicating a practice from the repository grants no presumption of compliance with Article 4.
One last word on content. Understanding a tool also means understanding what it does with your data and what happens when it gets things wrong. Our guides on AI agent security and on the transparency obligation for AI agents cover two topics that belong in just about any serious programme.
Sorting it out
Article 4 has become a sales argument. It is short, it is in force, and its edges are blurred, which makes it convenient marketing material. Here is the sorting.
| What circulates | What the text says |
|---|---|
| "You must train 100% of your workforce" | The obligation covers those dealing with the operation and use of AI systems, not the entire headcount |
| "You need a recognised certification" | No certification scheme exists. The Commission writes that no certificate is needed |
| "There is a minimum number of hours" | No number of hours appears in the text or in the Commission’s documents |
| "You must assess every employee’s level" | The Commission states that Article 4 entails no obligation to measure employees’ knowledge |
| "You face EUR 15 million or 3% of turnover" | That tier is Article 99(4), which does not cover Article 4. See the next section |
| "A body can certify your Article 4 compliance" | No attestation or presumption-of-conformity mechanism is provided for Article 4 |
None of this means the obligation is decorative. It exists, it applies, and a company with nothing to tell an inspector would be in breach. But the bar to clear is a proportionate, documented programme, and not a certification plan.
The real risk
Precision matters here, because loose talk is expensive in both directions. Article 99 of the Regulation does not mention Article 4. Its three fining tiers target named breaches:
| Tier | Articles covered | Cap |
|---|---|---|
| Article 99(3) | Article 5, prohibited practices | EUR 35m or 7% of total worldwide annual turnover |
| Article 99(4) | Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50 | EUR 15m or 3% |
| Article 99(5) | Incorrect or misleading information supplied to authorities | EUR 7.5m or 1% |
What remains is Article 99(1): each Member State lays down the rules on penalties applicable to infringements of the Regulation, which must be effective, proportionate and dissuasive, with regard to the viability of SMEs. A Member State may therefore penalise a breach of Article 4. The Regulation simply does not do so itself, and sets no cap for that case.
The Commission, for its part, indicates that oversight of Article 4 sits with the national market surveillance authorities rather than the AI Office, and that those authorities can in principle impose penalties and other enforcement measures from 2 August 2026, any sanction having to remain proportionate and assessed case by case.
In France, the machinery is not in place yet. The law designating the national competent authorities sits in an EU-adaptation bill adopted by the Senate on 18 February 2026 and passed to the Assemblée nationale; we could not confirm its final adoption as at 29 September 2026. As long as no authority is designated and no national penalty regime is published, nobody can tell you what a breach of Article 4 costs in France. Anyone quoting a figure for that specific case is inventing it.
Two good reasons not to wait remain. The first is that the obligation has been running since 2 February 2025: a penalty regime adopted tomorrow will not apply retroactively, but your own records will show how late you started. The second is that Article 4 is the one part of the AI Act that pays off regardless of enforcement. Teams that understand what they are handling make fewer confidentiality mistakes and are better at spotting a model output that should not be trusted.
Taking action
The Commission suggests a four-stage progression in its questions and answers: a general understanding of AI, the role of the organisation, the risks specific to the systems in use, then a deeper layer matched to each person's level. Here is that logic turned into six executable steps.
These steps overlap with the scoping work we run as AI consulting before any deployment, and step 4 is the heart of our AI training programmes. If your uses touch recruitment, healthcare or legal work, the requirements arriving on 2 December 2027 are worth preparing for now.
Do not confuse them
One frequent confusion is worth clearing up, because it changes the nature of the risk. If your company deploys a high-risk AI system within the meaning of Annex III, screening job applications or assessing creditworthiness for instance, a second requirement applies to you.
| Article 4 | Article 26(2) | |
|---|---|---|
| Who | Every provider and every deployer | Deployer of a high-risk system |
| What | Support the development of AI literacy | Assign human oversight to people with competence, training and authority |
| Since when | 2 February 2025 | 2 December 2027 for Annex III |
| Dedicated fining tier | None in Article 99 | Yes, Article 99(4): EUR 15m or 3% |
Put differently: Article 4 is a broad obligation with little attached penalty, Article 26(2) is a narrow one with a clear penalty. A programme that handles the first without checking the second misses the real financial exposure. To work out whether your uses are high-risk, the sector table in our guide to AI Act obligations sets out the most common cases.
FAQ
Related guides
The wider view: what applies, on what date, and what changes on 2 December 2027.
The other obligation already in force, and the one your users notice first.
The technical material that belongs in an AI literacy programme.
Links verified at publication. Regulatory texts change — always defer to the official source.
A question, a project, an idea? We respond within 24h. Free audit, no commitment.