Skip to main content
Enterprise AI

EU AI Act Article 4: What AI Literacy Training Really Requires in 2026

Article 4 of the EU AI Act obliges every provider and deployer to support AI literacy among staff. Here is what the July 2026 rewrite changed, what the penalties actually are, and how to evidence compliance.

kju Team

AI Education Experts

11 min read
Diverse team of European professionals reviewing AI training materials on a large display in a sunlit office, reflecting EU AI Act Article 4 workforce literacy obligations

Article 4 of the EU AI Act is the obligation most organisations know they have and fewest can evidence. It is also the one that changed most recently: on 27 July 2026 the Digital Omnibus on AI rewrote the article, and a good deal of the compliance commentary written before that date — including, until this update, parts of this post — is now describing a text that no longer exists.

This is a rewritten and corrected guide to what Article 4 says today, what it actually costs to get wrong, and how to show your work.

The short answer. Article 4 of the EU AI Act requires providers and deployers to take measures supporting AI literacy among staff and anyone operating AI on their behalf. It has applied since 2 February 2025. It carries no direct EU fine — Article 99 does not list it — but Member States set their own penalties, enforced by national market surveillance authorities.

What Does Article 4 of the EU AI Act Require?

The legal text is deliberately short. Since 27 July 2026, Article 4(1) — as amended by the Digital Omnibus on AI — reads:

Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.

AI literacy itself is defined in Article 3(56) as the "skills, knowledge and understanding" that let providers, deployers, and affected persons "make an informed deployment of AI systems, as well as gain awareness about the opportunities and risks of AI and possible harm it can cause."

What Changed in the July 2026 Digital Omnibus?

This is the part most Article 4 guidance has not caught up with. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It amended Article 4 directly.

Before 27 July 2026After
Core duty"ensure, to their best extent, a sufficient level of AI literacy""take measures to support the development of AI literacy"
Individual outcomesimplied a level to be reachedexpressly "does not require... to guarantee any specific level of AI literacy of any individual"
Whose context countsstaff's knowledge and use contextsame, plus "the persons or groups of persons on whom the AI systems are to be used"
Supporting dutiesnonenew Article 4(2) obliges the Commission and Member States to support providers and deployers, "in particular SMEs", and publish practical compliance examples

Three things follow from that, and they matter more than the wording change looks:

Article 4 became an obligation of effort, not an obligation of result. You are no longer on the hook for whether a given employee reached a given standard. You are on the hook for whether you took measures. That is easier to satisfy and much easier to fail visibly, because "we took measures" is a claim about what you did, and a claim about what you did is a claim you can be asked to evidence.

Article 4 was not delayed. The omnibus delayed the high-risk regime substantially — Annex III standalone high-risk systems moved to 2 December 2027 and Annex I embedded high-risk systems to 2 August 2028 — but Article 4 has applied since 2 February 2025 and continues to. Teams reading "the AI Act got pushed back" and concluding they have another year are reading the wrong article.

The new scope clause widens who you must think about. "The persons or groups of persons on whom the AI systems are to be used" brings the subjects of your AI systems into the literacy analysis, not just the operators. If you screen candidates, triage patients, or score customers, that clause is pointed at you.

Who Does the AI Literacy Obligation Apply To?

Article 4 applies to every provider and deployer of an AI system used in the EU — regardless of risk class, industry, or company size. That includes non-EU companies whose AI outputs are used inside the EU, and it extends to contractors, vendors, and anyone else operating AI on your behalf.

This is the scope that trips most organisations up. Article 4 is not limited to high-risk AI systems. In practice the obligation covers:

  • Providers — anyone who develops or places an AI system on the EU market. Builders of internal AI tools count.
  • Deployers — anyone using an AI system under their own authority, which includes almost every company using a general-purpose assistant, a copilot, or any AI feature embedded in SaaS.
  • Staff and "other persons" — the European Commission's guidance is explicit that this reaches beyond the payroll: "these are not employees, but persons broadly under the organisational remit. It could be, for example, a contractor, a service provider, a client."
  • Extraterritorial reach — like the GDPR, the AI Act reaches non-EU companies whose AI output is used inside the EU.

If you have ever heard a leader say "we don't do AI, we just use a chatbot", they are describing a deployer. Deployers have Article 4 obligations too.

What Counts as "Sufficient" AI Literacy?

Strictly, nothing does any more: the word "sufficient" left the text in July 2026, and the new sentence says the obligation does not require guaranteeing any specific level for any individual. But the practical question — how much is enough? — survives the rewrite, and the European Commission's AI literacy guidance is the best answer available.

The Commission is unusually plain about how light the bar is. It states that "the AI Office does not intend to impose strict requirements or mandatory trainings", that "there is no one size fit all", and that Article 4 "does not entail an obligation to measure the knowledge of AI of employees". No governance structure is mandated either; you do not need to appoint an AI officer.

It is equally plain about the floor. On the most common shortcut it says: "in many cases, simply relying on the AI systems' instructions for use or asking the staff to read them might be ineffective and insufficient." Handing staff a vendor manual is not a measure.

Between those two markers, the Commission's guidance asks organisations to build on four things: a general understanding of AI within the organisation, clarity about whether you are a provider or a deployer, consideration of the risk of the systems you actually use, and actions built on that analysis. That maps cleanly to a role-based competency model.

AudienceCore AI literacy focus
Executives and boardAI strategy, regulatory landscape, governance, reputational risk, oversight duties
People managersUse-case approval, exception handling, coaching staff, flagging misuse
Front-line usersResponsible prompting, evaluating outputs, data handling, recognising hallucinations, when to escalate
Technical teams (data, engineering, security)Model behaviour, bias, evaluation, red-teaming, integration risk, logging and audit
Procurement and legalVendor due diligence, DPIAs, model cards, contractual safeguards, AI Act classification

The US Department of Labor's 2026 AI literacy framework, released in February 2026, reaches the same conclusion from a different direction: fundamentals, automation versus augmentation, generative AI, data ethics, algorithmic bias, and practical prompting all belong in the curriculum, but the weighting depends on role.

What Are the Penalties for Breaching Article 4?

This is where most published guidance, including earlier versions of this post, gets it wrong. The correction is worth stating bluntly.

Article 4 carries no direct EU-level fine. Article 99 sets the AI Act's administrative fines, and paragraphs 3, 4 and 5 each name the specific articles they cover. Article 4 appears in none of them. Any source telling you an Article 4 breach costs "up to €7.5 million or 1%" has misread Article 99(5), which is the penalty for supplying incorrect, incomplete or misleading information to authorities.

Here is what Article 99 actually says, so you can hold any vendor claim against it:

TierCeilingWhat it covers
Article 99(3)€35,000,000 or 7% of total worldwide annual turnover, whichever is higherNon-compliance with the prohibited AI practices in Article 5
Article 99(4)€15,000,000 or 3%, whichever is higherObligations of providers (Art. 16), authorised representatives (22), importers (23), distributors (24), deployers (26), notified bodies (31, 33, 34), and transparency (50)
Article 99(5)€7,500,000 or 1%, whichever is higherSupplying incorrect, incomplete or misleading information to notified bodies or national competent authorities
Article 101€15,000,000 or 3%, whichever is higherProviders of general-purpose AI models. Imposed by the Commission itself, not national authorities

Two details are worth knowing. For SMEs and start-ups, Article 99(6) inverts the rule: the fine is capped at the percentage or the amount, "whichever thereof is lower". And Article 101 (the GPAI tier) was carved out of the August 2025 penalties start date and applies from 2 August 2026.

So what is the actual exposure? It runs through Article 99(1), which requires Member States to "lay down the rules on penalties and other enforcement measures, which may also include warnings and non-monetary measures, applicable to infringements of this Regulation by operators", and requires those penalties to be "effective, proportionate and dissuasive". National market surveillance authorities enforce Article 4, not the AI Office.

The Commission's own guidance confirms the route and — importantly — the trigger:

National market surveillance authorities could impose penalties and other enforcement measures to sanction infringements of Article 4. This will be based on national laws that Member States are due to adopt by 2 August 2025.

Any sanction must be proportionate, based on the individual case and take into account factors such as nature and gravity and the intentional and negligent character of the infringement. This might, however, be more likely if there is proof of an incident due to lack of appropriate training and guidance of employees or other persons.

That last sentence is the whole risk model in one line. Article 4 exposure is incident-triggered. Nobody is going to fine you for having a thin training programme. They are going to look at your training programme after something goes wrong, and the question will be whether the harm traces back to staff who were never equipped to avoid it.

One thing Article 4 does not create: a private right to sue. The Commission is explicit that "the AI Act doesn't create criminal offences or a right to compensation." A person harmed by an AI system can bring a claim, but under national law, not under the AI Act itself.

How Do You Document and Evidence Article 4 Compliance?

Start with an honest statement of the legal position, because a lot of compliance marketing overstates it: the AI Act imposes no record-keeping obligation for Article 4. The Commission's guidance, answering directly how organisations should document their actions, says only this:

There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives.

Note the register. "Can", not "must". Anything stronger than that is inferred good practice, and you should treat claims to the contrary with suspicion.

The reason to keep records anyway is evidential, not statutory. Article 4 is now an obligation of effort, and enforcement is incident-triggered. Both point the same way: the thing you will one day be asked to produce is proof that you took measures, before the incident, for the people involved in it. An audit trail is how you answer that question in an afternoon instead of a quarter.

A record that actually does the job has six fields:

FieldWhy a regulator would care
WhoNamed individual or role group, including contractors and service providers — the "other persons" limb of Article 4
WhatTopic and depth, mapped to the risk of the systems that person actually uses
WhenDated, so you can show coverage predates any incident under investigation
Why this contentThe link back to your AI inventory and risk analysis — this is the "measures built on that analysis" the Commission asks for
Delivery evidenceCompletion, participation, or attempt data. Not a test score: Article 4 does not require you to measure knowledge
Review dateWhen the content was last refreshed against tool changes

Two things to avoid. Do not build the record around assessment scores — the Commission has said Article 4 carries no obligation to measure employees' knowledge, and inventing a pass mark creates a standard you can then fail against. And do not treat the Commission's Living Repository of AI Literacy Practices as a safe harbour: it is explicit that "replicating the practices collected in this living repository does not automatically grant presumption of compliance with Article 4."

An Article 4 Compliance Checklist

A working sequence, in the order the obligations actually bite:

  1. Determine your role for each system. Provider, deployer, or both. The answer differs per system and drives everything downstream.
  2. Inventory your AI exposure, including shadow AI. You cannot train for AI you do not know staff are using. Run a use survey and map approved against unapproved tools.
  3. Extend the inventory to "other persons". Contractors, service providers, agencies, and clients operating your systems on your behalf are inside Article 4's scope.
  4. Record the risk of each system, and note who the system is used on — the July 2026 text now asks you to consider affected persons, not just operators.
  5. Tier the content by role. Executives, managers, front-line users, technical teams, and procurement need different depth. One thirty-minute module for the whole company is not a measure built on an analysis.
  6. Cover responsible use, not just prompting. Risk awareness, data boundaries, output accountability, and escalation are the parts the Commission actually names.
  7. Retire the manual-only approach. Pointing staff at instructions for use is specifically called out as likely to be ineffective and insufficient.
  8. Make it continuous. Tools change monthly; an annual programme is stale before it is audited.
  9. Log delivery as you go, using the six fields above. Retrofitting a training record after an incident is exactly what it will look like.
  10. Re-check your national regime. Penalties for Article 4 come from Member State law under Article 99(1), so exposure varies by country and is not uniform across the EU.
  11. Set a review trigger, not just a review date: a new AI tool, a new use case, or a near-miss should all force a refresh.

Why Most Organisations Are Not Ready

The data on workforce readiness is the reason Article 4 exists.

MetricFigureSource
Employees who have received formal AI training32%Savia Learning
Employees using AI tools without IT approval68%Gartner via SQ Magazine
Enterprise leaders reporting an AI skills gap in 202659%DataCamp 2026 State of AI Literacy
Organisations with a mature, workforce-wide upskilling programme35%DataCamp
Organisations with mature programmes reporting strong AI ROI42% (vs 21% average)DataCamp

The combined picture: most European workforces are already using AI that IT does not fully see, without a formal understanding of how it works, when to question its outputs, or where the legal lines are. Given that Article 4 enforcement is incident-triggered, that is precisely the condition under which an incident becomes an enforcement matter rather than an embarrassment.

How to Build an Article 4 Programme That Holds Up

The Commission has not mandated a training format, which means the design constraint is not regulatory but practical: the programme has to survive contact with the working week.

Research on how adults retain knowledge is unambiguous about pace. Microlearning delivered in short daily sessions achieves 80% completion rates against roughly 20% for conventional long-form courses, and role-specific, contextualised training delivers 40% better comprehension and retention than generic content, with a 25-30% improvement in actual tool adoption. The full evidence is in why most AI training programs fail.

Those numbers are not compliance fluff. Under an obligation of effort, a programme people actually complete is the difference between a measure you took and a measure you announced — a 20% completion rate means four out of five staff received no measure at all.

Three design choices follow:

Build the curriculum from the inventory, not from a catalogue. The Commission's four-part guidance is an analysis, and the analysis is the compliance artefact. A course list bought off the shelf cannot show why this content went to these people.

Weight towards judgment. A curriculum that is ninety per cent prompt technique misses the point of the article. The literacy Article 4 describes is the ability to recognise opportunities, risks, and possible harm — that is judgment, and judgment is built by repetition against realistic cases.

Instrument it from day one. Delivery data you did not collect at the time cannot be reconstructed later. This is the cheapest thing on the list and the one most often skipped.

Key Dates

DateWhat happens
2 February 2025Article 4 becomes applicable
2 August 2025The AI Act's penalties regime (Chapter XII, including Article 99) applies, with Article 101 carved out. Member States were due to have national penalty rules in place
27 July 2026The Digital Omnibus on AI enters into force and rewrites Article 4
2 August 2026Article 50 transparency duties apply; the Commission takes up general-purpose AI enforcement under Article 101
2 December 2027Annex III standalone high-risk system rules apply, delayed from 2026
2 August 2028Annex I embedded high-risk system rules apply, delayed from 2027

One caveat on dates worth knowing if you are drafting board papers: the Commission's own AI literacy Q&A gives both 2 August 2026 and 3 August 2026 as the point national authorities begin supervising Article 4. The difference is immaterial in practice, but if a source quotes one with great confidence, that confidence is not coming from the primary text.

How kju Helps You Meet Article 4

kju is built to support daily AI fluency at work. It combines role-specific tracks, industry context, and an admin surface for recording delivery across teams, which is the evidence layer Article 4 quietly rewards.

If you are mapping a programme now, start with what AI fluency really means in 2026, the difference between AI literacy and AI fluency, and our enterprise page for how teams deploy kju at scale. The why AI training fails deep-dive covers why annual workshops struggle against a continuous obligation.

Article 4 has been in force since February 2025 and was rewritten last month. The programmes that hold up will not be the ones assembled in a panic after an incident — they will be the ones already embedded in the rhythm of work, with a dated record to prove it.

Frequently Asked Questions

What is Article 4 of the EU AI Act?
Article 4 is the AI literacy obligation in the EU AI Act. It requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff and anyone else operating AI on their behalf. It has applied since 2 February 2025. It was amended on 27 July 2026 by the Digital Omnibus on AI, which replaced the original 'ensure a sufficient level' wording with 'support the development of' and added that the obligation does not require guaranteeing any specific level of literacy for any individual.
Who has to comply with the AI literacy requirement?
Any organisation that provides or deploys an AI system in the EU — including chatbots, copilots, generative AI tools, and automated decisioning — has to comply. Article 4 is sector-agnostic, size-agnostic, and applies regardless of risk class. It also reaches non-EU companies whose AI outputs are used inside the EU, and covers contractors and vendors acting on your behalf.
What are the penalties for non-compliance with Article 4?
There is no direct EU-level fine for Article 4. The AI Act's fine tiers in Article 99(3), (4) and (5) list the articles they cover, and Article 4 is not among them. Instead, Article 99(1) requires each Member State to lay down its own penalties for infringements not otherwise covered, which must be effective, proportionate and dissuasive, and national market surveillance authorities enforce them. The European Commission has said enforcement is more likely where there is proof of an incident caused by a lack of appropriate training.
What counts as 'sufficient' AI literacy under Article 4?
Since the July 2026 amendment the text no longer uses the phrase 'sufficient level', and it states that the obligation does not require guaranteeing any specific level of literacy for any individual. The European Commission has said it does not intend to impose strict requirements or mandatory trainings, and that there is no single approach that fits every organisation. Its guidance asks organisations to build training on a general understanding of AI, their role as provider or deployer, and the risk of the systems they actually use.
Do we have to document our AI literacy training?
The AI Act imposes no record-keeping duty for Article 4, and the European Commission has said no certificate is needed and that organisations 'can' keep an internal record of trainings and other guiding initiatives. Keeping records is therefore evidential good practice rather than a statutory requirement. Because the Commission has also said enforcement is more likely where an incident traces back to inadequate training, a dated record of who was trained on what is the practical way to rebut that claim.
Is ChatGPT or Microsoft Copilot covered by Article 4?
Yes. Article 4 applies to all AI systems regardless of risk class, so everyday generative assistants and copilots fall inside the obligation. If your staff use them for work, you are a deployer and must take measures to support their AI literacy.
How should companies train for AI literacy under Article 4?
The European Commission does not mandate a format, but its guidance says that simply relying on a system's instructions for use, or asking staff to read them, is in many cases ineffective and insufficient. Its guidance points to role-specific, risk-aware training built on an analysis of the systems the organisation actually uses. The Commission's Living Repository of AI Literacy Practices collects what organisations are doing, though replicating those practices does not by itself grant a presumption of compliance.