EU AI Act Article 4: The AI Literacy Obligation — Complete Guide (2026)
EU AI Act Article 4 requires every provider that places an AI system on the market, and every deployer that uses one, to take measures to ensure a sufficient level of AI literacy among their staff — regardless of the system's risk category. The obligation has applied since 2 February 2025. It sets no exam, certificate, or mandatory number of training hours; the Digital Omnibus softened it in summer 2026 from an obligation of result to a best-efforts obligation.
What exactly does Article 4 require?
Under the current text, providers and deployers take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The provision requires action, not a guaranteed outcome — it does not prescribe a specific form. Training, an internal policy, a user guide, and a role-specific briefing all count, provided the organisation actually did something, and what it did was reasonable given the circumstances.
Article 4 itself sets the criteria for judging the level: the technical knowledge, experience, education and training of the people involved; the context the systems will be used in; and the persons on whom the systems will be used. There is consequently no absolute threshold — "sufficient level" is a relative concept, measured against the context of use. Recital (20) states the underlying purpose: AI literacy should equip providers, deployers and affected persons to make informed decisions.
What exactly does "AI literacy" mean?
Article 3(56) defines AI literacy as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, and to gain awareness about the opportunities, risks and possible harm it can cause. The definition describes a capability, not a curriculum — the yardstick is not the volume of material delivered, but whether the person in that role can make an informed decision.
Who does it cover? Provider vs deployer — the difference
Article 4 sits among the AI Act's general provisions, with no risk-based filter — so it applies to both providers and deployers, regardless of the system's risk category. A provider is a natural or legal person that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer is a natural or legal person using an AI system under its own authority in a professional context. Mere use, however intensive, does not by itself turn a company into a provider — most SMEs are deployers: they use a purchased or subscribed AI tool.
The obligation does not stop at direct employees: the text also covers "other persons dealing with the operation and use of AI systems on their behalf," which the Commission's AI literacy Q&A reads as potentially including contractors, agency staff, and, in some cases, service providers acting on the company's behalf. This is not a binding interpretation, but supervisory authorities tend to follow it. Because there is no employment authority over such external persons, the practical route is a contractual clause covering the literacy requirement and its proof.
Does it apply to small companies — a five-person office?
Yes. The AI Act does not carve out an exemption by company size, and Article 4 has no SME exemption. The regulation's only carve-out for purely personal, non-professional use applies to natural persons, not to companies — a five-person consultancy that uses an AI tool in its professional work is a deployer. The practical burden, however, is much lighter than many assume: the realistic minimum is not a full conformity assessment, but essentially three things — an AI system inventory, an internal usage policy, and a documented literacy measure. It also makes no difference whether the tool in question is free and publicly available (for example, a free chatbot tier) — professional use is what triggers deployer status, not price.
Since when has it been mandatory, and is there a grace period?
Article 4's date of application is 2 February 2025, and the Digital Omnibus did not grant it a grace period. What the Omnibus changed was not the deadline, but the nature of the obligation. One nuance is worth noting: the Article 99 penalty regime only became applicable from 2 August 2025, so for the period between 2 February and 2 August 2025 the legal basis for imposing a fine is contested — a finding of infringement and market-surveillance measures, however, were already possible in that window. The Commission's AI literacy Q&A also states that the supervisory and enforcement rules specific to Article 4 apply from 3 August 2026 — a date that has now passed, so enforcement action is, in principle, open from that point.
Is a few minutes of training enough? Is a minimum number of hours prescribed?
No number of hours, frequency, or minimum duration is set out in law — the yardstick is not duration but whether the measure taken is reasonable for the role and the risk involved. A short module, tightly targeted at the systems actually in use, formally counts as a "measure" exactly as much as a multi-hour course does; the real question is whether that short form reaches the level of informed decision-making the role requires. What the Commission's Q&A flags as a risk in itself is relying purely on sending out a user manual, or asking staff to "read this," with no documented, content-level follow-through.
Is an exam or a certificate required?
No. The regulation prescribes no exam, no mandatory curriculum, no accredited training provider, no individual or organisational certification, no external training-provider requirement, and no registration or notification duty — and there is no certificate that creates a presumption of conformity. There is also no harmonised standard for Article 4 today. An in-house, self-resourced programme is exactly as capable of satisfying the obligation as a purchased course — the difference lies in evidentiary strength, not in form.
What evidence should be kept? What does a regulatory inspection ask for?
No prescribed documentation format exists, so the mode of proof is open — but in practice, what demonstrates compliance is evidence of both the assessment process and its execution, not a bare attendance sheet. Four layers together give a substantive answer: an AI system inventory (which systems, for what purpose, under which risk category); a role-to-risk mapping (a written decision on which role needs which level of literacy, and why — arguably the single most important element, because it documents the reasonable-care assessment itself); evidence of execution (dated training or briefing material, attendee lists, an internal policy and its rollout); and a maintenance trail (updates triggered by a new system, a role change, or an incident). What tends to prove little: a one-off email with a user manual attached, a content-free certificate, or training unrelated to the systems actually in use.
What is the penalty if a company doesn't comply?
None directly. Article 99(4)'s closed list of fineable provisions — Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50 — does not include Article 4, so no EU-level fine amount attaches to it. Anyone who quotes a "€15 million Article 4 fine" is contradicted by the regulation's own text.
Three indirect channels remain, however. First, under Article 99(1), member states may set their own non-monetary measures, including warnings, for infringements not otherwise fineable — national market surveillance authorities can, per the Commission Q&A, act on Article 4 non-compliance through these. Second, an absent literacy programme can serve as indirect evidence of a breach of Article 26(2), which requires a competent human overseer for high-risk systems — and that provision is fineable under Article 99(4)(e). Third, the absence can be treated as an aggravating factor when a fine for a different infringement is calculated, and it feeds into general civil-law and employment-law standards of reasonable care; in practice, the strongest real-world pressure is contractual and procurement-driven — an AI-literacy representation is an increasingly common clause in B2B contracts.
How Article 4 relates to human oversight (Articles 14 and 26)
The three provisions are concentric. Article 4 is a general baseline, applying to every AI system and every affected staff member. Article 26(2), on top of that and only for high-risk systems, requires the specific person carrying out human oversight to have the necessary competence, training, and authority — and that is fineable. Article 14 is the provider-side design obligation: a high-risk system must be designed so that natural persons can effectively oversee it. Satisfying Article 4 alone does not satisfy Article 26(2); conversely, Article 26(2) preparation also counts toward Article 4.
What did the Digital Omnibus change in Article 4?
It replaced the normative core — "ensure... a sufficient level of AI literacy" — with "take measures to... support the development of AI literacy," and explicitly stated that the provision does not oblige anyone to guarantee any individual's specific literacy level. The obligation itself remained; its date of application is still 2 February 2025. The Commission's proposal of 19 November 2025 (COM(2025) 836 final) had originally targeted Article 4 for full deletion; the European Parliament's compromise restored the obligation but lowered its bar. The legislator therefore made a deliberate choice to keep the norm while softening its rigour.
The distinction between an obligation of result and an obligation of best efforts (diligence) matters in practice. Under an obligation of result, the obligor is responsible for the promised state of affairs, and the room for excuse is narrow. Under an obligation of best efforts, the obligor is responsible for a reasonably diligent process, and an infringement is established only if that process fell short of what was generally expected in the situation — more favourable to the obligor, but not toothless: doing nothing at all remains an infringement even under a best-efforts standard. The Digital Omnibus on AI, (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 — this is current law, not a draft.
How does it relate to the GDPR?
The two apply in parallel and independently. AI Act Article 2(7) explicitly states that the regulation does not affect EU data protection law — so there is no substitution relationship between Article 4 and the GDPR's own training-related provisions (Articles 29, 32(4), 39), even though they overlap substantively. The two training tracks can be run as a single programme, but the documentation should still show which element satisfied which regulation.
There is also an employment-law dimension. Article 2(11) allows member states to maintain or introduce more favourable rules for workers — Article 4 is therefore a minimum standard, which national labour law or collective agreements may exceed. A separate rule, Article 26(7), requires a deployer acting as an employer to inform workers' representatives and affected workers before putting a high-risk system into use at the workplace — an information right, not a co-determination right.
In-house training or an external provider?
The law favours neither format. The AI Office's "living repository" of practices — e-learning platforms, in-person training, bootcamps, industry-academia partnerships — explicitly states that publication neither endorses nor certifies any individual practice, and that copying an entry does not create a presumption of conformity with Article 4. Functionally, it is a benchmarking resource, showing what the sector treats as reasonable effort — not a legal floor.
In practice, the choice between an internal briefing and a purchased course is an organisational question, not a legal one: team size, how fast the tool stack changes, and how much the content needs tailoring to internal processes. What the law actually requires — a documented assessment, role-specific calibration, and evidence of execution — applies equally to both routes.
Step by step: how to comply with Article 4
Build an AI system inventory
Record which AI systems your organisation uses or places on the market, for what purpose, and under which risk category. Without this, "adequate level" cannot be assessed.
Map roles to risk
Document, in writing, which role needs which level of AI literacy and why — this is the single most important element, because it is what demonstrates the reasonable-care assessment.
Set the level using Article 4's own criteria
Weigh the technical knowledge, experience, education and training of the people involved, the context of use, and the persons on whom the system's output will have an effect.
Deliver the measure and document it with a date
Training, an internal policy, a user guide, or a role-specific briefing — the form is open, but who received what, and when, needs to be recorded.
Cover contractors and agency staff contractually
The obligation extends to people acting on your behalf outside an employment relationship — since there is no instruction authority over them, this is typically addressed through a contractual clause and proof requirement.
Maintain the programme
Review and re-document the literacy measures whenever a new AI system is introduced, a role changes, or an incident occurs.
Provider vs deployer — which obligation applies to whom
| Aspect | Provider | Deployer |
|---|---|---|
| Definition | Develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark | Uses an AI system under its own authority in a professional context |
| Typical example | A company building or white-labelling an AI tool | Most SMEs: a company using a purchased or subscribed AI tool |
| Core obligations for high-risk systems | Art. 8–22: risk management, data governance, technical documentation, logging, quality management, conformity assessment, CE marking, EU database registration | Art. 26: use per the instructions for use, competent human oversight, input-data relevance, monitoring, log retention, information duties |
| Applies to both | Article 4 (AI literacy) and part of Article 50's transparency obligations | |
| Role-shift risk | Under Art. 25(1), a deployer becomes a provider if it puts its own name/trademark on a high-risk system, substantially modifies it, or changes its intended purpose so that it becomes high-risk | |
Frequently asked questions
Does every employee need the same AI training?
No. Article 4 expects a level matched to the role, experience, and context of use, not a single uniform curriculum. A data scientist and a manager who only reads AI-generated output need different content.
Is it enough to send staff the AI tool's user manual?
Often not, according to the Commission's AI literacy Q&A. Simply forwarding a manual, or asking staff to "read this," is typically not treated as a sufficient measure on its own.
Do contractors and agency staff need to be covered too?
Article 4 extends to "persons dealing with the operation and use of AI systems on the provider's or deployer's behalf," which the Commission Q&A reads to include contractors and temporary staff. Since there is no employment authority over them, this is typically handled through a contractual clause.
If a company doesn't use AI at all, is there anything to do?
Not under Article 4 — the obligation is tied to placing an AI system on the market or putting it into use. If that changes, the obligation applies from that point.
Does it matter if the company only uses a free, publicly available AI tool?
Yes, in the sense that using it in a professional capacity is what triggers deployer status — the fact that a tool is free does not exclude Article 4.
How long must AI-literacy documentation be kept?
Article 4 sets no statutory retention period. In practice it is prudent to keep records for as long as the system in question stays in use, and to update them at each significant version change.
Does Article 4 apply to management, or only to day-to-day users?
Yes — the text refers to "staff" without limiting this by seniority. Managers typically need a different, but equally documented, literacy measure than operational staff.
Does an ISO/IEC 42001 certification automatically satisfy Article 4?
The knowledge base underlying this page contains no confirmed statement to that effect, and there is no harmonised standard or official presumption of conformity for Article 4 — certification alone does not replace a documented, role-specific assessment.
Is it true that the Digital Omnibus abolished the AI literacy obligation?
No. The Commission did propose deleting Article 4 entirely in November 2025, but the European Parliament's compromise reinstated the obligation — only its standard was softened, from an obligation of result to an obligation of best-efforts.
Does documented Article 4 compliance protect a company against a fine?
Article 4 itself carries no fine, so there is nothing to defend against directly under it. The documentation matters elsewhere: as evidence for Article 26(2) human oversight compliance, and as a mitigating factor when other fines are calculated.
Is the "€15 million Article 4 fine" claim circulating online accurate?
No. Article 99(4)'s closed list of fineable provisions does not include Article 4 — that is a fact directly readable from the regulation's text.
Why do some sources call this the "AI competence" or "AI skills" obligation instead of "AI literacy"?
These are informal variations used in market communication; the regulation's own defined term, in Article 3(56), is "AI literacy."
- · Regulation (EU) 2024/1689 (AI Act) — Art. 3(56), 4, 14, 25, 26, 99
- · Digital Omnibus on AI, (EU) 2026/1744 — the amendment to Article 4
- · COM(2025) 836 final — the Commission proposal for the Digital Omnibus
- · European Commission / AI Office — AI Literacy Questions & Answers (non-binding)
- · AI Office living repository — AI literacy practices
- · GDPR, (EU) 2016/679 — Art. 2, 6, 9, 29, 32, 39
Related deep-dive reading (Hungarian-language knowledge base)
These link to our 100-question EU AI Act knowledge base, written and legally verified in Hungarian — useful if you read Hungarian or want the underlying source questions this page draws on.
- Mit ír elő pontosan az EU AI Act 4. cikke az AI-jártasságról?A hatályos 4. cikk szerint a szolgáltatók és az alkalmazók intézkedéseket hoznak a személyzetük és a nevükben eljáró más személyek AI-jártasságának fejlesztése támogatása érdekében. A rendelkezés kifejezetten kimondja, hogy nem kell egyetlen ember meghatározott jártassági szintjét sem garantálni. Kockázati kategóriától függetlenül mindenkire vonatkozik.
- Hogyan változtatta meg a Digital Omnibus az AI Act 4. cikkét?A normatív magot „a kellő szint biztosítása” helyett „az AI-jártasság fejlesztésének támogatása” fordulatra cserélte, és kifejezetten kimondta, hogy a rendelkezés nem kötelez senkit egyetlen egyén meghatározott jártassági szintjének garantálására. A kötelezettség maga megmaradt, az alkalmazási dátum változatlanul 2025. február 2.
- Van-e kötelező AI-képzés, óraszám vagy tanúsítvány az EU AI Act szerint?Nincs. A rendelet nem ír elő óraszámot, kötelező tananyagot, akkreditált képzést, vizsgát, tanúsítványt vagy külső auditot, és nincs olyan tanúsítvány sem, amely megfelelőségi vélelmet keletkeztetne. A Bizottság AI-jártassági Q&A-ja ezt kifejezetten rögzíti. Belső, saját erőforrásból megvalósított felkészítés ugyanúgy alkalmas a teljesítésre.
- Bírságolható-e az AI Act 4. cikkének, az AI-jártassági kötelezettségnek a megsértése?Önmagában nem. A 99. cikk (4) bekezdésének zárt felsorolása nem tartalmazza a 4. cikket, ezért uniós bírságtétel nem tartozik hozzá, és Magyarországon sincs hozzá rendelt forintösszeg. Aki 15 millió eurós fenyegetést kapcsol a 4. cikkhez, a jogszabály szövegével kerül szembe. Ami marad: nem pénzbeli piacfelügyeleti intézkedések és bizonyítási hátrány.
- Hogyan dokumentálható és bizonyítható az AI-jártassági megfelelés egy hatósági vizsgálatnál?Előírt dokumentációs forma nincs, ezért a bizonyítás szabad. A gyakorlatban az bizonyít, ami a mérlegelés folyamatát és annak végrehajtását együtt mutatja, nem a puszta jelenléti ív. Négy réteg együttese ad érdemi választ: AI-rendszerleltár, szerepkör-kockázat leképezés, a végrehajtás bizonyítéka, és a karbantartás nyoma.
A glossary of EU AI Act terms is also in progress at /fogalomtar.
What AI Work Fluency offers for this obligation: role-specific, 5-minute training modules, documentable records, and an audit-ready compliance file — matched to the four evidence layers described above. Pricing is set in HUF for the Hungarian market: a one-time starter package at 49,000 HUF for 1–10 employees (149,000 HUF for 10–50), and an ongoing Fluency Academy subscription at 14,900 HUF/month for 1–10 employees, or 1,190 HUF per employee/month for 11–50 employees. See the compliance overview, or run a quick, no-signup AI Act check for your own situation.