
EU AI Act Article 4: What the AI Literacy Duty Actually Requires
The AI literacy duty in Article 4 of the EU AI Act has applied since February 2, 2025 — to providers AND deployers, which includes companies whose team simply uses ChatGPT. It requires measures ensuring a sufficient level of AI understanding, tailored to role and context: no certificates, no AI officer, no mandatory seminars — internal training with records is enough. There are no direct EU fines for Article 4 (it's absent from the fine list in Art. 99); the risk runs through national law and liability when something goes wrong. From August 2, 2026 market surveillance starts — your documentation should exist by then at the latest.
"Does the AI Act even apply to us? We don't build AI." It does: Article 4 attaches to use, not to building. The European Commission's official Q&A explicitly names the example of employees using ChatGPT for ad copy or translations — they too must be informed about risks like hallucination.
What Article 4 requires — and what it doesn't
| Required | Not required |
|---|---|
| Measures for a "sufficient level of AI literacy" for everyone operating or using AI systems | Certificates or mandatory external seminars |
| Tailored to prior knowledge, role, and context of use | An "AI officer" or a new role |
| Covers contractors and external staff working with AI on your behalf | Measuring learning outcomes |
| Internal documentation of the measures | Sector-specific programs |
Important: merely pointing at the tool's instructions for use is explicitly not enough for the Commission.
Which penalties are actually real?
A lot of fear is being sold here, so let's be precise: Article 4 does not appear in the AI Act's fine catalog (Article 99) — the famous €35M fines are for prohibited practices, not missing training. Sanctions for Article 4 run through national law, and Germany's implementation act (with the Bundesnetzagentur as central authority) is still in the legislative process as of July 2026. The real risk is different: if improper AI use causes an incident — customer data leaked into a prompt, a hallucinated answer sent to a client — the missing training becomes a liability and evidence problem. The Commission puts it dryly: consequences are more likely "if there is proof of an incident due to lack of appropriate training."
The 5-step program for one afternoon
- Inventory: Which AI tools are in use — officially and as shadow AI in private accounts? The latter is the norm, not the exception.
- Define roles: Everyone gets the basics (what AI can do, hallucinations, which data never goes into prompts). Whoever builds AI into processes or uses it for HR decisions needs more depth.
- Train: A 60-minute session built on your real use cases beats any generic webinar. Record it for new hires.
- Document: Who was trained, when, on what — a simple list suffices as evidence.
- Write the AI policy: Allowed tools, forbidden data categories, approval paths. One page everyone understands beats ten pages nobody reads.
By the way: the Digital Omnibus adopted in June 2026 softens the wording going forward ("support the development of AI literacy" instead of "ensure") — it changes nothing about the underlying duty or the value of these five steps. And August 2, 2026 brings the next stage anyway: the transparency obligations of Article 50 kick in, and market surveillance begins.
For the full timeline — including the high-risk obligations postponed to December 2027 — see our EU AI Act engineering checklist. And if you'd rather not build the inventory, risk classification, and policy yourself: our fixed-price AI Act check is part of our AI consulting for SMEs.

