Back to Blog
EU AI Act Article 4: What the AI Literacy Duty Actually Requires

EU AI Act Article 4: What the AI Literacy Duty Actually Requires

Dennis Reinkober2 min read
TL;DR

The AI literacy duty in Article 4 of the EU AI Act has applied since February 2, 2025 — to providers AND deployers, which includes companies whose team simply uses ChatGPT. It requires measures ensuring a sufficient level of AI understanding, tailored to role and context: no certificates, no AI officer, no mandatory seminars — internal training with records is enough. There are no direct EU fines for Article 4 (it's absent from the fine list in Art. 99); the risk runs through national law and liability when something goes wrong. From August 2, 2026 market surveillance starts — your documentation should exist by then at the latest.

"Does the AI Act even apply to us? We don't build AI." It does: Article 4 attaches to use, not to building. The European Commission's official Q&A explicitly names the example of employees using ChatGPT for ad copy or translations — they too must be informed about risks like hallucination.

What Article 4 requires — and what it doesn't

RequiredNot required
Measures for a "sufficient level of AI literacy" for everyone operating or using AI systemsCertificates or mandatory external seminars
Tailored to prior knowledge, role, and context of useAn "AI officer" or a new role
Covers contractors and external staff working with AI on your behalfMeasuring learning outcomes
Internal documentation of the measuresSector-specific programs

Important: merely pointing at the tool's instructions for use is explicitly not enough for the Commission.

Which penalties are actually real?

A lot of fear is being sold here, so let's be precise: Article 4 does not appear in the AI Act's fine catalog (Article 99) — the famous €35M fines are for prohibited practices, not missing training. Sanctions for Article 4 run through national law, and Germany's implementation act (with the Bundesnetzagentur as central authority) is still in the legislative process as of July 2026. The real risk is different: if improper AI use causes an incident — customer data leaked into a prompt, a hallucinated answer sent to a client — the missing training becomes a liability and evidence problem. The Commission puts it dryly: consequences are more likely "if there is proof of an incident due to lack of appropriate training."

The 5-step program for one afternoon

  1. Inventory: Which AI tools are in use — officially and as shadow AI in private accounts? The latter is the norm, not the exception.
  2. Define roles: Everyone gets the basics (what AI can do, hallucinations, which data never goes into prompts). Whoever builds AI into processes or uses it for HR decisions needs more depth.
  3. Train: A 60-minute session built on your real use cases beats any generic webinar. Record it for new hires.
  4. Document: Who was trained, when, on what — a simple list suffices as evidence.
  5. Write the AI policy: Allowed tools, forbidden data categories, approval paths. One page everyone understands beats ten pages nobody reads.

By the way: the Digital Omnibus adopted in June 2026 softens the wording going forward ("support the development of AI literacy" instead of "ensure") — it changes nothing about the underlying duty or the value of these five steps. And August 2, 2026 brings the next stage anyway: the transparency obligations of Article 50 kick in, and market surveillance begins.

For the full timeline — including the high-risk obligations postponed to December 2027 — see our EU AI Act engineering checklist. And if you'd rather not build the inventory, risk classification, and policy yourself: our fixed-price AI Act check is part of our AI consulting for SMEs.

Similar Posts