AI literacy: the EU AI Act's Article 4 duty, in practice
Updated July 8, 2026
Article 4 of the EU AI Act is the AI literacy duty. It requires providers and deployers to ensure, to their best extent, a sufficient level of AI literacy among their staff and anyone else using AI on their behalf. In plain terms: the people using your AI have to understand enough about it to use it responsibly, and making that happen is your job, not theirs. It has applied since February 2025, it is not limited to high-risk AI, and it is one of the easiest obligations to meet and to overlook.
People assume the EU AI Act is all about high-risk systems and distant deadlines. Article 4 is neither. It is already in force, it reaches ordinary AI use, and it lands on far more organisations than realise it. Here is what it actually asks, and how to meet it without overcomplicating things.
What Article 4 actually requires
The wording matters. Providers and deployers must take measures to ensure a sufficient level of AI literacy of the people operating and using AI on their behalf, taking into account their technical knowledge, experience, education and training, and the context the systems are used in, and who they are used on.
Two things follow from that:
- It is proportionate, not exhaustive. “Sufficient” and “to their best extent” mean the bar scales with the role and the risk. A marketer using an approved writing assistant needs less than an engineer building an automated decision system.
- It is an outcome you own. You cannot outsource the responsibility to employees “being sensible”. You have to take active measures.
Who it applies to, and when
- Who: both providers (build or place AI on the market) and deployers (use AI in the course of work), where they are in scope of the Act. That scope is wide and can reach organisations outside the EU.
- When: it has applied since 2 February 2025, one of the first obligations to bite, ahead of most high-risk rules. See the full EU AI Act timeline.
- Which AI: unlike most of the Act, this is not limited to high-risk. Deploy AI systems in scope of any kind, and the literacy duty applies.
That last point is the trap. Organisations that assume “the Act is not about us because we do not do anything high-risk” can still be carrying the literacy obligation for the everyday tools their staff use.
What “AI literacy” means in practice
It is the understanding needed to use AI informed, aware of the opportunities, the risks, and the possible harm. Not everyone needs to be a data scientist. The practical level depends on the role:
| Group | What they need |
|---|---|
| All staff using AI | What the tools can and cannot do, the main risks (inaccuracy, bias, data leakage), your AI policy, and when to involve a human |
| Managers and process owners | The above, plus how AI affects decisions in their area and their oversight responsibilities |
| Builders and those running higher-risk AI | Deeper understanding of the systems, their limits, testing, and the specific obligations that attach |
The goal is that each person can use the AI in front of them without being naive about it.
How to actually meet it
A proportionate, defensible approach:
- Know who uses AI. You cannot train people you have not identified. This starts from the same place as finding shadow AI and your AI system register: who is using what.
- Assess the current level. Where are the gaps, by role?
- Tailor the training. General awareness for everyone using AI; more depth for those building or overseeing higher-risk systems. Tie it to your actual tools and your AI policy, not generic theory.
- Cover the essentials. Capabilities and limits, the real risks, safe use of approved tools, your policy, and when to escalate to a human.
- Keep records. Who was trained, on what, and when. AI literacy is an accountability duty, and the evidence is part of your governance trail.
- Refresh it. Tools and rules move; a one-off session in 2025 does not cover a workforce using different tools a year later.
The misconceptions to avoid
- “It is just an e-learning tick-box.” A generic course nobody remembers is not “sufficient” and, if it ignores your actual tools and policy, barely counts.
- “It is only for high-risk AI.” It is not. This duty applies more broadly than almost anything else in the Act.
- “Our staff are sensible, we are fine.” The obligation is to take active measures, not to hope. Without evidence, you cannot show you met it.
Where this fits in governance
AI literacy is not a standalone chore. It maps directly to the competence and awareness part of an AI Management System, and ISO 42001 covers the same ground, which is why running a real management system gets you most of the way to Article 4 as a matter of course. We set out how the two align in ISO 42001 vs the EU AI Act.
The short version
Article 4 requires you to make sure the people using AI on your behalf understand it well enough to use it responsibly. It has been in force since February 2025, it applies to everyday AI and not just high-risk, and it is an active duty you own and have to evidence. Meeting it is straightforward: know who uses AI, train them in proportion to their role and your actual tools, and keep the records. It is one of the cheapest parts of the Act to comply with, and one of the easiest to forget.
Want to know which EU AI Act obligations actually apply to you, Article 4 included? The free EU AI Act check gives you a read in about ten minutes, no email required. When you want to build the training and the governance around it, talk to us.
For the full picture, see the EU AI Act guide.
Frequently asked questions
What is Article 4 of the EU AI Act?
Article 4 is the AI literacy obligation. It requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and any other people operating or using AI on their behalf. In plain terms: the people using your AI need to understand enough about it to use it responsibly, and you have to make sure they do.
Who does the AI literacy requirement apply to?
Both providers (those who build or place AI on the market) and deployers (those who use AI in the course of their work) that are in scope of the EU AI Act. That scope is broad and can reach organisations outside the EU whose AI output is used there. Crucially it is not limited to high-risk AI: if you deploy AI systems of any kind in scope, the literacy duty applies to the people using them.
When did the AI literacy obligation start?
It has applied since 2 February 2025, making it one of the first EU AI Act obligations to take effect, well ahead of most of the high-risk rules. So it is already live, not a future deadline.
What counts as AI literacy training?
Whatever gives your people the understanding to use AI responsibly for their role, proportionate to what they do. For most staff that means the basics: what the tools can and cannot do, the risks (inaccuracy, bias, data leakage), your AI policy, and when to involve a human. For those building or overseeing higher-risk systems it means more depth. It is not one fixed course; it is a level of competence you are responsible for reaching and evidencing.
Does Article 4 apply to low-risk AI too?
Yes. Unlike most of the EU AI Act, the AI literacy duty is not tied to the high-risk category. It applies to providers and deployers of AI systems in scope generally. So even organisations that only use everyday AI tools, and think the Act does not touch them, can carry the literacy obligation.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert