Article 4 is the EU AI Act obligation that applies to almost everyone and gets the least attention. It is not limited to high-risk systems. It has been in force since 2 February 2025. And its wording changed in July 2026 — in a direction most published guidance has not caught up with.
This page states what the obligation is now, what it is not, and what a proportionate response looks like for a company of ten to two hundred and fifty people.
What Article 4 says, as amended
The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — replaced Article 4 in full. The current text reads:
"Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."
The previous version required providers and deployers to "ensure a sufficient level of AI literacy". That phrase is gone, and its removal was deliberate: Recital 8 of the Omnibus records that "a solution imposing stringent obligations to ensure a sufficient level of AI literacy would not be suitable for all types of providers and deployers".
Two further paragraphs were added. Article 4(2) obliges the Commission and Member States to support compliance efforts and requires the Commission to publish practical examples on the single information platform under Article 62(3)(b). Article 4(3) tasks the AI Board with adopting recommendations informed by European competence frameworks.
What changed, in one line
Before: you had to ensure your people reached a sufficient level of AI literacy. Now: you have to take measures that support the development of AI literacy — and you are expressly not required to guarantee any individual reaches a particular level.
The duty did not disappear. The outcome guarantee disappeared. What remains is an obligation of means, and it is one you can discharge and evidence.
Who it applies to
Both providers and deployers of AI systems. Not only high-risk. Not only EU-established companies — Article 2 extraterritoriality applies, so a non-EU company placing an AI system on the EU market or whose system output is used in the EU is in scope.
The population covered is broader than "employees": the text reads "their staff and other persons dealing with the operation and use of AI systems on their behalf". Contractors, agency staff and outsourced operators fall inside it.
If your company uses ChatGPT, Copilot or any commercial AI tool in its work, you are a deployer, and Article 4 applies to you. This is the most common misreading we see — companies assume Article 4 is for AI builders. It is not.
What the obligation is calibrated against
The text names the factors explicitly. Your measures must take into account:
- the technical knowledge, experience, education and training of the people concerned;
- the context in which the AI systems are used;
- the persons or groups of persons on whom the AI systems are used.
That last factor is the one most often skipped. If your AI system makes decisions affecting job applicants, patients, borrowers or students, the literacy your staff need is not only technical — it extends to the effects on those people. A recruiter using a CV-screening tool needs to understand what it can get wrong about a candidate, not only how to operate the interface.
Proportionality runs both ways. A ten-person company using one commercial chatbot owes considerably less than a two-hundred-person company deploying a bespoke scoring model. The Article is written to accommodate that.
When it applies, and who enforces it
Article 4 has applied since 2 February 2025. That date did not move in the Omnibus.
Enforcement runs through the national market surveillance authorities and the Chapter IX machinery, which took effect on 2 August 2026 under Article 113. One caveat worth stating plainly: the European Commission's own AI literacy FAQ gives both "2 August 2026" and "3 August 2026" on the same page for when supervision begins, and neither date appears in the Regulation itself. We cite 2 August 2026, which is the date Article 113 actually carries, and flag the discrepancy rather than resolve it silently.
Penalties for Article 4 are set by Member States under Article 99, whose national regimes were due by 2 August 2025. For SMEs and start-ups, Article 99(6) caps each fine at the percentage or the fixed amount, "whichever thereof is lower" — the inverse of the rule applied to larger undertakings.
What a proportionate programme looks like
The Article requires measures, and measures need to be evidenced. A defensible minimum for an SME:
1. Know what you actually use. An inventory of the AI systems your company provides and deploys, including the commercial tools staff use day to day. You cannot calibrate training to a context you have not mapped. This inventory does double duty — Article 6 classification needs it too.
2. Segment your audience. General awareness for everyone who touches an AI tool; deeper content for the people who operate systems that affect others; specific content for whoever owns the compliance file. The Article's own criteria — knowledge, experience, context, affected persons — are the segmentation.
3. Cover the right ground. Capabilities and limitations of the systems in use; how to recognise and handle a wrong or fabricated output; what data may and may not go into a third-party tool; the disclosure duties under Article 50 if your staff deploy chatbots or generate synthetic content; and who to escalate to.
4. Record it. Dates, attendees, content version, and the reasoning behind the calibration. In an inspection, a documented programme with a rationale is the evidence. A certificate stating that an individual reached a level is not what the Article asks for.
5. Refresh when the estate changes. New tool, new use case, new affected population — revisit. A one-off session in 2025 covering tools you no longer use is not a live measure.
What you do not have to do
The amended text is unusually direct about this, so it is worth being direct in return:
- You do not have to guarantee any individual's level of AI literacy. The Regulation says so expressly.
- You do not have to test or certify your staff. Assessment can be useful; it is not the obligation.
- You do not have to appoint an AI literacy officer or build a governance structure. No such requirement exists in Article 4.
- You do not have to buy a certification programme. If a vendor tells you a certified curriculum is how you comply with Article 4, they are describing their product, not the law.
There is a real commercial incentive to overstate this obligation, and we would rather lose a sale than contribute to it.
The two traps
Trap 1: assuming the Omnibus made Article 4 optional. It relaxed the standard from an outcome guarantee to an obligation of means. An obligation of means with no measures behind it is still a breach.
Trap 2: assuming Article 4 only applies to AI you build. Deployers are named in the first line. Most companies in scope are in scope as deployers of tools they bought.
Sources
This page states the law as published. It is not legal advice.