Free course

EU AI Act AI-Literacy Course

A free Article 4 micro-course on using AI responsibly — six short lessons, a quick quiz, and a certificate. Nothing to install.

Lesson 1 / 6

Why AI literacy matters (Article 4)

Article 4 of the EU AI Act — as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) — requires every provider and deployer of AI systems to take measures to support the development of AI literacy of their staff and of other persons operating or using AI systems on their behalf. The duty has applied since 2 February 2025 and is universal — it is not limited to high-risk AI. It is an obligation of effort, not of result: the law states expressly that it does not require guaranteeing any specific level of AI literacy for any individual.

AI literacy means the skills, knowledge, and understanding that let people use AI systems soundly, grasp the opportunities and risks, and recognise the harm they can cause. The measures should fit each person's technical knowledge, experience, education and training, the context the AI system is used in, and the people it affects. The Commission and Member States support these efforts, including with practical examples on the Commission's single information platform, and the AI Board may issue recommendations on AI literacy.

Taking this short course is exactly such a measure. Completing it gives your organisation documented evidence of the AI-literacy support it provides to its team.

Lesson 2 / 6

How the EU AI Act classifies AI: the four risk tiers

The EU AI Act is risk-based. It sorts AI systems into four tiers and the rules get stricter as the risk rises.

Prohibited: a small set of practices banned outright, such as social scoring by public or private actors or manipulative systems that cause harm. From 2 December 2026 the list also covers AI that generates non-consensual intimate imagery or child sexual abuse material (Digital Omnibus).

High-risk: AI used in sensitive areas listed in Annex III — recruitment, credit scoring, education, essential services, law enforcement, biometrics. These carry the heaviest obligations.

Limited risk: systems that interact with people or generate content, which carry transparency duties under Article 50.

Minimal risk: everything else (spam filters, recommendation engines), with no mandatory obligations.

Knowing which tier a system falls into is the first step in handling it correctly.

Lesson 3 / 6

High-risk AI and what it demands

If an AI system is high-risk, the obligations are substantial. The provider must run a risk-management system, govern the training and validation data, produce Annex IV technical documentation, keep logs, design for human oversight, and pass a conformity assessment before the system reaches the market.

Deployers — organisations that use a high-risk system — also have duties: use the system as instructed, ensure human oversight, monitor its operation, and keep records.

Most obligations for stand-alone high-risk systems apply from 2 December 2027 under the rescheduled timeline. If your work touches hiring, lending, education, or similar areas, assume a system may be high-risk and check before relying on it.

Lesson 4 / 6

Transparency: telling people when AI is involved (Article 50)

Article 50 sets transparency duties for AI that interacts with people or creates content. They exist so nobody is misled about whether they are dealing with a human or a machine.

When someone interacts with an AI system — a chatbot, a voice assistant — they must be told clearly, unless it is obvious. AI-generated or manipulated content, including text, images, audio, and video (deepfakes), must be labelled as artificially generated.

The disclosure should be clear, accessible, and given at the right moment. For most teams this means a simple, honest notice: "You are chatting with an AI assistant." Transparency builds trust and is a legal requirement.

Lesson 5 / 6

Human oversight and common AI pitfalls

AI systems are powerful but fallible. Three pitfalls come up again and again.

Bias: a model trained on skewed data can produce unfair outcomes for certain groups — a serious risk in hiring or lending.

Hallucination: generative AI can state false information confidently. Always verify facts, figures, and citations before you rely on them.

Over-reliance: treating AI output as automatically correct. The system supports your judgement; it does not replace it.

Human oversight is the safeguard. A competent person should be able to understand, monitor, question, and override an AI system's output. When something looks wrong, pause and check it against a reliable source.

Lesson 6 / 6

Using AI responsibly in your daily work

AI literacy is something you practise every day. A few habits keep you and your organisation on the right side of the AI Act.

Protect data: never paste personal data, secrets, or confidential information into a tool unless it is approved for that use. Follow your organisation's AI-usage policy.

Be transparent: tell people when they are interacting with AI, and label AI-generated content.

Verify before acting: treat AI output as a draft to check, not a final answer.

Escalate: if you are unsure whether a system is high-risk or compliant, raise it with the person responsible for compliance rather than guessing.

These simple habits turn the law into everyday good practice.

The lessons are free to read. Sign in or create an account to take the assessment and earn your named certificate.

EU AI Act Article 4: the AI literacy obligation, after the Digital Omnibus

Article 4 is the EU AI Act obligation that applies to almost everyone and gets the least attention. It is not limited to high-risk systems. It has been in force since 2 February 2025. And its wording changed in July 2026 — in a direction most published guidance has not caught up with.

This page states what the obligation is now, what it is not, and what a proportionate response looks like for a company of ten to two hundred and fifty people.

What Article 4 says, as amended

The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — replaced Article 4 in full. The current text reads:

"Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."

The previous version required providers and deployers to "ensure a sufficient level of AI literacy". That phrase is gone, and its removal was deliberate: Recital 8 of the Omnibus records that "a solution imposing stringent obligations to ensure a sufficient level of AI literacy would not be suitable for all types of providers and deployers".

Two further paragraphs were added. Article 4(2) obliges the Commission and Member States to support compliance efforts and requires the Commission to publish practical examples on the single information platform under Article 62(3)(b). Article 4(3) tasks the AI Board with adopting recommendations informed by European competence frameworks.

What changed, in one line

Before: you had to ensure your people reached a sufficient level of AI literacy. Now: you have to take measures that support the development of AI literacy — and you are expressly not required to guarantee any individual reaches a particular level.

The duty did not disappear. The outcome guarantee disappeared. What remains is an obligation of means, and it is one you can discharge and evidence.

Who it applies to

Both providers and deployers of AI systems. Not only high-risk. Not only EU-established companies — Article 2 extraterritoriality applies, so a non-EU company placing an AI system on the EU market or whose system output is used in the EU is in scope.

The population covered is broader than "employees": the text reads "their staff and other persons dealing with the operation and use of AI systems on their behalf". Contractors, agency staff and outsourced operators fall inside it.

If your company uses ChatGPT, Copilot or any commercial AI tool in its work, you are a deployer, and Article 4 applies to you. This is the most common misreading we see — companies assume Article 4 is for AI builders. It is not.

What the obligation is calibrated against

The text names the factors explicitly. Your measures must take into account:

  • the technical knowledge, experience, education and training of the people concerned;
  • the context in which the AI systems are used;
  • the persons or groups of persons on whom the AI systems are used.

That last factor is the one most often skipped. If your AI system makes decisions affecting job applicants, patients, borrowers or students, the literacy your staff need is not only technical — it extends to the effects on those people. A recruiter using a CV-screening tool needs to understand what it can get wrong about a candidate, not only how to operate the interface.

Proportionality runs both ways. A ten-person company using one commercial chatbot owes considerably less than a two-hundred-person company deploying a bespoke scoring model. The Article is written to accommodate that.

When it applies, and who enforces it

Article 4 has applied since 2 February 2025. That date did not move in the Omnibus.

Enforcement runs through the national market surveillance authorities and the Chapter IX machinery, which took effect on 2 August 2026 under Article 113. One caveat worth stating plainly: the European Commission's own AI literacy FAQ gives both "2 August 2026" and "3 August 2026" on the same page for when supervision begins, and neither date appears in the Regulation itself. We cite 2 August 2026, which is the date Article 113 actually carries, and flag the discrepancy rather than resolve it silently.

Penalties for Article 4 are set by Member States under Article 99, whose national regimes were due by 2 August 2025. For SMEs and start-ups, Article 99(6) caps each fine at the percentage or the fixed amount, "whichever thereof is lower" — the inverse of the rule applied to larger undertakings.

What a proportionate programme looks like

The Article requires measures, and measures need to be evidenced. A defensible minimum for an SME:

1. Know what you actually use. An inventory of the AI systems your company provides and deploys, including the commercial tools staff use day to day. You cannot calibrate training to a context you have not mapped. This inventory does double duty — Article 6 classification needs it too.

2. Segment your audience. General awareness for everyone who touches an AI tool; deeper content for the people who operate systems that affect others; specific content for whoever owns the compliance file. The Article's own criteria — knowledge, experience, context, affected persons — are the segmentation.

3. Cover the right ground. Capabilities and limitations of the systems in use; how to recognise and handle a wrong or fabricated output; what data may and may not go into a third-party tool; the disclosure duties under Article 50 if your staff deploy chatbots or generate synthetic content; and who to escalate to.

4. Record it. Dates, attendees, content version, and the reasoning behind the calibration. In an inspection, a documented programme with a rationale is the evidence. A certificate stating that an individual reached a level is not what the Article asks for.

5. Refresh when the estate changes. New tool, new use case, new affected population — revisit. A one-off session in 2025 covering tools you no longer use is not a live measure.

What you do not have to do

The amended text is unusually direct about this, so it is worth being direct in return:

  • You do not have to guarantee any individual's level of AI literacy. The Regulation says so expressly.
  • You do not have to test or certify your staff. Assessment can be useful; it is not the obligation.
  • You do not have to appoint an AI literacy officer or build a governance structure. No such requirement exists in Article 4.
  • You do not have to buy a certification programme. If a vendor tells you a certified curriculum is how you comply with Article 4, they are describing their product, not the law.

There is a real commercial incentive to overstate this obligation, and we would rather lose a sale than contribute to it.

The two traps

Trap 1: assuming the Omnibus made Article 4 optional. It relaxed the standard from an outcome guarantee to an obligation of means. An obligation of means with no measures behind it is still a breach.

Trap 2: assuming Article 4 only applies to AI you build. Deployers are named in the first line. Most companies in scope are in scope as deployers of tools they bought.

Sources

This page states the law as published. It is not legal advice.