EU AI Act · Article 4
Since early August, market surveillance authorities have been enforcing an obligation that has applied for a year and a half and that most companies never implemented: the AI literacy of their own staff.
Article 4 of the AI Act entered into application on 2 February 2025. It requires providers and deployers to take measures ensuring that their staff and other people acting on their behalf have AI literacy. The monitoring and enforcement provisions took effect on 2 and 3 August 2026 respectively. Put differently: the obligation is old, the scrutiny is new.
At the same time, a headline has been circulating since late June that muddies the picture: "the AI training obligation has been scrapped". That is wrong, though not entirely invented.
Obligation applies since
2 February 2025
Article 4 has been applicable for eighteen months. There is no transition period still running.
Enforcement since
August 2026
National market surveillance authorities have started monitoring and enforcement. In Germany that is the Federal Network Agency (Bundesnetzagentur).
What the Digital Omnibus actually changed
The amendments to Article 4 entered into force in mid-July 2026. Ensuring AI literacy remains an obligation for providers and deployers of AI systems. What has gone is the requirement of a specific, "sufficient" level in paragraph 1. In parallel, under paragraph 3 the AI Board is to adopt recommendations supporting the Commission and the Member States in promoting AI literacy, drawing on existing European competence frameworks such as DigComp.
In practice: the yardstick has become softer, the obligation itself has not disappeared.
Still stands
The duty of providers and deployers to take AI literacy measures. The competence of national market surveillance authorities. The duty under Art. 26 for deployers of high-risk systems to train the staff responsible for human oversight.
Has gone
The requirement of a specific or "sufficient" level of literacy in paragraph 1. The emphasis on promotion shifts more strongly towards the Commission and the Member States.
Common misconception
"The Omnibus deleted the training obligation." It did not. Anyone concluding that nothing needs to be done still has a live obligation in the house, an authority responsible for it since August, and no record of having addressed it.
Who is covered, and it reaches further than expected
Article 4 applies regardless of company size. There is no "only from X employees" threshold. And the obligation does not stop at the edge of your own payroll.
Your own staff
Everyone in the organisation who deals directly with an AI system. Not just developers, but marketing, HR, support and sales too.
Externals acting on your behalf
Contractors, service providers and freelancers who fall broadly within your organisational remit. Best handled contractually.
In certain cases, customers
Depending on the risk, it can make sense to extend literacy measures to affected persons as well. That is the exception, not the rule.
Important for mid-sized companies: anyone using ChatGPT, Copilot or Gemini in day-to-day work generally qualifies as a deployer and therefore falls under the provision. Even for simple use cases such as ad copy or translation, staff should be informed about the specific risks, hallucinations among them.
What the AI Office describes as the minimum
The AI Office has deliberately refrained from setting rigid requirements and considers a degree of flexibility necessary. It does name four points as a minimum.
Ensure a general understanding of AI across the organisation
What is AI, how does it work, which AI is in use here, and what opportunities and risks does that bring?
Determine your own role
Does the organisation build AI systems itself, or only use systems built by others? Providers and deployers need different content.
Account for the risk of the systems in use
What do staff need to know when working with this particular system? Which risks must they recognise and be able to mitigate?
Build the measures on that analysis and differentiate
By the prior knowledge, experience and training of each group, and by sector, intended purpose and the people the system is used on. Different levels of depth are expressly permitted.
One point deserves separate attention: handing staff the instructions for use and asking them to read it is not enough. That approach is classified as ineffective and insufficient.
What is expressly not required
Here the official guidance clears away several expensive assumptions currently being sold in the market.
No certificate
A certificate is not required. Internal records of training and other initiatives are sufficient.
No knowledge test
Article 4 contains no obligation to measure the level of AI literacy among staff.
No AI officer
Unlike the GDPR, no dedicated role is prescribed. No particular governance structure is mandatory for compliance with Art. 4.
No sector-specific rules
There are no sector-specific requirements. Sector and intended purpose do have to be reflected in how measures are designed.
That no structure is prescribed does not mean one would hurt. If you need responsibilities and records for the rest of the AI Act anyway, do not build them twice.
What happens if nothing has happened?
Article 4 has no dedicated penalty provision in the sanctions catalogue of Article 99. That is why the topic keeps sliding down the priority list. The conclusion "so there are no consequences" still does not hold.
National sanctions law
National market surveillance authorities can impose penalties and other enforcement measures, based on national provisions. Enforcement follows a proportionate approach.
The incident as trigger
Enforcement becomes considerably more likely where there is evidence of an incident caused by inadequate training and guidance. It is not the gap that gets noticed, it is the damage.
Private enforcement
Anyone suffering harm and attributing it to a breach of Art. 4 can sue under national law. The AI Act itself creates no separate right to compensation.
Then there is the point that keeps getting lost in the Omnibus debate: for deployers of high-risk AI systems, the duty under Article 26 is untouched. They must ensure the staff working with the system are trained well enough for human oversight to actually function. That is not a promotional task for Member States, it is a hard deployer obligation.
A plan you can complete in four weeks
Start from an AI inventory
Without a list of the systems in use, no risk-appropriate training can be planned. If you do not know what is running in the building, you cannot determine who needs to know what. Shadow AI counts.
Group your audiences instead of training everyone the same
Three tiers usually suffice: fundamentals for everyone with AI contact, deeper content for power users in marketing, HR and support, technical and legal depth for engineering and compliance.
Bring externals in contractually
Service providers and contractors working with AI on your behalf need literacy appropriate to the task at hand. A clause in the framework agreement is the simplest route.
Document what took place
Who was trained when, on what content, in relation to which systems, and who was responsible? Internal records are enough, but they have to exist.
Schedule a refresh
A one-off mandatory session with no discernible learning effect barely meets the requirement. An annual rhythm is realistic given the pace of the technology.
Use the free offerings: There are routes for SMEs with no budget. The EU AI Skills Academy began operating in May 2026, the 251 European Digital Innovation Hubs offer training and workshops, and the Commission maintains a public repository of practices from other organisations. Replicating those practices does not, however, create an automatic presumption of conformity.
The point that matters
Article 4 is the obligation with the weakest sanction and the greatest practical effect. Almost every AI incident inside a company, from sensitive data typed into an open tool to a published hallucination, traces back to a gap in understanding among the people operating the system. That is exactly what Article 4 targets.
It also forces the same groundwork as everything else in the AI Act. Risk-appropriate training presupposes that you know which systems are in use, which role you hold for each and who operates them. Build that for Article 4 and it is already done for Article 50 and for the high-risk obligations due from December 2027.
With SimpleAct
Training needs an inventory. Otherwise you are training blind.
EU AI Act and GDPR in one platform: register AI systems centrally, classify them rule-based, assign responsibilities and export audit-ready evidence at any time. Made in Germany, hosted in Germany.
Start your AI inventory →This article is for general information only and does not constitute legal advice. Last updated: 6 August 2026.
Tags
Ready to put EU AI Act compliance on autopilot?
SimpleAct helps you inventory AI systems, classify risk, and generate the required documentation automatically.
Yannick | SimpleAct Team
Author · SimpleAct Team