Definition
Article 3(56) of the AI Act defines AI literacy as the “skills, knowledge and understanding” that allow providers, deployers and affected persons “to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause”. So it means more than knowing which buttons to press. Anyone working with an AI system should also be able to tell when its output does not hold up.
Article 4 turns this into an obligation for organizations. In German it is often called the “KI-Schulungspflicht”, the AI training obligation. The label is too narrow, because the law allows other means besides training.
Origin and purpose
Article 4 is among the first rules of the EU AI Act to apply. It has applied since 2 February 2025, together with the prohibitions in Article 5. Risk classes, transparency duties and human oversight achieve little if the people working with AI do not know its limits. That is why literacy comes first.
In July 2026 the legislator adjusted course. In its view, strict requirements to ensure a “sufficient level” of literacy did not suit every organization and placed a particular burden on smaller companies. At the same time it states that AI literacy “should be a strategic priority, regardless of regulatory obligations and potential sanctions” (recital 8 of Regulation (EU) 2026/1744).
What Article 4 requires today
Until 26 July 2026, providers and deployers had to take measures “to ensure, to their best extent, a sufficient level of AI literacy” of their staff and other persons acting on their behalf.
Since 27 July 2026 the version introduced by Regulation (EU) 2026/1744 applies. Providers and deployers “shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”. They must take into account technical knowledge, experience, education and training, the context of use and the people on whom the systems are used. A new sentence reads: “This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.”
What has gone is the target level. Previously, providers and deployers had to make their best efforts towards a sufficient level. Now they must take measures to support literacy without owing any particular level. Two new paragraphs address the authorities. The Commission and the Member States must support organizations, especially SMEs, and the Commission publishes practical examples. The AI Board adopts recommendations setting out common objectives.
Who is affected
The obligation applies to providers and deployers of AI systems. A deployer is anyone who uses an AI system under their own authority in a professional context, which covers most organizations. A chat assistant for staff, a translation tool or AI features in office software are enough. Unlike the high-risk obligations, Article 4 does not depend on the risk class. It applies to every AI system used at work.
Besides employees, the law names “other persons” working with AI on the organization’s behalf, such as service providers or freelancers. Customers, applicants or citizens on whom a system is used are not the addressees of the measures. How strongly they are affected does, however, shape how deep the literacy needs to go.
What counts as a measure
The regulation does not prescribe a format, and no certificate is required. Both the European Commission in its questions and answers on AI literacy and Germany’s Federal Network Agency (Bundesnetzagentur) in its guidance note of June 2025 make this clear. The guidance note still refers to the old wording. We nevertheless find its four building blocks a useful orientation:
- 1. Identify the need. Who uses which AI systems, for what purpose and with what risk?
- 2. Tailor the measures. To people’s prior knowledge and tasks, to the context of use and to the organization’s role.
- 3. Refresh regularly. Tools and use cases change faster than any curriculum.
- 4. Document. Type of measure, scope in content and time, participants.
Training is only one building block. A clear usage policy belongs here just as much as named contact persons, office hours for concrete questions or a collection of good examples from your own organization. For building learning offers systematically, the ADDIE model is a good fit. The weakest option is usually one mandatory course for everyone. A sales representative drafting proposals with a chat assistant needs different knowledge from an HR specialist who has AI pre-sort job applications.
Evidence and documentation
Article 4 contains no explicit duty to provide evidence. Once the supervisory authority asks, however, it helps to be able to show what has been done. According to the Commission, organizations can keep an internal record of trainings and other measures. In practice a table with the group of people, the AI systems used, the measure and the date is often enough.
More telling than attendance lists is whether usage actually changes. The Kirkpatrick Model distinguishes four levels for this: reaction, learning, behavior and results. Early signals, such as the kind of questions asked in the internal channel, make good leading indicators. Steering by attendance rates alone leads straight to Goodhart’s Law: the rate goes up, but literacy does not necessarily follow.
Supervision and sanctions
In Germany, the Federal Network Agency has been the market surveillance authority with general responsibility since 29 July 2026 (Section 2(1) KI-MIG, the German act implementing the AI Act). Neither the AI Act nor the German catalog of fines in Section 15 KI-MIG provides a specific fine for breaches of Article 4. Yet Article 99(1) requires Member States to lay down penalties and other enforcement measures for any infringement of the regulation, expressly including fines, warnings and non-monetary measures. Germany has so far not created a fine for Article 4.
For deployers of high-risk systems, competence still becomes a hard requirement. Under Article 26(2) they must assign human oversight to people “who have the necessary competence, training and authority”. Breaches can be fined under Article 99(4), although Germany imposes no fines on authorities and other public bodies (Section 17(2) KI-MIG). For Annex III systems the obligation applies from 2 December 2027. Anyone who only trains the designated staff in autumn 2027 is late.
Common misconceptions
- - “Since the Digital Omnibus there is no obligation any more.” The obligation is still in Article 4, just without the target of a “sufficient level”.
- - “We need a certificate.” No. For people who will later carry human oversight of a high-risk system, proof of their qualification can still make sense.
- - “This only concerns high-risk AI.” Article 4 does not distinguish between risk classes. The chat assistant in the browser counts too.
- - “One e-learning course for everyone and we are done.” A shared basic course is a reasonable start. But the law expressly requires knowledge, experience and context of use to be taken into account. Uniform courses often fail here, being too shallow for HR and too abstract for many others.
- - “We have banned AI, so this does not concern us.” A ban on paper helps little if employees copy work texts into private AI accounts. Nobody learns to handle this shadow AI responsibly through a ban.
Example from practice
An organization with 400 employees introduces a chat assistant in its office software. HR is also testing a tool that pre-sorts job applications. Recruitment is listed in Annex III of the regulation, so this use will as a rule fall under the high-risk obligations, which apply to such systems from 2 December 2027.
Everyone using the assistant gets a short introduction: how it works, why it makes mistakes that sound convincing, which data must not go into it and where the usage policy can be found. The team that writes texts for customers practices checking results on its own cases in a workshop. HR receives in-depth training on bias and on the role of human oversight. Managers agree who decides on new AI tools. Everything is recorded in a simple table. After three months the team looks at which questions come up in the internal channel and whether they have changed.
Criticism and limitations
The legislator justifies the amendment with the burden on smaller companies. One can object that an obligation without a target level and without its own fine achieves little if nobody takes it seriously. Organizations now have to justify for themselves what is “enough”, and that is more demanding than a fixed rule.
The starting point in Germany is mixed. According to a Bitkom survey of 603 companies with 20 or more employees (July/August 2026), 70 percent train their staff on AI, while a quarter offer no training at all. Two thirds rate their employees’ AI skills as low.
This article places Article 4 in its professional context and is not legal advice.
The CALADE perspective
For us, Article 4 is above all a leadership question. Training conveys knowledge. Whether it takes hold in daily work depends on whether managers allow time to experiment, whether mistakes with AI can be discussed openly (psychological safety) and whether it is clear who decides on new tools. In terms of the ADKAR model: knowledge can be trained, ability only develops through use.
Suitable formats at CALADE are AI 4Teams for teams that want to use AI in daily work, AI Leadership for managers and Safe AI – AI Compliance, Governance and Security for everyone who sets up rules and responsibilities.
Related terms
EU AI Act – risk classes, roles and deadlines of the AI Act
Tokens – processing units in AI language models
ADDIE model – developing learning offers systematically
Kirkpatrick Model – evaluating the effect of training
Human oversight – Articles 14 and 26 of the AI Act
Shadow AI
Sources: Regulation (EU) 2024/1689, Art. 3(56), Art. 4, 26 and 99; Regulation (EU) 2026/1744, recital 8 and Art. 1(5), (38) and (40), EUR-Lex; KI-MIG Sections 2, 15 and 17, Federal Law Gazette 2026 I No. 223; Bundesnetzagentur, guidance note on AI literacy under Article 4 (June 2025); European Commission, AI Literacy – Questions and Answers; Bitkom press release of 14 September 2026. As of September 2026.
Summary
AI literacy is the ability to use AI competently and to recognize its risks. Since February 2025, Article 4 of the AI Act has required providers and deployers to take measures to build it. Since 27 July 2026 the target of a “sufficient level” has gone, but the obligation itself has not. The law prescribes no format. What makes sense are measures that fit the role and the use, are refreshed regularly and are documented simply.