Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures supporting AI literacy among staff and anyone operating those systems on their behalf. The duty has applied since 2 February 2025. National market surveillance authorities gained supervisory powers in August 2026, and the July 2026 Digital Omnibus rewrote the article without removing it.
Table of Contents
ToggleWhat Article 4 of the EU AI Act Requires, and Who It Binds
Article 4 of Regulation (EU) 2024/1689 places a duty on two categories of organization: providers, who develop an AI system or place it on the EU market, and deployers, who use one under their own authority. Both must take measures so the people operating those systems understand what the systems can do, what they cannot do, and what risks they carry in the context they are used in.
The scope is wider than most organizations assume, in two directions. It reaches beyond employees to contractors and anyone else operating a system on the organization’s behalf. Contractor exposure is the part that surprises people, since attackers already treat generative tooling as infrastructure, as this piece on attackers building attack vectors with ChatGPT describes. Article 4 also reaches beyond the EU, on the same logic as GDPR: an organization headquartered anywhere is bound if its AI system is placed on the EU market or its output is used in the Union. A company in Bengaluru or Dubai running an AI-assisted screening tool for an EU client is a deployer, and Article 4 applies to it.
Article 4 also does not care whether the AI system is high-risk. High-risk classification changes what else applies, not whether literacy is required. An organization using nothing more exotic than a general-purpose chatbot for drafting is still inside the duty, which is a point covered further in this overview of how AI is reshaping cybersecurity.
The Article 4 Timeline, and the Date Most Coverage Gets Wrong
The single most common error in coverage of Article 4 is placing the start date in February 2026. The AI literacy obligation became applicable on 2 February 2025, six months after the Act entered into force on 1 August 2024, on the same date as the Article 5 prohibitions. Organizations working from the later date have assumed they had a year they did not have.
| Date | What applies |
|---|---|
| 1 August 2024 | Regulation (EU) 2024/1689 enters into force |
| 2 February 2025 | Article 4 AI literacy and Article 5 prohibited practices become applicable |
| 2 August 2025 | General-purpose AI model rules, the governance chapter, and the Article 99 penalty regime apply; member states designate national competent authorities |
| 27 July 2026 | Regulation (EU) 2026/1744, the Digital Omnibus on AI, enters into force and rewrites Article 4 |
| August 2026 | National market surveillance authorities begin supervising and enforcing Article 4 |
| 2 December 2026 | Two further Article 5 prohibitions apply, covering non-consensual intimate imagery and AI-generated child sexual abuse material |
| 2 December 2027 | Core obligations for standalone Annex III high-risk systems apply, deferred from 2 August 2026 |
| 2 August 2028 | Full applicability for high-risk AI embedded in regulated products under Annex I |
Governance questions raised by that sequencing are explored in this conversation on AI automation and the governance layer. The high-risk deferrals in the table above are the reason many organizations believe the whole Act was postponed. It was not. The deferral moved Annex III obligations to December 2027 and Annex I obligations to August 2028. Article 4 was never part of that deferral, and its enforcement architecture came online on schedule.
Book a Free
Demo Call
with Our Expert
Discover how Threatcop protects your workforce from modern cyber threats.
What the Digital Omnibus Changed in July 2026
The Digital Omnibus on AI, Regulation (EU) 2026/1744, was adopted by the European Parliament on 16 June 2026, approved by the Council on 29 June, published in the Official Journal on 24 July, and entered into force on 27 July 2026. It is the first amendment to the AI Act since adoption, and it rewrote Article 4 in full.
The change is one of legal character rather than scope. The original wording required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy. The amended wording requires measures to support the development of AI literacy. The obligation moved from one of result to one of effort, and the reference to a sufficient level was deleted.
That reads as a relaxation, and for one specific question it is: an organization is no longer being asked to guarantee that any individual reached a threshold. For every other question it raises the bar on documentation. A result obligation can be evidenced by an outcome. An effort obligation can only be evidenced by showing the measures themselves: what was delivered, to which roles, on what schedule, and why those measures suited those systems. The European Parliament’s adopted text on the Digital Omnibus records the amendment, which passed by 569 votes to 45.
What Penalties Apply When AI Literacy Is Missing
Article 99 of the AI Act sets the penalty tiers, and it does not list Article 4 as a standalone fineable provision at EU level. Penalties for an AI literacy failure are set by member states in national law, which means exposure differs by jurisdiction rather than following one European figure. Any post quoting a single confident number for an Article 4 fine is describing one country’s transposition, or guessing.
The Act’s general tiers still matter as context, because a literacy gap rarely surfaces on its own. Article 99 provides for penalties up to €35,000,000 or 7% of total worldwide annual turnover for breaches of the Article 5 prohibitions, up to €15,000,000 or 3% for most other obligations, and up to €7,500,000 or 1.5% for supplying incorrect or misleading information to authorities. The higher figure applies in each case.
The realistic exposure for most organizations is indirect. A documented absence of AI literacy measures becomes an aggravating factor once a regulator is already investigating something else, and negligence is one of the factors the Commission has said enforcement should weigh. The pattern is familiar from other regimes, as this look at how weak human controls raise compliance costs and this survey of ISO 27001, GDPR, and HIPAA obligations on the human layer both set out.
What Counts as AI Literacy, According to the Commission’s Own Frameworks
With the threshold wording removed from Article 4, the question of what literacy actually means moves to the frameworks the European institutions have published. Two are worth knowing by name because they give a supervisory conversation a shared vocabulary.
AILit, formally “Empowering Learners for the Age of AI”, is a joint European Commission and OECD initiative supported by Code.org. It was opened for consultation in May 2025 and finalized in 2026, and it structures literacy around four domains: Engage with AI, Create with AI, Manage AI, and Design AI, broken into 22 competences. DigComp 3.0, published by the Commission’s Joint Research Centre in 2025, integrates AI competence across the European digital competence framework and introduces more than 500 learning outcomes.
Neither framework is binding on a private employer, and neither was written for corporate compliance. Both are useful anyway, because they describe the ground an organization can be asked to show it covered. A program that only teaches employees which chatbot is approved reaches a fraction of one domain. Judgment about when to rely on an AI output, and how to recognize a manipulated one, sits closer to the centre of what these frameworks describe, and that judgment is what this guide to spotting AI-generated fakes and this discussion of AI deception and authenticity are built around.
Why Is an Effort Obligation Harder to Evidence Than a Completion Report?
A completion report answers the question an old-style compliance regime asked: did people attend. Article 4 as amended asks a different question: what measures did the organization take, and were they appropriate to the systems actually deployed and the people actually operating them. A single annual module delivered identically to everyone answers neither half of that.
The gap is specific. An organization can hold 100% completion on a general AI awareness course and still have no record showing that the team using an AI-assisted recruitment tool received anything about automation bias, or that the finance team using a generative assistant was told what happens to data pasted into it. Completion measures delivery. Article 4 asks about fit.
Building the record therefore starts with knowing which roles touch which systems, not with choosing a course. Approaches to that sequencing are covered in this piece on role-based security awareness training, and the wider shift away from completion as a headline number is explored in AI-driven compliance training.
How to Map Article 4 Measures to Roles
The mapping below is a working structure, not a legal opinion. It starts from the way people actually encounter AI at work and assigns each group the literacy that matches what they can get wrong. Two principles drive it. Literacy follows the system a person operates, not their seniority, so a junior analyst running an AI screening tool needs more than a director who never opens one. And the evidence column matters as much as the content column, because an effort obligation is discharged by what an organization can show, not by what it believes it delivered. Baseline questions for that mapping are covered in this guide to cybersecurity awareness training for employees.
| Group | What they operate | Literacy the role needs | Evidence to retain |
|---|---|---|---|
| All staff | Approved assistants and embedded AI features | What an AI system is, what the organization approved and banned, what data must never be entered | Course version, delivery date, role coverage |
| Managers and HR | AI in recruitment, performance, and scheduling | Automation bias, contestability of decisions, Annex III sensitivity of employment use cases | Role-specific module, acknowledgement of policy |
| Finance and procurement | Generative assistants handling payment and vendor data | Output verification before action, escalation path when an instruction arrives through an AI-mediated channel | Module plus simulation results |
| Developers and data teams | Models, APIs, and agent integrations | Provider versus deployer duties, logging, prompt injection, output marking under Article 50 | Technical training records, design documentation |
| Executives | Approval of AI deployment and spend | Risk classification, accountability for deployer duties, penalty exposure | Briefing records, board minutes |
| Contractors and vendors | Any system operated on the organization’s behalf | The same literacy as the equivalent internal role | Contract clause plus delivery confirmation |
The last row is the one most programs miss. Article 4 names persons operating AI systems on the provider’s or deployer’s behalf, which pulls contractors inside the duty while leaving them outside most corporate learning systems.
The Evidence File a Market Surveillance Authority Will Ask For
Assemble six artifacts and keep them current. Each answers a question a supervisor can reasonably ask once national authorities are exercising the powers they gained in August 2026.
- An AI system inventory, listing each system in use, whether the organization is provider or deployer, and which roles operate it
- A role-to-measure map, showing which literacy measure each role received and the reasoning behind the match
- Delivery records with dates, versions, and coverage by role rather than a single organization-wide percentage
- The policy itself, naming approved and prohibited tools and the data categories that may not be entered
- A refresh schedule, because a measure delivered once in 2025 does not evidence ongoing effort against systems adopted in 2026
- Contractor confirmations, showing the duty was extended to people operating systems on the organization’s behalf
Threatcop’s TLMS carries this layer as role-based and category-based courses across multiple compliance frameworks, delivered in the languages a distributed workforce actually works in, with coverage reported by role rather than as one headline completion figure. The AI Awareness Manager sits alongside it, assigning content and producing the role-level reporting from prompts, so the evidence file is a by-product of running the program rather than a project someone starts when a regulator writes. Programs built this way tend to change behavior rather than records, which is the argument in this guide to building a cybersecurity culture.
Where to Start Before a Supervisor Asks
List the AI systems actually in use, including the ones nobody formally approved, then list who operates each of them. Most organizations discover at that point that their AI policy covers tools their staff stopped using and misses the ones they did not know about, and that gap is the whole Article 4 problem in miniature.
Build the role-level program from that list rather than from a course catalogue, so what gets delivered matches what people actually operate and the evidence file writes itself.
Frequently Asked Questions
When did the EU AI Act AI literacy requirement come into effect?
Article 4 became applicable on 2 February 2025, six months after Regulation (EU) 2024/1689 entered into force on 1 August 2024. The same date brought the Article 5 prohibited practices into effect. National market surveillance authorities gained formal powers to supervise and enforce Article 4 in August 2026. Coverage placing the start date in February 2026 is a year out.
Does the EU AI Act apply to companies outside the EU?
Yes, on the same extraterritorial logic as GDPR. An organization based anywhere is a provider if it places an AI system on the EU market, and a deployer if it uses one under its own authority in a way that affects people in the Union. Article 4 travels with that status, so a company in India, the UK, or the Gulf serving EU clients carries the literacy duty.
Did the Digital Omnibus remove the AI literacy obligation?
No. Regulation (EU) 2026/1744, in force since 27 July 2026, rewrote Article 4 rather than repealing it. The duty changed from ensuring a sufficient level of AI literacy to taking measures that support its development, which makes it an obligation of effort rather than result. Organizations that have taken no measures are in the same position they were before.
What is the fine for failing to meet Article 4?
Article 99 does not list Article 4 as a standalone fineable provision at EU level, so penalties are set by member states in national law and vary by jurisdiction. The Act’s general tiers reach €35,000,000 or 7% of worldwide turnover for prohibited practices and €15,000,000 or 3% for most other obligations. In practice a literacy gap most often surfaces as an aggravating factor in another investigation.
Is annual AI training enough to satisfy Article 4?
Rarely. The duty is framed around measures appropriate to the systems deployed and the people operating them, and AI tooling inside most organizations changes faster than once a year. A single annual module also produces coverage evidence at the organization level rather than the role level, which is the level at which the obligation is written.

Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
