AI Literacy: The Only AI Act Obligation Already Binding on You Today

TL;DR


What does Article 4 say and who exactly does it bind?

The AI Act has a tiered architecture: the higher the risk, the more obligations. Most of the articles that cause concern (technical documentation, conformity assessment, CE marking, registration in the EU database) only activate if your system is high-risk, and those obligations do not arrive until December 2027 or August 2028, depending on the case.

Article 4 is the exception. It is in Chapter I, "General provisions", and Article 113, paragraph 3, point (a) fixes the date: Chapters I and II apply from 2 February 2025. No transition, no dependence on risk level and no dependence on company size.

It binds two roles, defined in Article 3:

That last qualifier is what separates the business from the private individual. Using a chatbot to write a poem on a Sunday is personal activity. Using it on Monday to draft commercial proposals is not.

What changed on 27 July 2026?

The Digital AI Omnibus, published in the Official Journal of the EU on 24 July 2026 and in force three days later, replaced Article 4 in its entirety in point 5 of its Article 1. The new wording has three paragraphs. The first, verbatim:

"1. Providers and deployers of AI systems shall take measures to support the promotion of AI literacy of their staff and any other persons dealing on their behalf with the operation and use of AI systems, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to ensure a specific level of AI literacy of any particular person."

Paragraph 2 transfers some burden to the public sector: "The Commission and Member States shall support and facilitate the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling their obligation pursuant to paragraph 1 of this Article. To that end, the Commission shall publish practical examples of how to fulfil that obligation on the single information platform referred to in Article 62(3)(b)".

Paragraph 3 charges the AI Board with recommendations that take into account European competence frameworks, "including through the establishment of common objectives".

What has changed in practice:

Original wording (2 Feb 2025 – 26 Jul 2026)Current wording (from 27 Jul 2026)
Verb"shall take measures to ensure that… have a sufficient level""shall take measures to support the promotion of AI literacy"
Scope"to the extent possible"That clause is deleted
Required levelNot clarifiedClarified: does not require ensuring a specific level of any particular person
Public supportNot provided for in the articleCommission and Member States must support; practical examples on the single platform
RecommendationsNot provided forThe AI Board will adopt recommendations with common objectives

Recital 8 of the Omnibus explains the reason with unusual candour: stakeholder experience showed that "a solution that imposes strict obligations to ensure a sufficient level of AI literacy would not be suitable for all types of providers and deployers", and that such obligations create "an additional compliance burden, particularly for small businesses". And it adds an idea that should not be lost: AI literacy "should be a strategic priority, regardless of the regulatory obligations and possible penalties".

Translation for an SME: the obligation has become more reasonable, not disappeared.

Does it bind me if my company only uses ChatGPT or Copilot?

Yes. And this is what is hardest to accept.

Article 3, point 1, defines "AI system" as "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments".

A generative conversational assistant fits without question. So do the module that writes product descriptions in your online shop, the one that summarises calls in your CRM, the one that suggests email replies or the one that classifies incoming invoices. Article 4 does not distinguish by risk level: it says "AI systems", full stop.

What it does distinguish is the intended context of use. The measure you take with a team of five people using a chatbot for drafts need not resemble that of a consultancy using AI to pre-classify client files. The article itself says this: you must take into account the knowledge, experience and training of staff and the context of use.

What is a "sufficient level" of AI literacy?

The Regulation defines the concept in Article 3, point 56: "skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness of the opportunities and risks of AI and possible harms it can cause".

Recital 20 develops it: the concepts "may vary depending on the relevant context" and include understanding the correct application of technical elements during development, the measures to apply during use, "appropriate ways of interpreting the AI system's output" and, for affected persons, understanding how decisions taken with AI assistance affect them.

Applied to an SME, a sufficient level means that whoever uses the tool knows:

If your staff knows this and you can demonstrate that you taught them, you have complied with the spirit and the letter of Article 4.

What does Article 4 NOT require?

It is worth being clear, because there is significant commercial noise around this.

How is it demonstrated in practice?

With dated documents. The logic is the same as in data protection or occupational risk prevention: if it is not documented, it did not happen.

Four documents, and none need be more than a couple of pages.

1. AI systems inventory. A table with: tool, vendor, purpose, who uses it, what data goes in, who approved it and date. It is the foundation of everything else and, moreover, it is the first thing any auditor will ask for.

2. AI use policy. The document to create on Monday. Minimum content:

3. Training log. Date, duration, content, attendees and signature or acknowledgement of receipt. A 45-minute internal session is valid. Leaving no trace is not.

4. Evidence. Materials used, the email communicating the policy to staff, acknowledgement replies, clauses incorporated in contracts with subcontractors who operate systems on your behalf.

Add a review date. The Regulation will keep moving and the Commission has been tasked with publishing practical examples.

What happens if I do not? Is there a fine?

Precision matters here — and fear should not be sold.

Article 99, paragraph 4 of the AI Act lists non-compliances sanctioned with up to €15,000,000 or 3% of worldwide business volume: provider obligations (Art. 16), authorised representatives (Art. 22), importers (Art. 23), distributors (Art. 24), deployer obligations (Art. 26), notified bodies and transparency (Art. 50). Article 4 is not in that list.

However, paragraph 1 of the same Article 99 charges Member States with establishing the sanctions regime "applicable to infringements of this Regulation". In other words: the door is left open to the national legislator.

In Spain, that door has not yet been closed. The Draft Organic Law on the sound use and governance of artificial intelligence was published in the Official Gazette of the Cortes Generales (Congress, Series A, No. 97-1) on 12 June 2026. In its chapter on infringements and sanctions (Articles 13 to 29), the published text does not typify failure to comply with Article 4. It is a draft subject to amendments and is not in force, so this may change.

Operational conclusion: today there is no named fine for not training your staff. There are two practical reasons to do it anyway. First: if an employee leaks client data to a public tool, the problem arrives not via the AI Act but via the GDPR, and the use policy is your defence. Second: any corporate client or public tender that asks you for AI governance evidence will be satisfied with exactly what Article 4 requires.

What official guidance exists and which is binding?

No guidance is binding. Worth making clear before paying for interpretations.

AESIA published in December 2025 a package of 16 guides: two introductory (01 and 02), thirteen technical (03 to 15) and a checklist usage manual (16), plus a compressed file with the checklists and examples. The agency itself warns on its website that the guides "have no binding character and do not substitute or develop applicable legislation", and that they will be updated "once the Digital Omnibus amending the AI Regulation is approved". In other words: useful as a template, pending revision in their content.

At European level, the new Article 4, paragraph 2, tasks the Commission with publishing practical examples of compliance on the single information platform provided for in Article 62, paragraph 3, point (b). When they appear, they will be the closest reference to a de facto standard.

How to set it up in four weeks

WeekWhat you doWhat is written up
1Written enquiry to each department: what AI tools do they use, including unapproved onesAI systems inventory, version 1
2Draft the use policy from the inventory: authorised tools, prohibited data, human review, incidentsAI use policy, approved and dated
345–60 minute internal session with real examples from your business: a tool error, data that must not leave, output that must be verifiedTraining log with attendees and materials
4Communicate the policy, collect acknowledgements, review contracts with subcontractors operating systems on your behalf, set a review dateEvidence filed and review date noted

Four weeks at the pace of one afternoon per week. That is the real size of the problem.


Frequently asked questions

Does Article 4 apply to the self-employed too?

Yes, if they use AI systems in their professional activity. The definition of deployer includes natural persons and only excludes use "under a personal non-professional activity".

If my software vendor already trains my team, am I covered?

It can serve as part of the measure, but the obliged party remains your company. Keep the certificate of attendance, the syllabus and the dates, and incorporate them into your training log.

Do I need to train all staff or only those who use AI?

Article 4 refers to staff "and any other persons dealing on their behalf with the operation and use of AI systems". The proportionate approach is to train those who use the tools and circulate a brief informational note to the rest, especially if they may start using them at some point.

How long does training have to be?

The regulation sets no duration. What matters is that it is appropriate to the prior knowledge and context of use. A short, well-documented session repeated when new people join is more defensible than a long course with no record.

Does it change if my company develops its own AI rather than buying it?

A great deal, but not because of Article 4. You also become a provider, with the obligations corresponding to the system's risk level. Article 4 applies to you in both cases.

With the Omnibus, can I relax and do nothing?

No. The obligation still exists and its application date has not moved: 2 February 2025. What has changed is the bar, which is now one of reasonable effort rather than guaranteed outcome.


Sources