Many of us have read Article 4 of the AI Act and been left with the same question: AI literacy? What does that actually mean?
Complying with Article 4 of the AI Act is not simply a matter of sending the whole workforce on an AI course. A course can help, but how useful it is depends on which tools the company uses, who uses them and what decisions they make with them.
Let's look at what the regulation asks for when it talks about AI literacy, and how to put it into practice in a company, especially an SME.
Article 4 in a few lines
- Article 4 of Regulation (EU) 2024/1689 on Artificial Intelligence (the AI Act) requires providers and deployers to take measures to support the AI literacy of their staff and of the people who use those systems on their behalf.
- Since the Digital Omnibus, Regulation (EU) 2026/1744, it no longer requires a «sufficient level» to be ensured. The obligation still stands, but it asks for measures, not for each person to reach a specific level.
- There is no mandatory course and no certificate. Measures are tailored to what each person knows, the context of use and who may be affected.
- In practice it comes down to eight steps: understand the goal, inventory the AI, find out who uses it and for what, analyse the risks, decide what each role needs, apply measures, document them and review them when something changes.
What Article 4 of the AI Act requires after the Digital Omnibus
Following the amendment introduced by the Digital Omnibus, Regulation (EU) 2026/1744, Article 4 requires providers and deployers to take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of these systems on their behalf.
Ensure a sufficient level
Providers and deployers had to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff.
Take measures to support it
The «sufficient level» is gone. Measures must be taken to support the development of AI literacy, without the regulation setting a specific level each person has to reach.
Those measures must take into account people's technical knowledge, experience, education and training, the context in which the systems are used, and the persons who may be affected by them.
The regulation itself defines AI literacy in Article 3, point 56: the skills, knowledge and understanding that allow an informed deployment of AI systems and awareness of their opportunities, their risks and the harm they can cause. It is about understanding the tool and its limits, not about knowing how to build models.
- A specific course or a certificate. The European Commission says an internal record of training and other initiatives is enough.
- A minimum level for each person.
- Measuring staff's AI knowledge. The Commission also makes this clear in its questions and answers.
The fact that the regulation does not require something does not mean it is not worth doing. We come back to this in the first step.
How to apply Article 4 in a company: eight steps
How do you put this into practice in a company, especially an SME? It can be organised into eight steps or stages.
Step 0. Understand this is not only about compliance
AI literacy is not solved with «I have a plan and look how nice it turned out». There are dozens of ways to find out that a company's staff do not know how to use AI: customer data pasted into a chat, a report with a made-up figure, an image published without the rights to it. That is why we need a plan, to apply it, to assess people, to measure the results and to make sure mistakes are not made through negligence.
The AI Act does not require anyone to be tested. Assessing is a management decision: it is how you find out whether the measures work or only exist on paper.
Step 1. Identify which AI is being used
Start with a simple inventory. It usually covers four types of tools:
- Conversational assistants, such as ChatGPT, Copilot, Gemini or Claude.
- Image generators, and video or voice generators.
- Specialised tools, such as those used in recruitment.
- AI features built into everyday software: email, office suites, CRM or ERP.
It is worth asking the teams. Some tools may be in use without the organisation having the full picture, whether through personal accounts or because a supplier switched the feature on in an update.
Step 2. Identify who uses it and what for
The same tool can be used to prepare a draft, summarise a contract or assess job applications, and each of those uses calls for different guidance. For each use, record:
- The use: what task is done with the tool.
- The roles involved: which people or teams use it.
- The data entered: whether it includes personal data, confidential information or customer data.
- Where the output goes: whether it stays as an internal draft, gets published or is used to make decisions about someone.
You also need to consider those acting on the company's behalf, such as external collaborators or service providers who use AI systems for it.
Step 3. Analyse the risks of each use
With the inventory and the uses in front of you, it is time to look at what could go wrong in each case. These are the risks that come up most often:
Personal or confidential data
Entering it into a tool can expose information that should be protected.
Convincing but false answers
A well-written answer can contain invented data, references or conclusions.
Discriminatory results
The output can reproduce stereotypes or harm certain people or groups.
Third-party content
Generated text, images or code can reproduce protected works or be used without the necessary rights.
Overconfidence and a lack of human oversight can turn those errors into harmful publications, decisions or actions.
Step 4. Decide what each role needs to know
Not everyone needs to know the same things. With the risk analysis done, you can decide what each role needs:
| Role | Typical use | What they need to know |
|---|---|---|
| General use | Summarising documents or drafting with ChatGPT | What information they can enter and how to check the output against the original, including possible omissions. |
| Marketing | Text and images for publication | Criteria for reviewing claims, images, third-party rights and content that reproduces stereotypes before publishing it. |
| Human Resources | Screening or assessing applications | How bias can harm an application and why an automated score deserves critical review. |
| Technical team | Developing or integrating AI | Data quality, testing, security, limitations and oversight mechanisms, in greater depth. |
Needs change depending on the task and on people's prior knowledge. If your company uses AI in recruitment, we cover it in depth in the guide on AI in recruitment screening.
Step 5. Apply tailored measures
Several measures can be combined:
- Workshops built on the company's own real cases.
- Short guides per tool or per task.
- An AI acceptable use policy.
- Awareness sessions.
- Procedures for reviewing outputs and reporting incidents.
The acceptable use policy is the first thing I would sort out. And it is more useful if people understand how to apply it: a five-page PDF that hardly anyone will read does not do that job.
There is no single format and no mandatory course for complying with Article 4. Completing a particular training course does not, on its own, guarantee compliance with the AI Act either, as the European Commission's guidance points out.
How to write an AI policy under ISO/IEC 42001
Draft, approve and review your AI use policy with a step-by-step guide, examples and an editable Word template.
Create my AI policy →Step 6. Document the measures taken
As a matter of good management, it is worth keeping a record of:
- The needs identified.
- The actions taken and who they were for.
- Dates and materials.
- Why those measures were chosen.
This record lets you explain your decisions and spot what is still outstanding. It also ties in closely with an AI management system such as the one set out in ISO/IEC 42001, which requires the necessary competences to be determined and evidence of them to be kept.
Step 7. Review when the context changes
Measures are not done once and filed away. They need updating when there is:
- A new tool.
- A different use of an existing tool.
- An incident.
Guidance prepared for drafting documents may fall short if AI is later used to support decisions about people.
If you use high-risk AI systems
High-risk systems also carry specific obligations that must be met according to their scope and application timetable. After the Omnibus, they apply from 2 December 2027 to Annex III systems (recruitment systems among them) and from 2 August 2028 to Annex I systems. We cover this in detail in the article on the Digital Omnibus.
Article 26(2) of the AI Act requires deployers to assign human oversight to people with the necessary competence, training and authority. General AI literacy needs to connect with those responsibilities: whoever oversees a high-risk system needs considerably more than the general training.
Could any of your company's AI uses be high-risk?
I review, system by system, which AI you use, your company's role, the risk level of each use and what the AI Act requires from when. From there come the AI literacy measures for each role, the acceptable use policy and any human oversight you need.
See the applicability review →How to tell whether AI literacy is working
AI literacy should also be judged in day-to-day work: whether people understand the AI they use, its limitations, its risks and how to use it properly within the organisation. Some questions that help check this:
- Do they know what data they must not enter into each tool?
- Do they check outputs before using or publishing them?
- Do they know who to tell if something goes wrong?
- Are uses of AI turning up that nobody had anticipated?
The percentage of courses completed, on its own, gives an incomplete picture.
Frequently asked questions about Article 4 of the AI Act
What is AI literacy under the AI Act?
Article 3, point 56, of Regulation (EU) 2024/1689 defines it as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems and to gain awareness of their opportunities, their risks and the harm they can cause.
Which companies does Article 4 apply to?
To providers of AI systems and to deployers, meaning anyone who uses an AI system under their authority in a professional activity. A company whose staff use ChatGPT or Copilot for work is a deployer, whatever its size.
Is an AI course mandatory to comply with Article 4?
No. There is no mandatory course and no required certificate. Measures can combine workshops, guides, an acceptable use policy, awareness sessions and procedures, tailored to each role. Completing a particular course does not, on its own, guarantee compliance either.
What did the Digital Omnibus change in Article 4?
Regulation (EU) 2026/1744 replaced the obligation to ensure a sufficient level of AI literacy with an obligation to take measures to support its development. The obligation still applies to providers and deployers, but it no longer sets a specific level each person must reach.
Do staff's AI skills have to be assessed?
Article 4 does not require staff's AI knowledge to be measured, as the European Commission makes clear. Even so, assessing is good management practice: it is how you find out whether the measures work in day-to-day work.
How do you show compliance?
With an internal record of the needs identified, the actions taken, who they were for, dates and materials, and why they were chosen. No external certificate is needed.
AI ActRegulation (EU) 2024/1689 on Artificial Intelligence, Articles 3(56), 4 and 26(2) (EUR-Lex).
Digital OmnibusRegulation (EU) 2026/1744, text of the amendment (EUR-Lex, PDF).
European CommissionAI Literacy - Questions & Answers.
This is a courtesy translation of the Spanish original. Antonio Cebreiro Bernárdez is a computer engineer and a cybersecurity and AI consultant. His specialisms, certifications and background are on his author page.