Art. 4 AI Act: the AI literacy duty — what a company must do before 2 Aug 2026

This duty has applied since 2 February 2025. For 17 months nobody enforced it — so the market decided it did not exist. On 2 August 2026 supervision starts, and it can ask for documents covering the prior period too. Good news: it is the cheapest duty in the whole AI Act. Bad news: “we ran a webinar once” is not an answer.

In short
  • Art. 4 requires a “sufficient level of AI literacy” among staff and persons acting on the company’s behalf — proportionate to roles and use context. It covers providers and deployers, with no size threshold.
  • The key is not training alone, but proof: programme, register, role-based scopes, cadence. Training without documentation does not exist in a regulator’s eyes.
  • Compliance can be reached in 2 weeks and 5 steps — without certificates, LMS platforms, or 40-hour courses.
The rule

What Art. 4 actually says

The provision is short — and that is why it misleads. In plain terms: providers and entities using AI systems take measures to ensure a sufficient level of AI competence for their staff and other persons acting on their behalf when operating AI systems — taking into account their knowledge, experience, education and the context in which the systems are to be used.

Three implications that are easy to miss:

  • “Take measures” — an obligation of action, not of outcome. But action you cannot evidence legally did not happen.
  • “Staff and other persons acting on their behalf” — also covers B2B contractors and external collaborators operating your AI systems.
  • “Taking into account the context” — one training for everyone fails by definition, because the rule demands proportionality.
Scope

Who is covered — short answer: almost everyone

Organisation typeIn scope?How far
Company building AI systems (provider)YesBroadest: engineering, product, AI solution sales.
Any company using AI (deployer) — from a chatbot to Copilot in WordYesProportionate to roles: who uses what, at what risk.
Micro and small firmsYesNo exemption. Proportionality helps — scope can be modest, but it must exist and be documented.
Public bodiesYesAs deployers — with extra reputational exposure.
Contractors acting for the companyYesDuty sits with the company — include them in the programme or require proof of competence.
Interpretation

What “sufficient level” means

The rule deliberately gives no hour count or syllabus. The measure is role risk. The practical rule we use: the closer AI sits to decisions about people and money, the deeper the human competence next to it must be.

  • Receptionist using ChatGPT for email — must understand basics: hallucinations, ban on pasting personal/confidential data, which tools are allowed.
  • Marketing generating content and graphics — additionally: copyright, AI content labelling duties (Art. 50 — covered next).
  • HR using AI in recruitment — much more: bias risk, candidate right to human review (GDPR Art. 22), awareness this is high-risk under Annex III.
  • Team deploying AI systems — full scope: architecture, security, model limits, company policy.
Thesis of the day

Training without documentation does not exist to a regulator

This is the sentence worth taking from this article into a board meeting. When a supervisory authority — or, far more often, your corporate client’s procurement team — asks about Art. 4 compliance, they will not ask “did you train people?”. They will ask for documents:

  1. Training programme — what, for whom, at what depth, with role-based scope rationale.
  2. Participant register — who, when, what scope completed. With dates.
  3. Role matrix — proof that scope is proportionate to use context (required by the provision itself).
  4. Update cycle — AI changes every quarter; a one-off 2024 training does not show a “sufficient level” in 2026.
  5. Path for new joiners — onboarding module and its trail in the register.

Notice the implication: a company that ran an excellent workshop and has no paper trail is in a worse evidentiary position than one that ran modest e-learning with a complete document set. Unfair — and entirely typical of law. Play the game that is actually in force.

Plan

Compliance in 2 weeks: 5 steps

  1. Days 1–3 — AI use inventory. Formal and informal (shadow AI): a short survey “which AI tools do you use at work?” with a no-penalty guarantee for honesty. Without this step the role matrix is fiction.
  2. Days 3–5 — role × risk matrix. Split the organisation into 3–5 groups (e.g. everyone / power users / HR & finance / tech / board) and assign required scope to each.
  3. Days 5–8 — programme. Three modules suffice: (1) AI basics and limits, (2) regulation and duties, (3) company policy and safe use. The board needs a separate short briefing — under NIS2/KSC-style rules, management liability can be personal.
  4. Days 8–12 — delivery. Mixed formats: e-learning for all, workshop for power users, 90 minutes for the board.
  5. Days 12–14 — register and cycle. Certificates, dated register, calendar review every 6–12 months, and an onboarding module.
What you do NOT need to do
  • Buy external certificates — Art. 4 requires no certification.
  • Send everyone on 40-hour courses — proportionality cuts both ways.
  • Teach everyone prompt engineering — reception does not need to prompt; they need to know what not to paste into a prompt.
  • Deploy an LMS platform — a dated spreadsheet register with sign-offs meets the evidentiary function.
Why it matters — beyond the fine

The cheapest insurance policy in the whole AI Act

Art. 4 itself has no dedicated sanction — which is why it gets ignored. That is an accounting error. From December 2026 software, including AI systems, enters the product liability regime (PLD). In a civil dispute, lack of training becomes the simplest negligence evidence for the other side: “the company deployed AI and did not train the people who used it”. The reverse also holds: a documented programme is ready-made due diligence evidence — cheap to produce, priceless in a dispute. More on that chain in the article on fines.

Download

Compliance checklist: Art. 4 + Art. 50 before 2 August

One page: 12 control points, fields for dates and owners. A completed checklist = the first document in your evidence file.

Download checklist (PDF)
FAQ

Common questions

Is a one-off webinar enough?

Alone — no. Without a role matrix, register and update cycle it shows neither the proportionality nor the continuity the rule demands.

Does e-learning count?

Yes — as a baseline for everyone, with documented completions. Teams working intensively with AI should get an additional workshop.

What about new employees?

AI literacy module in onboarding + register entry. The duty is continuous, not one-off.

Who in the company should “own” this?

One owner (usually COO, HR or compliance). Diffused ownership is no ownership in practice — and no documents when the question comes.

If you would rather have this handled

We run closed Art. 4 workshops — with full documentation for the regulator

Role-fitted programme, delivery before 2 August, and a complete document pack: programme, role matrix, register, certificates, update schedule. On Friday we publish the full programme openly — you can also implement it yourself.

See the training programme →

This article is informational and is not legal advice. Cited duties come from Regulation 2024/1689 (AI Act); verify the current legal state before business decisions.

RW

Rafał Wiatrowski — for 25 years has built and deployed technology: from code, through CTO roles, to GenAI strategy for large organisations. Designs production AI systems (agents, RAG, MCP) and helps companies move from pilots to accountable deployments. Executive MBA (Carlson School of Management).

Jeden artykuł tygodniowo. Zero lania wody.

Subskrybuj →