Regulation & governance7 min read

AI Literacy Under the EU AI Act: What Article 4 Means

What the AI literacy requirement in Article 4 of the EU AI Act means for companies, who it covers, what good training includes and how to document it.

Article 4 of the EU AI Act requires companies that provide or use AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and others who operate or use those systems on their behalf. It has applied since 2 February 2025 and is not limited to high-risk AI: a company whose employees use a general AI assistant at work is covered. The Act does not prescribe a specific course or certificate. What counts as sufficient depends on people's existing knowledge, their role and the context in which AI is used. In practice, that means role-based training on how the tools work, where they fail, the company's rules, and when to escalate, plus a record of what was done.

This article is general information, not legal advice. Guidance from the European Commission and national authorities on AI literacy continues to develop, and changes to the framing of the obligation have been discussed at EU level. Check the current consolidated text and official guidance.

What the law says, in plain terms

The key elements of Article 4:

Element Meaning
Who must act Providers and deployers of AI systems
Who must be literate Their staff and other persons dealing with the operation and use of AI systems on their behalf, such as contractors
What is required Measures to ensure, to their best extent, a sufficient level of AI literacy
What sufficient depends on Technical knowledge, experience, education and training of the people; the context of use; the persons or groups affected

The Act defines AI literacy broadly as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause.

Who is covered

If your company uses AI systems in a professional context, you are a deployer. That includes:

  • employees using AI assistants for drafting, research or summarising,
  • AI features in software you use, such as CRM, office, HR or accounting tools,
  • AI systems you have built or integrated, such as chatbots or document automation.

If you develop AI systems and place them on the market or put them into service under your name, you are a provider, and the same requirement applies to your staff involved.

The EU AI Act deployer obligations article explains the provider and deployer roles in more detail.

What a sufficient level looks like

There is no single standard, so think in terms of roles. A reasonable approach distinguishes at least three groups:

Group Typical people What they need to understand
All users Anyone using AI tools at work What AI can and cannot do, hallucinations, data rules, approved tools, checking outputs, where to ask
Power users and reviewers People who use AI daily, write prompts, review outputs, or oversee automated processes Prompting techniques, systematic review, recognising failure patterns, escalation, documentation
Decision-makers and owners Managers, process owners, IT, compliance Risk categories, legal obligations, vendor assessment, governance, incident handling

People involved with high-risk AI systems, especially those assigned to human oversight, need deeper, system-specific training on that system's capabilities, limits and correct use.

Core topics for a basic AI literacy programme

1. How generative AI works, at a useful level

  • AI models predict likely text; they do not look up truth.
  • Output can be fluent and wrong.
  • Quality depends on the instructions and the context provided.
  • Models have knowledge cut-offs and do not know your company's internal information unless it is provided.

2. Limits and risks

  • Hallucinations: invented facts, figures and sources. See how to reduce AI hallucinations for practical techniques.
  • Bias: outputs may reflect biases in training data.
  • Over-reliance: the tendency to accept AI output without enough scrutiny.
  • Prompt injection: instructions hidden in documents or web pages can manipulate AI tools.
  • Inconsistency: the same prompt can produce different answers.

3. Company rules

  • Which tools are approved for what.
  • What data may and may not be entered.
  • Review requirements before outputs are used.
  • Uses that are prohibited or need approval.
  • How to report problems.

These rules usually live in an AI policy. Our guide to writing an AI acceptable use policy includes an outline and a one-page summary you can use in training.

4. Using AI well

  • Writing clear prompts with task, context, format and rules. The prompt engineering guide is a good basis.
  • Checking outputs efficiently.
  • Knowing when not to use AI.

5. Regulation and accountability

  • The basic risk categories of the AI Act. EU AI Act risk categories explained gives an overview.
  • Why some uses, such as evaluating job applicants, need special care.
  • Who in the company is responsible for AI questions.

Formats that work

AI literacy does not have to mean long courses. Effective formats include:

  • Short live sessions with real examples from your own work, including examples of AI getting things wrong.
  • Hands-on exercises: improve a weak prompt, find the errors in an AI-generated summary, decide whether data may be entered into a tool.
  • Quick reference cards with the data rules and approved tools.
  • Onboarding modules for new employees.
  • Refreshers when tools, rules or use cases change.
  • Peer champions in each team who help colleagues and collect questions.

Training that uses your actual tools and tasks is usually more effective than generic material.

Documenting your measures

The AI Act does not prescribe a specific form of documentation for AI literacy, but being able to show what you did is sensible. A simple record could include:

Field Example
Measure "AI basics session for all staff"
Target group All employees using AI tools
Content Topics covered, materials used
Date and duration
Participants List or count
Trainer or source Internal, external provider
Next review

Keep materials and attendance records together with your AI policy and your inventory of AI tools and use cases.

A practical 30-day plan

Week Action
1 Inventory AI tools and use cases; identify who uses what
1 Define target groups and what each needs
2 Finalise or update the AI use policy and data rules
2–3 Run a basic session for all users; hand out a reference card
3–4 Run deeper sessions for power users, reviewers and owners
4 Document measures, collect questions, set a review date

Small companies can compress this considerably. The point is to start with the basics for everyone and go deeper where responsibility is greater.

Linking literacy to other obligations

AI literacy supports other parts of the AI Act and good practice generally:

  • Human oversight of high-risk systems requires people with the competence and training to do it.
  • Transparency duties require staff to know when disclosure is needed, for example for deepfakes.
  • Avoiding prohibited practices requires managers to recognise where the lines are.

It also has business value beyond compliance: trained staff get better results from AI tools and make fewer costly mistakes, which shows up in the time savings you can measure with the AI ROI calculator.

Common mistakes

  • Assuming it only applies to high-risk AI. Article 4 applies to all providers and deployers.
  • One generic e-learning for everyone. Needs differ by role and context.
  • Only theory. Without hands-on practice with your own tools, behaviour rarely changes.
  • No record. Without documentation, it is hard to show what you have done.
  • One-off training. Tools and rules change; plan refreshers.
  • Forgetting contractors and temporary staff who use AI on your behalf.

Summary

AI literacy under the EU AI Act means making sure the people who use AI on your behalf understand it well enough for their role: what it does, where it fails, what the rules are and when to escalate. Start with an inventory, train by role, use real examples, keep a record and update regularly. To see which of your AI uses may need deeper training because of their risk level, try the EU AI Act risk checker.

FAQ

What does Article 4 of the EU AI Act require?

It requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with AI systems on their behalf, taking into account their knowledge and the context of use.

Since when does the AI literacy requirement apply?

Article 4 has applied since 2 February 2025. The EU has discussed changes to how this obligation is framed, so check the current consolidated text for the latest position.

Is a certificate required for AI literacy?

The AI Act does not prescribe a specific certificate or course. Companies decide which measures are appropriate. Keeping a record of what training was provided, to whom and when is good practice.

Does AI literacy apply if we only use ChatGPT or similar tools?

Yes. Using AI systems in a professional context makes you a deployer, and the literacy requirement applies regardless of the risk level of the system.

Related articles

Regulation & governance9 min read

EU AI Act for Deployers: What Businesses Must Do

EU AI Act obligations for deployers: AI literacy, transparency duties, high-risk use rules, when a user becomes a provider, and a practical checklist.

Regulation & governance9 min read

EU AI Act Risk Categories Explained With Examples

The four EU AI Act risk categories explained with business examples: prohibited, high-risk, transparency and minimal risk, plus GPAI rules and borderline cases.

← Back to the blog