Regulation & governance7 min read
AI Literacy Under the EU AI Act: What Article 4 Means
What the AI literacy requirement in Article 4 of the EU AI Act means for companies, who it covers, what good training includes and how to document it.
Published
Article 4 of the EU AI Act requires companies that provide or use AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and others who operate or use those systems on their behalf. It has applied since 2 February 2025 and is not limited to high-risk AI: a company whose employees use a general AI assistant at work is covered. The Act does not prescribe a specific course or certificate. What counts as sufficient depends on people's existing knowledge, their role and the context in which AI is used. In practice, that means role-based training on how the tools work, where they fail, the company's rules, and when to escalate, plus a record of what was done.
This article is general information, not legal advice. Guidance from the European Commission and national authorities on AI literacy continues to develop, and changes to the framing of the obligation have been discussed at EU level. Check the current consolidated text and official guidance.
What the law says, in plain terms
The key elements of Article 4:
| Element | Meaning |
|---|---|
| Who must act | Providers and deployers of AI systems |
| Who must be literate | Their staff and other persons dealing with the operation and use of AI systems on their behalf, such as contractors |
| What is required | Measures to ensure, to their best extent, a sufficient level of AI literacy |
| What sufficient depends on | Technical knowledge, experience, education and training of the people; the context of use; the persons or groups affected |
The Act defines AI literacy broadly as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause.
Who is covered
If your company uses AI systems in a professional context, you are a deployer. That includes:
- employees using AI assistants for drafting, research or summarising,
- AI features in software you use, such as CRM, office, HR or accounting tools,
- AI systems you have built or integrated, such as chatbots or document automation.
If you develop AI systems and place them on the market or put them into service under your name, you are a provider, and the same requirement applies to your staff involved.
The EU AI Act deployer obligations article explains the provider and deployer roles in more detail.
What a sufficient level looks like
There is no single standard, so think in terms of roles. A reasonable approach distinguishes at least three groups:
| Group | Typical people | What they need to understand |
|---|---|---|
| All users | Anyone using AI tools at work | What AI can and cannot do, hallucinations, data rules, approved tools, checking outputs, where to ask |
| Power users and reviewers | People who use AI daily, write prompts, review outputs, or oversee automated processes | Prompting techniques, systematic review, recognising failure patterns, escalation, documentation |
| Decision-makers and owners | Managers, process owners, IT, compliance | Risk categories, legal obligations, vendor assessment, governance, incident handling |
People involved with high-risk AI systems, especially those assigned to human oversight, need deeper, system-specific training on that system's capabilities, limits and correct use.
Core topics for a basic AI literacy programme
1. How generative AI works, at a useful level
- AI models predict likely text; they do not look up truth.
- Output can be fluent and wrong.
- Quality depends on the instructions and the context provided.
- Models have knowledge cut-offs and do not know your company's internal information unless it is provided.
2. Limits and risks
- Hallucinations: invented facts, figures and sources. See how to reduce AI hallucinations for practical techniques.
- Bias: outputs may reflect biases in training data.
- Over-reliance: the tendency to accept AI output without enough scrutiny.
- Prompt injection: instructions hidden in documents or web pages can manipulate AI tools.
- Inconsistency: the same prompt can produce different answers.
3. Company rules
- Which tools are approved for what.
- What data may and may not be entered.
- Review requirements before outputs are used.
- Uses that are prohibited or need approval.
- How to report problems.
These rules usually live in an AI policy. Our guide to writing an AI acceptable use policy includes an outline and a one-page summary you can use in training.
4. Using AI well
- Writing clear prompts with task, context, format and rules. The prompt engineering guide is a good basis.
- Checking outputs efficiently.
- Knowing when not to use AI.
5. Regulation and accountability
- The basic risk categories of the AI Act. EU AI Act risk categories explained gives an overview.
- Why some uses, such as evaluating job applicants, need special care.
- Who in the company is responsible for AI questions.
Formats that work
AI literacy does not have to mean long courses. Effective formats include:
- Short live sessions with real examples from your own work, including examples of AI getting things wrong.
- Hands-on exercises: improve a weak prompt, find the errors in an AI-generated summary, decide whether data may be entered into a tool.
- Quick reference cards with the data rules and approved tools.
- Onboarding modules for new employees.
- Refreshers when tools, rules or use cases change.
- Peer champions in each team who help colleagues and collect questions.
Training that uses your actual tools and tasks is usually more effective than generic material.
Documenting your measures
The AI Act does not prescribe a specific form of documentation for AI literacy, but being able to show what you did is sensible. A simple record could include:
| Field | Example |
|---|---|
| Measure | "AI basics session for all staff" |
| Target group | All employees using AI tools |
| Content | Topics covered, materials used |
| Date and duration | |
| Participants | List or count |
| Trainer or source | Internal, external provider |
| Next review |
Keep materials and attendance records together with your AI policy and your inventory of AI tools and use cases.
A practical 30-day plan
| Week | Action |
|---|---|
| 1 | Inventory AI tools and use cases; identify who uses what |
| 1 | Define target groups and what each needs |
| 2 | Finalise or update the AI use policy and data rules |
| 2–3 | Run a basic session for all users; hand out a reference card |
| 3–4 | Run deeper sessions for power users, reviewers and owners |
| 4 | Document measures, collect questions, set a review date |
Small companies can compress this considerably. The point is to start with the basics for everyone and go deeper where responsibility is greater.
Linking literacy to other obligations
AI literacy supports other parts of the AI Act and good practice generally:
- Human oversight of high-risk systems requires people with the competence and training to do it.
- Transparency duties require staff to know when disclosure is needed, for example for deepfakes.
- Avoiding prohibited practices requires managers to recognise where the lines are.
It also has business value beyond compliance: trained staff get better results from AI tools and make fewer costly mistakes, which shows up in the time savings you can measure with the AI ROI calculator.
Common mistakes
- Assuming it only applies to high-risk AI. Article 4 applies to all providers and deployers.
- One generic e-learning for everyone. Needs differ by role and context.
- Only theory. Without hands-on practice with your own tools, behaviour rarely changes.
- No record. Without documentation, it is hard to show what you have done.
- One-off training. Tools and rules change; plan refreshers.
- Forgetting contractors and temporary staff who use AI on your behalf.
Summary
AI literacy under the EU AI Act means making sure the people who use AI on your behalf understand it well enough for their role: what it does, where it fails, what the rules are and when to escalate. Start with an inventory, train by role, use real examples, keep a record and update regularly. To see which of your AI uses may need deeper training because of their risk level, try the EU AI Act risk checker.
FAQ
What does Article 4 of the EU AI Act require?
It requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with AI systems on their behalf, taking into account their knowledge and the context of use.
Since when does the AI literacy requirement apply?
Article 4 has applied since 2 February 2025. The EU has discussed changes to how this obligation is framed, so check the current consolidated text for the latest position.
Is a certificate required for AI literacy?
The AI Act does not prescribe a specific certificate or course. Companies decide which measures are appropriate. Keeping a record of what training was provided, to whom and when is good practice.
Does AI literacy apply if we only use ChatGPT or similar tools?
Yes. Using AI systems in a professional context makes you a deployer, and the literacy requirement applies regardless of the risk level of the system.
Related articles
Regulation & governance9 min read
EU AI Act for Deployers: What Businesses Must Do
EU AI Act obligations for deployers: AI literacy, transparency duties, high-risk use rules, when a user becomes a provider, and a practical checklist.
Regulation & governance9 min read
EU AI Act Risk Categories Explained With Examples
The four EU AI Act risk categories explained with business examples: prohibited, high-risk, transparency and minimal risk, plus GPAI rules and borderline cases.
Regulation & governance8 min read
How to Write an AI Acceptable Use Policy for Your Team
How to write an AI acceptable use policy: the sections to include, a copyable outline, a traffic-light data rule, rollout steps and mistakes to avoid.