AInora
EU AI ActAI LiteracyRegulationAI Training2026

EU AI Act Article 4: What the AI Literacy Rule Actually Requires

JB
Justas ButkusFounder, Ainora
··20 min read

Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures to support the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. Since 27 July 2026 the same Article states expressly that this obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual. There is no mandated training format, no exam, no certificate, no required governance structure and no set number of hours, and Article 4 has never appeared in the AI Act’s own fine schedule at Article 99(4).

Published 5 September 2026. Last updated 5 September 2026, the date on which every source cited below was fetched and read at primary source.

Why this page exists

A large share of the material circulating about AI literacy still quotes the 2024 wording and tells readers that the AI Act obliges them to train their staff or face fines of up to 15 million euro. Neither half of that survives contact with the current text. The verb changed in July 2026, and Article 4 has never been listed in the fine schedule that the 15 million euro figure belongs to. The same July 2026 Regulation did open one narrow route to a fine at that level, for a small and precisely defined set of operators supervised directly by the Commission’s AI Office, and the fines section below sets out who that is and who it leaves out. This page is built on the texts published on EUR-Lex, the European Commission’s own AI literacy Q&A, and the framework documents those texts name. It is general information, not legal advice.

2 Feb 2025
the date from which Article 4 has applied, as part of Chapters I and II, never suspended
Source: Regulation (EU) 2024/1689, Art. 113
27 Jul 2026
the date the softened wording of Article 4 entered into force
Source: Regulation (EU) 2026/1744
Art. 99(4)
the fine schedule lists Articles 16, 22, 23, 24, 25(2) and (4), 26, 31, 33, 34 and 50. Article 4 is not among them
Source: Regulation (EU) 2024/1689, Art. 99, as amended
19 pp
drop in the likelihood of a correct solution when AI was used on a task outside its capability frontier
Source: Dell’Acqua et al., HBS WP 24-013

What does Article 4 require today?

The AI literacy duty sits in Article 4 of Regulation (EU) 2024/1689, the EU AI Act. Article 4 is the last article of Chapter I, and under Article 113 of the Regulation, Chapters I and II apply from 2 February 2025. The obligation has been live since that date. It has never been suspended and it has never been postponed.

On 8 July 2026 the European Parliament and the Council adopted Regulation (EU) 2026/1744, the Digital Omnibus on AI. It was published in the Official Journal on 24 July 2026 and, by its own final article, entered into force on the third day following publication, which is 27 July 2026. Article 1(5) of that Regulation reads “Article 4 is replaced by the following” and sets out a new text.

The distinction that matters most here is easy to get wrong. Article 4 was not delayed. It was softened in place. The same Regulation did postpone other things: Article 1(40) rewrote the third paragraph of Article 113 so that Chapter III, Sections 1, 2 and 3 now apply from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for those under Article 6(1) and Annex I. Chapters I and II, which contain Article 4, kept the 2 February 2025 date untouched. Because both changes travelled in one instrument, they are frequently reported as one. They are not.

It is also worth checking which edition of Article 4 you are reading. Widely used unofficial collections of the AI Act update at different speeds and currently disagree with each other: some serve the amended text without marking that it changed, and some still carry the wording repealed in July 2026. The authentic text is on EUR-Lex.

The old and new wording, side by side

The whole change turns on one verb and one added sentence. Here is the original Article 4, which applied from 2 February 2025 until 26 July 2026:

“Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.”

And here is Article 4(1) as it has read since 27 July 2026:

“Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.

Article 4 also gained two paragraphs that put work on the institutions rather than on companies: paragraph 2 has the Commission and Member States support providers and deployers, in particular SMEs, and publish practical examples of compliance on the single information platform in Article 62(3), point (b), while paragraph 3 tasks the AI Board with adopting recommendations.

QuestionUntil 26 July 2026From 27 July 2026
The operative verbensure, to their best extentsupport the development of
Is a level of literacy specified?a sufficient levelno level named
Must an individual’s level be guaranteed?the text was silentexpressly not required
Date of application2 February 20252 February 2025, unchanged
Listed in the Article 99(4) fine tier?NoNo
Duty on the Commission and Member Statesnone in Article 4support and facilitate, publish examples

Recital 8 of the amending Regulation explains the reasoning, and it is unusually direct for a legal text. It records that stringent obligations to ensure a sufficient level of AI literacy “would not be suitable for all types of providers and deployers”, that they create “an additional compliance burden, particularly for smaller enterprises”, and then adds the line worth remembering: “AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions.” The legal floor was lowered precisely because the EU takes the view that the activity stands on its own merits.

Is there a fine for not supporting AI literacy?

For most organisations, not at EU level. Article 99(4) of the AI Act sets administrative fines of up to 15 million euro, or up to 3 percent of total worldwide annual turnover, whichever is higher, and it does so by enumerating the provisions it applies to: obligations of providers under Article 16, of authorised representatives under Article 22, of importers under Article 23, of distributors under Article 24, of providers and operators under Article 25(2) and (4), of deployers under Article 26, requirements for notified bodies under Articles 31, 33(1), (3) and (4) and 34, and the transparency obligations of providers and deployers under Article 50. The Article 25 entry is the newest one: Article 1(38)(b) of Regulation (EU) 2026/1744 inserted it as point (da), “obligations of providers and operators pursuant to Article 25(2) and (4)”, and it covers the value-chain duties, the initial provider’s duty to cooperate with a new provider and the written agreement between a high-risk provider and the third parties supplying it. Article 4 does not appear on that list, before or after the amendment. The higher band of up to 35 million euro or 7 percent, in Article 99(3), applies to the prohibited practices in Article 5 and to nothing else.

There is, however, a second door to a fine of that size, and material that stops at the Article 99(4) list walks straight past it. The same Regulation inserted four new articles into the AI Act, one of which is Article 75c, on non-compliance, fines and periodic penalty payments by the AI Office. Its paragraph 4 allows a non-compliance decision to be accompanied by penalties under Article 99(3) to (7), and then says that the following “shall be subject to administrative fines as referred to in Article 99(4)”, point (a) being: “infringement of any applicable provision of this Regulation, including those not listed in Article 99(4)”. Article 4 is an applicable provision of the Regulation. So for the operators the AI Office supervises, the Article 99(4) list is not the outer boundary of the Article 99(4) fine level. Article 75c sits in Chapter IX and therefore applies from 2 August 2026.

Everything then turns on which operators those are, and the answer is narrow and written down. Article 1(31)(b) of the same Regulation replaced Article 75(1), which now gives the AI Office exclusive competence over two categories of AI system: systems based on general-purpose AI models “where the model and the system are developed by the same provider, or by providers forming part of the same undertaking as that provider”, and systems that constitute or are integrated into a very large online platform or very large online search engine designated under the Digital Services Act. Four carve-outs sit inside the first category, for systems related to products under the Annex I harmonisation legislation, systems in point 2 of Annex III, systems provided by law enforcement authorities, border management authorities and financial institutions insofar as they fall under Article 74(6), and the Annex III point 8 systems concerning the administration of justice.

The sentence that decides it for almost every reader is the last one in that paragraph: “The exclusive competence referred to in the first subparagraph shall apply to the providers of those systems. It shall apply to the deployers of those systems only when they are also the provider or form part of the same undertaking as the provider.” Recital 31 of the amending Regulation says the same thing in plainer words: “The personal scope of this exclusive competence should extend to the providers of those AI systems and to their deployers within the same undertaking. Other deployers should remain subject to national supervision and enforcement.”

Read together, the Article 75c(4)(a) route reaches the organisation that builds a general-purpose model and ships the system on top of it, the operator of a designated very large platform or search engine that is or embeds an AI system, and companies inside the same corporate undertaking as one of those providers. It does not reach a company that subscribes to an assistant somebody else built and lets its staff use it at work. That company is a deployer of a system provided by another undertaking, it is not the provider and not part of the provider’s undertaking, and it stays with its national market surveillance authority. If you are on this page to work out your own exposure and your organisation uses AI systems that other people build, the AI Office is not your supervisor and Article 75c is not your provision. Nothing here converts Article 4 into a 15 million euro risk for an ordinary deployer.

What applies to everyone outside that circle is Article 99(1), which the July 2026 Regulation also rewrote. Member States lay down their own rules on penalties and other enforcement measures, “which may also include administrative fines, warnings and non-monetary measures”, applicable to any infringement of the Regulation by operators. The penalties “shall be effective, proportionate and dissuasive”, and “The Member States shall take into account the interests of SMEs, including start-ups, and SMCs, and their economic viability when imposing penalties.” Both changes are worth noticing: administrative fines are now named on the face of the paragraph instead of being left to inference from the words that follow, and the protective clause was widened to small mid-cap enterprises and tied to the moment a penalty is imposed. A companion amendment added Article 99(6a), which caps each fine for an SMC at the lower of the percentage or the amount. The honest answer to “what is the fine” for an ordinary deployer is still that it depends on national penalty law, and that any single euro figure quoted for Article 4 across the EU is quoting something that does not exist.

One point is genuinely unresolved, and it is better to leave it open than to pick a side. The Commission’s Q&A, in its revision of 27 July 2026, states flatly that “The supervision and enforcement of Article 4 of the AI Act is not with the AI Office, but it is under the remit of national market surveillance authorities”, and does not qualify that for operators inside Article 75(1). The text of Article 75(1), in force from the same month, gives the AI Office exclusive competence for “the supervision and enforcement of the obligations under this Regulation” in relation to those systems, and Article 4 is one of the obligations under that Regulation. Whether the AI Office would in practice treat an Article 4 failure by an operator in its own remit as within Article 75c, or continue to leave Article 4 to national authorities across the board, has not been settled by guidance or by any published decision. The two texts can be read together and they can be read against each other, and until something resolves it, anyone in that narrow category should assume the question is live rather than closed.

None of this makes Article 4 a recommendation. It is a binding obligation in a directly applicable Regulation, for providers and deployers alike. What the EU legislator did not do is put it on the harmonised fine schedule.

What does enforcement realistically look like?

For the ordinary deployer, supervision does not sit with the Commission’s AI Office. The Commission’s Q&A is explicit: “The supervision and enforcement of Article 4 of the AI Act is not with the AI Office, but it is under the remit of national market surveillance authorities.” The rest of this section describes that national route, which is the one almost every reader is on. The narrower AI Office remit under Article 75(1), and the question it leaves open, are set out in the fines section above.

On the date supervision begins, the Commission’s own page contradicts itself, and it is better to say so than to pick a day and sound certain. In the same revision, dated 27 July 2026, one answer reads “The supervision and enforcement rules apply from 3 August 2026 onwards” while another says national market surveillance authorities “will start supervising and enforcing the rules as of 2 August 2026”. The Regulation resolves it: Article 113 states “It shall apply from 2 August 2026” and lists the exceptions to that date. Chapter IX, which covers post-market monitoring, information sharing and market surveillance, is not among them, so it applies from 2 August 2026. That is the date used here, with the discrepancy noted rather than smoothed over.

How supervision is described by the Commission

On consequences, the Q&A says that national market surveillance authorities “could impose penalties and other enforcement measures to sanction infringements of Article 4”, based on national laws, and then stresses proportionality: “Any sanction must be proportionate, based on the individual case and take into account factors such as nature and gravity and the intentional and negligent character of the infringement.” The sentence that follows is the practically important one: “This might, however, be more likely if there is proof of an incident due to lack of appropriate training and guidance of employees or other persons.” In other words, the realistic exposure is not a routine inspection of a training register. It is what surfaces after something goes wrong and the cause traces back to somebody not knowing what to avoid.

Source: European Commission, AI literacy Q&A

Two further limits are worth stating plainly. First, whether a Member State has actually attached a penalty to Article 4 is a national question, and national penalty regimes were not uniformly complete. In Lithuania the market surveillance authority is the Communications Regulatory Authority (RRT), which publishes guidance for AI operators, while the national implementing law setting out liability for infringements was still moving through the legislature. The Lithuanian position is set out in the companion to this article, ES DI aktas ir raštingumas DI srityje. Second, private enforcement is narrow: the Q&A states that “The AI Act doesn’t create criminal offences or a right to compensation.”

Who is bound, and who counts as acting on your behalf?

Article 4 binds providers and deployers of AI systems, which is narrower than “every company”. Under Article 3(4) a deployer is “a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity”. A provider, under Article 3(3), develops an AI system or has one developed and places it on the market or puts it into service under its own name or trademark. If your organisation does not build or commission AI systems and only uses systems built by someone else in the course of its business, the role you hold is deployer, not provider. If it does both, it holds both roles for the respective systems.

That definition is broad enough to catch ordinary office use, and the Commission answered the case directly rather than leaving it to inference. Asked whether a company whose employees use ChatGPT for, for example, writing advertisement text or translating text needs to comply with Article 4, the Q&A answers: “Yes, they should be informed about the specific risks, for example hallucination.” Note the shape of that answer. It is not a requirement to run a course. It is a requirement that the person knows an answer can be fluent and wrong at the same time.

The phrase “other persons dealing with the operation and use of AI systems on their behalf” reaches beyond the payroll. The Commission glosses it as: “these are not employees, but persons broadly under the organisational remit. It could be, for example, a contractor, a service provider, a client.” Asked whether a service provider using AI should be contractually obliged to demonstrate AI literacy, it answers that this depends on the type of system and its risk, and that “in general, people working for a service provider or contractor need to have the appropriate AI skills to fulfil the task in question (same as the employees)”. An outsourced contact centre answering in your name, a freelance copywriter drafting your content or an agency running your campaigns therefore falls inside the same sentence as your own staff. On how those responsibilities are split with an outside partner, see our guide on GDPR and EU AI Act compliance in white-label AI voice.

Two more scoping points. The duty is extraterritorial, applying “to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union or its use has an impact on people located in the EU”, which the Q&A confirms holds for Article 4. And technical qualifications are not an automatic exemption: asked whether people with a degree or experience in AI development can be treated as AI literate without further action, the Commission answers “Normally yes, but it depends on the AI tool in question and their specific qualification.”

What does an AI literacy programme contain?

There are no Commission guidelines on Article 4. Unlike prohibited practices and the AI system definition, which each got a published guidelines document, Article 4 did not. The Q&A says so: “So far, practical guidance has been provided via informative material, such as webinars and this Q&A.” The Article 4(2) examples of compliance and the Article 4(3) Board recommendations are still to come. The only official “what to do” list is the four-part one in the Q&A itself.

1

Establish a general understanding of AI in your organisation

What is AI, how does it work, what AI is used in our organisation, and what are its opportunities and dangers? In practice this starts with an unglamorous inventory: which tools people actually use for work, including the ones nobody formally bought.

Source: European Commission, AI literacy Q&A
2

Determine your organisation’s role

Is the organisation developing AI systems, or only using systems developed by another organisation? The answer decides whether you are a provider, a deployer, or both, and the rest of the AI Act reads differently depending on which.

Source: European Commission
3

Assess the risk of the systems you provide or deploy

What do employees need to know when dealing with this particular system, which risks must they be aware of, and do they need to know how to mitigate them? A drafting assistant used on internal notes and a system that speaks to customers are not the same exposure.

Source: European Commission
4

Build your actions on that analysis

Take account of differences in technical knowledge, experience, education and training among staff and other persons, the context the systems are used in, and the people the systems are used on. The Commission confirms that differentiated levels of training or learning approaches can be appropriate.

Source: European Commission

One boundary is drawn firmly. The Q&A states that “in many cases, simply relying on the AI systems’ instructions for use or asking the staff to read them might be ineffective”, and that Article 4 “is intended to provide trainings and guidance as most appropriate on the basis of each target group’s technical knowledge, experience, education and training”. The Lithuanian regulator puts the same point more bluntly in its guidance for AI operators: relying on the user manual alone is not considered sufficient.

A second boundary protects you from a sales pitch. The AI Office maintains a living repository of AI literacy practices submitted by organisations, and it is useful reading. The caveat is not on the repository page itself but in the Commission’s AI literacy Q&A, which states that “at the moment replicating the practices collected in this living repository does not automatically grant presumption of compliance with Article 4”. Nothing there is EU-approved, and any programme sold as such is mislabelled.

A role-based map of who needs what

Step four is where the work lives, because it is the step that says one session for everybody is the wrong shape. The table below is our synthesis, not a prescribed curriculum. Each row is anchored either in the Commission’s four steps, in the EU’s digital competence framework, or, in the last row, in a separate provision of the AI Act.

WhoWhat they need to be able to doWhy this row exists
Everyone who uses a general assistant for workRecognise that output can be inaccurate while sounding plausible; know that the person sending the output owns its accuracy; know which systems are sanctioned hereCommission Q&A step (a), plus the hallucination answer on ordinary chatbot use
Customer-facing staffKnow when a person must be told they are dealing with an AI system, and how to hand over to a humanArticle 50 transparency duties sit on deployers as well as providers
Marketing and content teamsStructure a request, supply context, check claims against a source of record, and label AI-generated content where requiredDigComp 3.0 treats prompting as a competence with its own progression
Managers who approve tools and budgetsDecide whether a task suits AI at all before choosing a tool; know what a business account changes about data handlingStep (b) and step (c): the role and the risk assessment are management decisions
Legal, compliance and data protectionRead the current text of the obligations, distinguish Article 4 from Article 26 and Article 50, and keep the internal recordStep (d), and the fact that Article 4 changed in July 2026
Technical staff who build or integrateUnderstand where the organisation becomes a provider rather than a deployer, and what that switch addsArticle 3(3) and Article 16 obligations attach to providers
Contractors, freelancers and outsourced teams acting in your nameThe same understanding as the equivalent internal role, arranged contractuallyQ&A: contractors and service providers are inside the Article 4 wording
Anyone assigned human oversight of a high-risk systemCompetence, training and authority to intervene, plus the support to use itArticle 26(2), which was not softened and is a separate duty

The rows are deliberately written as capabilities rather than topics, because a topic list can be delivered and still leave nobody able to do anything differently on Monday. The first row is the one that reaches furthest and is the easiest to skip, because it looks too basic to schedule. It is also the row the Commission answered with a named example. One recurring question inside it is what happens to material people paste into a tool, which is a factual question whose answers differ by product and by account type: we keep a separately sourced page on it, does your AI vendor train on your data.

What belongs in the evidence file

The documentation question has a short official answer. Asked how organisations should document their actions and whether certificates are needed, the Commission replies: “There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives.” It adds that no specific governance structure is mandated, that neither an AI officer nor an AI governance board is required, and that “Article 4 of the AI Act does not entail an obligation to measure the knowledge of AI of employees.”

A sensible internal record is therefore not a certificate wall. It is the material that would let you show what you did and why, if you were asked after an incident:

  • An inventory of the AI systems actually in use, including the ones adopted informally by teams rather than procured centrally.
  • Your written answer to step (b): for each system, whether the organisation is acting as provider, deployer, or both.
  • Your step (c) notes: for each system, the risks staff need to know about, and where the output is checked before it leaves the building.
  • What was delivered, to whom, and when. Dates and attendee lists, not scores.
  • The materials themselves, versioned, so it is clear what people were actually told and when the guidance last changed.
  • The internal AI policy: what is permitted, what is not, who approves a new tool, and who to tell when something confidential was submitted by mistake.
  • A refresh cadence, with the date of the last review. The obligation names “the speed of the technological developments” as a reason qualifications do not settle the question permanently.
  • For high-risk deployments only: the named individuals assigned human oversight, and the record of their competence, training and authority under Article 26(2).

Two things are deliberately absent from that list: a pass mark and a certificate. Neither is required, and building a programme around them tends to produce a compliance artefact instead of a capable team.

Why run a programme when the legal floor is this low?

If the legal floor is this low, the honest question is why bother. The answer is not in the Regulation. It is in what happens when people use these systems without knowing where they work and where they do not.

The clearest evidence comes from a pre-registered field experiment with 758 consultants, published as Harvard Business School Working Paper 24-013. Participants were randomly assigned to no AI access, AI access, or AI access plus a short prompt-engineering overview. On a set of 18 realistic tasks within the capability frontier, those using AI completed 12.2 percent more tasks, completed them 25.1 percent more quickly and produced more than 40 percent higher quality than the control group, with the largest gains going to those who had been performing below average. On a task deliberately selected to fall outside that frontier, the same tool inverted the result: participants using AI were 19 percentage points less likely to produce a correct solution. In the underlying figures the control group was correct about 84.5 percent of the time, while the AI conditions scored 60 and 70 percent.

That figure is often repeated as “19 percent”. It is percentage points, and the distinction matters. The finding is not that AI is bad, but that the same tool in the same hands produces a large gain or a measurable loss depending on whether the task suits it. Telling those two cases apart is a learned skill, and it does not arrive with the licence.

The second support is institutional. On 27 November 2025 the Commission’s Joint Research Centre published DigComp 3.0, report JRC144121, the update of the European digital competence framework that supersedes the 2022 edition and integrates AI competence systematically across all areas. Its competence statement CS1.2.10 reads: “Recognise that AI systems may produce output which is inaccurate, even if it may seem plausible, and that the human using the AI system is responsible for checking the quality and validity of information and content generated.” That is an EU framework placing accountability on the individual using the tool. Box 3 of the same report records that of the 362 competence statements in DigComp 3.0, 50 are AI-explicit and 246 more are AI-implicit, and that AI features across all 21 competences. Those figures and the statement are in the report itself, not in the announcement that carried it.

What did not change: Article 26(2)

Only Article 4 was softened. A specific, unambiguous training duty survives elsewhere in the AI Act, and for the organisations it covers it is the stronger and more accurate thing to talk about. Article 26(2) is unchanged and reads in full: “Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.”

That applies to deployers of high-risk AI systems. The Commission connects the two provisions directly: “Article 26 introduces an obligation for deployers of high-risk systems to ensure that the staff dealing with the AI systems in practice is sufficiently trained to handle the system and ensure human oversight. Relying on the instructions of use is therefore not sufficient, further measures are necessary.” It also confirms this survived the amendment: for high-risk deployers, “the obligation to ensure that their staff is trained to ensure human oversight remains in place.” Note too that Article 26, unlike Article 4, is in the Article 99(4) fine tier. If your organisation uses AI in recruitment and CV screening, creditworthiness assessment, educational assessment or worker management, this is the provision to work from, and the corresponding obligations bite from 2 December 2027 under the revised timetable. Whether a given system lands in that category is its own analysis, which we walk through in are voice agents high-risk AI under the EU AI Act.

Keep Article 4 separate, too, from the AI Act’s disclosure duty, a different obligation with a different mechanism. Article 50 governs transparency towards the people interacting with a system, including telling a person they are dealing with an AI system, and it is in the Article 99(4) fine tier. Article 4 is about the capability of the people operating the system on your side. We cover disclosure separately in must AI callers identify themselves, in the broader EU AI Act and voice agents overview, in the EU AI Act compliance checklist for voice AI, and, for one regulated sector, in EU AI Act and debt collection compliance. Confusing the two is how a page ends up attaching an Article 50 fine figure to an AI literacy duty.

Outside the high-risk categories the accurate summary is the modest one. Article 4 asks you to take measures that support the development of AI literacy among the people using these systems on your behalf, proportionate to what they do and what the systems are used for. It does not set a level or demand a certificate, and it is not on the Article 99(4) fine schedule. The reason to do it well is that the cost of an untrained mistake is real and the cost of the training is not. If you want to move from the text to the work, our AI training for companies page describes how a programme is assembled around the roles a team holds and the systems it uses. And once more, plainly: this is general information, not legal advice. For your own situation, read the current texts or speak to a lawyer.

Frequently Asked Questions

Not in the form that phrase suggests. Since 27 July 2026, Article 4 requires providers and deployers to take measures to support the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. The same Article states that the obligation does not require them to guarantee any specific level of AI literacy of any individual. No format, exam or certificate is mandated. The European Commission does say that in many cases simply relying on the instructions for use, or asking staff to read them, might be ineffective.Source: Regulation (EU) 2026/1744, Art. 1(5)

For an ordinary deployer, there is no harmonised EU fine attached to Article 4. Article 99(4) of the AI Act, which sets the tier of up to 15 million euro or 3 percent of worldwide annual turnover, lists the provisions it covers: Articles 16, 22, 23, 24, 25(2) and (4), 26, 31, 33(1), (3) and (4), 34 and 50. Article 4 is not among them, and the Article 25 entry is itself a July 2026 addition. Penalties for Article 4 therefore come from national law under Article 99(1), which since July 2026 says expressly that national rules may include administrative fines, and they must be effective, proportionate and dissuasive. One narrow exception exists: under the new Article 75c(4)(a), the AI Office can impose fines at the Article 99(4) level for infringement of any applicable provision, including those not listed in Article 99(4). That reaches only operators inside the AI Office remit under Article 75(1), meaning providers of systems built on their own general-purpose models, providers of systems that are or are embedded in a designated very large online platform or search engine, and deployers within the same undertaking as those providers. All other deployers stay with national supervision.Source: Regulation (EU) 2026/1744, Art. 1(31), 1(32) and 1(38)

No. Regulation (EU) 2026/1744 postponed the high-risk rules, moving Chapter III Sections 1 to 3 to 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and to 2 August 2028 for those under Article 6(1) and Annex I. Chapters I and II, which contain Article 4, continue to apply from 2 February 2025. Article 4 was not postponed. It was rewritten in place, and the new wording has applied since 27 July 2026.Source: Regulation (EU) 2026/1744, Art. 1(40)

No. The European Commission answers directly that there is no need for a certificate, and that organisations can keep an internal record of trainings and other guiding initiatives. It also confirms that no specific governance structure is mandated, that neither an AI officer nor an AI governance board is required, and that Article 4 does not entail an obligation to measure employees’ knowledge of AI.Source: European Commission, AI literacy Q&A

Very likely. Article 3(4) defines a deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the system is used in a personal non-professional activity. The Commission addressed this case directly: asked whether a company whose employees use ChatGPT to write advertisement text or translate text must comply with Article 4, it answered yes, and said those employees should be informed about the specific risks, for example hallucination.Source: European Commission, AI literacy Q&A

Yes, where they act on your behalf. The wording covers staff and other persons dealing with the operation and use of AI systems on the provider or deployer’s behalf. The Commission explains that these are not employees but persons broadly under the organisational remit, giving a contractor, a service provider and a client as examples, and adds that people working for a service provider or contractor generally need the appropriate AI skills to fulfil the task in question, the same as employees.Source: European Commission, AI literacy Q&A

National market surveillance authorities, not the Commission’s AI Office. On the start date the Commission’s Q&A is internally inconsistent within one revision, saying both 3 August 2026 and 2 August 2026. Article 113 of the AI Act states that the Regulation applies from 2 August 2026 and lists its exceptions, and Chapter IX on market surveillance is not among them, which points to 2 August 2026. Whether a particular Member State has attached a penalty to Article 4 is a separate national question.Source: European Commission, AI literacy Q&A

Yes, in Article 26(2), which was not amended. It requires deployers of high-risk AI systems to assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. The Commission confirms that this duty remains in place and that relying on the instructions for use is not sufficient. Unlike Article 4, Article 26 is inside the Article 99(4) fine tier.Source: Regulation (EU) 2024/1689, Art. 26(2)

JB
Justas Butkus

Founder & CEO, AInora

Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.

View all articles

Ready to try AI for your business?

Hear how AInora sounds handling a real business call. Try the live voice demo or book a consultation.