Business and governance

The EU AI Act's AI literacy obligation, practically

Shared methods · A shared method; linked tool guides explain the exact steps.

In force since 2 February 2025. It covers your contractors too, no format is mandated, and the standard is proportionate rather than absolute.

Applies to
Shared methods
Last verified
Reviewed by
Timothy Fehr

Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures ensuring a sufficient level of AI literacy among their staff and anyone else operating AI systems on their behalf.

It has applied since 2 February 2025. If your organisation uses AI in the EU and has done nothing about this, the deadline is behind you.

What the obligation actually says

Three parts, and each is narrower or wider than people assume.

Who it covers. The text reaches beyond employees to "other persons dealing with the operation and use of AI systems" on your behalf: contractors, consultants, outsourced teams, agency staff. Organisations that scoped a training programme to permanent staff have scoped it too narrowly.

What "AI literacy" means. Skills, knowledge and understanding sufficient to make informed deployment decisions, and awareness of the opportunities, risks and possible harms. Notably: awareness of harms is part of the definition, not an optional extra.

How hard you must try. The standard is "to their best extent", which is a proportionality qualifier. You are not required to reach some defined literacy level regardless of practicability; you are required to take measures suited to the context, the systems in use, and what each group already knows.

Nobody will tell you what to do, and that is deliberate

This is the part organisations find most uncomfortable and it is the most useful thing to understand.

The AI Office, which coordinates enforcement, has published non-binding guidance, a Q&A and a living repository of literacy practices. It explicitly declines to impose mandatory training formats, prescribed durations or certification, calling instead for measures appropriate to each target group's existing knowledge and to the context and purpose of the systems in use.

So there is no certificate to buy that discharges the duty. Anyone selling one is selling reassurance. What you need is measures you can justify.

What defensible looks like

Since the format is yours to choose, the burden is showing your reasoning:

Segment by exposure. Someone pasting text into a chat tool, someone running an agent against a shared drive, and someone procuring an AI system need different things, and seniority does not predict which of the three a person is. An all-hands session treats them all alike, which inverts the proportionality argument it was meant to satisfy.

Cover the harms. The definition explicitly names awareness of risks and possible harms, so training that teaches prompt tricks while omitting confabulation, prompt injection and data handling has covered only the enjoyable half.

Include the contractors — see above; it is the commonest gap.

Write down what you did and why: which groups, what they received, and what judgement made that appropriate. Proportionality is only usable as a defence if you can show the reasoning behind the proportion you chose.

Then refresh it. Systems change, and a measure that suited last year's tools may suit nothing now. One session, once, does not leave an organisation in a standing state of literacy.

Where it sits in the wider timeline

Article 4 is among the earliest obligations to bite, which is why it catches people out: most AI Act attention has gone to high-risk classification and GPAI provider duties, both of which arrive later. Obligations for general-purpose AI model providers applied from 2 August 2025, and rules for systems in certain high-risk areas apply from 2 December 2027.

Most organisations reading this are deployers: they use AI systems, and do not place them on the market. Deployer duties are lighter, and Article 4 is among the few already in force for them.

What goes wrong

Assuming it does not apply because you only use a chat tool. The obligation attaches to any deployer of an AI system. There is no sophistication threshold below which it lapses.

Scoping training to employees. Contractors and consultants are named.

Buying a certificate. No format is mandated, so none discharges the duty. What gets assessed is whether your measures suited your situation.

Treating it as a training problem. Literacy includes knowing when not to use the system, and what it does with data. That is as much policy as teaching — see What data may go into a model.

Doing it once. Proportionate to context means the measure moves when the context moves.

A worked starting point, to adapt

Here is one shape "measures appropriate to the context" can take in a small organisation. Yours will differ: the whole point of a proportionality standard is that the proportion is yours to choose and to justify.

  1. List the AI systems actually in use. Including the ones nobody approved. You cannot size a measure against a system you have not admitted exists.
  2. List who touches each, grouped by exposure — job titles will mislead you here.
  3. Write one page per group: what the system does, what it gets wrong, what must never go into it, and who to ask.
  4. Record why that was appropriate for each group. This is the part that makes the proportion defensible, and the part people skip.
  5. Put a date on it and a trigger for revisiting — a new system, a new model, a new team.

That is a day of work rather than a programme, and it is a defensible beginning. Adapt the shape; the reasoning is the transferable part.

How to check

Take one real task from each group in the inventory. Have someone demonstrate how they check an output, handle material they cannot upload, and find the responsible contact. Record the gaps and update that group's material. Have the accountable owner check the proposed measures against the current official guidance; attendance alone does not show what a person can do.

Further reading

The AI Office's living repository of literacy practices is the closest thing to an official answer, and it is non-binding by design. The Commission's own framework page and the implementation timeline are the primary references for what applies when.

Sources

  1. AI Act implementation timeline — EU Artificial Intelligence Act Tier 3 2026-08-31
  2. Regulatory framework for AI — European Commission Tier 1 2026-08-31
  3. Code of Practice for General-Purpose AI Tier 3 2026-08-31