EN
Book a discovery call

EU AI Act AI Literacy: What Employers Must Do (and How to Prove It)

Article 4 of the EU AI Act has required AI literacy measures since 2 Feb 2025. What employers must do, what to document, and what the 2026 changes mean.

Typographic cover reading 'EU AI Act AI Literacy: What Employers Must Do' on a dark lab-grid background
On this page
  1. What Article 4 actually says
  2. What employers should do: a six-step plan
  3. Enforcement and fines: what’s known
  4. Common mistakes
  5. Is this worth doing beyond compliance?
  6. Next step

The AI Act AI literacy rule (Article 4 of Regulation (EU) 2024/1689) has applied since 2 February 2025. It requires every organisation that provides or uses AI systems in the EU to take measures to build the AI literacy of its staff and others using AI on its behalf, proportionate to how AI is used. In practice that means: know which AI tools people use, train them for their role and risks, and keep an internal record that you did.

This article is a practical summary, not legal advice. For your specific situation, check with a lawyer or your data protection officer.

What Article 4 actually says

Article 4 applies to two groups:

  • Providers: organisations that develop an AI system or place it on the market.
  • Deployers: organisations that use an AI system under their authority in a professional context.

If your team uses ChatGPT, Microsoft Copilot, an AI note-taker in meetings or an AI feature inside your CRM for work, you are a deployer. Company size doesn’t exempt you, and neither does the fact that the tool is someone else’s.

The obligation covers your staff and “other persons dealing with the operation and use of AI systems on their behalf.” According to the European Commission’s AI literacy Q&A, that can include contractors and service providers working for you.

The 2026 update: from “ensure” to “support”

The original text required organisations to take measures to ensure, to their best extent, a sufficient level of AI literacy. The Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, rewrote Article 4. Providers and deployers must now “take measures to support the development of AI literacy” of their staff and others acting on their behalf, taking into account their knowledge, experience, training and the context of use. The amended text makes clear that you don’t have to guarantee a specific literacy level for each person.

Read that carefully. It’s softer on outcome, not on effort. You still have to take measures, and you still need to show what they were. If someone in your company causes harm with an AI tool and you have nothing on file, “the rule got softer” won’t help much.

What employers should do: a six-step plan

1. Map who uses which AI, for what

Make a simple inventory: tool, team, purpose, what data goes in, who approved it. Include the AI features hidden inside software you already pay for. Most companies discover more AI use than they expected, including personal accounts used for work.

2. Group people by role and risk

Not everyone needs the same training. A sensible split:

Group Typical use Training focus
All staff Occasional chat assistants, AI in office tools What AI is, limits, hallucinations, data rules, company policy
Heavy users Daily drafting, analysis, customer replies Prompting, verification, bias, confidentiality, when to escalate
Builders and admins Configure agents, automations, integrations Data protection, access control, testing, monitoring, vendor terms
Managers and decision makers Approve tools, rely on AI outputs Risk, accountability, AI Act basics, procurement questions

3. Write a short AI use policy

Two pages beat twenty. Cover approved tools, what data must never go in, when a human must check outputs, how to label AI-generated content where needed, and who to ask. Training without a policy leaves people guessing; a policy without training stays unread.

4. Deliver training that matches the use

The Commission’s Q&A suggests covering a general understanding of AI, the organisation’s role (provider or deployer), and the risks of the specific systems used, adapted to people’s knowledge and context. In practice: short sessions on the actual tools your team uses, with your own examples, beat a generic video course. Hands-on work on real tasks also gets more adoption, which is the business case on top of the compliance one. If your team runs on Microsoft 365, see Copilot training for teams.

5. Document it

The European Commission’s Q&A states that no certificate is needed and that an internal record of trainings and other guidance initiatives is sufficient. A good record includes:

  • The AI inventory and the date it was last reviewed
  • The AI use policy and version history
  • Training sessions: date, topic, audience, materials, attendance
  • Onboarding steps for new hires and contractors
  • Any incident or near miss, and what changed afterwards
  • The person responsible for keeping all this current

That fits in one shared folder. You don’t need new software for it.

6. Repeat when things change

New tool, new use case, new team, new hire: update the inventory and train the people affected. A yearly refresh is a reasonable default for everyone else.

Enforcement and fines: what’s known

The Commission’s Q&A says supervision and enforcement rules apply from 3 August 2026, through national market surveillance authorities. The AI Act doesn’t set a specific fine for Article 4; penalties are left to Member State rules, and the Commission stresses that any sanction must be proportionate and case-specific. It also notes enforcement is more likely where there’s proof of an incident caused by a lack of appropriate training.

Our reading: the realistic risk for most companies isn’t a random audit. It’s an incident, such as client data pasted into a consumer chatbot or an AI-drafted answer sent unchecked, followed by the question “what did you do to prevent this?” Your records are your answer. Your national authority may publish its own guidance, so check it.

Common mistakes

  • Treating it as a one-off webinar. A single session in 2025 with no record and no follow-up won’t show much.
  • Training only IT. The people pasting data into chatbots are usually in sales, HR, finance and support.
  • Ignoring contractors. If they use AI on your behalf, they’re in scope.
  • Generic content. A course about AI history doesn’t help someone decide whether to paste a client contract into a chatbot.
  • No policy behind the training. People need clear rules to apply what they learned.
  • Buying the expensive license and skipping the training. You pay for the tool and get neither the productivity nor the paper trail. If you’re choosing plans, see ChatGPT Team vs Enterprise.

Is this worth doing beyond compliance?

Yes, and that’s the honest pitch. Teams that understand what AI is good and bad at use it more, and more safely. Compliance gives you the deadline; productivity gives you the return. If you’re planning a broader rollout, how to implement AI in your business covers the next steps.

Next step

We run practical AI training for teams: role-based sessions on the tools your people already use (ChatGPT, Copilot, Claude), a short AI use policy, and an attendance and materials record you can file as evidence of your Article 4 measures. Scope and price are a custom quote. Book a discovery call to plan your programme.

FAQ

Questions merchants ask

When did the AI literacy obligation start?

Article 4 of Regulation (EU) 2024/1689, the AI Act, has applied since 2 February 2025. According to the European Commission's AI literacy Q&A, supervision and enforcement by national market surveillance authorities apply from 3 August 2026.

Does every company using ChatGPT or Copilot have to train staff?

If your organisation uses AI systems in a professional capacity, you are a deployer, and Article 4 applies to you whatever your size. The measures should be proportionate to how you use AI, so a light-touch use needs a lighter programme.

Do employees need an AI literacy certificate?

No. The European Commission's Q&A says no certificate is required and that an internal record of trainings and other guidance initiatives is enough.

What changed with the Digital Omnibus on AI?

Regulation (EU) 2026/1744, in force since 27 July 2026, rewrote Article 4. Providers and deployers must now take measures to support the development of AI literacy, instead of ensuring a sufficient level. The duty to act remains.

What are the fines for not complying with Article 4?

The AI Act does not set a specific fine for Article 4. Penalties are left to national rules, and the Commission's Q&A stresses proportionality. Treat it as a duty you must be able to show you met, especially if an incident happens.