Let’s talk
Wondering how this plays out in your organisation? Get in touch — I answer personally.
Short answer
The AI literacy obligation in Article 4 of the AI Act is described through measures, not through a level reached by particular individuals. It binds providers and deployers within the meaning of Article 3(3) and (4) of the Regulation. A deployer is anyone using an AI system under its authority other than in the course of a personal non-professional activity. They are to take measures that support the development of AI literacy among their staff and other persons acting on their behalf. The obligation has applied since 2 February 2025 and was not caught by the July deferral of the requirements for high-risk systems. The provision carries no evidentiary rule of its own, so in my assessment it is demonstrated by describing the measures taken and justifying their selection.
Why this question arises at all
The AI literacy obligation in Article 4 is short and contains no procedure of its own. It indicates neither a form, nor a frequency, nor a document to prepare. Organisations read it in two opposite ways. Some treat the obligation as a declaration without content, others translate it into recurring training with a final test.
The second source of confusion is the calendar. The obligation has no transitional period and has applied since February 2025. The July package moved the requirements for high-risk systems and two new prohibitions under Article 5, and did not move the date of this provision.
The third source is the most recent. The amending regulation of July 2026 rewrote the whole of Article 4. Commentary based on the original wording describes the obligation more strictly than the text in force warrants.
What has to be established before a decision
What changed in July 2026
The original wording spoke of measures taken “to ensure, to their best extent, a sufficient level of AI literacy”. The point of reference was the level.
The wording in force speaks of measures “to support the development of AI literacy”. The point of reference is the action. The AI literacy obligation has therefore stopped being described by a level to be reached in particular individuals. The definition in Article 3(56) itself was left unchanged. The provision adds a decisive sentence, that this obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
The effect is evidentiary. An organisation does not have to show that a particular person reached a given level. In my assessment it must be able to show what measures it took and why it considered them adequate.
What AI literacy means under the Regulation
The definition sits in Article 3(56) and tends to be overlooked. AI literacy means skills, knowledge and understanding that allow an informed deployment of AI systems. The definition adds awareness of the opportunities and risks of AI and the possible harm it can cause. It covers providers, deployers and affected persons. It ties that literacy to their respective rights and obligations in the context of the Regulation.
The definition opens with the word “skills” and does not narrow them to operating a tool. In my assessment product training run by the provider does not on its own discharge the obligation, because it answers the question of how to operate the tool.
Whom the AI literacy obligation covers
The provision points to the staff of the provider or deployer and to other persons dealing with the operation and use of AI systems on their behalf. In my assessment the second limb covers contractors and subcontractors as well, because it is wider than an employment relationship.
Article 4(1) lists the circumstances for selecting measures in three groups. The first is the technical knowledge, experience, education and training of those persons. The second is the context the AI systems are to be used in. The third is the persons or groups of persons on whom the AI systems are to be used.
The third group tends to be overlooked and carries the most content. The same text assistant calls for different preparation in a marketing team and in a team handling job applicants’ cases. The difference is made by the recipient of the output, not by the tool.
The starting point is a register of uses, described in What should an AI use register contain?.
The Commission’s practical examples and the limit of a presumption of compliance
Article 4(2) requires the Commission and the Member States to support and facilitate the efforts of providers and deployers, in particular SMEs. For that purpose the Commission publishes practical examples on the single information platform.
The Commission maintains a repository of practices collected in two rounds, more than forty initiatives in all. The first covered AI Pact pledgers, the second was open to any interested organisation. The Commission announces that it will leverage the repository for the publication under Article 4(2).
The repository has a clear limit, however. Replicating the practices collected in it does not automatically grant a presumption of compliance with Article 4. The document says so expressly, so the Commission’s example is a point of reference rather than a list to tick off.
Article 4(3) adds recommendations of the Board, that is the European Artificial Intelligence Board, adopted taking into account European competence frameworks. In my assessment neither source creates an obligation, but both set out what the authorities will expect.
Why the absence of Article 4 from the catalogue of fines settles nothing
Article 99(4) lists the obligations covered by an administrative fine. The list covers the obligations of providers, authorised representatives, importers and distributors. It also covers the obligations under Article 25(2) and (4) and the obligations of deployers under Article 26. It covers the requirements and obligations of notified bodies as well as the transparency obligations under Article 50. Article 4 appears in none of the points of that list.
The opening words of the paragraph describe the listed provisions in general terms, as provisions related to operators or notified bodies other than those laid down in Article 5. They close the list, however, with the words “any of the following provisions”. Article 99(1) is stronger still, requiring Member States to lay down rules on penalties and other enforcement measures applicable to any infringement of the Regulation by operators. In my assessment the mere absence of Article 4 from the list therefore does not settle that this obligation falls outside any penalty.
Polish law adds supervisory tools, but with a deferred start. Article 104(1) of the Polish Act on Artificial Intelligence Systems does not extend the basis for a fine to Article 4, it carries over the catalogue from Chapter XII of the Regulation. Its own domestic tools sit elsewhere.
Poland’s national supervisor is the Commission for the Development and Security of Artificial Intelligence, the AI Commission. Article 48(1) allows it to carry out an inspection of compliance with the Regulation and with the Act, subject to Article 2(2) of the Act. Article 61(1) allows the AI Commission to issue a warning to a party by way of a procedural decision, where there is a reasonable suspicion of an infringement and in the course of proceedings.
Article 62(1) requires a decision to be issued where the AI Commission finds an infringement of obligations under the Regulation or the Act by an entity referred to in Article 2(1), points (a) to (f), of the Regulation. The second condition is that no settlement under Chapter 5 of the Act has been concluded. Paragraph 2 requires the decision to contain measures ordering the effects of the infringement to be removed within 14 days of its service.
All four provisions sit in Chapters 3, 4 and 8 of the Act, and those enter into force three months after publication (Article 127, point 2). The Act was published on 27 July 2026, so the calculation gives 28 October 2026. Until that day the Act gives the AI Commission only its institutional basis. Article 5(1) and Article 6 sit in Chapter 2 and have applied since 11 August 2026. What is deferred are the procedural tools, from inspection and proceedings through to a warning and a decision with a fine.
Article 26(2) of the Regulation works separately and is addressed to the deployer of a high-risk AI system. It requires human oversight to be assigned to natural persons who have the necessary competence, training and authority, as well as the necessary support. Article 26(3) reserves the deployer’s freedom to organise its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider. It also states that the obligations under paragraphs 1 and 2 are without prejudice to other deployer obligations under Union or national law. In my assessment competence ceases there to be an obligation of due care and becomes a condition for admitting a person to the role. The provision applies from 2 December 2027 or from 2 August 2028. Article 113, third paragraph, point (c) separates systems under Annex III from those under Annex I.
An obligation of means against an obligation of result
Setting this against neighbouring regimes shows why a ready-made training programme does not carry over directly.
| Provision | What it requires | Exceptions and limits | Applicable from |
|---|---|---|---|
| Article 4 AI Act | from providers and deployers — measures supporting the development of AI literacy | the provision expressly excludes guaranteeing any specific level in particular individuals; it binds providers and deployers within the meaning of Article 3(3) and (4), and a deployer is anyone using an AI system under its authority other than in a personal non-professional activity | obligation from 2 February 2025, this wording from 27 July 2026 |
| Article 32(1)(d) GDPR | a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing | the list in points (a) to (d) is open (“including inter alia”) and applies “as appropriate”; measures are selected taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons | 25 May 2018 |
| Article 8d, point 4, of the Polish Act on the National Cybersecurity System (KSC) | from the head of the entity — ensuring that the entity’s personnel are aware of cybersecurity obligations and know the entity’s internal rules in that area | the addressee is the head of an essential or important entity, not the entity itself | 3 April 2026, with a 12-month deadline for implementation for entities meeting the criteria on that day |
Article 4 and Article 32(1) call for measures to be weighed. Article 8d, point 4, states its requirement categorically. In my assessment they also differ in what demonstrates compliance. Article 4 is demonstrated by a description of measures. Article 32(1)(d) is demonstrated by the result of testing and assessment. Article 8d, point 4, is demonstrated by the state of awareness among personnel. An organisation caught by all three regimes may combine the measures, but in my assessment it will not combine the evidence.
What the AI literacy obligation requires you to document
The provision carries no evidentiary rule of its own. In my assessment compliance is demonstrated by describing the measures rather than by measuring knowledge. Three elements make that up.
- A register of roles that come into contact with AI systems, with a description of what those systems affect.
- A description of the measures assigned to each role, from induction at deployment through to rules of use and consultation.
- The reasoning behind the selection, that is the answer to why those particular measures were considered adequate.
The third element tends to be omitted, and it is the one that distinguishes documentation from an attendance sheet. The scope and the form are matched to roles, which also covers training matched to roles and processes.
Remember
Training is one of the measures, not the content of the obligation.
Common mistakes
- Assuming the AI literacy obligation requires a specific level of literacy. The provision states expressly that it does not.
- Quoting the original wording of Article 4. A different wording has applied since July 2026, and commentary based on the 2024 text describes the obligation more strictly.
- Narrowing the circle to employees. The provision also covers persons acting on the organisation’s behalf on another basis.
- Treating the provider’s product training as discharging the obligation. In my assessment that is not enough, because the definition in Article 3(56) also speaks of awareness of opportunities, risks and possible harm.
- Treating the Commission’s repository as a list to tick off. Replicating a practice does not automatically grant a presumption of compliance.
- Postponing the subject to 2027. The obligation has applied since February 2025, and the July deferral covered the requirements for high-risk systems and two new prohibitions under Article 5.
Conclusions and next steps
The AI literacy obligation is the simplest one in the AI Act and at the same time the one most often misread. It calls for no certification programme and no measurement of knowledge. It calls for a deliberate matching of measures to roles and to the people whom the systems’ outputs affect. An organisation that does this also prepares, along the way, for the requirement under Article 26(2).
Five steps that set this area up in an organisation.
- Establish in which roles people come into contact with AI systems today.
- Add to each role what the system in question affects and whom its outputs concern.
- Check whether those persons include contractors from outside an employment relationship.
- Match the measures to the roles, separating tool induction from awareness of risks and limits.
- Record the reasoning behind the selection, because it is that reasoning which evidences the measures taken.
Return to this register at every new deployment. A new use changes the context and the circle of recipients, and literacy ages together with the tools.
Related materials
- Who is responsible for AI Act transparency obligations? — the transparency obligation applicable from 2 August 2026, with 2 December 2026 as the deadline for bringing older generative systems into line with Article 50(2).
- When does an organisation using AI become the provider of a system? — the role that settles the remaining obligations.
- What should an AI use register contain? — the register from which the selection of measures starts.
- Who else needs NIS2 training besides the management board? — the same question about the circle of persons in the cybersecurity regime.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), consolidated version as at 27 July 2026 — Article 3(56), Article 4, Article 26(2) and (3), Article 99(1) and (4), Article 111(4) and Article 113 — eur-lex.europa.eu (dostęp: 13.09.2026).
- Regulation (EU) 2024/1689, version as published — original wording of Article 4 — eur-lex.europa.eu (dostęp: 13.09.2026).
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 — new wording of Article 4 — eur-lex.europa.eu (dostęp: 13.09.2026).
- Regulation (EU) 2016/679 (GDPR), consolidated version — Article 32(1)(d) — eur-lex.europa.eu (dostęp: 13.09.2026).
- Act of 5 July 2018 on the National Cybersecurity System, consolidated text — Article 8c(1) and Article 8d, point 4 (in Polish) — isap.sejm.gov.pl (dostęp: 13.09.2026).
- Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — Article 33(1) and Article 49 (in Polish) — isap.sejm.gov.pl (dostęp: 13.09.2026).
- Act of 3 July 2026 on Artificial Intelligence Systems (Journal of Laws 2026, item 1003) — Article 5(1), Article 6, Article 48(1), Article 61(1), Article 62(1) and (2), Article 104(1) and Article 127 (in Polish) — isap.sejm.gov.pl (dostęp: 13.09.2026).
- European Commission, Repository of AI literacy practices — digital-strategy.ec.europa.eu (dostęp: 13.09.2026).
Check who in your organisation uses AI today
The obligation follows roles, not departments. It starts, then, with establishing where AI systems already work. An AI use case review gives you the register on which the selection of measures and its reasoning can rest.
This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.
Legal status: September 2026.