Since 2 February 2025, Article 4 of the EU AI Act applies. Providers and organisations that use AI systems must, to the extent possible, take measures to ensure that the staff concerned have a sufficient level of AI literacy. The requirement therefore does not only affect companies that develop AI. It also applies to organisations that use AI in their work.
Key milestones in the AI Act
- 1 August 2024: The AI Act entered into force.
- 2 February 2025: Article 4 on AI literacy began to apply. Since then, providers and organisations that use AI systems must take measures so that the staff concerned have a sufficient level of AI literacy.
- 2 August 2026: The main part of the AI Act begins to apply, including the transparency requirements in Article 50 for synthetic content. Member states were to have designated their national competent authorities by 2 August 2025.
- 2 December 2027: The requirements for high-risk systems under Annex III begin to apply. This includes AI in education, for example systems that determine admission, assess learning outcomes or monitor participants during exams. The date was moved here from 2 August 2026.
- 2 August 2028: Corresponding requirements for high-risk systems under Annex I, that is AI built into already regulated products.
The summer 2026 postponement and what it did not cover
In July 2026 the so-called Digital Omnibus package entered into force and deferred the obligations for high-risk systems: Annex III from 2 August 2026 to 2 December 2027, and Annex I to 2 August 2028. The announcement spread widely, and the conclusion many drew was that the AI Act as a whole had been postponed.
That is not correct. Article 4 on AI literacy was not affected by the postponement. It has applied since February 2025 and still applies. Nor were the transparency requirements in Article 50 moved. What was deferred were the requirements on the systems, not the requirements on the people who use them.
What does Article 4 actually say?
The requirement is simply expressed but broad and far-reaching: both providers and users of AI systems must, to the greatest extent possible, ensure that the people who work with the systems have sufficient AI literacy. What is sufficient depends on the person's technical knowledge, experience and education, and on the context in which the AI is used.
Examples of situations where Article 4 is relevant: a lawyer reviews AI-generated contract drafts, a recruiter uses AI support in selection, or a developer builds with AI tools. Roles with different responsibilities, knowledge and risks need different training.
Who is covered?
An organisation that uses AI systems is to be regarded as a so-called deployer, for example if tools such as Copilot, ChatGPT or other AI features are used in various business systems. Which measures are reasonable depends on the use, the risks and which roles work with the system.
What counts as sufficient training?
Article 4 does not set out a mandatory curriculum. The content of the training should instead start from the organisation's AI systems, the roles concerned and the actual risks. Structured work can for example cover:
- a basic understanding of generative AI and its limitations
- risks such as hallucinations, bias and gaps in information security
- GDPR and confidentiality when using AI
- situations where human control and review are required
- the organisation's internal guidelines, responsibilities and policies
The list is not an explicit detailed requirement in the regulation. It shows areas that often need to be addressed for the organisation to be able to describe, document and follow up its work on AI literacy.
Role-based, not generic
Everyone concerned needs a relevant baseline, but the content should be adapted to responsibility and use. Roles where AI affects decisions about people, personal data or business-critical processes may need particular scenarios, guidelines and deeper modules.
Documented
Document which needs you have identified, which measures you have chosen and how they are followed up. Completion data, knowledge checks and version history can provide a verifiable basis. xAPI can be a support when you need to collect more detailed learning data, but the standard or the way of measuring and collecting data is not in itself a requirement under Article 4.
Living, not a one-off effort
Training in AI literacy is not an initiative that is delivered once and then closed. It needs to be an ongoing process where content, knowledge checks and support are updated when AI tools, ways of working, risks or regulations change. Regularly follow up what employees need to know and adapt the training to how AI is actually used in the organisation.
How to create training based on how you use AI
1. Map your AI use. Which tools are used, by which roles, with which risks? The map steers everything else.
2. Define levels. A base for everyone, deeper training for exposed roles, specialist depth for those who introduce and maintain AI systems.
3. Choose formats for goals and audience. Combine short digital modules, interactive video and scenarios from your own organisation with instructor-led conversations, workshops or practical exercises. Such a blended learning setup can be especially relevant when participants need both shared foundational knowledge and a chance to discuss how AI should be used in their own role.
4. Measure and document. Knowledge checks per module, a diploma on pass, and all data traceable. That is your compliance evidence.
5. Update and maintain. Appoint a responsible owner, update the content when tools, ways of working or rules change, and regularly follow up completion and knowledge needs.
Common mistakes
Common mistakes are waiting for finished practice, choosing a generic course that does not reflect actual use, or running an initiative without clear ownership and follow-up. Start with the risks and roles in your own organisation and document your choices.
We help you design role-based training in AI literacy with relevant scenarios, knowledge checks and traceable follow-up, in your own environment or on our platform.
