AI Literacy Obligation Under the EU AI Act Article 4
By Alexandre Saint-Jean

Audio version
Audio version produced by text-to-speech from the article. Our AI charter
Since 2 February 2025, Article 4 of the EU regulation on artificial intelligence has required every organisation using AI to ensure a sufficient level of AI literacy across its teams. This obligation is already in force, well ahead of the August 2026 deadlines. It applies to every deployer of an AI system, regardless of company size. Here is what the law actually requires, what it means in practice, and how to meet it efficiently.
What is AI literacy under Article 4 of the EU AI Act?
The term "AI literacy" covers the basic knowledge a user needs to understand what an AI system is, how it produces its outputs, what its limits are, and in what contexts its use can cause problems. It is not technical mastery of algorithms: it is a practical understanding that lets someone use AI in an informed way.
Article 4 of Regulation (EU) 2024/1689 puts the obligation this way: providers and deployers take measures to ensure, to their best extent, a sufficient level of AI literacy for staff and other people dealing with the operation and use of AI systems on their behalf. The phrase "to their best extent", and the way the text factors in a person's experience and context, signals that the obligation scales with someone's role. It does not aim to turn every employee into an AI expert; it aims to remove blind spots.
How does AI literacy differ from a technical certification?
An administrative assistant using a document-summarising tool does not need to know what a transformer is. They need to know that the tool can produce errors without flagging them automatically, that confidential information entered into it leaves the organisation's boundary, and that final validation remains their responsibility. That is the level of understanding Article 4 asks for from a non-technical profile.
For an IT manager choosing and deploying AI tools, the expected level is higher: risk assessment, access governance, decision traceability. The law scales the requirement to the role, which is a pragmatic and workable approach.
Since when has the obligation been in force, and who does it cover?
The AI literacy obligation took effect on 2 February 2025. It is the first binding deadline under the regulation, alongside the ban on so-called unacceptable AI practices (social scoring, subliminal manipulation, certain real-time biometric identification). Obligations on high-risk systems only apply from 2 August 2026.
Article 4 makes no distinction by company size or sector. It applies to any organisation that uses an AI system as part of its activities. That includes a micro-business whose sales staff use an AI writing assistant, a mid-sized company whose CRM includes automated recommendations, a school using a teaching assistant, and an accounting firm processing documents with AI.
As detailed in our full article on the EU AI Act for SMEs, literacy is not only the first obligation in force, it is also the one that covers the widest range of organisations, often underestimated by compliance guides that focus only on high-risk systems.
Provider or deployer: Article 4 covers both
The AI Act distinguishes the provider (who develops and places an AI system on the market) from the deployer (who uses it in their operations). Most businesses are deployers: they use ChatGPT, Copilot, or management software with AI built in, without building it themselves. Article 4 addresses both roles. As a deployer, you carry an obligation of result on your staff's understanding, not just an obligation of effort.
What does a "sufficient" level of AI literacy look like in practice?
This is the question business owners and HR managers ask immediately. The level expected of a business owner is not the same as that expected of a frontline employee: we cover that specifically in what a small business leader needs to know about AI. The regulation gives no numeric benchmark, but the logic of the text, together with early guidance from regulators, converges on four key areas. One concrete, documented practice worth adopting straight away: few-shot prompting, the technique that changes the quality of your AI outputs.
Understanding what AI is. Knowing that a language model predicts words without "understanding", that a recommendation system optimises a metric that can diverge from real interests, that an AI system is neither infallible nor omniscient. This baseline prevents over-delegation and post-deployment disillusionment.
Knowing the limits and risks of error. An AI system can hallucinate, meaning it can invent facts with a convincing appearance of reliability. It can carry forward biases present in its training data. Its errors are not always flagged. An informed user checks before sending; an untrained user delegates without a safety net.
Protecting data. Knowing that certain information should never be entered into a consumer-grade AI tool: customer personal data, confidential business information, trade secrets. This point overlaps with both the AI literacy obligation and GDPR, two complementary rules that data protection authorities, such as France's CNIL, cover in their practical guidance on artificial intelligence.
Locating responsibility. Understanding that a human signing off on a document produced with AI assistance is the one accountable, not the tool. Responsibility stays with the person who validates, and that reality needs to be internalised before any professional use.
How much training does it take to cover these four areas?
The goal is not to turn every employee into an AI specialist. It is to make sure nobody uses these tools unaware of their mechanics and risks. For an organisation whose teams use an AI assistant daily, half a day of structured, well-documented and traceable training is generally enough to cover the fundamentals Article 4 expects from non-technical profiles.
How do you demonstrate compliance with the Article 4 obligation?
The regulation does not mandate a specific format, but two elements matter most for proving compliance: traceability of what was done, and the actual level of understanding reached.
Traceability means keeping evidence of the training delivered. A course run by an accredited provider generates a dated, named completion certificate per participant. A documented internal session, with an attendance list and training materials, also produces admissible evidence. What matters is being able to answer, in the event of an inspection: when, who was trained, on what content, with what proof?
Level of understanding is harder to measure objectively, but a simple assessment at the end of training (a few questions, a quiz, a scenario exercise) shows the exercise was not purely a formality. It is also a protective factor if an incident involving an AI tool occurs: having trained your teams, and being able to prove it, is a serious mitigating factor.
The most robust approach combines training with an internal AI use policy. The policy sets out which tools are approved, what data can be entered into them, and who validates outputs. It anchors literacy in concrete, everyday rules. Data control goes beyond regulatory compliance alone: our page on AI data control and sovereignty covers the governance questions that sit alongside AI Act compliance.
Can AI literacy training be funded, for a business operating in France?
Yes, and this is often the deciding factor for business owners. Training in AI literacy delivered by a provider certified Qualiopi (France's official training-quality accreditation) is eligible for funding through an OPCO (France's sector-based training funding bodies), as part of the workforce development plan.
Funding can cover all or part of the cost depending on your funding pot and your sector's OPCO. Some schemes let you fund the needs assessment and the training plan at the same time, which reduces the administrative load on the business. France's Ministry of Labour publishes guidance on which schemes apply depending on employer type and company size.
This is precisely what our OPCO-funded AI training for teams covers: a structured session on AI literacy and use cases, deliverable in half a day or a full day, eligible for OPCO funding, and designed so teams leave with reference points they can use immediately. For more on the available mechanisms, funding AI training in France via your OPCO covers the routes available depending on business size and sector.
Where should you start to bring your teams into compliance?
For most businesses, meeting the Article 4 obligation comes down to three simple steps, with no IT project required first.
Map existing use. Find out who in the organisation is using what. This inventory rarely takes more than an hour with line managers. It often reveals uncoordinated usage and data-leak risks nobody had identified.
Target training groups by role. Not every user has the same context or the same level of responsibility. A salesperson drafting emails with AI does not have the same needs as an HR manager using AI to screen applications (a use that shifts into high risk under the AI Act, with additional obligations). Segmenting training by profile makes it more effective and more proportionate.
Organise, document and retain. Choose an accredited provider, set a date, make sure a completion certificate is generated for each participant, keep the training materials. This is also the moment to draft or refresh your internal AI use policy.
For an organisation already using AI tools daily that has not yet formalised any of this, compliance can be wrapped up in four to six weeks. The obligation has been in force since 2 February 2025: every extra month without action increases regulatory exposure without adding any operational value.
Frequently asked questions
- Does the AI literacy obligation apply to every business, even the smallest?
- Yes. Article 4 covers every deployer of an AI system, with no size threshold. As soon as one employee uses an AI tool at work, the organisation has to make sure they have a sufficient level of understanding. Proportionality relates to the person's role, not the size of the business.
- Since when has the AI literacy obligation applied?
- Since 2 February 2025. It is the first binding deadline under the EU AI Act, alongside the ban on unacceptable AI practices. Obligations on high-risk systems only apply from August 2026. Literacy could not wait.
- What counts as evidence of compliance with Article 4?
- There is no mandated format, but the strongest evidence includes: a certificate of completion from an accredited training provider, dated training materials, an attendance list, and an assessment of understanding at the end. Traceability is the key requirement.
- Can AI literacy training be funded, if my business operates in France?
- Yes. Training delivered by a provider certified Qualiopi (France's official training-quality accreditation) is eligible for funding through an OPCO (France's sector-based training funding bodies) as part of the workforce development plan. Coverage can be full or partial depending on your funding pot and sector.
Sources
Go further
AI training for teams