What has Art. 4 AI Act required since 27 July 2026?
Art. 4 requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff. Until 26 July 2026, they had to ensure “to their best extent” that their staff had a “sufficient level of AI literacy”. An obligation to achieve a result has thus become an obligation to make an effort.
Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf […]. That obligation shall not require providers or deployers to guarantee a specific level of AI literacy for any person.
| Version of 13 June 2024 (applicable from 2 February 2025) | Version since 27 July 2026 | |
|---|---|---|
| Obligation | Measures to ensure “to their best extent” that a “sufficient level of AI literacy” exists | Measures to support the “development of AI literacy” |
| Level per person | not expressly regulated | expressly no particular level owed |
| Obliged | Providers and deployers | unchanged: providers and deployers |
| To be taken into account | Knowledge, experience, education, context of use, persons affected | unchanged |
| Commission and Member States | no provision in Art. 4 | support companies, especially SMEs; the Commission publishes practical examples (para. 2) |
| European Artificial Intelligence Board | no provision in Art. 4 | adopts recommendations with common objectives (para. 3) |
The amendment has been adopted and is in force; it is no longer a draft. Regulation (EU) 2026/1744 (“Digital Omnibus on AI”) is dated 8 July 2026, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. On 19 November 2025, the Commission had proposed shifting the obligation entirely to the Commission and the Member States. What was adopted is a middle way: companies keep the obligation, but as an obligation to make an effort. The reasoning is in recital 8: strict obligations did not suit all companies and placed a particular burden on smaller ones.
Who has to ensure AI literacy?
The obligation applies to every company that provides an AI system or uses one professionally, regardless of size and industry. Under Art. 3(4) AI Act, a deployer is anyone “using an AI system under its authority”, except where it is used in the course of a personal, non-professional activity. So if you run an office with AI tools, you are a deployer; how providers and deployers are distinguished is explained in the article on the deadlines of the EU AI Act.
- Employees who use AI tools, even occasionally. The Commission expressly confirms the obligation for a company whose employees use ChatGPT, for example for advertising copy or translations: they should be informed about the specific risks, such as invented information.
- Other persons who operate or use AI systems on your behalf. The Commission names contractors, service providers and customers as examples. They too need the skills their task requires.
- Not covered is purely private use. Anyone in the business who does not work with AI systems is not among the persons covered by Art. 4.
The rules are stricter for high-risk systems: deployers must assign human oversight to persons who have the “necessary competence, training and authority” (Art. 26(2) AI Act). For systems under Annex III, for example in recruitment or lending, this applies from 2 December 2027 under the Omnibus.
What belongs in AI training?
The Regulation does not specify what content training must have. The benchmark is the definition in Art. 3(56); in addition, the Commission names four considerations, and the Federal Network Agency recommends a step-by-step structure.
“AI literacy” means skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause.
- General understanding: what is AI, how does it work, which AI is used in the company, and what are its opportunities and dangers?
- Role: does the company develop AI systems, or does it use other people's systems?
- Risk: what do employees need to know about the specific system, and which risks do they need to know about and avoid?
- Tailoring: measures according to the people's prior knowledge, experience and training, and according to the purpose of use.
This is how the Commission's questions and answers (last updated on 27 July 2026) summarise the minimum considerations. The Federal Network Agency proposes three levels: basics for everyone, advanced literacy for the systems in use, and role-specific in-depth knowledge, for example on technology, law or ethics. The Federal Network Agency stresses that its suggestions are neither mandatory nor exhaustive; the Commission says there is no one-size-fits-all solution and there are no strict requirements.
- How language models work: they calculate probable answers and can therefore invent information.
- Which AI tools are approved in the business, and for which tasks.
- Which data may go in: no personal data, trade secrets or client data without express approval.
- Checking results: trace figures, quotations, references and calculations; a person makes the decision.
- Third-party rights: only use other people's texts, images and data if the business is allowed to.
- Labelling under Art. 50(4) AI Act: disclose deepfakes, as well as AI texts intended to inform the public on matters of public interest, unless they are subject to editorial review and responsibility.
- Recognising manipulated inputs, such as documents or web pages with hidden instructions to the AI.
- Reporting channel: who employees turn to in the event of errors, data breaches or doubts.
Do you need a certificate or a particular course?
No. The EU AI Act prescribes neither a certificate nor a particular format; the measures can take place internally or externally, as a self-study programme, a workshop or multi-stage further training. The Commission states briefly that no certificate is needed; companies can keep internal records of training and other measures.
The AI Act does not provide for any certification requirement for the training or qualification measures used. The measures can be carried out either internally or externally.
According to the Federal Network Agency, the following are expressly not required:
- guaranteed levels of AI literacy for individual persons
- formalised or standardised training measures
- external certification of the measures carried out
- appointing an AI officer
Conversely, in the Commission's view, it is in many cases not enough to rely solely on a tool's instructions for use or to ask employees to read them. A certificate from a training provider can be part of your documentation, nothing more: the Regulation does not require any particular form of evidence.
How do you document the measures?
With a simple table: the Federal Network Agency recommends recording at least the type of measure, its scope in terms of content and time, and the participants, plus regular evaluation and refreshers as needed. In its view, a lack of AI literacy can count as a breach of the duty of care, especially if damage occurs; the documentation is then your evidence.
| Date | Measure | Contents | Scope | Participants | Refresher |
|---|---|---|---|---|---|
| 6 October 2026 | Basic training, internal | Basics, approved tools, data rules, checking results, reporting channel | 90 minutes | all 12 employees, list with signatures | October 2027 or with a new tool |
| 13 October 2026 | Briefing on a tool | Operation, limits, typical errors using your own example | 45 minutes | Accounting, 3 people | with a major new version |
| 20 October 2026 | AI policy issued | permitted purposes, prohibited data, duty to check, contact person | Read confirmation | all employees | review annually |
Keep the table, materials and participant lists together. When a new tool, a new task or a new person comes along, add a new entry. The participant list contains personal data; keep it as brief as possible.
Who supervises, and what are the consequences of breaches?
In Germany, the Federal Network Agency is responsible, and as of 23 September 2026 there is no fine for breaches of Art. 4 either in the EU AI Act or in the German implementing act. The German AI Market Surveillance and Innovation Promotion Act (KI-MIG) of 22 July 2026 entered into force on 29 July 2026.
- Supervision: under § 2(1) KI-MIG, the Federal Network Agency is the market surveillance authority responsible for compliance with the AI Act, unless the Act provides otherwise; for supervised financial companies, it is BaFin (the Federal Financial Supervisory Authority).
- Powers: the authorities have the powers under Art. 14 and 16 of the Market Surveillance Regulation (EU) 2019/1020 (§ 11 KI-MIG), so they can request documents, carry out checks and order measures.
- Fines: Art. 99(3) to (5) AI Act do not mention Art. 4. § 15 KI-MIG only covers certain information, access, impact assessment and explanation obligations, with fines of up to 50,000 euros.
- Liability: if damage occurs, a lack of AI literacy can be regarded as a breach of the duty of care; that is another reason why clean documentation is worthwhile.
The Commission stresses that any sanction must be proportionate, and considers it more likely if an incident can be shown to result from a lack of training or guidance. According to its questions and answers, the national market surveillance authorities have supervised Art. 4 since August 2026.
How do you implement Art. 4 in your business?
In five steps, from taking stock to refreshers. Nobody requires a standard solution, but according to the Federal Network Agency the decision should be “plausible and comprehensible”: record why the measures you have chosen suit your tools, tasks and prior knowledge.
- Take stock
Which people use which AI systems for what? This includes AI features in existing software and tools that employees use on their own initiative.
- Clarify role and risk
Are you only a deployer, or also a provider? Are there uses with particular risk, for example in personnel decisions or with health data?
- Set rules
A short AI policy: approved tools, permitted purposes, prohibited data, duty to check, reporting channel. What belongs in it from a data protection perspective is covered in the article ChatGPT and data protection.
- Train your team
Basic training for everyone who uses AI, a briefing on the relevant tool for those who operate it, and in-depth training for roles with particular risk.
- Document and refresh
Keep the table up to date, evaluate the measures once a year, and provide follow-up training for new tools, tasks or people.
Frequently asked questions
Does Art. 4 also apply if employees only use ChatGPT?
Yes. Anyone who uses an AI system professionally under their own authority is a deployer within the meaning of the EU AI Act. The Commission expressly confirms the obligation for a company whose employees use ChatGPT for advertising copy or translations; they should be informed about the specific risks, such as invented information.
Is AI training with a certificate mandatory?
No. Neither the EU AI Act nor the Federal Network Agency requires a certificate or an external provider. Internal training with a participant list is sufficient evidence if it fits the tools and tasks in use.
Is there a fine if we do not provide training?
As of 23 September 2026, there is no specific offence carrying a fine: neither Art. 99 AI Act nor § 15 KI-MIG mentions Art. 4. However, the Federal Network Agency can request documents and order measures, and after damage has occurred, a lack of training can be regarded as a breach of the duty of care.
Do all employees have to be trained?
Measures are needed for everyone who operates or uses AI systems on your behalf, including service providers. Scope and depth may differ according to role, prior knowledge and risk. Anyone in the business who does not work with AI systems is not among the persons covered by Art. 4.
How often does AI training have to be repeated?
There is no fixed interval. The Federal Network Agency recommends evaluating the measures regularly and refreshing them as needed, for example when tools, tasks or the technology change. An annual session and follow-up training with every new tool are a practical rhythm.
What did the Digital Omnibus change in Art. 4?
It weakened the obligation but did not delete it. Instead of ensuring a sufficient level of AI literacy to the best of their ability, providers and deployers have, since 27 July 2026, had to take measures to promote it, without owing a particular level per person. The Commission and the Member States are to support companies in this, especially small and mid-sized ones.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) of 8 July 2026, Official Journal of 24 July 2026
- Regulation (EU) 2024/1689 (AI Act), Art. 3, 4, 26, 50 and 99
- European Commission: AI Literacy – Questions & Answers (last updated on 27 July 2026)
- Federal Network Agency: AI literacy
- Federal Network Agency: guidance paper on AI literacy under Article 4 AI Act, June 2025 (old version)
- German AI Market Surveillance and Innovation Promotion Act (KI-MIG) of 22 July 2026, §§ 2, 11 and 15
- § 98 BetrVG: implementation of in-company training measures
- European Commission: Living repository of AI literacy practices
This text is not legal advice. It is the groundwork we had to do for ourselves, with the legal references, so that your lawyer does not have to start from scratch. Where a question depends on your circumstances, the text says so.
