> Bron: https://neuralex.nl/en/blog/ai-geletterdheid-artikel-4
> Article 4 of the AI Act requires providers and deployers to take measures supporting AI literacy among staff — proportionate to role and risk, with no mandatory certificate. In force since 2 February 2025, amended in 2026.

[Back to Insights](/en/blog)

AI Act ·29 August 2026 ·7 min read

# AI literacy (Article 4): what does the law expect from your staff?

Article 4 of the AI Act requires providers and deployers to take measures supporting AI literacy among staff — proportionate to role and risk, with no mandatory certificate. In force since 2 February 2025, amended in 2026.

Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures supporting the development of AI literacy among their staff and other people operating or using AI systems on their behalf. Those measures should reflect factors such as technical knowledge, experience, education, training, the context in which the AI is used and the people or groups on whom the system may be used. The obligation has applied since 2 February 2025.

There is an important recent amendment to take into account. The original version of Regulation (EU) 2024/1689 required providers and deployers, to their best extent, to ensure a "sufficient level" of AI literacy. Regulation (EU) 2026/1744 replaced Article 4. Since that amendment entered into force on 27 July 2026, the provision instead requires organisations to take measures supporting the development of AI literacy and expressly states that they do not have to guarantee any specific level of AI literacy for each individual.

## What does the AI Act mean by AI literacy?

AI literacy under the AI Act means considerably more than knowing how to write a good prompt. The Regulation defines it as the skills, knowledge and understanding that allow providers, deployers and affected persons to make informed use of AI systems and to become aware of AI's opportunities, risks and potential harms.

In practical terms, someone using an AI system should understand enough about what it does, what it can be used for and where its limitations lie. A person using a generative AI tool should know that fluent and confident output can still be factually wrong. Someone handling personal or confidential information should understand that entering information into an external AI service can create privacy and security implications — see also [AI and GDPR](/en/blog/ai-en-de-avg). A person relying on AI in processes affecting individuals should be aware that inaccurate, biased or misunderstood output may have real consequences.

Recital 20 of the AI Act makes clear that the required understanding can differ depending on context. Developers may need to understand relevant technical aspects of an AI system, while operational users may need to know how the system should be used, what safeguards apply and how its output should be interpreted. The purpose is informed decision-making rather than turning every employee into an AI engineer.

## Not every employee needs the same training

Article 4 does not prescribe a single standard course that every employee must complete. The current provision expressly requires organisations to consider people's technical knowledge, experience, education and training, as well as the context in which the AI system is used. AI literacy measures can therefore be proportionate to the role and risk involved.

A developer integrating an AI model into a customer-facing application needs a different level and type of knowledge from an employee using ChatGPT to create a first draft of an email. Someone working with AI in recruitment faces different issues from an employee generating an image for an internal presentation.

The European Commission also states that Article 4 does not require a particular certificate. Organisations can maintain internal records of training and other guidance initiatives instead. Nor does compliance with Article 4 require a dedicated AI officer or a particular governance board.

## What can an SME do in practice?

For an SME, implementing Article 4 does not necessarily require a large compliance programme. A practical first step is identifying which AI systems people actually use and for what purposes. This should include unofficial or "shadow AI" use, where employees use publicly available AI tools even though the organisation has never formally adopted them.

Internal policies can then establish basic rules. These might cover entering personal or confidential information, checking AI-generated facts and figures, using AI-generated material in customer communications and situations where human review is required before an output is published or used in a decision.

Short, role-specific training or onboarding can sit on top of those rules. General users may need to understand what generative AI is, why hallucinations occur and what information should not be entered into external systems. Developers may need additional knowledge about model behaviour, security, evaluation and technical limitations. HR, finance and legal teams may benefit more from examples and risks directly connected to their own workflows. It is also sensible to retain evidence of what the organisation has done. The Commission does not require certification, but records of policies, training materials, participation and updates can demonstrate which measures were actually taken.

## AI literacy is not the same as high-risk AI compliance

Article 4 is a general obligation applying to providers and deployers of AI systems. An AI system does not first have to qualify as "[high-risk](/en/blog/hoog-risico-ai-systeem)" for AI literacy to become relevant. A business using ordinary AI tools may therefore still fall within the scope of Article 4.

High-risk AI systems are subject to additional and considerably more specific requirements. Article 26, for example, requires deployers to assign human oversight to natural persons who have the necessary competence, training and authority, together with the necessary support. That is a more concrete operational requirement than the general literacy duty in Article 4. The application dates for high-risk requirements also follow a separate timetable, which was amended in 2026. Article 4 should therefore not be treated as shorthand for the entire high-risk AI compliance regime.

## Why AI literacy is a foundation for compliance

The rationale is straightforward. Many AI governance measures are ineffective if the people expected to implement them do not understand the technology well enough. Requiring human review of AI output, for example, provides little protection if the reviewer does not know that a language model can fabricate sources, misinterpret a question or produce a plausible-looking but incorrect answer.

The AI Act therefore places AI literacy within the broader framework for responsible AI use. Recital 20 states that AI literacy should give relevant actors in the AI value chain the insights necessary for appropriate compliance with the Regulation and its correct enforcement. The Commission has also published a repository of AI literacy practices to illustrate possible approaches, while explicitly warning that copying one of those examples does not automatically create a presumption of compliance.

## Conclusion

For an SME, Article 4 essentially means that business use of AI should be accompanied by appropriate knowledge and guidance. Identify the AI systems being used, determine what people in different roles need to understand, establish practical rules and provide targeted training or onboarding where appropriate. The law does not prescribe one identical course for everyone or require a statutory AI-literacy certificate, but doing nothing while staff use AI for business purposes is difficult to reconcile with the duty to take measures. Neuralex does not provide legal advice; have the applicability of Article 4 and your chosen compliance measures reviewed by a lawyer for your specific circumstances.

Making AI literacy concrete

## Want to implement Article 4 for your organisation?

We help with an inventory of your AI use, practical usage guidelines and role-based onboarding — so you have demonstrable measures in place. Curious what that looks like for your situation?

[Ask your question](/en/contact) [Read the EU AI Act for SMEs](/en/blog/ai-act-voor-het-mkb)

---
Volledige (opgemaakte) versie: https://neuralex.nl/en/blog/ai-geletterdheid-artikel-4
