VocalFuse is a Fuse Intelligence product.

EU AI ACT · ARTICLE 4 · IN FORCE SINCE FEB 2025

EU AI Act Article 4: the AI literacy requirement, explained for employers

Since 2 February 2025, every provider and deployer of an AI system in the EU must take measures to develop AI literacy in the people who use AI on its behalf — employees, contractors, and agency staff alike. The July 2026 Digital Omnibus did not delay this duty; it softened the wording and left the duty, the dates, and the penalties intact. National market surveillance authorities have held formal supervisory powers over Article 4 since 2 August 2026. Here is what the law actually asks for, what counts as evidence, and the fastest way to make the obligation real for a workforce that already uses AI tools daily.

What Article 4 actually requires — and what changed in July 2026

The operative duty sits with providers and deployers of AI systems — that is, any organisation that supplies AI systems or uses one in its own operations. It applies regardless of risk class: not only high-risk systems, but the chatbot in customer service and the AI assistant drafting documents. The obligation has been in force since 2 February 2025, together with the prohibited-practices chapter. There is no de minimis carve-out.

The Digital Omnibus on AI (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026) amended the wording. Before: providers and deployers must “ensure, to their best extent, a sufficient level of AI literacy.” After: they “shall take measures to support the development of AI literacy” of their staff and other persons dealing with the operation and use of AI systems on their behalf — and the amendment states expressly that no specific, or “sufficient,” level is required of any individual. In plain terms, Article 4 moved from an obligation of result to an obligation of effort: the question a regulator asks is no longer “did you guarantee literacy?” but “what did you do about it, and can you show us?”

Two things the amendment did not touch. First, the applicability: the duty still began 2 February 2025, and the high-risk deferrals (Annex III systems to 2 December 2027, Annex I embedded systems to 2 August 2028) do not postpone it. Second, the separate duty for high-risk deployers to train staff for human oversight (Articles 14 and 26) remains in place — the Commission's own page says so explicitly. Article 4 is the floor; high-risk oversight training stacks on top.

The amendment also moved part of the burden to the public side: the Commission and Member States must support providers' and deployers' efforts (with particular attention to SMEs), the Commission will publish examples of compliance on a Single Information Platform, and the AI Board is to adopt recommendations on common objectives — which do not exist yet. Any training vendor marketing a course “aligned with the AI Board guidelines” is promising something nobody has published.

The obligation, clause by clause

Element What the law says What it means in practice
Who is coveredProviders and deployers of AI systems — any risk class, no de minimisIf your staff use ChatGPT, a coding assistant, or a meeting bot at work, you are a deployer
Who counts as staffEmployees and “other persons dealing with the operation and use of AI systems on your behalf”Contractors, freelancers, agency staff, outsourced service teams are in scope
The dutyTake measures to support the development of AI literacy (amended wording, 27 Jul 2026)An obligation of means: demonstrable, role-appropriate measures — not a guaranteed level
Scaling factorsTechnical knowledge, experience, education, training, and the context of use; consider the persons the AI acts onA developer needs depth; a recruiter using AI screening needs bias + oversight literacy; an agent needs escalation judgment
CertificationNone mandated; the Commission Q&A: no certificate needed, an internal record sufficesKeep who/what/when records of measures — evidence beats certificates
MeasurementNo obligation to measure employees' knowledgeTests are allowed but not what the law demands
CadenceContinuous — “to their best extent” as systems and staff changeAnnual refresh + ad-hoc training whenever a new AI system is introduced
EnforcementNational market surveillance authorities, supervisory powers from 2 Aug 2026; penalties per Article 99Up to EUR 15M / 3% global turnover (providers); in investigations, missing training reads as an aggravating gap

The single most common misreading of the 2026 reforms: “the AI Act is delayed.” The Digital Omnibus deferred high-risk obligations — Article 4 kept its February 2025 in-force date, and national enforcement began on schedule on 2 August 2026.

The evidence pack: four moves that satisfy Article 4

The Commission's AI literacy Q&A sets the practical minimum as a sequence: (a) a general understanding of AI across the organisation — what it is, how it works, what AI your organisation actually uses, the opportunities and dangers; (b) an inventory of which staff deal with which AI systems; (c) a risk-based read of what those staff need to know about the systems they touch; and (d) literacy actions built concretely on that analysis. Formats are deliberately free — no course, duration, or certification is mandated — because the obligation is proportionate to your systems and roles.

1. Map who touches AI

Include contractors and agency staff. HR using AI in recruitment (a high-risk use), support agents on chatbots, marketing on generative tools, developers on coding assistants, decision-makers receiving AI recommendations — staff who never touch AI are out of scope, everyone else is in.

2. Tier the training by role

A shared general module for everyone (what AI is, what your org uses, the risks), then role-specific depth: oversight duties and escalation for high-risk-system operators, prompt-and-verification discipline for builders, policy awareness for managers. The interface-eu framework formalises exactly this three-tier pattern.

3. Write the usage policy

The DOL's February 2026 AI-literacy framework (no legal force, but a field-tested checklist) puts clear AI use policies first: data protection, output verification, prohibited uses, accountability. A one-page policy beats a video course nobody finishes — see our free vibe coding policy template for the developer slice.

4. Record and refresh

A spreadsheet or LMS report with attendee, measure, date, and duration is the record the Commission says suffices. Repeat annually, and add ad-hoc training whenever a new AI system is introduced — one-off onboarding is not enough where the technology moves.

The AI Office maintains a living repository of AI literacy practices — 40+ voluntarily shared initiatives, last updated 10 August 2026 — as inspiration, not as a mandatory curriculum. Copying a practice does not create a presumption of conformity; what matters is that your measures match your systems, roles, and risk context, and that you can show the reasoning.

Where organisations get Article 4 wrong

Assuming it only applies to high-risk AI. Article 4 applies to every provider and deployer of any AI system. A company whose employees use ChatGPT for advertising copy or translation must comply — the Commission Q&A answers this scenario directly.

Counting contractors out. The obligation explicitly extends to “other persons dealing with the operation and use of AI systems on your behalf.” If you outsource customer service and the agency's staff run your chatbot, the literacy duty follows the work, not the payroll. Expect AI-literacy clauses to appear in service contracts as standard.

Buying a certificate instead of building a practice. No certificate is required and no measurement is mandated. A vendor selling “Article 4 certification” is selling comfort, not compliance — the defensible evidence is your own inventory, tiered training, policy, and records.

Waiting for the high-risk deadline. The Digital Omnibus moved the Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028. Article 4 and the Article 50 transparency chapter did not move — Article 50 (chatbot disclosure, deepfake labelling) has applied since 2 August 2026. Organisations that read the delay headlines and paused AI-literacy work are now a year behind on an obligation that has been live since February 2025.

The AI-coding slice: what developers' literacy must cover

Coding assistants are AI systems and developers are staff dealing with their operation and use, so Article 4 reaches engineering teams directly. A proportionate programme for a development team covers: what the assistant can and cannot do (probabilistic outputs, hallucination, and — per Veracode's finding that 45% of AI-generated code samples introduce a known OWASP Top 10 flaw — vulnerability risk in generated code); verification duties (you own every line that merges, and another human reviews); which data may and may not enter a prompt; and the org's AI coding policy itself. Literacy here is not training people to write code — it is training them to direct, verify, and escalate.

The fastest way to make that real is to put the rules where the work happens. The free one-page vibe coding policy template covers sanctioned tools, data rules by classification, agent task boundaries, review gates, and the app register; the vibe coding security guide carries the code-level risk detail. A staff that has read both pages and works under the policy is functionally AI-literate for the coding use case — and the register plus review cadence gives you the Article 4 evidence trail as a by-product.

Keep reading

Article 4 is one clause of the governance picture. The vibe coding governance guide covers the five controls for AI-built software, the free policy template operationalises them, and the security guide plus 15-point checklist handle the code-level half. For the discipline layer around agents, see harness engineering. Teams building on the harness can publish training and governance widgets to the open marketplace.

FREE VIBEFUSE · FIRST WIDGET · VS CLOUD · CREATOR CHALLENGE · FOR AGENTS · START · BUILD IN PUBLIC · EARN · NO $100 PAYWALL

Join agentic developers who ship widgets, post on the forum, and sell on the marketplace — free VibeFuse license on every account. Create a free account · For Agents · Start · Build in Public · First Widget · vs Cloud Computers · Creator Challenge · Earn · Creator Playbook · FAQ.

Widget Wars: publish a free custom widget the agent can drive, open a forum build thread with install steps, earn Founders-track perks while seats remain — public rubric, no purchased votes.

  • ✓ Free forever VF- license
  • ✓ Local/offline processing
  • ✓ Named reviewable sessions
  • ✓ No cloud upload required
  • ✓ 80% creator payouts

Explore VibeFuse & harness guides

AI literacy requirement FAQ

What is the EU AI Act Article 4 AI literacy obligation?

Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. It has been in force since 2 February 2025 and applies to every provider and deployer of any AI system regardless of risk class - not only high-risk systems. As amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), the duty is framed as supporting the development of AI literacy rather than ensuring any specific level: an obligation of means, not of result.

Do employers need an AI literacy certificate for employees?

No. The Commission's AI literacy Q&A answers this in one sentence: there is no need for a certificate, and an organisation may keep an internal record of training and other measures. Article 4 introduces no obligation to test or measure employees' knowledge either - a test is allowed but not what the law demands. What an inspector will ask for is evidence of measures taken: an AI usage inventory, role-appropriate training, an internal policy, and records of who was trained on what and when.

Did the Digital Omnibus delay or remove the AI literacy requirement?

No - this is the most common misreading of the 2026 reforms. Regulation (EU) 2026/1744 (Digital Omnibus on AI), published 24 July 2026 and in force 27 July 2026, deferred the high-risk system obligations (Annex III systems to 2 December 2027, Annex I embedded systems to 2 August 2028). It did not defer Article 4: the AI literacy duty remains in force from 2 February 2025, national enforcement begins 2 August 2026, and only the wording softened - from ensuring a sufficient level of AI literacy to taking measures to support its development, with no guarantee required for any individual.

Who counts as covered staff under Article 4?

Everyone who deals with AI systems in their work for the organisation: employees, and explicitly "other persons dealing with the operation and use of AI systems on your behalf" - contractors, freelancers, agency staff, and service providers. A company whose employees use ChatGPT for drafting advertisement text or translating documents must comply. Staff who never touch AI systems in their role are not covered, and the level expected scales with role: a developer building AI systems needs deep technical literacy, while an agent using an AI chatbot needs to understand what it can and cannot do and when to escalate.

What counts as an AI literacy measure in practice?

The Commission's Q&A sets a practical minimum: (a) a general understanding of AI across the organisation (what AI is, how it works, what the organisation uses, opportunities and dangers), (b) an inventory of which staff deal with which AI systems, (c) consideration of the risk of the systems provided or deployed and the risks staff need to know, and (d) AI literacy actions built concretely on that analysis. Formats are free: no course, duration, or certification is mandated. One-off onboarding training is not enough where the technology evolves - the obligation is continuous, and the AI Office's living repository (40+ practices, last updated 10 August 2026) collects examples.

What are the penalties for ignoring Article 4?

Article 4 violations fall under the AI Act's Article 99 penalty regime: fines up to EUR 15 million or 3% of global annual turnover for providers, and up to EUR 1.5 million or 1.5% for deployers where the obligation applies to them, whichever is higher. Enforcement runs through national market surveillance authorities, whose formal supervisory powers over Article 4 began 2 August 2026. The practical exposure is also softer: in incident investigations the first question is often whether staff had relevant training, and no answer reads as an aggravating gap.

Does Article 4 require training on AI coding assistants specifically?

Yes - coding assistants are AI systems, and developers are staff dealing with their operation and use. A proportionate literacy programme for a development team covers what the assistant can and cannot do, hallucination and vulnerability risk in generated code, verification duties (you own every line that merges), what data may and may not enter a prompt, and the org's AI coding policy. Pair this page's requirement with the free one-page vibe coding policy template to put the rules in a document agents and reviewers both read.

Where is the official AI literacy guidance and example repository?

The European Commission's AI literacy questions and answers page (digital-strategy.ec.europa.eu) is the authoritative reading of Article 4, and the AI Office maintains the living repository of AI literacy practices - 40+ voluntarily shared initiatives from AI Pact pledgers and other organisations, last updated 10 August 2026. Copying a repository practice does not create a presumption of conformity, and the AI Board's Article 4(3) recommendations on common objectives do not exist yet - any course marketed as aligned with them is promising something not yet published. The Commission will publish examples of compliance on the Single Information Platform under Article 4(2).