AI literacy under Article 4 — what's required
Article 4 of the EU AI Act requires staff AI literacy from every provider and deployer. What it means in practice, and how to document a programme regulators accept.
Article 4 of the EU AI Act is short, broad, and binding on every European company that uses AI in any capacity. It has been enforceable since 2 February 2025. Most teams have not yet treated it seriously — but supervisory authorities are starting to ask. This guide is the practical interpretation.
What Article 4 actually says
Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.
In plain language: anyone whose work involves AI systems — your developers, your product managers, your customer-support reps using AI-augmented tooling, your sales team using AI prospecting tools — must have a level of AI literacy appropriate to what they actually do.
Who’s in scope
The provision binds both providers and deployers — which means almost every European company. If you build AI features, you’re a provider. If you use a third-party AI tool (Copilot, ChatGPT for Work, an AI candidate-screening service), you’re a deployer.
It covers your staff (employees and contractors) and also “other persons dealing with the operation and use of AI systems on your behalf” — which means your offshore developers, your agencies, your support outsourcers. The literacy requirement follows the work, not the org chart.
What “sufficient level” means
There is no certification scheme — the European Commission deliberately avoided creating one. “Sufficient” is judged contextually:
- An ML engineer training a high-risk model needs to know risk management, data governance, evaluation methodology, fairness metrics, and the relevant Articles of the Act
- A product manager scoping a chatbot needs to understand Article 50 transparency obligations and what the Article 5 prohibitions mean for prompt engineering
- A customer-support rep using an AI summariser needs to understand that summaries can be wrong, what to do when they are, and how to flag failures
- An executive who buys AI tools needs to understand vendor due diligence and the deployer obligations under Article 26
The level rises with both the role and the risk tier of the AI involved. A team using a minimal-risk autocomplete needs less AI literacy than a team operating a high-risk credit scoring engine.
What supervisory authorities expect
There’s no written rulebook yet, but draft guidance and early enforcement signals point to four expectations:
- A documented programme. “We mentioned AI in onboarding” doesn’t count. A written training plan does.
- Role-specific content. A one-size-fits-all training video is not “sufficient.” Engineers need different content than account managers.
- Periodic refresh. The AI landscape moves fast. Annual or bi-annual refreshers are the emerging norm.
- Records of completion. Names, dates, training modules. The audit trail.
What a defensible programme looks like
A minimal but defensible AI literacy programme for an SME has five elements:
1. A baseline module for all staff
A 30–45 minute primer covering:
- What AI is and isn’t (rough generative-vs-discriminative, ML-vs-rules)
- The EU AI Act in one page: prohibited, high-risk, limited, minimal
- The company’s policy on using AI tools (which are approved, which aren’t)
- How to flag AI errors and harms
- Where to ask questions
2. Role-specific extensions
Layer on top of the baseline:
- Engineering / data science: model evaluation, bias testing, the Article 9–15 obligations if you build high-risk systems
- Product: intended-use classification, Article 50 transparency design, human oversight design patterns
- Customer-facing roles: when AI assistance can be wrong, escalation paths, what users must be told
- HR / people: what Article 5 prohibits in workplace AI, what Annex III item 4 means for the ATS
3. Tool-specific micro-trainings
A 5–10 minute walk-through every time a new AI tool is rolled out — what it does, what it doesn’t do, when not to trust it.
4. Records
A simple table: who, what, when, evidence (e.g., a course-completion timestamp). Per Article 4 there’s no specific record-keeping rule, but supervisory authorities asking “how do you ensure AI literacy?” want documentation, not promises.
5. Refresh cadence
Annual baseline refresh. Role-specific refresh whenever the regulation, your AI stack, or the role substantially changes.
What you can borrow
You don’t have to build all of this from scratch. The European Commission has published guidance on AI literacy as part of its broader AI Pact materials. The OECD has a free AI literacy framework. The CEN-CENELEC JTC 21 group has work in progress on standards. Use them as scaffolding.
Inside Maditon specifically, the “Learn EU AI Act” tutor and its quizzes are designed to give each member of your team a structured way to develop and demonstrate AI literacy as part of normal product use. Every learning session and every quiz score is captured per user — feeding directly into your Article 4 records.
What this is not
Article 4 does not require:
- A specific certification (none exists)
- Identical training for every employee
- External validation (you can run the programme in-house)
- Training the public — only your staff and “other persons dealing with the operation and use”
It does require proportionate, documented effort. The single biggest mistake teams make is treating Article 4 as an aspiration rather than a legal obligation. It’s been in force since February 2025. Build the programme now if you haven’t.