The EU just started enforcing AI Act Article 4. Here's what organisations need to know

The real risk isn't being fined – it's the questionable decisions people make with AI they don't understand.

Editorial Team
04.08.2026
Copy link

Somewhere in your organisation, someone is using an AI tool to draft a client email, screen a CV, or flag a compliance risk – and trusting the output more than they should, or less than they need to.

That is an AI literacy gap, and it has been written into EU law since February 2025.

Article 4 of the AI Act requires providers and deployers to take measures supporting sufficient AI literacy among their staff. On August 2, 2026, national market surveillance authorities across the EU – including Germany's BNetzA and the newly established AI Office of Ireland – gained the formal power to check whether organisations are meeting it.

What Article 4 actually asks for

Article 4 tends to get misread in two opposite directions: organisations either assume it doesn't apply to them, or brace for a strict pass/fail bar. Neither is right.

Article 4 is broader than many expect. It applies to providers and deployers alike, and to any AI system in scope, not just high-risk systems, and it doesn't prescribe a universal training standard – instead, it requires organisations to support AI literacy appropriate to each person's role and the risks of the systems they use.

A finance team running its own credit-scoring model needs a different depth of understanding than an office using a chatbot to draft internal memos. In practice, that means one blanket AI-literacy course sent to the whole company won't satisfy the obligation on its own; training has to be calibrated to what each role actually does with AI, and how much risk that use carries.

The bar, on the other hand, is lower than a strict reading suggests. The Digital Omnibus, endorsed by the European Parliament in June 2026 and approved by the Council the same month, shifted the wording from a duty to ensure AI literacy to a duty to support its development – in legal terms, a move from an obligation of result to an obligation of effort. Organisations don't have to guarantee every employee clears some fixed literacy bar. They do have to show real, ongoing effort, and document it.

Does the AI literacy requirement come with a fine?

The obligation turns out to be lighter than expected in another respect too. Article 99, the AI Act's penalty framework, doesn't list Article 4 as a fineable provision in its own right. But Article 99 also sets out the aggravating and mitigating factors that regulators weigh once they've found a violation elsewhere – and a documented AI literacy gap is exactly the kind of thing that shows up there. If a high-risk AI system causes harm and an investigation finds the staff overseeing it didn't understand what it was doing, that missing training doesn't need its own clause to make the resulting fine worse.

It is important to remember that member states remain free to set their own national penalties for infringements the EU-level tiers don't cover, so "no EU-wide fine" isn't the same as "no fine anywhere" – so one must check domestic implementing legislation before assuming otherwise. 

But fines aren't the main reason organisations should care about AI literacy. 

Why AI literacy matters, regardless of any penalty

AI literacy, at its core, is the judgement to know when an AI's output can be trusted and when it needs checking – and that argument doesn't need a regulator behind it. An employee who doesn't understand how a model can be confidently wrong will act on a fabricated figure as though it were fact. Someone who doesn't understand what a screening tool was trained on will trust its shortlist without checking who it quietly filtered out.

Therefore the organisations getting real value from AI right now aren't the ones with the most sophisticated tools – they're the ones where people know enough to exercise judgement about when to trust an output and when to check it. That's what AI literacy actually protects: not a compliance file, but the quality of every decision AI touches.

The commercial driver is probably closer than the regulatory one

For most mid-market organisations, a market surveillance authority knocking on the door over an AI literacy gap is a distant scenario. A client due-diligence questionnaire asking for evidence of one is not. 

The pattern will look familiar to anyone who lived through SOC 2 or ISO 27001 becoming commercial prerequisites rather than regulatory ones – the requirement showed up in procurement long before anyone worried about a regulator, because the client wanted assurance the vendor's people knew what they were doing with sensitive systems. AI literacy looks to be on the same track. Whether it's being asked for yet inside any specific contract, it's a reasonable bet for anyone selling into a client base that already asks about ISO or SOC 2.

What AI literacy training evidence looks like

Enforcement guidance is consistent on one point: a policy document sitting in a folder doesn't count as evidence. What regulators – and increasingly, procurement teams – expect is contemporaneous, auditable training records: who was trained, when, on what, and how their understanding was assessed. That's a records problem as much as a training-content problem, and it's the same records problem organisations already solve for ISO 9001 Clause 7.2, SOC 2, or sector-specific certifications: proving who holds what, and when it was last verified.

Organisations already tracking certification and competence records for other standards have a head start here – the infrastructure for AI literacy evidence is the same infrastructure, pointed at a new subject. It sits alongside other workforce-facing obligations landing on the same desk this year, including the narrower but related reporting requirements under CSRD's ESRS S1.

Frequently Asked Questions

What is Article 4 of the EU AI Act? 

Article 4 requires providers and deployers of AI systems to take measures supporting sufficient AI literacy among staff and anyone operating AI systems on their behalf, so they understand the AI's capabilities, limitations and risks. It has applied since 2 February 2025.

When did Article 4 become enforceable? 

The obligation has been legally in force since February 2025, but national market surveillance authorities only gained formal powers to enforce it on 2 August 2026, when the AI Act's enforcement infrastructure became operational across EU member states.

Are there fines for not complying with Article 4? 

Not a standalone one at EU level – Article 99 doesn't list Article 4 as a fineable provision on its own. But a documented gap can still act as an aggravating factor if a regulator investigates another AI Act violation, and member states remain free to attach their own national penalties as they transpose the Act into domestic law.

What counts as evidence of AI literacy training? 

Enforcement guidance points toward contemporaneous, auditable records – who was trained, when, on what content, and how their understanding was assessed – rather than a general policy statement or a training slide deck.

The takeaway

Article 4 didn't get sharper teeth this week so much as a working enforcement mechanism. Whether that produces an early headline case or not is almost beside the point. The organisations that come out ahead will be the ones treating AI literacy as a living competence for using AI well, not a compliance line item such as a completed training course – and building the record to prove it before anyone asks. If you're already tracking certification and competence evidence for other standards, this is one more thing worth putting in the same place.

Cute fox
Contents

Subscribe to our newsletter

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Continue reading

The EU just started enforcing AI Act Article 4. Here's what organisations need to know

Learn more

SOC 2 and ISO 27001 certification tracking: What IT services firms need beyond a folder of PDFs

Learn more

Talent mapping software: What to look for and how to choose

Learn more