What is the AI literacy obligation (Article 4)?
In short: Article 4 requires providers and deployers of AI systems to ensure staff have sufficient AI literacy for their role — understanding the systems they build or operate, their limits, and their risks. It has applied since 2 February 2025, with no grace period and no exemption tied to the Digital Omnibus reform, and it applies well beyond high-risk systems.
Already in force — this is not a future deadline
Article 4 has applied since 2 February 2025, with no grace period and no transitional arrangement — it sits in the Act's first tranche of obligations, alongside the prohibited practices, not in the deferred high-risk timeline. The Digital Omnibus postponement covers the high-risk product deadlines only; it does not touch Article 4. So while much of your AI Act work still has runway, this piece doesn't: it's a live obligation for providers and deployers alike, today. One proportionate note: Article 4 has no dedicated fines regime attached to it, and the broader enforcement machinery matured only from August 2026 — but "not separately fined" is not "optional," and the sensible move is to confirm compliance now and document what you've done, because the practical question from an authority is "show me."
What "sufficient AI literacy" actually means
The obligation applies to both providers (organizations building AI systems) and deployers (organizations using them), and requires staff and other people dealing with the operation and use of AI systems on your behalf to have a level of skills, knowledge, and understanding sufficient to make informed decisions about the systems, and to be aware of the opportunities, risks, and possible harms the technology can cause. There's no single prescribed training format — what matters is that the level of literacy is genuinely proportionate to each person's role, from an engineer building a model to a customer support agent explaining a triage tool's output to a user.
Why it applies more broadly than "high-risk" work
Article 4 isn't limited to teams working on high-risk AI systems — it applies to any provider or deployer of an AI system covered by the Act, which is a broader population than the Article 6(1) or Annex III high-risk categories discussed elsewhere in this cluster. Closing this gap is comparatively inexpensive relative to the rest of AI Act compliance work, and unlike the deferred obligations, there's no remaining runway to plan around.
Where next: When Medical Device AI Becomes High-Risk · When do the AI Act deadlines hit medical devices?
Talk to us about your AI literacy programme. Book an expert conversation →
The full guide to health data and AI governance covers this question in context.