EU AI Act Article 4: AI Literacy Obligations and the Shadow AI Problem
Article 4 is easy to miss because it has no product to point to, no chatbot disclosure, no risk assessment form, just a duty to make sure people using AI actually understand what they’re using. It applies to every AI system, not just high-risk ones, and it’s already enforceable.
- Article 4 has applied since 2 February 2025, the AI Act’s earliest applicability date alongside the Article 5 prohibitions.
- National authorities gained formal enforcement powers for it on 2 August 2026.
- It applies to ALL AI systems, not only high-risk ones, unlike most of the Act.
- Not delayed by the 2026 Digital Omnibus, which only affected high-risk deadlines.
- Literacy must be proportionate to three factors: the context of use, the system’s technical complexity, and the role of the person using it.
- There is no prescribed format: no mandated course length, certificate, or platform, the obligation is the outcome, not a specific method.
What Article 4 actually says
Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other people dealing with the operation and use of AI systems on their behalf. The required level is proportionate to the person’s technical knowledge, experience, education, and training, the context the AI system is used in, and who it affects.
It applies to every AI system a company provides or deploys, not just the ones classified as high-risk or transparency-tier. That makes it the broadest-reaching obligation in the entire Regulation, and also the easiest one to overlook, since it doesn’t come with a specific form, label, or filing.
Why this is the "shadow AI" provision
Article 4’s scope, all staff dealing with AI, not just IT or a designated compliance function, is exactly why it collides with the shadow AI problem: employees adopting AI tools (chatbots, browser extensions, personal ChatGPT accounts for work tasks) without going through any approval process. You cannot deliver proportionate AI literacy training to staff using tools you don’t know exist. That makes an honest, judgment-free inventory of actual AI usage, not just officially sanctioned tools, a precondition for Article 4 compliance, not an optional nice-to-have.
This is also why Article 4 compliance and the AI Asset Inventory work described in the risk tier guide are the same underlying task, viewed from two angles: one asks "what AI do we use," the other asks "does everyone using it understand it well enough."
What "sufficient AI literacy" looks like in practice
The Regulation deliberately doesn’t prescribe a specific training format. In practice, a defensible approach covers:
- A basic explanation of what the AI tools your staff actually use do, and don’t do (what they generate, what data they see, their known failure modes).
- Role-specific depth: a marketer using a generative writing tool needs different literacy than an HR team using an AI screening tool, or a developer integrating an AI API.
- Awareness of the company’s AI Act obligations that touch their role: e.g., customer-facing staff need to know about Article 50 chatbot disclosure duties if they manage a chatbot.
- A record that the training happened: who, when, on what, since "we did it" isn’t evidence without a timestamp and a name attached.
What this is not
Article 4 is not a data science course, and it is not the same as high-risk system documentation. It is closer to a workplace safety briefing than a technical certification: proportionate, role-specific, and focused on the practical risks and limits of the specific tools people actually touch. A generic "AI 101" video with no connection to your company’s actual tools is unlikely to satisfy "sufficient" for anyone whose role involves meaningful AI use.
Questions
Does Article 4 apply to a company with no in-house AI development?
Yes. Article 4 applies to deployers as well as providers. Using third-party AI tools (a chatbot platform, a generative writing tool, an AI-powered SaaS feature) makes you a deployer, and the literacy obligation follows from that, regardless of whether you built any AI yourself.
Is a single company-wide training session enough?
It depends on whether it’s genuinely proportionate to each role’s actual AI exposure, which a single generic session often isn’t once different departments use different tools for different purposes. Treat "one video for everyone" as a starting point to build on, not a finished answer, and confirm your specific approach with qualified counsel if you need certainty.
Want this tracked automatically, not read about?
The EU AI Act Governance Cockpit is a Notion + n8n workspace that logs your AI systems, runs this exact risk classification, tracks the required actions, and keeps the evidence. One-time payment from €49.