Short definition (citable, 47 words)
Article 4 of the AI Act requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff and the people acting on their behalf. The level depends on prior knowledge, role and context of use. The rule prescribes no specific certificate or fixed competence level.
Where the article comes from and how to place it
The AI Act, formally Regulation (EU) 2024/1689, is the first comprehensive legal framework for artificial intelligence. It follows a risk-based approach. Prohibited practices, high-risk systems with strict duties, and lower-risk systems are treated differently. Article 4 sits deliberately near the start, in the general provisions, and applies broadly. It does not attach to the high-risk classification but to the use of AI systems as such. The idea is simple. Anyone deploying or providing AI must ensure that the people working with it understand what they are doing, what limits a system has and where risks lie. The duty has applied since 2 February 2025. It lifted the term AI literacy from the educational into the legal space and turned it into an organisational obligation that must be met in a traceable way.
The mechanism: a duty without a fixed exam standard
Article 4 names no curriculum, no number of hours and no certificate. That is intentional. Adequacy is to be determined proportionately, graded by what a person really needs in their role.
Duty under Art. 4
|
Who uses which AI? (roles, systems, risk, context)
|
What level is adequate? (prior knowledge + role + use)
|
Choose a measure (training, workshop, briefing, practice)
|
Secure internal evidence (what, for whom, when, with what content)
The practical lever is the first line. Without knowing which roles work with which systems, no adequate level can be set. So sound implementation begins with a short stocktake, not with buying a course. The stocktake shows who needs only a baseline and who must be trained more deeply because they decide, approve or handle sensitive cases.
A worked mini-example
An illustrative case in a company of 120 staff running an AI writing tool and an internal assistant. Stocktake: 80 people use the tools occasionally for text, 30 work with them intensively, 10 decide on use, approvals and data access. Adequate grading: for the 80 a short baseline and safety module, for the 30 a role-based deepening with practice, for the 10 an additional governance part on responsibility and limits. That yields three measures with a clear audience each, rather than one uniform mandatory training for everyone. These numbers are a planning model, not legal advice. The point is the logic: adequacy comes from mapping role to level, and that mapping can be documented and, if needed, justified.
Who in the company is affected, by function
| Function | Contribution to compliance | Typical task |
|---|---|---|
| Executive management | owns the organisational duty | resources and policy decision |
| HR and L&D | plans and documents measures | training plan, record-keeping |
| IT and information security | names systems and risks | system inventory, access rules |
| Data protection and legal | assesses adequacy and limits | classification, documentation rules |
| Department heads | know the context of use | report roles and real use |
| Works council | accompanies participation rights | co-determination on measures |
Industries for which the article matters most
The duty applies across industries, but the required depth rises with risk. In finance and insurance and in health and pharma, the general literacy duty meets possible high-risk classifications of individual systems, raising the bar on judgment and governance. In public administration, the focus is on traceable, documented measures. In marketing agencies and digital natives that use many tools broadly, the emphasis is on confident operation and a shared baseline across the team. The common denominator is not the industry but the question of which roles work with which systems at which risk.
Distinction from related rules and terms
| Term | What it is | Relation to Article 4 |
|---|---|---|
| Article 4, AI literacy | general literacy duty for all deployers and providers | the framework covered here |
| High-risk duties (Art. 8 ff.) | strict requirements for certain systems | apply only to classified systems, on top of Art. 4 |
| Transparency duties (Art. 50) | labelling AI interaction and content | a separate duty, no substitute for literacy |
| GDPR training | data protection briefing | related but a different protective aim |
| voluntary certification | private mark of conformity | not required by Art. 4, can support evidence |
The most common mistake is reading a certificate as a requirement. Article 4 requires adequate measures and their traceability, not a particular seal.
When stricter requirements apply, and when lighter ones
A higher level is adequate when roles decide on use, approvals or sensitive data, when systems are classified as high-risk, or when errors have strong downstream effects. A lighter level suffices when staff use AI only occasionally for uncritical tasks. Documentation matters in both cases, because without records the adequacy is hard to prove afterwards. Justifying and recording the grading meets the duty more traceably than a blanket mandatory training for everyone.
Next step
Two ways, depending on where you are.
- Book directly: Book a discovery call. 30 minutes, we map your roles and systems and derive adequate measures for Article 4.
- Read along first: Enter your email and get the EU AI Act checklist plus a template for the role and measures inventory. No spam, unsubscribe anytime.
Build directive (Lovable): two side-by-side CTA cards (stacked on mobile). Card 1 = primary "Book a discovery call" button to https://cal.com/jamboula/ai-hackathon. Card 2 = email capture (<input type="email">, GDPR consent checkbox, double opt-in, submit to the lead list, inline success/error). Buttons carry a Phosphor icon (phosphoricons.com: CalendarCheck, EnvelopeSimple), hover/focus states via Motion (motion.dev, transform/opacity only), respect prefers-reduced-motion. This block also appears once higher up after the short definition.
FAQ
Does Article 4 prescribe a specific certificate? No. The rule requires an adequate level of AI literacy and suitable measures, but no specific certificate and no fixed exam level. Internal records of training and other measures can document implementation.
Since when has the duty applied? Article 4 has applied since 2 February 2025. Other parts of the AI Act apply on a staggered timeline. For the current legal status, see the dated note further down this page.
Does Article 4 also apply to small companies? Yes. The duty attaches to the role of deployer or provider of AI systems, not to a company size. The adequate level may, however, be proportionate, so smaller for simple, uncritical use.
Does a training or hackathon satisfy Article 4 automatically? No, not automatically. A role- and context-appropriate measure can contribute to literacy and create suitable internal evidence. Whether the overall programme is adequate must be assessed by the company against roles, systems and risks.
Is this legal advice? No. Regulatory questions require review of the specific facts and current law by qualified counsel.
Related glossary terms
AI literacy record · AI literacy · AI training · Practical transfer · In-house AI training · Copilot training
Sources and technical context
- EU Regulation 2024/1689 (AI Act), EUR-Lex
- European Commission: AI literacy questions and answers
- NIST AI Risk Management Framework
- OWASP Top 10 for LLM Applications
Rechtsstand Artikel 4, 20.08.2026
Artikel 4 ist seit dem 02.02.2025 anwendbar und wurde im Juli 2026 durch die Verordnung (EU) 2026/1744 geändert. Der aktuelle Wortlaut verpflichtet Anbieter und Betreiber von KI-Systemen, Maßnahmen zur Unterstützung der Entwicklung von KI-Kompetenz bei Beschäftigten und weiteren Personen zu treffen, die in ihrem Auftrag mit den Systemen arbeiten. Ein bestimmtes individuelles Kompetenzniveau oder ein bestimmtes Zertifikat ist nicht vorgeschrieben. Interne Aufzeichnungen zu Schulungen und weiteren Maßnahmen können die Umsetzung dokumentieren. Ein Hackathon kann Teil eines kontextbezogenen Maßnahmenpakets sein, garantiert aber nicht automatisch Rechtskonformität.
Primärquellen: https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng und https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1744. Erläuterungen der EU-Kommission: https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers.
Article 4 legal status, 20 August 2026
Article 4 has applied since 2 February 2025 and was amended in July 2026 by Regulation (EU) 2026/1744. The current text requires providers and deployers of AI systems to take measures supporting the development of AI literacy among staff and other persons working with the systems on their behalf. It does not mandate a specific individual level or a specific certificate. Internal records of training and other measures can document implementation. A hackathon can form part of a context-appropriate set of measures but does not automatically guarantee legal compliance.
Primary sources: https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng and https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1744. European Commission guidance: https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers.
Einordnung zu Artikel 4 / Article 4 scope
Ein Hackathon, Workshop oder eine Schulung kann als rollen- und kontextbezogene Maßnahme zur KI-Kompetenz beitragen und geeignete interne Evidenz erzeugen. Das Format ist kein behördlich vorgeschriebenes Zertifikat, ersetzt keine Rechtsberatung und garantiert für sich allein keine Compliance. Das Unternehmen muss sein gesamtes Maßnahmenpaket anhand von Rollen, Systemen, Risiken und Nutzungskontext beurteilen.
A hackathon, workshop or training can contribute to role- and context-appropriate AI literacy measures and create suitable internal evidence. It is not an officially prescribed certificate, does not replace legal advice and cannot guarantee compliance on its own. The organisation must assess its complete programme against the relevant roles, systems, risks and use context.