AI Literacy Under Article 4: What Changed in July 2026
Article 4 is the part of the EU AI Act that most organisations are subject to and fewest have addressed. It applies whether or not you build AI, whether or not your systems are high-risk, and regardless of company size. It was also rewritten in July 2026, which changed what it demands without removing it.
What Article 4 originally said
In the original text of Regulation (EU) 2024/1689, applicable from 2 February 2025, providers and deployers were required to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and among other people operating AI systems on their behalf. That wording set a standard to be reached, and it was widely read as demanding a demonstrable level of competence.
What it says now
The Digital Omnibus on AI, Regulation (EU) 2026/1744, replaced Article 4 in full with effect from 27 July 2026. Under the new text, providers and deployers must take measures to support the development of AI literacy among their staff and those operating systems on their behalf, still taking account of technical knowledge, experience, education and the context in which the systems are used.
The amendment adds an explicit clarification: the obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual. A second paragraph asks the Commission and Member States to support these efforts, with particular attention to small and medium-sized enterprises.
What that actually changes
The obligation shifted from an obligation of result to an obligation of effort. That is a meaningful softening, and it removes the awkward question of how any organisation was meant to prove a sufficient level had been reached.
What it does not do is make Article 4 optional. It remains binding on every provider and every deployer. It was not deferred alongside the high-risk obligations, and national market surveillance authorities took up supervision of it from August 2026. An organisation that has done nothing at all has not taken measures to support anything, and the change in wording does not help it.
What a reasonable response looks like
The law prescribes no particular course, certificate or syllabus, which is deliberate. Proportionality is built into the text through the reference to knowledge, experience, education and context. A five-person office using a chatbot to draft emails is not in the same position as a company screening job applicants.
In practice, a defensible programme tends to include:
- An inventory of which AI tools are actually in use, including the ones nobody formally approved
- Training that matches roles, so that the people making decisions with AI output understand its limits
- Clear internal guidance on what may and may not be put into a third-party AI tool
- Something written down, so that measures taken can be described rather than asserted
- Review when tools or use cases change, rather than a single session that is never revisited
What does not meet a serious reading of Article 4, even in its softened form, is a vendor training module nobody opened, or an annual lunchtime session with no connection to how staff actually use the tools.
Who counts as staff
The obligation extends beyond employees to other people operating the systems on your behalf. Contractors, agency staff and outsourced functions using your AI tools fall within scope. This is often the gap in otherwise reasonable programmes.
Getting the training in place
The EU AI Act Article 4 Training Course is built specifically around this obligation and what satisfying it looks like in an ordinary organisation. There is a plain-English reference at the Article 4 AI literacy guide. For teams that need the underlying skills before the compliance layer makes sense, the AI Essentials course is the better starting point.
If you are not yet sure which obligations attach to your organisation, start with provider or deployer roles.
