Insights · AI literacy
EU AI Act Article 4: AI Literacy Requirements
Understand the EU AI Act Article 4 AI literacy requirement, the people in scope, role-based learning, and practical evidence for providers and deployers.
Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy for staff and others dealing with AI systems on their behalf. It has applied since 2 February 2025. The Commission's guidance makes clear that a generic course is not automatically enough: measures should reflect the person's knowledge and training, the system context, and the people affected by its use.
Build literacy around real roles and real systems
- System owners and product teams — intended purpose, limitations, change control, and escalation routes.
- People exercising human oversight — what the system can and cannot do, when to challenge an output, and how to record an intervention.
- Operational users — practical risks such as hallucination, confidentiality, bias, and the limits of approved use cases.
- Procurement and leadership — supplier evidence, accountability, and when a use case needs legal, security, or fundamental-rights review.
Make the programme auditable
Maintain an AI system inventory, role-to-system mapping, learning or guidance delivered, completion evidence, and a refresh trigger for material system changes. A high-risk system or a sensitive use case may justify deeper role-specific measures than a low-impact internal tool.
How Agent Mai fits
Agent Mai can link literacy and human-oversight evidence to the same system record as risk, documentation, and audit outputs. It is not a substitute for an organisation's training programme or legal assessment of sufficiency.
Create an AI literacy programme from the system inventory
Generic awareness is a baseline, not the whole programme. Map each role to the AI systems it develops, procures, operates, oversees, or governs. For each pairing, identify the knowledge needed to use the system responsibly, recognise limitations, protect data, challenge outputs, intervene, report incidents, and stay within the approved purpose. Higher-impact systems need deeper and more frequent measures.
Role-based learning objectives
- All users — what AI is in use, approved and prohibited uses, hallucination and bias, confidentiality, verification, intellectual property, and incident reporting.
- Product and engineering — intended purpose, system boundaries, data and model limitations, evaluation, logging, change control, secure development, and evidence ownership.
- Human overseers — operating limits, automation bias, interpretation of outputs, authority to intervene, fallback procedures, override logging, and escalation.
- Procurement and legal — provider and deployer roles, supplier evidence, contractual controls, Article 5 signals, classification, GDPR overlap, and material changes.
- Executives and boards — risk appetite, accountability, inventory coverage, unresolved high-impact risks, evidence freshness, incidents, and resource decisions.
Evidence an Article 4 programme
Keep the role and system scope, learning objectives, content version, delivery method, completion or acknowledgement record, practical assessment where appropriate, exceptions, refresher date, and owner. Link evidence to the system record so a reviewer can see whether the people operating a specific version had relevant guidance. Certificates alone do not show that content matched the actual system or role.
Include contractors and service providers
Article 4 refers to staff and other persons dealing with AI systems on a provider's or deployer's behalf. Scope can therefore include contractors, outsourced operations, consultants, and service-provider personnel where they operate or use the system for the organisation. Define competence expectations in onboarding and contracts, provide system-specific guidance, retain appropriate evidence, and remove access when the engagement ends. Supplier training does not automatically cover your approved purpose, data rules, or escalation process.
Measure effectiveness without creating theatre
The Commission does not require employee knowledge testing, but organisations can still evaluate effectiveness proportionately. Useful signals include scenario exercises, correct escalation rates, reduction in prohibited data entry, quality of human overrides, incident trends, policy exceptions, and whether teams recognise material system changes. Refresh content after significant releases, new use cases, incidents, guidance changes, or role changes.
A proportionate annual operating cycle
- Review the AI inventory and role map at least annually and whenever a material system or organisational change occurs.
- Deliver baseline guidance at onboarding and system-specific guidance before access to higher-impact tools.
- Use short release briefings when capabilities, risks, controls, or approved purposes change.
- Test escalation and human-oversight scenarios for roles where an error could affect rights, safety, employment, education, or essential services.
- Report coverage, overdue actions, incidents, and effectiveness signals to the accountable governance forum.
Frequently asked questions
Is an AI literacy certificate required under Article 4?
No specific certificate is required. The Commission says organisations can keep internal records of training or other guidance initiatives and should tailor measures to role, knowledge, context, people affected and system risk.
Does Article 4 require a formal training course?
Not in every case. Training, guidance, supervised practice, policies, system instructions and targeted briefings can form part of a proportionate programme. Simply asking staff to read instructions may be insufficient depending on the role and risk.
Does Article 4 cover employees using common generative AI tools?
The Commission Q&A says organisations using tools such as ChatGPT should inform relevant people about specific risks such as hallucination. Measures should also address confidentiality, approved use, verification and escalation where relevant.
Related articles
- EU AI Act Article 50: Transparency RequirementsA practical guide to EU AI Act Article 50 transparency obligations for AI interactions, AI-generated content, deepfakes, and the evidence teams should retain.
- EU AI Act Article 5: Prohibited AI PracticesArticle 5 prohibited AI practices: social scoring, manipulative AI, biometric categorisation, facial scraping, and a practical product-and-legal review lens.
- EU AI Act GPAI Obligations: Provider and Buyer GuideGPAI model obligations under the EU AI Act: documentation, copyright policy, systemic risk, and what downstream deployers should verify.
Educational content only — not legal advice. Verify obligations with qualified counsel.