What Article 4 of the EU AI Act asks of your team
Updated 21 July 2026: the Digital Omnibus amendments adopted in June 2026 rewrote Article 4. This post reflects the amended text — here is exactly what changed.
Your employees are already using AI at work — drafting emails, summarising documents, answering customers. The EU AI Act assumes exactly that, and Article 4 makes their AI literacy your obligation. Not someday: the article has been in application since 2 February 2025, and national authorities supervise it from 2 August 2026.
What Article 4 requires — and how it changed
As adopted in 2024, Article 4 required providers and deployers of AI systems to ensure, to their best extent, “a sufficient level of AI literacy” among staff and anyone operating AI on their behalf. The June 2026 amendments softened the verb: organizations must now take measures to support the development of AI literacy — an obligation of effort rather than outcome, with no guaranteed level per person. The full text of the Act is at Regulation (EU) 2024/1689; the revised timeline around it is its own story.
Three things stand out once you read the obligation closely — and all three survived the rewrite:
- It covers users, not just builders. You don’t need to ship an AI product to be in scope. A support team pasting customer questions into a chatbot is “operating an AI system” — and so are agencies and freelancers doing it on your behalf.
- It is context-dependent by design. The regulation prescribes no certificate and no fixed curriculum — the recitals now say openly that one-size-fits-all literacy was considered unsuitable. What fits is measured against what your people actually do with AI: which tools, which data, which decisions.
- An effort obligation is evidenced by records of effort. With no score threshold to point at, the measures you took — and can show — are the whole answer. An obligation you can’t evidence is an obligation you can’t demonstrate you met.
Literacy depends on the role
The same tool creates different risks in different hands. The AI literacy your HR lead needs — where AI touches hiring and performance decisions — is not the AI literacy your support team needs, and neither matches what your engineers need when they integrate a model into your product.
That’s why a single generic AI awareness session is a measure in name only — the decisions people face are role-specific:
- Can support send an AI-drafted answer straight to a customer?
- Can HR use AI to rank job candidates?
- What customer data can anyone, in any role, paste into a chatbot?
Literacy that changes behaviour teaches the rule, then practises the decision each role actually makes — grounded in your own AI policy and your own tools, not a vendor’s abstractions. (And if a vendor is still selling you certificates and €35M fines, read this first.)
Literacy you can’t show is literacy you can’t prove
When your board, an auditor, or a regulator asks how you meet Article 4, “we ran a workshop in spring” is a weak answer. A strong answer names who has been trained, on what, to what level, and shows the record behind it — per person, per role, per topic.
That means the evidence has to be produced by the learning itself: which scenarios each person worked through, how they responded, and what they have demonstrably mastered — not an attendance sheet. Since the amendment made the duty effort-based, the record of your measures is the compliance artifact — there is nothing else to point at.
Where to start
- Inventory your AI reality. Which tools are in use (approved or not), what data flows into them, and which roles rely on them.
- Set the baseline for everyone. Safe use, data handling, hallucinations, confidentiality — the shared floor every employee needs.
- Add specialist roles in phases. Managers, HR, support, product, engineering — each gets the decisions that belong to them. Keep records from day one, so the evidence accumulates as people learn.
This is precisely the shape of our AI Act readiness program: your policy and tools turned into role-based learning, a personal tutor for every person, and readiness evidence you can export when someone asks. If you’re mapping your own rollout, book a walkthrough and bring your AI policy.
Ulern builds readiness and evidence. This post explains the obligation in plain terms — it is not legal advice.