EU AI Act
AI literacy under Article 4 of the EU AI Act: what is required now
Article 4 has applied since 2 February 2025. After the Digital Omnibus, providers and deployers must take measures to support AI literacy among staff and others operating or using AI systems on their behalf. They no longer have to guarantee a particular level for any individual. The duty is not tied to the high-risk dates.
Who this applies to
- Providers of AI systems
- Their staff and other persons dealing with the operation and use of AI systems on their behalf.
- Deployers of AI systems
- The same, for any AI system they use, regardless of risk tier. Article 4 is not limited to high-risk systems.
- The Commission, Member States and the AI Board
- Paragraphs 2 and 3 oblige them to support providers and deployers, especially SMEs, with practical examples and recommendations.
What Article 4 says now
The following follows Article 4 on the AI Act Service Desk as amended by Regulation (EU) 2026/1744.
- Duty. Providers and deployers must take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf.
- Calibration. The measures take into account the people's technical knowledge, experience, education and training, the context in which the systems are used, and the persons on whom they are used.
- No guaranteed level. The duty does not require providers or deployers to guarantee any specific level of AI literacy for any individual. Before the Omnibus, the text required "a sufficient level" to be ensured "to their best extent".
- Support. The Commission and Member States support compliance, especially for SMEs, and the Commission publishes practical examples on a single information platform. The AI Board adopts recommendations, taking European competence frameworks into account.
"AI literacy" is defined in Article 3(56) as the skills, knowledge and understanding that allow providers, deployers and affected persons to make informed deployment of AI systems and to be aware of AI's opportunities, risks and potential harm.
Dates: Article 4 applies from 2 February 2025. Article 4 contains no penalty provision of its own, and the Article 99 tiers do not name it, so how a breach would be handled depends on national rules. National and EU enforcement for AI literacy is listed as starting on 2 August 2026 in the Commission timeline. Ask counsel about your Member State.
What "measures to support" looks like in practice
| Audience | What they need to understand | Example measure |
|---|---|---|
| Everyone who uses AI at work | What the tool does and does not do, hallucination and bias, data-handling rules, when to escalate. | Short onboarding module and a one-page usage policy. |
| People who approve AI output | How to review output, automation bias, what an approval means legally. | Role-specific review training tied to the approval step in the workflow. |
| Builders and operators | Model limits, evaluation, logging, security and prompt-injection risks. | Technical training and a runbook. |
| Managers and executives | Risk tiers, accountability, how to read the evidence pack. | Briefing and a governance review cadence. |
| High-risk system overseers | The system's instructions for use, limits and override procedure (Art. 14 and Art. 26(2)). | Competence record naming each overseer. |
Because the duty is about supporting literacy rather than guaranteeing it, evidence of reasonable, role-based measures is the point. A training attendance record alone is thin. A policy, a role map, content, completion records, and a refresh trigger together are stronger.
Evidence to keep
- The AI literacy policy and the date it was approved.
- A role map: who uses, approves, builds and oversees AI systems.
- Training content versions and completion records per role.
- A trigger list for refreshing training: new system, new model, new use case, incident.
- For high-risk deployments, the named overseers and their competence records.
How the platform supports it
Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.
| Requirement | Platform control | Evidence artifact | Fabric facets |
|---|---|---|---|
| Know who operates and uses each AI system | Identity for every user, agent and workflow, with scoped access and ownership in the Trust Profile. | Role and access map per AI system. | Identity, Access |
| Make safe use the default for people who are less expert | Policy that filters, warns or requires approval, so literacy gaps are covered by guardrails. | Policy configuration and warning/denial records. | Policy, Human oversight |
| Show competent human overseers (Art. 14, 26(2)) | Named approver roles and approval rules. | Approver list and approval records. | Human oversight, Evidence |
| Spot where training is needed | Monitoring of denied actions, warnings and escalations by team. | Usage and policy-event reports. | Monitoring, Auditability |
Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.
Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.
What this does not cover
- Swfte does not provide your legal AI literacy programme. Training content for your staff is yours to commission.
- Platform controls do not replace literacy. They help make safe use the default and show who did what.
- Swfte does not certify anyone's competence, and this page is not legal advice.
Frequently asked questions
Is AI literacy training mandatory?
Article 4 requires providers and deployers to take measures to support AI literacy among staff and others using AI on their behalf. It does not prescribe a specific course or require a guaranteed level for each person.
What did the Digital Omnibus change in Article 4?
It reworded the duty to "take measures to support" literacy, clarified that no specific level must be guaranteed for any individual, and added Commission and Member State support, especially for SMEs, plus AI Board recommendations.
Does Article 4 apply to low-risk AI like a chatbot?
Yes. Article 4 applies to providers and deployers of AI systems generally, not only high-risk ones, and has applied since 2 February 2025.
What is the fine for breaching Article 4?
Article 4 has no fine provision of its own and is not named in the Article 99 tiers. Enforcement depends on national rules, so check your Member State.
What evidence should we keep?
A policy, a role map, role-specific training content and completion records, and a refresh trigger list. For high-risk systems, the named human overseers and their competence records.
Sources
Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.
- AI Act Article 4, AI literacy (AI Act Service Desk)
- Regulation (EU) 2026/1744, the Digital Omnibus on AI (EUR-Lex) (Adopted 8 July 2026, published 24 July 2026, in force 27 July 2026.)
- AI Act Service Desk: implementation timeline (European Commission) (Reflects the Digital Omnibus amendments.)
- AI Act Article 99, penalties (AI Act Service Desk)
- Regulation (EU) 2024/1689, the AI Act (EUR-Lex)
Across the platform
The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.
AI governance
Governance that runs inside AI, not beside it.
AI sovereignty
Seven kinds of control over your AI estate.
Trust Profile
The record of what each AI system is and may do.
Trust centre
What Swfte can show today, and what it does not claim.
Build EU-first AI with the evidence already running
Start with one entry point. Add governance, in-region options and evidence as your requirements grow.