The email arrives from a German enterprise customer's procurement team, three questions into a vendor security questionnaire: 'Describe the measures you have taken under Article 4 of the EU AI Act to support the AI literacy of staff and other persons operating AI systems on your behalf.' The COO of the 120-person UK software firm reads it twice. The company's people use ChatGPT daily, a support bot answers tickets, and an AI SDR tool drafts outbound emails. Nothing about any of it is written down. Legal's first instinct is 'we're not in the EU,' and procurement's instinct is that the customer will accept a sentence in the contract. Both instincts are wrong in ways that matter, and since 2 August 2026 there is a regulator whose job is to ask the same question.
What does Article 4 of the EU AI Act actually require?
It requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff and the other people who operate or use AI systems on their behalf. The text of Article 4 says those measures should take into account people's technical knowledge, experience, education and training, the context the AI will be used in, and the people or groups the system will be used on. It is a duty to act, not a guarantee of any specific competence level per person.
That last point is the recent change. The European Commission's AI literacy page notes that the Digital Omnibus amendments clarified that no specific or 'sufficient' literacy level is mandated, and that the Commission and Member States must support providers' efforts, particularly SMEs. The obligation still applies to all providers and deployers, and it has been applicable since 2 February 2025.
When does enforcement begin, and who enforces it?
Supervision and enforcement by national market surveillance authorities began on 2 August 2026, according to the Commission's AI literacy page. That means enforcement is national: each Member State's authority decides how it investigates, so your practical exposure depends on where your EU customers and operations are.
On penalties, be careful with the confident numbers circulating in vendor blogs. Travers Smith's analysis of the Commission's guidance reads it as treating inadequate staff training mainly as an aggravating factor in wider AI Act enforcement rather than a standalone offence, and notes the Commission equivocated on whether penalties could reach back to the February 2025 start date. The realistic risk is that a weak literacy record makes every other finding, a misclassified system, a missing disclosure, look worse.
Does Article 4 apply to a company outside the EU?
Often yes, indirectly. Article 2(1)(c) extends the Act to providers and deployers located in a third country where the output produced by the AI system is used in the Union. A UK, US, Dubai or Indian company whose AI-generated outputs (a support reply, a scored lead, a screening decision, generated content) reach EU users falls within that reach, even with no EU office.
There is a second, more common route: customers. Enterprise buyers in the EU are deployers themselves, and they are passing Article 4 diligence down their supply chain. If you're the vendor or contractor whose staff operate AI on their behalf, Travers Smith notes the Commission reads 'other persons dealing with the operation and use of AI systems' broadly, including contractors and service providers, with obligations scaled proportionately. Your questionnaire is that broad reading arriving in your inbox.
What can a regulator or customer actually ask you to show?
Based on Travers Smith's summary of the Commission's guidance, the standard is flexible rather than a checklist: there is no minimum training duration, no mandated curriculum, no obligation to measure literacy levels and no requirement to appoint an AI officer. What the guidance does say is that simply asking staff to read an instruction manual may be ineffective and insufficient, and that organisations should document the training they have undertaken.
So the defensible position is evidence of a considered, role-appropriate program. Concretely, a reviewer can reasonably expect to see the following:
- **An inventory of the AI systems in use**, including the unsanctioned ones, since shadow AI means the tools you don't know about are still your literacy problem.
- **A role map:** who builds, who operates, who supervises outputs, who only uses a chat tool, and who is affected by the results.
- **A curriculum matched to those roles**, covering what AI is and how it works, the risks, the organisation's own rules, and the legal and ethical context.
- **Dated records of delivery:** who attended what, which version of the material, and when it was refreshed.
- **A path for contractors and vendors operating AI on your behalf**, whether that's your training, theirs, or a documented equivalent.
What does a role-based AI literacy program look like in practice?
One deck for everyone fails the 'taking into account their knowledge and context' test in the text of Article 4. A tiered structure fits the wording, and it's also what actually changes behaviour. The table below is our working model, not a regulator-issued template.
| Audience | What they do with AI | Core content | Evidence to keep |
|---|---|---|---|
| Leadership and board | Approve AI use, own accountability | Strategy, risk appetite, risk classification under the Act | Session record, decision log |
| General staff using generative AI | Draft, research, summarise with chat tools | How models fail (hallucination, bias), data-handling rules, acceptable-use policy | Attendance, policy acknowledgement |
| Operators of customer-facing AI | Run support bots, sales agents, screening tools | Oversight duties, escalation, disclosure obligations | Role-specific training log |
| Builders and technical staff | Configure, integrate and evaluate AI | Evaluation, security, logging, model limits | Course records, review checklists |
| Contractors and vendors | Operate AI on your behalf | Your policies plus role-specific content | Contract clause, delivery record |
Illustrative tiering aligned to the factors Article 4 names: knowledge, role, context of use and the people affected.
How do you make it stick instead of ticking a box?
Design for behaviour change, because a literacy program that produces attendance sheets but no change in how people use AI is the worst outcome: you carry the cost and the false comfort. Hands-on sessions built on staff's real tasks outperform passive modules, and it's the same adoption problem behind corporate AI training that doesn't stick. Pair delivery with a measurement habit, using the approach in how to measure corporate AI training ROI, so the program earns its budget beyond compliance.
Then schedule the refresh. Tools, model behaviour and rules keep changing, and even the Act's own timelines have moved, as with the delayed high-risk deadline for financial-services automation. A dated refresher cycle is both good practice and better evidence than a one-off session from 2025.
How AIBOOTSTRAPPER helps
We don't have a published client case study for an Article 4 program, and we're not a law firm, so treat this as delivery capability rather than legal advice. What we do run is corporate AI training: 25+ programs delivered and 5,000+ professionals trained across 12+ industries, built around a mapped-pain-points, validated-curriculum, hands-on, AI-champions and monthly-refresher process, delivered on-site and remotely for teams in India, the UAE, the UK and beyond.
That structure lines up with what the Commission's guidance implies is credible: tailored to roles, practical rather than read-the-manual, and continuously refreshed, with attendance and curriculum records as a natural by-product. If you want to know where your organisation stands before you design anything, start with the AI Readiness Score, or contact us to scope a role-based program.
Want this done for you?
Book a free strategy call and we'll show you how to build and market your business with AI.
