The AI literacy requirement
It reaches everyone who handles your AI systems as part of their work, whatever their job title says.
Providers and deployers must take measures to support the development of AI literacy among staff dealing with AI. The amended Article 4 does not require them to guarantee any specific level for any individual.
The duty is live, and the omnibus reworded it. Regulation (EU) 2026/1744 replaced Article 4: the obligation is now to take measures to support the development of AI literacy, and it expressly does not require providers or deployers to guarantee any specific level of AI literacy of any individual. It still applies from 2 February 2025, and it was not moved with the deferred high-risk obligations.
It applies by role. A provider develops an AI system or places it on the market under its own name, while a deployer uses an AI system under its authority, and a company can hold both roles at once, so if you build one system and use another don't assume a single answer covers both (Article 3). The EU AI Act overview covers the roles alongside the scope rules.
Who does the AI literacy duty cover?
Article 4 covers staff and other people dealing with AI on behalf of providers and deployers, and Regulation (EU) 2024/1689 does not narrow that phrase to technical teams, senior leaders or employees with an AI job title. Start with whoever handles your AI systems as part of their work, then take measures matched to the risks attached to those uses.
They won't all need the same thing. A customer-service employee using a chatbot, a manager relying on screening output and a developer placing a system on the market are dealing with AI in materially different ways, so match the measures to what the role actually does. The amended Article 4 asks you to support the development of AI literacy, and it does not require you to guarantee any specific level for any individual (Regulation (EU) 2026/1744).
What does this look like for an SME?
Tie the learning to the systems you actually run. Your people should know what each system is used for, where its limits bite on their own work, and when to question a result or pass it to someone with more authority.
What people need also depends on which role you're in (Article 3): a provider team needs literacy about developing and placing a system on the market under its own name, and a deployer team needs literacy about using a supplier's system under the organisation's authority.
Keeping a record of who was trained, on which systems and when, shows you where the gaps are and when a change of role or of technology means someone needs another look. The amended Article 4 prescribes no template, course length or renewal timetable, and does not require a guaranteed level of literacy for any individual, so keep whatever lets you answer the question when someone asks.
How does literacy connect to prohibited practices?
Article 5 has also applied since 2 February 2025. It prohibits specified practices including manipulative or deceptive techniques causing significant harm, exploitation of listed vulnerabilities, defined social scoring, predictive policing based solely on profiling, untargeted scraping of facial images, certain emotion inference, biometric categorisation to infer sensitive attributes, and specified real-time remote biometric identification.
Training doesn't make a prohibited use acceptable, and no amount of literacy answers whether a use is prohibited: Article 5 decides that. What literacy does is help your people spot that a proposed use needs a look before it's introduced, which is one way the Article 4 duty feeds the rest of your governance.
Why start with literacy?
It applies to providers and deployers alike and has been live since 2 February 2025, so you can work on it without waiting for the deferred high-risk dates (Article 4). The omnibus softened it to an effort-based duty to support the development of AI literacy, so treat it as a live obligation to make reasonable, matched provision rather than a guaranteed outcome (Regulation (EU) 2026/1744). Prohibited practices have applied since 2 February 2025, general-purpose AI model obligations since 2 August 2025, and transparency obligations since 2 August 2026 (Article 5, Chapter V and Article 50). The post-omnibus timeline has those dates with the 2027 and 2028 deferrals, and you can download it as a one-page PDF.
Scope comes first for a UK organisation. The Act covers providers placing systems on the EU market or putting them into service there, deployers established or located in the EU, and cases where AI output is used in the EU. A UK organisation with no EU customers, users or outputs used in the EU is not bound today (Article 2), so read the UK scope guide before treating Article 4 as a current legal duty for a UK-only operation.
Where Article 50 reaches you as well, your people need to understand those duties too. Our transparency guide covers notices for AI interactions, machine-readable marking, emotion recognition, biometric categorisation and deepfake disclosure.