The AI literacy requirement
Article 4 requires providers and deployers to ensure sufficient AI literacy among staff dealing with AI.
The AI literacy duty has applied since 2 February 2025. Providers and deployers must ensure that staff dealing with AI have a sufficient level of AI literacy (Article 4). It is already in force and was not moved with the high-risk obligations deferred under Regulation (EU) 2026/1744.
The wording is short, but it establishes a real organisational duty. It applies by role: a provider develops an AI system or places it on the market under its own name, while a deployer uses an AI system under its authority. A company can hold more than one role, so an organisation that builds one system and uses another should not assume a single answer covers both activities (Article 3).
Who needs sufficient AI literacy?
Article 4 concerns staff dealing with AI for providers and deployers. The facts sheet does not narrow that phrase to technical teams, senior leaders or employees with an AI job title. An organisation should therefore begin with the people who actually handle its AI systems as part of their work, then consider what knowledge is sufficient for the decisions and risks attached to those uses.
This is different from assuming that every person needs the same course. A customer-service employee using a chatbot, a manager relying on screening output and a developer placing a system on the market may deal with AI in materially different ways. Role-appropriate learning is a reasonable governance response to the duty, but it should be described as the organisation's method for meeting Article 4 rather than as a checklist written into the legal text.
What can sufficient literacy involve for an SME?
For a small or medium-sized organisation, the practical aim is to connect learning to the systems in use. Staff can be taught what those systems are used for, where their limits affect a person's work, and when a result should be questioned or passed to someone with more authority. These are plausible elements of role-appropriate training, not separate statutory requirements stated in the facts sheet.
The content can also reflect whether the organisation is a provider, deployer or both (Article 3). A provider team may need literacy relevant to developing and placing a system on the market under its own name. A deployer team may need literacy relevant to using a supplier's system under the organisation's authority. The legal duty remains to ensure a sufficient level; the organisation chooses a proportionate way to make that real for the people involved (Article 4).
Records that training occurred can help an organisation see who has been covered, which systems the learning addressed and where a change in role or technology calls for another look. Record-keeping is presented here as sensible evidence of the organisation's approach, not as a detailed Article 4 record format. The facts sheet does not prescribe a template, course length or renewal timetable.
How does literacy connect to prohibited practices?
Article 5 has also applied since 2 February 2025. It prohibits specified practices including manipulative or deceptive techniques causing significant harm, exploitation of listed vulnerabilities, defined social scoring, predictive policing based solely on profiling, untargeted scraping of facial images, certain emotion inference, biometric categorisation to infer sensitive attributes, and specified real-time remote biometric identification.
Literacy does not replace the prohibited-practices screen, and training does not make a prohibited use acceptable. It can help staff recognise why a proposed use needs review before it is introduced, which is one way the Article 4 duty supports a wider governance process. The legal conclusions still come from the applicable provisions, including Article 5.
Why start with literacy?
Literacy is often the least expensive governance gap to begin addressing because it can start with the systems and people already present in the organisation. A readiness review also tends to find it early: the duty applies broadly to providers and deployers, has been live since February 2025 and can be examined without waiting for the deferred high-risk dates (Article 4).
That does not mean it is the only current obligation. Prohibited practices have applied since February 2025, general-purpose AI model obligations since August 2025, and transparency obligations since August 2026 (Article 5, Chapter V and Article 50). The post-omnibus timeline places each of those dates alongside the 2027 and 2028 deferrals.
Scope comes first for a UK organisation. The Act covers providers placing systems on the EU market or putting them into service there, deployers established or located in the EU, and cases where AI output is used in the EU. A UK organisation with no EU customers, users or outputs used in the EU is not bound today (Article 2). Read the UK scope guide before treating Article 4 as a current legal duty for a UK-only operation.
Where Article 50 is also relevant, staff need to understand the live duties connected to their systems. Our transparency guide covers notices for AI interactions, machine-readable marking, emotion recognition, biometric categorisation and deepfake disclosure (Article 50).
Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Last reviewed 11 August 2026.