EU AI Act update: Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Check the consolidated AI Act and route-specific application dates before relying on older timelines. Consolidated AI Act EU AI Act update: Regulation (EU) 2026/1744 is in force; check route-specific application dates. Consolidated AI Act

EU AI Act · Pillar Guide 1B

AI Literacy Under the EU AI Act: How to Train and Document It

Use this guide to select proportionate literacy measures, distinguish legal duties from optional implementation choices, record useful evidence and route high-risk oversight questions to Articles 14 and 26.

Design your AI literacy programme → Brief managers on Article 4 → Build your training plan ↓
Published: 18 March 2026 | Last updated: 3 September 2026 |By Abhishek G Sharma
AI Literacy framework under EU AI Act Article 4 — three-tier training model with evidence requirements

What does Article 4 AI literacy require from providers and deployers?

Article 4 has applied since 2 February 2025 and was amended from 27 July 2026. The current text requires providers and deployers to take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf.

When selecting those measures, take account of the relevant people's technical knowledge, experience, education and training, the context in which the AI systems are used, and the persons or groups on whom the systems are used. The amended text also states that Article 4 does not require a provider or deployer to guarantee any specific AI literacy level for any individual.

The reference to other persons depends on the organisation's remit and the facts. It may reach contractors, service providers or others who operate or use an AI system on the provider's or deployer's behalf, but it does not make every contractor, vendor employee or client an automatic training audience. People affected by a system are a factor in the design of literacy measures; they are not automatically the direct audience for those measures.

Article 3(56) defines AI literacy through the skills, knowledge and understanding needed for informed deployment and awareness of AI opportunities, risks and possible harm. Article 4 leaves providers and deployers room to choose proportionate measures. It does not prescribe a fixed course format, quiz, pass score, employee test, external certificate, AI officer or AI governance board.

Current obligation, flexible implementation

Article 4 is binding and already applies, but its implementation is context-specific. Training courses, quizzes, certificates, tier models and completion targets can be useful internal methods; they are not statutory formats or outcomes. Supervision, enforcement measures and penalties depend on the applicable legal and national arrangements, so this guide does not attach a fixed Article 4 monetary fine.

Article 4 compared with Articles 14 and 26

These provisions can support the same control environment, but they impose different requirements. Completing a general Article 4 programme does not automatically satisfy Articles 14 or 26.

Article 4: horizontal organisational literacy measures

Article 4 requires providers and deployers to take context-sensitive measures supporting the development of AI literacy among the people within its scope. It is not limited to high-risk systems and does not prescribe one training or assessment model.

Article 14: effective human oversight of high-risk systems

Article 14 requires high-risk AI systems to be designed and developed so natural persons can oversee them effectively during use. The oversight measures must be proportionate to the system's risks, autonomy and use context. This system-level requirement is distinct from Article 4's organisational literacy duty.

Article 26: competence, training and authority for assigned oversight

Under Article 26(2), deployers of high-risk AI systems must assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. General Article 4 measures may help, but the deployer must separately address the role-specific requirements for the assigned oversight function.

Designing AI literacy by role: basic, intermediate, advanced

Article 4 does not create statutory literacy tiers. The following three-tier model is an optional practitioner framework for translating the current legal factors into role-based measures. Adapt it to the people, systems, context and affected groups in your organisation.

Dimension Basic Intermediate Advanced
Who People with occasional or low-complexity AI use, where this tier fits the context People who configure, integrate or make decisions using AI system outputs People with specialist AI, risk, compliance, development or system-owner responsibilities
Core topics What AI is, basic risks, acceptable use policy, data handling, when to escalate Model outputs and confidence levels, bias awareness, oversight duties, incident reporting EU AI Act obligations by role, risk classification, FRIA/DPIA, technical documentation, conformity assessment
Delivery format Optional briefing, guided reading or short e-learning Optional workshop, demonstration or scenario exercise Optional specialist workshop, technical exercise or supervised practice
Assessment Optional acknowledgement or knowledge check; no statutory pass score Optional scenario review or recorded discussion Optional practical demonstration or peer review
Refresh cycle Organisation-defined, revisited when roles, systems or context change Organisation-defined, including relevant system or duty changes Organisation-defined, including material technical, risk or legal changes
Article mapping Article 4 implementation context Article 4; assess other duties separately Article 4; assess high-risk and other role-specific duties separately

Table 1: Optional three-tier implementation framework. The tiers, delivery methods, assessments and review points are practitioner choices, not Article 4 requirements.

A seven-step operational approach to Article 4

The Act does not prescribe a programme structure, course format, accreditation body or curriculum. This seven-step method is a practitioner approach for selecting, delivering and reviewing proportionate measures. It is not a statutory model or a compliance guarantee.

Step 1: Inventory your AI touchpoints

Map the AI systems in use, including approved systems, unapproved tools you discover and vendor-supplied services with embedded AI features. Use the Shadow AI Discovery Protocol if you need a structured internal discovery exercise.

Step 2: Map roles to literacy levels

For each system, identify the staff and other people dealing with its operation or use on the organisation's behalf. If you use the optional three-tier model, assign levels by system and activity rather than job title alone. Record why the selected measure fits the legal factors and use context.

Step 3: Define the curriculum

Define learning objectives that match the relevant roles, systems and risks. Topics might include AI basics, acceptable use, data handling and escalation; output interpretation, bias and incident reporting; or specialist risk-classification and high-risk-system duties. Include Article 26 only for people whose work engages those separate deployer obligations.

Step 4: Choose delivery formats

Choose formats that suit the audience and subject. Guided reading or e-learning may suit straightforward topics; demonstrations, workshops or scenario exercises may suit people who configure systems or make decisions using outputs. Article 4 does not mandate any of these formats.

Step 5: Plan the rollout

Sequence measures using your actual exposure, use context and affected groups. You might prioritise system owners, people assigned high-risk oversight and teams making consequential decisions, but the appropriate order depends on the organisation's systems and gaps.

Step 6: Review and record

Review whether the selected measures were delivered and remain appropriate. Attendance records, acknowledgements, quizzes, scenario reviews or practical demonstrations are optional internal evidence methods. Article 4 does not require testing, certification or a particular pass score, and any assessment method should be suitable for the employment and data-protection context.

Step 7: Set the refresh cycle

Article 4 does not set a fixed refresh cycle. Define review triggers proportionately, such as a new system, a material change in use, new risks, incidents, role changes or relevant legal and official-guidance developments.

Use the AI Literacy Planner to structure your approach

We built a free tool specifically for this. The AI Literacy Training Planner walks you through each of the 7 steps above. It generates a role-to-level mapping, a curriculum outline, and a training schedule you can take straight into your LMS or workshop planning.

AI Literacy Training Planner

Design a role-based AI literacy programme aligned to Article 4. Map roles → literacy tiers → curriculum → delivery plan → evidence strategy. 100% browser-based, zero login required.

Launch Planner →
AI literacy evidence framework — documentation stack showing policy, curriculum, attendance records, and competency assessments

Figure: The four layers of an AI literacy evidence stack — policy, curriculum, attendance, and competency records.

Evidence that may support Article 4 review

Article 4 does not prescribe one evidence-log format. The Commission's Q&A says organisations may keep an internal record of training and other guidance initiatives. Proportionate records can help explain which measures were selected, who they covered, why they fitted the context and when they were reviewed.

Policies

Where useful, document the organisation's acceptable-use expectations and its approach to AI literacy. Article 4 does not mandate two policies, board approval, an AI officer or a governance board. Use the existing AI Literacy Policy Template only if it fits your governance model.

Training materials and curricula

Consider retaining the versions of modules, briefings, scenario exercises or job aids actually used. This helps connect the measure to the relevant audience and system context without turning one delivery format into a legal requirement.

Attendance and completion records

Depending on the context, record the audience, date, measure and completion or acknowledgement status. A score is optional. Limit personal data to what is necessary and apply the organisation's retention and access rules.

Optional reviews and assessments

A knowledge check, scenario discussion, survey or practical review may help the organisation test and improve its measures. These are internal choices, not statutory tests or certificates. Record the method and interpretation carefully, without treating a completion rate or score as proof of compliance.

Use the AI Literacy Evidence Log if a structured record is useful, and connect identified gaps to the organisation's broader AI risk and governance processes.

AI literacy as your first line of defence against shadow AI

Shadow AI means AI tools used without the organisation's approval or awareness. Appropriate literacy measures can help people recognise AI-enabled functions, understand data-handling restrictions and know when to raise a proposed tool or use with the responsible team.

Literacy measures are only one part of this control. Pair them with proportionate inventory, acceptable-use, procurement and escalation processes. The Shadow AI Discovery Protocol and AI Vendor Risk Screener can support those separate activities.

Two example AI literacy programme blueprints

These two illustrative models show how the same legal factors can produce different internal approaches. They are not statutory staffing, timing, cost or delivery assumptions.

Dimension Smaller organisation with straightforward use Larger organisation with mixed or high-risk use
AI inventory A small set of general-purpose or embedded AI functions Several systems across teams, potentially including high-risk uses
Audience design Group people by the systems and activities they actually perform Map system owners, users, decision-makers and any assigned high-risk oversight roles separately
Delivery A concise briefing or guided module, with role-specific follow-up where needed A mix of general modules, system-specific instruction and practical exercises
Timeline Set from the current gap, available resources and use context Phase by exposure and dependencies, without assuming a fixed deadline
Evidence artefacts A proportionate record of the measures, audience, materials and review decision Versioned materials, audience mapping, delivery records and separate high-risk oversight evidence where applicable
Resource model May use existing internal guidance and delivery channels May require specialist input, system owners and learning or governance support
Key risk if skipped Shadow AI incidents and weak evidence during authority or customer review Human oversight failures on high-risk systems, procurement due diligence failures, and weak evidence during authority or customer review

Table 2: Illustrative implementation patterns. Organisation size alone does not determine the appropriate measures; systems, roles, knowledge, use context and affected groups also matter.

Use the lighter model only where it is proportionate to the actual systems and roles. Where high-risk AI is involved, keep Article 4 measures distinct from the system and oversight requirements under Articles 14 and 26.

For SMEs specifically, our current application-dates guide for SMEs covers AI literacy alongside the provision-specific timeline.

Regulation (EU) 2026/1744: the Article 4 amendment

✓ Regulation (EU) 2026/1744 entered into force on 27 July 2026

The Regulation (EU) 2026/1744 amendment revised Article 4. Providers and deployers must take measures to support the development of AI literacy, taking account of technical knowledge, experience, education, training, context and affected persons. The amended text does not require them to guarantee a specific literacy level for any individual.

Article 4 has applied since 2 February 2025; the 2026 amendment changed its wording rather than postponing its application. Review existing measures against the current factors and retain proportionate records without treating a course or certificate as a compliance determination.

Existing Article 4 resources

Choose the existing resource that matches your next task. These resources support implementation and record-keeping; they do not determine compliance.

FAQ: AI literacy and Article 4

Does Article 4 AI literacy apply if we only use off-the-shelf AI tools?

Yes, where you are a provider or deployer and staff or other persons deal with the operation or use of the tool on your behalf. Its off-the-shelf origin does not remove Article 4. Select measures using the relevant technical knowledge, experience, education, training, use context and persons or groups on whom the system is used.

Do we need formal certification for AI literacy under the EU AI Act?

No. Article 4 does not mandate certification, an examination, an accredited programme, employee testing or a pass score. It requires measures supporting the development of AI literacy and does not require a guaranteed individual level. A quiz, assessment or certificate is an optional internal implementation or evidence choice.

How often must AI literacy training be repeated?

The EU AI Act does not specify a fixed refresh cycle. Set review triggers that fit the roles, systems and use context, such as a new system, a material change in use, new risks, incidents, role changes or relevant legal and official-guidance developments. An annual cycle may be an internal choice, not a statutory minimum.

Does Article 4 AI literacy apply to contractors and third-party staff?

Not automatically in every relationship. Article 4 covers staff and other persons dealing with the operation and use of AI systems on the provider's or deployer's behalf. Depending on the facts and organisational remit, this may include contractors, service providers or other third parties, but it does not make every contractor, vendor employee or client an automatic training audience.

What are the penalties for failing to comply with Article 4?

Article 4 has applied since 2 February 2025. Article 99 does not list Article 4 in the fixed maximum fine tiers in Article 99(3), (4), or (5). National market-surveillance authorities may impose penalties or other enforcement measures under Member State rules, with proportionality and case-specific factors. This page therefore avoids a fixed Article 4 monetary fine figure.

How did Regulation (EU) 2026/1744 change Article 4 requirements?

Regulation (EU) 2026/1744 amended Article 4 from 27 July 2026. The current text requires providers and deployers to take measures supporting the development of AI literacy, taking account of technical knowledge, experience, education, training, context of use and the persons or groups on whom the systems are used. It also states that they do not have to guarantee a specific AI literacy level for any individual.

Is there a standard curriculum for AI literacy under the EU AI Act?

No statutory curriculum is prescribed. Article 3(56) defines AI literacy broadly, and the Commission's Q&A gives examples of matters an organisation might cover. Providers and deployers choose proportionate measures using the Article 4 factors. The three-tier model and seven-step method on this page are optional practitioner approaches, not official curricula.

How does Article 4 AI literacy relate to Article 14 human oversight?

They are distinct requirements. Article 4 concerns horizontal organisational measures supporting AI literacy. Article 14 requires high-risk systems to be designed and developed for effective human oversight. Article 26 requires deployers to assign high-risk oversight to natural persons with the necessary competence, training and authority, and to give them the necessary support. General Article 4 training does not automatically satisfy Articles 14 or 26.

Further reading on EU AI Act compliance

AG

Abhishek G Sharma

Founder & CEO, Move78 International Limited. 20+ years in cybersecurity and AI risk management. Certifications: ISO 42001 LA, ISO 27001 LA, CISA, CISM, CRISC, CEH, CCSK, CAIGO, CAIRO.

Need More Practical Guidance?

Explore the free EU AI Compass tools and guides to classify your use case, understand your obligations, and move to the next compliance step.

Disclaimer & educational purpose

This guide is published by Move78 International Limited for educational purposes only. It does not constitute legal advice. The EU AI Act (Regulation (EU) 2024/1689), as amended by Regulation (EU) 2026/1744, is a complex legislative instrument, and its interpretation may vary by jurisdiction and national implementation. Organisations should consult qualified legal counsel for decisions specific to their circumstances. Regulatory status reviewed 3 September 2026.

Sources and legal basis

  • Binding law: Consolidated Regulation (EU) 2024/1689, version dated 27 July 2026, including Articles 3(56), 4, 14, 26, 99 and 113.
  • Binding amendment: Regulation (EU) 2026/1744, published 24 July 2026 and in force from 27 July 2026.
  • Official explanation: European Commission, AI Literacy Questions and Answers. This explains the Commission's current view of scope and possible measures; the consolidated regulation controls where summaries differ.
  • Practitioner recommendations: The three-tier framework, seven-step method, example delivery formats and evidence suggestions on this page are optional implementation approaches, not statutory or Commission-prescribed models.
  • Penalty qualification: This page does not state a fixed Article 4 monetary fine. Validate jurisdiction-specific enforcement and penalty statements against applicable Member State rules and qualified counsel.