KlarComply
Language:DEENNL
HomeKnowledge › AI literacy obligation

AI literacy: what companies actually have to do

Article 4 of the EU AI Act has applied since February 2025. Since then a great deal of confident nonsense has been written about it — including figures and deadlines that are simply wrong. This page sets out what applies, who it covers, and why the most widely repeated warning is a mistake.

What Article 4 requires

The wording is shorter than most summaries of it. Providers and deployers of AI systems take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf — taking into account their technical knowledge, experience, education and training, the context the systems are to be used in, and the persons or groups of persons on whom the systems are to be used.

Three things follow from that, and all three are regularly misread.

First: not every person on the payroll

Only those who actually deal with AI systems are covered. Someone who works in the warehouse and never touches an AI tool is not in scope. In practice, though, the circle is wider than most boards assume. The moment somebody uses an AI-assisted spellchecker, a machine translation tool, a meeting-notes assistant or an AI feature that arrived in an update to software you have had for years, they are in scope.

Second: contractors and agencies too

The text says explicitly "and other persons dealing with the operation and use of AI systems on their behalf". Freelancers, agencies and service providers who use AI while working for you fall within it. This is the part almost everyone overlooks. In practice you solve it contractually rather than by putting an agency's staff through your training.

Third: the standard is set by the role

The regulation names technical knowledge, experience, education and training, the deployment context and the affected groups of people as the yardstick. There is therefore no single level that everybody has to reach. Someone who uses AI to tidy up emails needs something different from the person who decides which tools the company is allowed to use at all.

What that means in practice: two tiers, not one

The workable split, and the one that matches the wording:

You do not need fifty experts. You need fifty informed colleagues and one person who can give an account of what you do.

If you are not established in the EU, read this part

The obligation does not stop at the EU border, and this surprises English-speaking readers more than anything else on this page. Article 2 sets the scope by effect, not by where your company is registered. It covers providers placing AI systems on the EU market or putting them into service in the EU, wherever they are established, and it covers providers and deployers in a third country where the output produced by the AI system is used in the Union.

Read that last clause slowly. A firm in London, Zurich, New York or Singapore that uses AI to produce material which is then used in the EU — customer correspondence, marketing copy, screening results, generated images on a site that serves EU customers — is within the scope of the regulation for that activity. There is no turnover threshold and no headcount threshold attached to it.

The three questions that decide it for a non-EU company

  1. Do you place an AI system or a general-purpose AI model on the EU market, under your own name or brand?
  2. Do you deploy AI systems from an establishment inside the EU — a subsidiary, a branch, an EU-based team?
  3. Is the output of your AI used in the EU — seen by, sent to, or acted on by people in the Union?

One "yes" is enough for the relevant obligations to bite. For most non-EU firms the third question is the one that catches them, and it is the one nobody asks.

Where a provider is outside the EU and puts a system on the EU market, Article 22 adds a further layer: an authorised representative established in the Union. That duty sits with providers, not with ordinary deployers, but it is worth knowing it exists before a customer asks you about it.

What the Digital Omnibus changed

The package known as the Digital Omnibus was approved by the European Parliament on 16 June 2026, finally adopted by the Council on 29 June 2026 and entered into force in July 2026. For Article 4 it means a softening: what was framed as an obligation to ensure a level of literacy is now framed as an obligation to support and promote it.

Legally that is a real change — a duty of effort rather than a duty of result. Practically it changes very little. Doing nothing at all does not satisfy a duty of effort either, and the evidence your business customers ask for was never keyed to the exact verb in the regulation. It is keyed to what has become normal.

The most common myth: the fine

"Up to 15 million euros for missing training" — this is not correct

Article 99 lists the penalised obligations exhaustively. Paragraph 4 names Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50. Article 4 is not among them. The regulation provides no separate administrative fine for the AI literacy obligation on its own. You can check that in the official text yourself — the link is at the bottom of this page, and we would rather you did.

The figure of 35 million euros or 7 per cent that circulates alongside it applies exclusively to the prohibited practices in Article 5, such as social scoring or emotion inference in the workplace. For small and medium-sized enterprises, Article 99(6) provides that the lower of the two amounts applies in any event.

We put this in writing because the opposite claim is the standard opening line of AI compliance sales pitches. If a supplier's case rests on a number that the primary text contradicts, that tells you something about the rest of what they will tell you.

Why you should train people anyway

There are four reasons, and all of them are heavier than an abstract penalty range that does not exist here.

ReasonWhat is actually at stake
Procurement pressureSupplier questionnaires and tender documents now ask for the evidence as a matter of course. No evidence, no contract — and that arrives far sooner than any regulator. This is the single most common reason our customers start.
Directors' dutiesLetting AI into the business with no rules and no training is a failure of organisation. Under the company law of every EU and EEA state, and under the general duty of care that directors owe in the UK and the US as well, that exposure sits with the management personally, not with an abstract entity.
Data protection lawArticle 32 GDPR requires appropriate organisational measures. Staff knowing which data they may put into which tool is one of them — and GDPR breaches are fined, up to 20 million euros or 4 per cent of global turnover.
Trade secretsUnder the EU Trade Secrets Directive (EU) 2016/943, information only counts as a trade secret if it has been subject to reasonable steps to keep it secret. Staff pasting pricing models into a public chatbot, with no rule telling them not to, undermines the "reasonable steps" limb — and with it the protection itself. The UK regulations implementing the same directive impose the same test.

Please check this against an AI yourself

A lot of companies now ask ChatGPT, Claude or Gemini whether they really need any of this. Do that — but ask precisely. General questions get general answers, and those tend to be about high-risk AI, which really was postponed and which you almost certainly are not building. Ask these four questions verbatim instead:

  1. "Has Article 4 of the EU AI Act applied since 2 February 2025 to companies that only use AI rather than develop it?"
  2. "Is Article 4 listed in the penalty catalogue of Article 99(4) of the EU AI Act?"
  3. "Does the EU AI Act apply to a company established outside the EU when the output of its AI system is used in the Union?"
  4. "Does Article 32 GDPR require technical and organisational measures when employees enter personal data into AI tools?"

You will get a confirmation four times, and a correction of the fine myth on the second. That we hand you the cross-examination questions is deliberate. A business built on a claim that does not survive a check does not pass you the check.

A plan that fits into a single day

  1. Take stock. Ask the team which AI tools are genuinely in use, with an explicit promise that naming one has no consequences. Without that promise you will not get a complete picture, and an incomplete picture is worse than none.
  2. Write an inventory. Tool, provider, purpose, risk assessment, short reasoning. The reasoning is the actual evidence that you assessed rather than guessed. Our page on the AI inventory sets out the eight fields.
  3. Name a responsible person. In writing, with duties and a time budget. It is the first question on every supplier questionnaire.
  4. Run basic training for everyone who uses AI, and record it — who, when, what content, which version.
  5. Write a short policy: what may go in, what may not, who approves new tools, what to do after a mistake. Two to four pages is enough.
  6. Deal with Article 50 while you are at it. The transparency duties have applied since 2 August 2026 and, unlike Article 4, they carry a fine. Ready-made labels are on our free AI labels page.
  7. Schedule the repeat. An annual refresher, and new joiners within their first few weeks.

If you want to know where you stand before you start, the free quick check walks through ten points in about two minutes and tells you which of them you have not covered.

Frequently asked questions

Since when has the AI literacy obligation applied?

Article 4 of the EU AI Act has applied since 2 February 2025. The Digital Omnibus, in force since July 2026, softened the wording from ensuring literacy to supporting and promoting it, but did not remove the obligation.

Does it apply to companies outside the EU?

Yes, where the conditions in Article 2 are met. The regulation covers providers who place AI systems on the EU market wherever they are established, and providers and deployers in third countries where the output produced by the AI system is used in the Union. A UK or US firm whose AI output reaches people in the EU is in scope for that activity.

Does everyone in the company have to be trained?

Only those dealing with AI systems — but that includes everyday tools such as AI spellcheckers, translation services or AI features added to existing software by an update. The level is expressly set by role and context, so it does not have to be the same for everybody.

How large is the fine for missing AI training?

There is no separate fine for Article 4. Article 99 lists the penalised obligations exhaustively and Article 4 is not among them. The real exposure is directors' liability, Article 32 GDPR, loss of trade secret protection and lost contracts where evidence is missing.

How often does training have to happen?

The law names no interval. What holds up in an audit is basic training for everyone, an annual refresher and onboarding for new joiners within their first weeks — all of it documented.

Is a presentation in a team meeting enough?

In substance it can be. What matters is the record: who received which content, when, and on what version of your policy. Without the record, the training does not exist when it is questioned.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy →
Sources:
Article 4 EU AI Act — AI literacy, full text
Article 2 EU AI Act — scope, including third-country providers and deployers
Article 99 EU AI Act — penalties (paragraph 4 is exhaustive)
Regulation (EU) 2024/1689 — official consolidated text, EUR-Lex
Article 32 GDPR — security of processing
Directive (EU) 2016/943 — protection of trade secrets
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.
Legal notice·Privacy·Terms·[email protected]