The European AI Act sounds like a matter for corporations and software vendors. One part of it, however, affects almost every business that uses AI tools: the AI literacy obligation in Article 4. It has applied since 2 February 2025 and was amended in summer 2026.

This article explains what lies behind it and what you can do in practice. It is not legal advice. The regulation and how it is interpreted are still developing, and experts do not agree on every point. Whether and how the obligations affect your business is something to clarify with a lawyer or your data protection officer (as of September 2026).

What Article 4 says

Article 4 is aimed at two groups: providers, who develop and sell AI systems, and deployers, who use AI systems in the course of their professional activity. Deployers therefore include companies that give their staff ChatGPT, Microsoft Copilot or an AI translation tool.

In its original wording, providers and deployers were to ensure that their staff have a sufficient level of AI literacy. This means the knowledge needed to use AI competently: what the tools can do, where they make mistakes and what consequences their use can have. Staff’s prior knowledge counts, and so does what the AI is used for.

What changed in 2026

With the so-called Digital Omnibus, the EU revised the AI Act. The amending regulation has been in force since 27 July 2026. For Article 4, as we understand it, this means: the obligation remains but is worded differently. Companies must take measures to promote the AI literacy of their staff. They no longer have to guarantee a particular level of literacy for each individual. What else the Omnibus changed is summarised in our news item AI Act amended.

In practice the task remains the same: whoever introduces AI tools also explains them. What has changed is rather what you are measured against. The point is that the business visibly takes care of it, not that every employee passes a test.

The Omnibus also postponed the obligations for so-called high-risk AI. For most of these systems they now apply from 2 December 2027, and for AI in certain regulated products from 2 August 2028. For a business that uses AI to write and summarise, this usually makes no difference. Pay attention if AI is to have a say in decisions about people, for example when selecting job applicants. Such uses may count as high-risk and should be checked legally beforehand.

What AI literacy means in practice

Nobody needs to understand how a language model calculates. Staff should know what matters for their work with the tool. That depends on the role:

Role What they should know
Everyone who uses an AI tool which tool is approved, which data may go in, that answers can be wrong and are checked
Managers what the department uses AI for, who is responsible for the results, when a question goes to the managing director
Whoever selects or sets up AI tools contracts and where data is stored, permissions and sharing, what is logged
Managing director where AI is and is not used in the business, and who looks after it

The core message for everyone is simple: AI delivers suggestions, not decisions. Whoever uses a result has read it and answers for it. Why that is so is explained in What AI cannot do for your business.

Which measures make sense

The regulation prescribes neither a particular training course nor a certificate. So be careful with offers that advertise a “mandatory certificate”. For most businesses a few manageable steps are enough:

  • Get an overview. Write down which AI tools are used in the business, by whom and for what. This includes the tools nobody officially introduced. How to find out about them without anyone having to be afraid is described in Shadow IT and shadow AI.
  • Write down the rules. Which tool is approved, which data may go in, who checks the result? One page is enough. What belongs on it is shown in ChatGPT and Copilot at work.
  • Brief your staff. A short briefing per tool, ideally with examples from your own work: a good answer, a wrong answer, a text that must not go out like that.
  • Name a contact. Someone people can ask when they are unsure or when something has gone wrong.
  • Record what has been done. Who was briefed when, and which rules apply. This helps if someone asks later, and it shows where something is still missing.
  • Refresh it. Tools change, new staff join. Make the briefing a fixed part of onboarding.

Labelling where customers talk to AI

Besides Article 4, the regulation contains transparency obligations that have applied since August 2026. Put simply: anyone talking to an AI system should be able to recognise that, and certain AI-generated content should be recognisable as such. For a business this matters above all when customers come into contact with AI, for example through a chatbot on the website. What to keep in mind is described in A chatbot on your website.

Checklist

  • Do you know which AI tools are used in your business?
  • Are there approved tools with business accounts instead of personal ones?
  • Are the rules for using them on one page that everyone knows?
  • Have staff been briefed, and is that recorded?
  • Is there a contact for questions?
  • Does AI have a say in decisions about people anywhere, and has that been checked legally?

AI literacy is less a formality than the precondition for AI to bring anything to the business at all. People who know their tools use them where they help. Where that might be in your business is something we can work out together. How is shown on our AI Consulting page.