COMPLIPATHDOC complipath.io/guides/eu-ai-act-ai-literacyRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Requirements ·By Yobel Tzegai ·Updated 20 August 2026

Who does the EU AI Act's AI literacy duty apply to?

Written 20 August 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

Every provider and deployer of AI systems, at any risk level. Article 4 carries no risk qualifier, so a company whose entire inventory is residual owes it — and since 27 July 2026 it asks for measures that support development, not a level you can certify.

Quick answer

What does Article 4 require now?

Regulation (EU) 2026/1744, point (5), replaced Article 4 in its entirety. Paragraph 1 reads:

"Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."

Two things in that sentence decide most programmes. The duty reaches staff and other persons dealing with the operation and use of AI systems on their behalf — contractors and outsourced operators are inside it, employment status is not the test. And the measures are calibrated on four inputs plus a fifth about other people: technical knowledge, experience, education and training, the context the systems are to be used in, and the persons or groups of persons on whom the systems are used. That last limb points outward, at the people a system is applied to, and it is the one summaries drop.

Two further paragraphs are new. Article 4(2) puts the Commission and the Member States behind providers and deployers, "in particular SMEs", and requires the Commission to publish practical compliance examples on the single information platform referred to in Article 62(3), point (b). Article 4(3) tasks the Board with adopting recommendations "taking into account European competence frameworks", including by setting out common objectives.

What changed against the 2024 wording?

The old formula — "ensure, to their best extent, a sufficient level of" AI literacy — is gone, and with it the idea that the article asks for an outcome per person. What replaces it is a duty of support, with a second sentence saying in terms that no particular level in any individual has to be guaranteed.

If your programme was built to evidence a level — a pass mark, a completion threshold per employee — the law no longer asks for that. It asks what measures you took to support development, and the four calibration inputs are what makes a measure defensible. A single company-wide course, unchanged for everyone, satisfies none of them by construction: it takes no account of technical knowledge, experience, education and training, or context.

The term itself is defined in Article 3, point (56) — a definition wider than "training":

"'AI literacy' means skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause"

When did it start applying?

2 February 2025. Article 4 sits in Chapter I, and Article 113, third paragraph, point (a) applies Chapters I and II from that date — eighteen months before the main 2 August 2026 application date and long before the high-risk regime.

The 2026 rewrite did not re-date it. The new wording binds from the amending regulation's own entry into force, 27 July 2026, under Article 113, third paragraph, point (d) as inserted. So there are two periods, and a programme documented before July 2026 was documented against a standard that no longer exists.

What happens if you ignore it?

Honestly: it depends on your Member State, and it is not assessable from the Regulation's text alone. Article 4 appears nowhere in the specific fine tiers of Article 99(3) to (5). It is enforced through Article 99(1) — also replaced in 2026 — which now requires Member States to lay down rules on "penalties and other enforcement measures, which may also include administrative fines, warnings and non-monetary measures, applicable to any infringement of this Regulation by operators", taking into account the Commission's Article 96 guidelines. The penalties must be "effective, proportionate and dissuasive".

That is a real duty with an exposure nobody can size for you from Brussels. The fine tiers that can be sized are in the penalties guide.

What this means for you

If you're a provider: the duty attaches to the systems you place on the market, whatever they classify as, so it does not wait for a high-risk verdict. Record which people deal with the operation and use of each system on your behalf, what you did for them, and why that was calibrated to their knowledge, experience, education and training and to the context. Contractors count. A register that carries each system's classification is where that record belongs, because the calibration argument is per system and not per company.

If you're a deployer: you owe the same duty for the systems you run, including bought ones — the vendor's training is a measure you took only if you actually gave it to the people who use the system. The limb about "persons or groups of persons on whom the AI systems are to be used" reaches your customers and your candidates, not only your staff. That is what makes an outward-facing explanation part of the programme rather than marketing. Which duties are yours rather than your vendor's is settled in provider versus deployer.

Which of your systems does it reach?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Does the AI literacy duty apply to minimal-risk AI?

Yes. Article 4 binds providers and deployers of AI systems without any risk qualifier, so it applies even when every system you run is residual. What minimal risk actually owes covers the rest of that tier, and the duty is the one obligation that survives it.

Do we have to certify that our staff reached a level?

No, and that changed in 2026. Article 4(1) now says the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". What it asks for is measures that support development, calibrated to knowledge, experience, education and training and to context.

Does it cover contractors?

Yes. The article reaches "staff and other persons dealing with the operation and use of AI systems on their behalf". Employment status is not the test; dealing with the operation or use of the system on your behalf is. An outsourced support team running a bought AI system is inside the duty.

What is the fine for breaching Article 4?

There is no tier for it. Article 4 appears in none of Article 99(3) to (5), and exposure comes from national rules made under Article 99(1), which requires effective, proportionate and dissuasive penalties and other enforcement measures. The amount is a national question, not a Regulation one.

Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 3, 4, 62, 96, 99 and 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 4 in its entirety (point (5)) and replaced Article 99(1) (point (38)(a)). This page was split out of what minimal-risk AI owes on 20 August 2026: the duty is not a property of the residual tier, and it was the longest section of a guide about a tier it does not belong to.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.