Providers and deployers of AI systems shall take measures to
ensure, to their best extent, a sufficient level of
support the development of AI literacy among their staff and other
persons dealing with the operation and use of AI systems on their behalf.
Read the change as a regulator would. When the obligation is one of effort rather than result, there is no outcome standard left to point at. The record of what you did becomes the only thing anyone can assess.
Check whether it applies to you or read what the obligation requiresProviders and deployers of AI systems must take measures to support the development of AI literacy among their staff and other people operating AI systems on their behalf, taking account of their skills, experience, education, and the context the systems are used in.
Regulation (EU) 2026/1744 replaced Article 4 in full on 27 July 2026. The redline at the top of this page is the whole of the change. What it does to your position is larger than the edit looks:
| Until 27 July 2026 | From 27 July 2026 |
|---|---|
| Implied a standard to be reached | Explicitly does not require you to guarantee any specific level of AI literacy of any individual |
| Obligation of result | Obligation of effort |
The duty was not repealed, and this was not automatic. The Commission's original proposal would have weakened Article 4 much further. The European Data Protection Board and the European Data Protection Supervisor advised against it, and the final text keeps a direct, binding duty on providers and deployers. A second paragraph now tasks the Commission and member states with helping organizations meet it, with particular regard to smaller companies.
Three features catch people out. It applies regardless of risk tier, so a finance team using a copilot is in scope just as much as a high-risk system is. It reaches contractors and anyone operating AI on your behalf, not only employees. And it remains explicitly proportionate to role and context, which means a single organization-wide briefing is thin for staff whose work is materially affected by AI output.
The AI Act does not follow where you are established. It follows where your AI is used and where its output lands. Providers and deployers based outside the EU are bound where the output produced by their AI systems is used within the union.
In practice that catches a lot of American mid-market companies who assume this is somebody else's problem:
| If this is true | Then |
|---|---|
| You have EU customers whose users receive AI-generated output | In scope as a provider or deployer depending on your role |
| You employ anyone based in an EU member state, including remote staff | Those people are staff for the purposes of the obligation |
| A partner embeds your AI output into a service sold in Europe | Reach can be indirect and still count |
| You screen candidates, including EU applicants, with automated tools | In scope, and additional obligations may apply on top |
The corollary matters too. If none of these are true today, Article 4 does not apply to you today. One European client changes that, usually without anyone noticing.
Most coverage of the Omnibus read the rewrite as a reprieve. Read it again as a regulator would. If the duty were to reach a standard, there would at least be a standard to argue about. Now the duty is to take measures. The only question anyone can ask is what measures you took, whether they were proportionate, and what proof exists that you took them.
Documentation is no longer part of your compliance position. It is the entire compliance position. Softening the standard raised the value of the record.
And the regulation still declines to define the shape of those measures. It mandates no curriculum, no certificate, and no examination. There is no approved course, no accreditation body, and no score to hit. You design the approach, and you carry the burden of explaining why it was reasonable for an organization like yours.
Two things are worth stating plainly, because vendors in this space often blur them. There is no legal obligation to measure your employees' AI literacy, and since July 2026 there is no obligation to guarantee any individual reaches a particular level. Measurement is not the requirement. It is simply the strongest available evidence that the measures you took were proportionate, that they were aimed at the right gaps, and that something changed.
You will find vendors, and some law firm marketing, asserting that Article 4 carries exposure of up to 15 million euro or 3 percent of worldwide turnover. Read the statute.
Article 99(4) sets that tier for an enumerated list of provisions: provider obligations under Article 16, authorised representatives under Article 22, importers under Article 23, distributors under Article 24, deployer obligations under Article 26, notified bodies under Articles 31, 33 and 34, and transparency under Article 50.
Article 4 is not on that list. There is no dedicated EU-level penalty tier attached to the AI literacy duty.
| Mechanism | What it means for you |
|---|---|
| National penalty regimes | Member states must lay down their own effective, proportionate and dissuasive penalties and designate competent authorities. Exposure varies by country rather than being set centrally. |
| Aggravating factor | Regulators have signalled that Article 4 is unlikely to be enforced in isolation, but that a literacy gap can weigh in the assessment of other breaches. Irish regulators have said as much publicly. |
| Proportionality in any investigation | A dated, maintained record is what separates a good-faith outcome from a maximal one when something else goes wrong. |
| Commercial friction | The cost most organizations actually meet first. Customer security reviews, vendor questionnaires and RFPs now ask about AI governance, and there is no regulator involved in losing that deal. |
We would rather tell you this than sell you a number. If a supplier is quoting you a headline fine for Article 4 specifically, ask them which subsection of Article 99 they are reading.
Under an obligation of effort the question is not whether your people are literate enough. It is whether you can show what measures you took, why they were proportionate to your organization, and what evidence exists that they were aimed at real gaps. Most organizations have a partial answer to the first. Very few have anything for the third.
| Weak position | Defensible position |
|---|---|
| Training was made available to anyone who wanted it | Training assigned by role, based on how each team actually uses AI |
| Completion records scattered across an LMS, Slack, and inboxes | One record: who, what, when, mapped to role |
| Completion rates reported as the outcome | A measured baseline showing what people understood before and after |
| Nobody named as accountable | A named owner, with the reasoning behind the chosen standard written down |
| Done once, at rollout | Re-measured as AI use in the organization changes |
The gap between the two columns is not usually effort. It is that most organizations bought training and assumed the evidence came with it. Under the amended Article 4, the evidence is the part that counts.
Find out whether Article 4 applies to your organization and what your current evidence position would look like if someone asked. Takes about three minutes.