Skip to content
Novot AI
NLBook a call
← Back to knowledge base

AI literacy: what does Article 4 ask of your staff?

Article 4 of the AI Act requires you to take measures supporting the AI literacy of everyone who works with an AI system on your company's behalf — including temp workers, freelancers and outsourced agencies. The duty has applied since 2 February 2025. The law prescribes no course, certificate or test: you choose the measures that fit your system, your people and the context of use. In practice it comes down to everyone knowing what the system does, where it fails, when a human takes over and which data may go into it — and recording that.

Published on

There is one rule in the AI Act that already applied before most business owners had even heard of it, and it is also the least spectacular one. No registration duty, no certification mark, no technical file. Just this: if you use AI, you have to make sure the people working with it understand what they are dealing with. That is Article 4, on AI literacy. It sits in Chapter I of Regulation (EU) 2024/1689, and that is exactly why it took effect early: it is the foundation the other obligations rest on.

For a small business that lets AI handle part of its email, WhatsApp or phone traffic, this is the first question a regulator can ask. Not "where is your conformity assessment", but "does the person operating this system know what it can and cannot do?" Below is what the law actually says, what changed in its wording in July 2026, and what you practically do with it in a small company.

Since when has this applied?

The AI Act was not switched on all at once. Article 113 governs the phase-in and states: "This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. It shall apply from 2 August 2026." That is the headline date, and it carries obligations such as the transparency duty in Article 50 — the notice telling a customer they are talking to AI.

But the same Article 113 moves two parts forward. Chapters I and II have applied since 2 February 2025. Chapter II is the list of prohibited practices. Chapter I contains the general provisions, and that is where Article 4 lives. The AI literacy duty is therefore a year and a half older than the rest of the regulation everyone talks about. If you only started thinking about the AI Act in 2026, you are already running behind on this point.

That is not a disaster, because the duty is continuous in nature. You do not have to prove you did something back in February 2025. You have to be able to show you have it arranged now, and that you keep it up to date when the system or the team changes.

What does Article 4 actually say?

The text as it currently stands reads: "Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account" their technical knowledge, their experience, their education and training, the context the systems are to be used in, and the people or groups of people the systems are used on.

Pay attention to one thing here, because this is where a lot of published guidance goes wrong. The original 2024 text said you had to ensure a sufficient level of AI literacy. That is an obligation of result: the level had to be there. Under Regulation (EU) 2026/1744, the so-called Digital Omnibus, that was softened as of 27 July 2026 into supporting the development of AI literacy. That is an obligation of effort: you have to do something about it and be able to show it.

In practice the difference matters less than it sounds — either way you have to take measures. But it shifts the bar from "can I guarantee everyone understands it" to "can I show I am making a serious effort". If you come across an article or a course brochure quoting the 2024 wording, you are reading outdated law.

What does "a sufficient level of AI literacy" mean?

The regulation defines AI literacy itself, in the definitions in Article 3: it is the skills, knowledge and understanding that allow someone to deploy an AI system in an informed way and to be aware of the opportunities, the risks and the possible harm. That is deliberately broad. It does not say "an eight-hour course" and it does not say "knowledge of machine learning".

The word doing the most work in Article 4 is context. The law says you take into account the context the system is used in and the people it is used on. For an AI that summarises internal meeting notes, the bar is low. For an AI that speaks to customers on behalf of your company, books appointments or gives price indications, the bar is higher: there, a mistake reaches a customer.

Translated to customer contact, a sufficient level roughly means this: the people working with the system know what the system does, where it goes wrong, when a human takes over, and what they may and may not put into it. No more than that, but no less either.

The law does not prescribe a single measure

This is the point where the market sells the most nonsense. The Dutch Data Protection Authority, the regulator watching this in the Netherlands, puts it as plainly as possible: organisations that develop or use AI systems are obliged to take measures to promote AI literacy among their staff, and exactly which measures those should be is not stated in the law.

So there is no mandatory course, no recognised certificate, no designated provider and no prescribed number of hours. A vendor claiming its training is "mandatory under the AI Act" is saying something that is not true. What is true: you have to do something, and that something has to fit your system and your people.

The same level-headedness comes from the European Commission, which writes in its questions and answers on AI literacy: "Article 4 of the AI Act does not entail an obligation to measure the knowledge of AI of employees." In other words: you do not have to test or measure your staff's knowledge level. No exam, no scoresheet, no annual re-assessment. That takes the sting out of the story that every business needs a certification programme.

Who does it cover — and why that includes your temp worker

Article 4 addresses "providers and deployers". For most small and medium-sized businesses you are the second one. The regulation defines a deployer as "a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of" a personal, non-professional activity. The builder of the chatbot is the provider; you, letting it loose on your own customers, are the deployer. The exemption for private use therefore does not help a business.

The scope inside your company is wider than just people with a contract. Article 4 speaks of "their staff and other persons dealing with the operation and use of AI systems on their behalf". That is the phrase that pulls in the temp worker, the freelancer on the service desk, the intern, the outsourced answering service and the external marketer. Whoever presses the button on your company's behalf is covered. Your system's vendor is a different story: that company has its own duty towards its own people, not towards yours.

The reason this matters is not only legal. Statistics Netherlands looked at why micro-enterprises that considered AI decided against it: for micro-enterprises that considered using AI technology in 2025 and still decided not to, "lack of experience" was by far the most important reason, at 71.6 percent. So lack of knowledge is not only something the legislator wants to fix; it is the reason most small businesses never start at all.

Who needs to know what in a small company?

A ten-person business has no departments, but it does have roles. The overview below translates Article 4 into those roles. It is not a legal scheme — the law names no roles — but a way to make the requirement to "take into account knowledge, experience and context" workable.

Roles around AI in customer contact at a small company, and what each person needs to understand as a minimum to satisfy Article 4
Role What that person needs to know as a minimum What goes wrong when that is missing
Owner or management Which role the company has (deployer or provider), which obligations follow from it, and who inside the company is the point of contact Nobody feels ownership; obligations are left with the vendor, who does not have them
Customer contact staff That the system makes mistakes and invents things, how a conversation is taken over, and that the customer must know they are talking to AI An invented answer goes out as a commitment and nobody steps in
Whoever manages instructions and answers How the system arrives at answers, which sources it uses, and that changing the instructions changes the behaviour Changes happen ad hoc; nobody knows any more why the system says what it says
Whoever enters or exports customer data Which data may and may not go into the system, and that special categories such as health data have extra protection Sensitive data ends up in a system it was never agreed for
Contractor or external agency The same basics as an employee, plus what happens to the data once the assignment ends The duty gets skipped because "that person is not on the payroll" — while Article 4 names them explicitly
Stand-in or backup How the system is switched off and who to call when it behaves strangely During a holiday week nobody dares to stop the system

What you can do in practice without turning it into a project

Because the law prescribes no measures, it is allowed to be small. A workable approach for a company of up to roughly twenty people looks something like this:

  1. Put on one page what the system does. Which channels it handles, which questions it takes and which it does not, and what it must never promise.
  2. Write down the boundaries. When does it hand over to a human, and which topics does it never touch.
  3. Explain the failure modes. That the system can say wrong things with full confidence, that it can repeat outdated information, and that it does not know what it does not know.
  4. Make one agreement about data. What may and may not be pasted in, and where conversations are stored.
  5. Spend half an hour together at the table. Let the system get something wrong live and discuss what you do then. That sticks better than an e-learning module.
  6. Repeat it whenever something changes. New employee, new vendor, new feature in the system: walk through it again.

Tie this to the instructions you already receive from your vendor. The system's instructions for use are not an AI literacy policy, but they are the best starting point: they state what the system is intended for and what it is not.

How do you show you have arranged it?

There is no prescribed form of evidence, just as there are no prescribed measures. But an obligation of effort that is recorded nowhere is hard to demonstrate when the regulator asks. Keep it simple and keep it up:

  • The one-pager on what the system does and where the boundaries are, with a date on it.
  • A short list of who received the explanation and when — including contractors.
  • The vendor's instructions or manual, stored with your own records.
  • A brief note with every change to the system: what changed and who was brought up to speed.

That is not a test, and it does not need to be: the Commission says explicitly that you do not have to measure the knowledge level. It is a log of your effort. For most small businesses it fits in a single folder, and keeping it up costs a few minutes per change.

Three misconceptions you often hear

A lot of sales talk circulates around this provision. Three things you can safely set aside:

  • "You have to buy a recognised AI course." No. The regulator states literally that the law does not say which measures they must be. So there is no recognition you need either.
  • "Your staff have to pass a test." No. The European Commission writes that Article 4 entails no obligation to measure employees' AI knowledge. Keeping a score is allowed, but it is not required.
  • "This only applies from August 2026." No. That is the date the regulation as a whole became applicable. Chapter I, containing Article 4, has applied since 2 February 2025.

Where does Article 4 stop?

AI literacy is a separate, standalone duty. It is independent of your system's risk class: even if your application is not high-risk, Article 4 applies. And it replaces nothing. The transparency duty — the customer must know they are talking to AI — is a different provision with a different date. The GDPR obligations around legal basis, retention periods and processor agreements stand on their own. A well-informed team does make those other obligations easier to meet, because most mistakes in customer contact happen because someone did not know what the system was doing.

In short: Article 4 asks for no investment, no certificate and no exam. It asks that you write down what your system does, that you explain it to everyone who works with it, and that you keep that current. Skip it, and you are empty-handed when something goes wrong — which is exactly the risk the provision is meant to cover.

See what Novot AI can do for your business.

Book a call