AI Literacy Training Under the EU AI Act: What Article 4 Requires in 2026

Aug 28, 2026

AI Literacy Training Under the EU AI Act: What Article 4 Requires in 2026

Every organisation in the EU that uses an AI system has been under a legal duty to see to the AI literacy of its staff since 2 February 2025. That duty did not go away this summer. It was rewritten, softened in one specific respect, and then handed to national supervisors who gained their enforcement powers in the first days of August 2026. If you have been waiting for the law to settle before doing anything, it has now settled, and the answer is that you have an obligation.

The confusion is understandable. Between November 2025 and July 2026 the AI Act was amended for the first time since its adoption, and the headlines said the EU had delayed its AI rules. Parts of that are true. The parts that matter most to an ordinary employer are not.

What actually changed on 27 July 2026

The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is the first set of amendments to Regulation (EU) 2024/1689 since the AI Act was adopted in June 2024. It followed a difficult negotiation: the first trilogue collapsed on 28 April 2026, agreement was reached on 7 May, the Parliament endorsed the text on 16 June and the Council approved it on 29 June.

Three things happened that an employer needs to hold separately in mind.

The high-risk obligations were deferred. Stand-alone high-risk systems under Annex III, which covers recruitment, credit scoring, education, biometrics and several other sensitive uses, now apply from 2 December 2027 rather than 2 August 2026. High-risk AI embedded in regulated products under Annex I moves to 2 August 2028. This is the deferral the headlines described, and it is real. It is also the part least likely to apply to you unless you build or deploy AI in one of those specific domains.

The transparency obligations were not deferred. Article 50, which requires disclosure when people are interacting with an AI system and marking of synthetic content, applies from 2 August 2026 as originally scheduled. A narrow carve-out moves the Article 50(2) marking requirements for systems already on the market to 2 December 2026, and two new prohibitions covering AI-generated non-consensual intimate imagery and child sexual abuse material also take effect on that date.

Article 4, the AI literacy duty, was softened but survived. This is the change that matters most to the largest number of organisations, and it deserves its own explanation.

2 Feb 2025Article 4 AI literacy duty applies
27 Jul 2026Digital Omnibus in force; Article 4 rewritten
2 Aug 2026Article 50 transparency; national supervision begins
2 Dec 2026Article 50(2) marking carve-out ends; two new prohibitions
2 Dec 2027Annex III stand-alone high-risk obligations
2 Aug 2028Annex I embedded high-risk obligations

The AI literacy duty, before and after

In its original form, Article 4 required providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy among their staff and other persons operating AI systems on their behalf, taking into account their technical knowledge, experience, education and training, and the context in which the systems are used.

The Commission’s November 2025 proposal would have removed the binding obligation altogether and turned it into a duty on the Commission and member states to encourage employers to act. That proposal did not survive. What emerged instead is a rewritten Article 4 that requires providers and deployers to take measures supporting the development of AI literacy among the same population.

The distinction is between an obligation of result and an obligation of effort. Under the original wording you had to arrive at a sufficient level of literacy, and a regulator could in principle ask you to demonstrate that your people had reached it. Under the amended wording you have to take appropriate measures aimed at developing that literacy, and you demonstrate compliance by showing what you did rather than by proving what your staff know.

That is a genuine relaxation and it is fair to describe it as such. It is not a repeal, and reading it as one is the mistake to avoid. The duty still binds every deployer, it has applied continuously since February 2025, and national market surveillance authorities gained their supervisory powers over it in the first days of August 2026. An organisation that has done nothing since February 2025 has been in breach for eighteen months, and the softening of the standard does not retroactively cure that.

Who this applies to

The AI Act divides responsibility mainly between providers, who develop AI systems and place them on the market, and deployers, who use AI systems under their own authority. Almost every Nordic employer reading this is a deployer.

Deployer status does not require you to have built anything. If your marketing team uses a generative writing tool, if your developers use an AI coding assistant, if your recruiters use a screening feature inside an applicant tracking system, if your customer service platform has an AI-drafted reply function, you are deploying AI systems and Article 4 applies to you. The threshold is not sophistication or scale. There is no employee-count exemption and no small-company carve-out.

The obligation covers your own staff and other persons dealing with the operation and use of AI systems on your behalf. That second category is broader than it looks and reaches contractors, agency workers and consultants who use AI in delivering work to you. It does not extend to private use of AI by employees on their own time and their own accounts, though as a practical matter the boundary is porous and is a good reason to have a policy, which is a separate topic.

What Article 4 does not require

Two misconceptions circulate widely and both cost money.

Article 4 does not require you to certify or test your employees. There is no mandated curriculum, no accreditation regime, no pass mark and no register. Vendors selling certification against Article 4 are selling a product that the law does not ask for. Certification may still be useful for your own assurance, but it is your choice rather than your obligation.

Article 4 also does not require the same training for everyone. The text expressly directs you to take into account technical knowledge, experience, education and the context of use. A developer integrating a model into a product and a finance assistant using an AI summarising feature need different things, and giving them the same course is both wasteful and weaker evidence of proportionate measures than a differentiated programme would be.

What the training should cover

Because the law sets an outcome rather than a syllabus, the content question is answered by working backwards from the risks your people can actually create.

Start with capability and limitation. Employees need a working mental model of what these systems do, which is generate plausible output rather than retrieve verified fact. The single most valuable thing you can teach is that fluency is not accuracy, because nearly every downstream failure begins with someone trusting a confident answer.

Then handle data. What may be entered into which tools, what may never be entered into any of them, and why the distinction between an enterprise deployment and a consumer account matters. For most organisations this is where the real exposure sits, and it connects directly to your GDPR obligations rather than sitting apart from them.

Then accountability. AI output is the responsibility of the person who uses it. Training should make clear that no employee can transfer responsibility for a decision, a document or a piece of code to a tool, and that review is not optional formality.

Then the specific rules of your organisation: which tools are approved, how to get a new one assessed, when disclosure is required, and who to ask.

Finally, add depth for the roles that need it. People who select or configure AI systems need to understand risk classification and the questions to put to a vendor. People deploying anything that touches recruitment, performance management, credit or access to services need to know that Annex III exists and that its obligations arrive in December 2027.

Evidence, and what an obligation of effort means for it

Because the standard is now effort rather than result, your compliance file should document measures rather than outcomes.

Keep a record of the assessment that shaped the programme: which staff groups use which AI systems, what level of literacy each needs, and why. Keep the training materials themselves with version dates, because a supervisor asking what you did in 2025 will want the 2025 material rather than this year’s. Keep delivery records showing who received what and when, including new joiners. Keep evidence that the programme is maintained, meaning a review cycle with dates, since AI tooling changes faster than annual training can follow.

This is a lighter evidentiary burden than proving comprehension across a workforce, which is what the original wording implied. It is not no burden. An organisation that cannot produce any of the above has not taken measures in any sense a supervisor would recognise.

The Nordic picture

Article 4 is supervised nationally, which means the practical question of what compliance looks like in Finland and Sweden depends on the authorities designated under the AI Act in each country and on the guidance they publish. Designation ran late across the EU and this is worth checking directly before you rely on any secondary source, including this one.

Two Nordic features shape how programmes actually get built.

The first is adoption. Nordic workplaces took up AI tooling early and broadly, often bottom-up, which means the population needing literacy training is larger than the IT function’s tool inventory suggests. Any assessment that starts from procurement records rather than from what people are actually using will understate scope substantially.

The second is process. Introducing AI systems that affect how work is monitored, assessed or organised engages consultation obligations in both countries, through the co-operation act in Finland and co-determination practice in Sweden. In Finland the act on the protection of privacy in working life places further constraints on monitoring employees, which limits how far an employer can simply observe AI use rather than govern it. The practical consequence is that Nordic employers depend more on training and less on surveillance than employers in some other markets, which raises the stakes on getting the training right.

What to do now, in order

If you have nothing in place, the sequence that produces the fastest defensible position is: inventory the AI systems actually in use, including the ones embedded in tools you already licensed; group your workforce by what they do with those systems; write down the level of literacy each group needs and why; deliver something to every group within a defined window; and record all of it.

If you already have a programme built against the original Article 4 wording, do not dismantle it. Training designed to ensure a sufficient level of literacy comfortably satisfies a duty to support its development. What you may reasonably do is stop chasing completion percentages as though they were the legal test, and redirect that effort into keeping the content current.

If you deploy anything that could fall under Annex III, the December 2027 date is closer than it looks given that procurement, assessment and remediation cycles run long. The deferral was granted because the standards needed to comply were not ready, not because the obligations were reconsidered.

Frequently asked questions

Is AI literacy training mandatory in the EU?

Yes. Article 4 of the AI Act has applied since 2 February 2025 and binds providers and deployers of AI systems. The Digital Omnibus softened the standard from ensuring a sufficient level of literacy to supporting its development, but did not remove the duty.

Did the EU delay the AI Act?

Partly. High-risk obligations for Annex III systems moved to 2 December 2027 and for Annex I systems to 2 August 2028. Article 4 and the Article 50 transparency obligations were not deferred.

Does using ChatGPT at work trigger the AI Act?

It makes your organisation a deployer, which brings Article 4 into play. It does not by itself make you a provider or bring you into the high-risk regime.

What are the penalties for failing to provide AI literacy training?

The Digital Omnibus removed the direct penalty pressure that had been associated with Article 4, and it does not sit in the prohibited-practices tier that carries the highest fines. Supervision is exercised by national market surveillance authorities from August 2026. Treat the reputational and evidential consequences as the operative risk rather than a headline fine figure.

Who has to be trained?

Staff and other persons who deal with the operation and use of AI systems on your behalf, including relevant contractors. The depth of training should vary with their role and technical background.

How often should AI literacy training be repeated?

The law sets no interval. Given the pace of change in the tools themselves, a programme reviewed less than annually will struggle to evidence that it reflects current use.

Sources and further reading