Discharge the EU AI Act literacy duty, and evidence it
The Omnibus turned Article 4 into an obligation of effort rather than result. That makes it far more achievable, and it changes what you should be recording.
By Parminder Kumar Sharma · · 7 min read

What the duty actually says now
Article 4 of the EU AI Act requires providers and deployers to take measures supporting the development of AI literacy among staff and others operating AI systems on their behalf, taking into account their technical knowledge, experience, education and training, and the context the systems are used in.
The Digital Omnibus rewrote it. What was a duty to ensure a sufficient level became a duty to take measures supporting development, and the amended text is explicit that no specific level need be guaranteed for any individual.
The duty has applied since 2 February 2025, and national market surveillance authorities gained formal supervisory powers over it from August 2026.

Who it covers
Everyone operating a system on your behalf
- In scopeEmployees
- In scopeContractors
- In scopeAgency staff
- In scopeOthers acting for you
The mistake worth avoiding
Buying a single generic AI awareness course for everybody.
The Article is explicit that measures should take account of the technical knowledge, experience and context of the people involved. One course pitched at everyone satisfies that badly: it bores the engineers and loses the finance team, and it demonstrates that you bought something rather than that you thought about it.
What tends to satisfy the duty
- Different material for different groups, matched to what each actually does with AI.
- Content covering how the systems fail, not just what they can do.
- Guidance tied to your own approved tools and your own policy.
- A record of what was offered, to whom, and when.
What tends not to
- One generic course for the whole organisation.
- Training that covers capability and never mentions failure modes.
- A slide deck sent by email with no record of who opened it.
- A policy document circulated in place of training.
Literacy is not one thing, and one course cannot deliver it
Article 4 asks for a sufficient level of AI literacy, taking into account the role, the context and the people affected. That wording rules out a single module sent to everybody, because sufficiency is measured against what a person actually does.
Four audiences, and what sufficient means for each
| Who | What they must be able to do | What that looks like in practice |
|---|---|---|
| Everyone who uses AI at work | Recognise that output can be confidently wrong, and know what must not be pasted in | Twenty minutes, refreshed when the approved tool list changes |
| People whose work is checked by AI | Understand where a decision came from, and how to challenge it | Explanation of the system used on them, and a named route to contest an outcome |
| People who build or configure AI systems | Recognise the failure modes they can introduce, including prompt injection and data leakage | Technical, role-specific, and repeated as the systems change |
| People who approve deployments | Ask the questions that decide whether it is safe to run at all | Enough to know what a bad answer sounds like, not enough to build it |
The fourth row is the one organisations skip. A director who approves an AI deployment without being able to interrogate the risk assessment is exactly the gap the duty exists to close, and it is not addressed by the same module the rest of the workforce receives.
Why this one is worth doing first
Of everything the AI Act asks for, this is the obligation with the best ratio of effort to exposure, and it is the one most organisations have not started.
It has applied since 2 February 2025, so unlike the high-risk requirements there is no future date to plan towards. It is late already.
It is also unusual in that it does not depend on any of the deferred machinery. The harmonised standards are not ready and the conformity assessment infrastructure is still being built, which is why the high-risk obligations moved to 2027 and 2028. None of that affects Article 4. You do not need a standard to tell people what the tools they use can get wrong.
And it produces something useful whether or not a regulator ever asks. The role mapping in the table above is the same mapping an AI system inventory needs, the refresh trigger is the same trigger a management system needs, and the record of who was told what is evidence for ISO 42001 as readily as for the Act. Almost nothing else on the compliance list pays for itself that way.
The uncomfortable corollary is that an organisation which has done nothing here has been non-compliant for over a year while waiting for a deadline that already passed.
A note on scope for UK organisations. The duty attaches to providers and deployers of AI systems caught by the Act, which reaches outside the Union through the market and output tests, so a UK company serving EU customers can owe it without holding a European entity. Where it does not apply as law, it still arrives commercially: an EU customer discharging its own Article 4 duty will ask what training your staff have had, and a supplier who cannot answer loses on the questionnaire rather than in a courtroom.
Building it
Group people by what they actually do with AI
A workable split: everyone who uses approved tools; people whose output informs decisions about individuals; people who build, configure or integrate AI; and the board or leadership who approve risk.
Groups defined by department rarely work. Groups defined by exposure do.
You should see: Three or four groups, each with a genuinely different relationship to the systems.
Write down what each group needs to be able to do
Not "understands AI". Something like: can tell when an output needs checking, and knows what must never be entered into a tool. Capability statements make the content obvious and make the evidence meaningful.
You should see: One sentence per group, describing a capability rather than a topic.
Cover failure, not just capability
Hallucination as a structural property rather than a bug. That confidence carries no information about accuracy. For anyone building: that untrusted content reaching a model is an instruction channel.
Training that only covers what AI can do produces enthusiasm without judgement, which is worse than nothing.
You should see: Every group's material addresses how the systems get things wrong.
Tie it to your actual tools and policy
Generic content teaches concepts nobody applies. Content referencing the tools you have approved and the boundaries you have set gets used on the same day.
You should see: Someone finishing the training could name your approved tools and your prohibited data classes.
Deliver it, and record the delivery
This is the evidence. Because the duty is one of effort, what you must be able to show is that support was provided and resourced, not that everyone passed a test.
You should see: A dated record of what was offered, to which group, and who attended.
Re-run it when something changes
A new tool class approved, a regulatory change, an incident. Annual training in a field that moves this fast is a compliance artefact rather than a control.
You should see: A trigger list, not just an annual date.
What counts as evidence, since nobody will ask until it matters
There is no certificate for this and no auditor arriving to check. The duty is enforced through supervision after something has gone wrong, which means the evidence has to already exist at the moment it is wanted.
Four artefacts, none of which takes long to produce, and all of which are much harder to reconstruct afterwards.
A record of who received what, and when. Completion data by role rather than a single organisation-wide percentage, because the duty is role-sensitive and an aggregate figure cannot show that.
The material itself, versioned. What people were actually told, dated, so you can show what was current when a given decision was made.
A statement of how sufficiency was judged. One paragraph naming the roles identified, why the level chosen fits each, and who approved that judgement. This is the artefact that turns training into compliance with Article 4 rather than training that happens to exist.
A trigger for refreshing it. New tool approved, new system deployed, new regulation applying. Literacy delivered once and never revisited is evidence of a project rather than of a duty being met.
What good looks like
Take this with you
Evidence that would satisfy a reasonable supervisor
- Groups defined by what people do with AI rather than by department.
- A capability statement per group, describing what someone should be able to do.
- Material covering failure modes, not only capability.
- Content referencing your approved tools and your prohibited data classes.
- A dated record of what was offered, to whom, and who attended.
- Contractors and agency staff included, not just employees.
- A trigger list for re-running it, alongside any calendar date.
- The material itself retained, so you can show what was actually taught.
Verified
Written 5 August 2026 against Article 4 of Regulation (EU) 2024/1689 as replaced by Regulation (EU) 2026/1744.


