Article 4

AI literacy: the duty everyone has.

No risk-tier threshold, no exemption for small companies, enforceable now. It is also the cheapest obligation in the regulation to discharge properly.

Last updated 21 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

Article 4 is the obligation almost nobody has heard of and almost everybody has. It applies to providers and deployers alike, it has no risk-tier threshold, and it has been enforceable since 2 August 2026. If your staff use AI systems in their work - including ChatGPT, a support copilot, or a scoring model - Article 4 applies to you.

It is also the cheapest obligation in the entire regulation to discharge. An afternoon and a dated document, done properly, closes it.

What it actually says

Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf - taking into account their technical knowledge, experience, education and training, and the context the systems are used in.

Three things follow from that wording, and each one trips people up:

What counts as compliance

There is no prescribed format, which is unsettling but also generous - it means a proportionate, well-documented effort is defensible. For a small company, that realistically looks like:

ElementWhat it means in practice
An inventoryWhich AI systems are in use, by whom, for what
A sessionWhat these systems do and don't do, where they fail, what they must not be used for, when a human decides
Role-appropriate depthMore for people operating consequential systems, less for occasional users
A recordDate, attendees, what was covered. This is the artefact that evidences the duty
OnboardingNew joiners get it too - a one-off session in 2026 doesn't cover a 2027 hire

The record is the point. An undocumented session and no session look identical to a regulator. If you have already briefed your team informally, write it up and date it - you may be most of the way there already.

What it is not

Not a certification. No accredited course is required and nobody issues you anything. Vendors selling "AI Act literacy certification" are selling convenience, not a legal requirement.

Not a prompt-engineering course. The objective is informed, critical use - understanding limitations, risks and when not to rely on output - not getting better results out of the tool.

Not only for high-risk deployers. This is the common misreading. Article 4 sits in Chapter I, ahead of the risk-tier machinery. A company whose every AI system is minimal risk still owes it.

Why it matters more than its size suggests

Article 4 breaches fall under Article 99(4) - up to €15m or 3% of worldwide turnover, or for SMEs whichever is lower. Nobody expects a literacy-only enforcement action. The realistic risk is different: it surfaces during a GDPR investigation, a procurement review, or due diligence, as evidence of whether you took the regulation seriously at all.

Article 99(7) requires authorities to weigh whether an operator acted negligently and what steps they took. A dated literacy record is cheap evidence that you did.

It also pairs with the other two live obligations. If you're doing this, do all three at once: Article 50 disclosure on anything user-facing, and an Article 5 check that nothing you run is prohibited outright.

What else is already enforceable for you?

Article 4 is one of three live duties. The free check tells you which of the others apply to your systems.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.