// eu ai act · article 4

EU AI Act Article 4: what AI literacy requires — and what it doesn’t

Article 4 asks providers and deployers of AI systems to ensure a sufficient level of AI literacy among the people who operate and use those systems. It is a duty about people and training — not a product you can buy. This page lays out what the text actually says, corrects the myths that have grown around it, and is honest about the one thing tooling like MoorAI can genuinely do: make the “measures taken” demonstrable.

First, the myths — corrected against the text

Most of what circulates about Article 4 is wrong on the dates and wrong on the penalties. Getting these right is the whole point — a compliance decision built on the wrong deadline or a phantom fine is a bad decision.

What you’ll often hear What the AI Act actually says
When Article 4 applies “A new rule that starts in August 2026” It has applied since 2 February 2025
What 2 August 2026 is “The start date / the deadline” Date national authorities gain enforcement powers
Penalty for a breach “A €15M / 3% fine” No direct EU fine — Art. 4 isn’t in the Art. 99 tiers
Who is covered “Just our own employees” Staff and contractors, service providers & clients acting on your behalf
What discharges it “Buy a tool and you’re covered” Proportionate measures — training, policy, and evidence

On the no-fine point: as Latham & Watkins put it, there are “no direct fines … for violating the AI literacy requirements under Article 4.” Enforcement instead flows through the national penalty regimes that Member States must lay down under Article 99(1), market-surveillance scrutiny, and indirect civil-liability exposure — not the Article 99 fine tiers (the €35M/7% and €15M/3% bands), which do not list Article 4. This is an accuracy note, not legal advice.

What Article 4 actually requires

The obligation itself is short. Providers and deployers of AI systems “shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf” — taking into account their technical knowledge, experience, education and training, and the context the systems are used in.

Two words carry the weight. “Measures” means there is no single prescribed curriculum — you choose proportionate steps. “To their best extent” is a reasonableness standard, scaled to risk, role and context: a team fine-tuning a high-risk system needs deeper literacy than one using a low-risk drafting assistant.

What “AI literacy” means (Article 3(56)). The Act defines it as the “skills, knowledge and understanding” that allow providers, deployers and affected persons to make an informed deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause. It is a people-capability standard, not a software feature.

Who is covered. The duty falls on both providers and deployers. Per the European Commission’s AI Office FAQ, the people in scope are not only your employees: the obligation reaches contractors, service providers, and clients who deal with the operation and use of the AI systems on your behalf.

What a defensible AI-literacy program looks like

Because the standard is “measures … to your best extent,” a defensible position is one you can show. In practice that tends to mean four things working together:

  1. Role-based training. Literacy proportionate to what each group actually does with AI — builders, deployers, and everyday users have different needs.
  2. A written AI-use policy. The rules of the road: approved tools, prohibited uses, escalation, and human oversight expectations.
  3. Documented “measures taken.” A record of what you did and why it was proportionate — the artifact that answers a market-surveillance question about your “best extent.”
  4. Ongoing evidence. Training completion, policy acknowledgements, and an audit trail that keeps pace as tools and staff change.

The AI Office maintains a “living repository” of AI-literacy practices from organisations. Treat it as illustrative inspiration, not a safe harbor: the Commission has been explicit that adopting or replicating those practices grants no presumption of compliance. It shows what others do; it does not certify what you did.

Where MoorAI fits — it delivers a slice of literacy, and proves it

Article 4 has two layers. The foundational people layer — teaching the skills, knowledge and understanding of Art. 3(56) — is training work, and no tool replaces it: MoorAI does not run your training program, does not achieve AI literacy on its own, and does not make you Article 4 compliant. But literacy isn’t only a classroom. Article 4 is explicitly risk- and context-proportionate, and the literacy that changes behaviour is delivered at the moment of the decision. That is exactly what MoorAI does: when a developer is about to do something risky, MoorAI coaches them in context — the why, the what-to-do, mapped to the OWASP LLM Top 10 and MITRE ATLAS — and records that coaching, content-free, as a demonstrable “measure taken.”

The foundational layer (people) MoorAI — in-context literacy + evidence
What it delivers Foundational skills, knowledge, understanding (Art. 3(56)) In-context, risk-specific understanding at the point of use
Just-in-time literacy Annual / onboarding training Coaching at the moment of the decision — the why + what-to-do, mapped to OWASP LLM Top 10 / MITRE ATLAS
Evidence it reached people Training-completion records Content-free literacy touchpoints — who was coached, on which topics, how often
Who owns it L&D / security / your training program On-device guardrails & the management console
Human oversight Awareness & judgement (taught) Coach / alert / block / justify, human-in-the-loop
Inventory of AI in use AIBOM — AI Bill of Materials, content-free
Managed vs unmanaged agents Discovery & governance of the agents your people run
Framework evidence Training records Compliance mapping incl. EU AI Act evidence records

Read the verbs carefully. MoorAI delivers just-in-time, context-specific AI literacy at the point of use, and proves it with content-free touchpoint records — and it operationalizes the technical-controls portion of your program (human oversight, AI inventory, agent governance). What it deliberately does not do: it does not replace a training program, does not achieve full AI literacy on its own, and does not satisfy, ensure, or certify Article 4 compliance — no tool discharges the legal duty. Think of it as the in-context layer that makes your literacy program land where the risk actually happens — and demonstrable.

See it in context: the MoorAI overview, how we prove telemetry is content-free, and the AI Bill of Materials for the EU AI Act.

The law is still moving. The European Commission’s proposed Digital Omnibus (published November 2025) would, among other changes, soften Article 4’s wording — from a duty to “ensure a sufficient level” of AI literacy toward a duty to “support the development of” it. This is a proposed, evolving change and was still settling as this page was written; do not treat it as settled law — verify the current text against the Official Journal before relying on it.

Not legal advice. This page is informational and summarises our reading of Regulation (EU) 2024/1689 and related Commission guidance; it is not legal advice and does not create a lawyer–client relationship. Obligations depend on your role, systems and jurisdiction — consult qualified counsel for your situation, and verify every date and citation against the primary sources.

See the evidence layer → How we prove content-free → AIBOM & the EU AI Act → Read Article 4 (EUR-Lex) ↗
glick.run — AGPL-3.0