AI Academy · Legal deep dive

AI Literacy under the EU AI Act

The AI Act turns AI literacy into a corporate duty: Art. 4 has applied since February 2025 to every business using AI. This page translates the requirements into practice, with an interactive risk check, the deployer duties under Art. 26 and a roadmap for meeting the training duty demonstrably.

4Risk classes decide your obligations
9Duty areas for deployers under Art. 26
7%of global turnover or €35m, maximum fine
2025Art. 4 applies since 2 February, no transition period

The essentials

What does the EU AI Act require in terms of AI literacy?

Art. 4 of the AI Act (Regulation (EU) 2024/1689) obliges providers and deployers of AI systems to ensure, to their best extent, a sufficient, role-based level of AI literacy among their staff, demonstrable and proportionate to the risk of the systems used. Deployers of high-risk AI additionally face a system-specific training and oversight duty under Art. 26.

  • Every company using AI professionally is covered, even without developing AI itself (deployer role).
  • There is no SME exemption from the literacy duty: Art. 4 and the Art. 5 prohibitions apply to all company sizes.
  • The duty scales with the risk class: minimal-risk tools require foundational literacy, high-risk systems add system-specific training (Art. 26(5)).
  • Without documentation, training counts as not having happened, records per person, content and date are part of the duty.
  • Violations of prohibited practices cost up to €35m or 7% of global annual turnover (Art. 99).

Status: July 2026 · deepens module 2 (units 15–18) of the AI knowledge base

Addressees

Provider or deployer, who carries which responsibility?

The EU AI Act distinguishes two central roles. A common misconception: if the provider is compliant, the user automatically is too. Wrong, deployers carry their own duties that no software contract takes away.

Provider

Whoever develops an AI system or places it on the market under their own name.

  • Conformity assessment and CE marking for high-risk AI
  • Technical documentation and instructions for use
  • Risk management across the lifecycle
  • Registration in the EU database (high-risk)

Deployer

Whoever uses an AI system professionally under their own responsibility, the role of most companies.

  • Ensure AI literacy of staff (Art. 4)
  • Use per the instructions, human oversight
  • Logging, incident reporting, informing affected persons
  • For high-risk: system-specific training (Art. 26(5))

Beware the role switch: whoever repurposes an AI system, using a system certified for area A in area B, or substantially modifying it, legally becomes a provider and assumes all provider duties.

The MindsMachines team on stage at the founding event in Düsseldorf
Real people instead of legal theory: the MindsMachines team at the founding event in Düsseldorf.

Interactive risk check

Which risk class is your AI application in?

The four-question heuristic from the knowledge base (unit 16), answer three yes/no questions to get the classification with its duties. Question 4 is the conclusion: if none was answered yes, minimal risk applies.

Question 1 / 3

Does the system fall under one of the prohibited practices in Art. 5?

E.g. social scoring, subliminal behaviour manipulation, emotion recognition in the workplace, untargeted scraping of facial images.

Prohibited

Unacceptable risk. Art. 5

This practice is banned in the EU and must not be used, regardless of benefit or consent.

Stop or do not start the use. Violations: up to €35m or 7% of global annual turnover.

High-risk

High risk. Annex I / Annex III

Use is allowed but strictly regulated. The full deployer duties under Art. 26 apply, from human oversight to logging.

Check the provider's conformity documents, run a fundamental-rights impact assessment where required, set up human oversight, train system-specifically (para. 5), log operation.

Limited risk

Limited risk. Art. 50

Transparency duties apply: people must be able to recognise they are interacting with AI or seeing AI-generated content.

Ensure labelling (chatbot notice, content labelling, deepfake marking), plus the Art. 4 literacy duty.

Minimal risk

Minimal risk, question 4: none answered yes

No specific AI Act requirements. GDPR, trade-secret protection and general liability law of course still apply.

Art. 4 remains: all users need role-appropriate foundational AI literacy, documented.

Practice note from the knowledge base: the risk class follows the context of use, not the tool, the same language model is minimal-risk in marketing and high-risk in HR screening. When in doubt, assume the higher class. This heuristic does not replace legal advice on the individual case.

Art. 4 · AI literacy duty

Implementing Art. 4: from duty to demonstrable programme.

Art. 4 prescribes no curriculum, it demands “sufficient” AI literacy, oriented to role, risk level and prior knowledge. Precisely this openness unsettles many companies. The following roadmap turns it into a robust, audit-proof programme.

Key takeaway: Art. 4 has applied since 2 February 2025, with no transition period. Whoever cannot show documented measures in an audit risks being classified as non-compliant, even if all systems in use are harmless.

The 5-step roadmap to Art. 4 compliance

This is how you build the literacy duty systematically, each step produces exactly the evidence supervisory authorities expect:

  1. AI inventory

    Record all AI tools in use, including shadow usage. Per application: purpose, data, user group, risk class (risk check above).

  2. Map roles & levels

    Every role gets a target level: Foundation for all users, Intermediate for regular users, Advanced for AI owners and high-risk oversight.

  3. Set up the training programme

    Blended instead of one-off seminars: self-paced foundations, live training on real use cases, supported practice. The 120-unit knowledge base provides the curriculum.

  4. Document without gaps

    Per person: date, content, level, duration, trainer, result. Plus the organisation's competence matrix and risk-based system mapping.

  5. Update & refresh

    Annual refresher; immediate re-training for new tools, system changes or new guidance from the Commission and AI Office.

MindsMachines AI training: a trainer explains scenario development in front of a presentation screen
This is what Art. 4 looks like in practice: a scenario workshop from our training programme.

Art. 26 · Deployer duties

High-risk in operation: the nine duty areas under Art. 26.

If your company deploys a high-risk system, such as AI-supported CV screening, the operator duties of Art. 26 kick in. Deployers are not passive users but active compliance owners:

Use per instructions

Operate the system only as documented by the provider (para. 1), deviation can trigger the role switch.

Human oversight

Qualified people must understand, monitor and be able to intervene in outputs (para. 1 with Art. 14).

Protection against misuse

Technical and organisational measures against unauthorised access and manipulation (para. 2).

Fundamental-rights impact assessment

Mandatory for public bodies and sensitive areas such as employment or education (para. 3 / Art. 27).

Logging

Keep and retain operating logs so decisions remain reconstructable (para. 6).

Informing affected persons

Inform people when AI takes or prepares decisions about them (para. 9 with Art. 50).

Incident reporting

Report serious incidents without delay, to the provider and the competent authority (para. 5).

Training the staff

System-specific training of all users, the bridge between Art. 26(5) and Art. 4.

Cooperation with the provider

Work with the provider on non-conformities and implement corrective instructions (para. 7).

The 7-step compliance roadmap for new high-risk systems

From unit 17 of the knowledge base, the structured approach before a high-risk system goes live:

  1. Identification

    Determine the risk class with the four-question heuristic, is it really Annex III?

  2. Check provider documents

    Conformity assessment, CE marking, technical documentation, no launch without them.

  3. Fundamental-rights assessment

    If required under Art. 27: conduct and document it.

  4. GDPR review

    Clarify the legal basis, run a DPIA if needed, sign a DPA with the provider.

  5. Configure human oversight

    Define responsibilities, escalation paths and technical intervention options.

  6. Train & evidence

    Train all users system-specifically, file the records (Art. 26(5) + Art. 4).

  7. Activate logging

    Switch logging on and secure retention periods, before go-live.

The traffic-light approval model: AI governance that works day to day

Practice-proven from the knowledge base: instead of debating every tool request individually, classify AI applications into three approval stages, understandable for every department:

Green, free use

Usable without individual approval: non-critical tasks, no personal data, no trade secrets.

  • Approved writing assistants for drafts
  • Translation of public content
  • Brainstorming without internal data

Yellow, use with conditions

Only after review and with organisational measures: tools that could touch personal or confidential data.

  • AI analysis of internal documents
  • Meeting transcription
  • Customer communication with AI drafts

Red, blocked until approved

Only with explicit approval by compliance, data protection and, where relevant, the works council: high-risk applications and sensitive data situations.

  • AI in hiring (Annex III No. 4)
  • Employee performance evaluation
  • Unvetted tools with customer data

The traffic-light model operationalises Art. 4 and Art. 26 at once: it governs who may use what, and defines which competence level an approval requires.

Competence matrix: which role needs which level?

This is what the risk-based mapping from the knowledge base looks like in practice, your matrix will be more specific but follows the same pattern:

RoleTypical AI useRisk classTarget level
Intern / assistantWriting assistant for draftsMinimalFoundation
Case handlingInternal AI assistant, documents & e-mailMinimal–limitedFoundation–Intermediate
Marketing / communicationsGenerated texts, images, campaignsLimited (Art. 50)Intermediate
HR / recruitingAI-supported application pre-screeningHigh-risk (Annex III No. 4)Advanced + Art. 26(5)
AI officer / complianceGovernance across all systemsAll classesAdvanced

Key for the evidence: the matrix does not just record the status quo, it justifies the mapping: which system, which risk class, which level, when trained, when refreshed.

Deadlines and fines: where application stands

The AI Act phases in, for the literacy duty the key point is: it already applies, whatever systems you use.

  1. 1 August 2024Entry into force

    Regulation (EU) 2024/1689 enters into force, the countdown of phased duties begins.

  2. 2 February 2025Art. 4 + Art. 5 apply

    The literacy duty and the prohibitions have been applicable law for all providers and deployers since then.

  3. 2 August 2025GPAI duties

    Rules for foundation models and the supervisory structure around the AI Office apply.

  4. 2 August 2026High-risk under Annex III

    The deployer duties of Art. 26 and transparency duties of Art. 50 are fully applicable.

  5. 2 August 2027Annex I products

    Final stage: high-risk AI in regulated products such as machinery or medical devices.

Fine system (Art. 99): up to €35m or 7% of global annual turnover for prohibited practices; up to €15m or 3% for violations of central duties, whichever is higher.

Self-test

How audit-proof is your company?

Eight statements, eight times yes or no. At the end you see your compliance score and know where you stand. No sign-up, the evaluation happens right in your browser.

  1. We keep a complete inventory of all AI tools used in the company.
  2. Every AI application is assigned to a risk class and the assignment is justified.
  3. All employees who use AI have received a documented basic training.
  4. Our training records contain date, content, level and duration per person.
  5. It is clearly regulated which tools may be used with which data.
  6. For high-risk applications, human oversight is assigned to named people.
  7. New AI tools pass an approval review before going productive.
  8. One responsible person steers AI compliance, trainings and incident reports.

Strong! You are on an audit-proof track.

Your organisation has the literacy duty under control. Keep the rhythm with annual refreshers and keep reviewing new tools before use.

Solid foundation, gaps in the evidence.

A lot is in place, but an auditor would find gaps. Prioritise documentation and role mapping now. Those are the fastest wins on the way to audit-proofness.

Starting phase: now is the right moment.

The most important building blocks are still ahead of you. The good news: with the 5-step roadmap above you build the basics within weeks. Start with the AI inventory.

FAQ

Frequent questions on the AI Act and the training duty.

The compliance questions managing directors and HR leaders ask us most often.

Yes. The literacy duty (Art. 4) and the prohibitions (Art. 5) apply to every company using AI professionally, with no size exemption. SME relief exists only selectively, e.g. simplified technical documentation for small providers, but not for literacy and operator duties.

Yes, that is exactly what the deployer role is for. Whoever uses an AI system professionally under their own responsibility is an operator under the regulation and must at minimum ensure staff AI literacy (Art. 4). Depending on the context, transparency (Art. 50) or high-risk duties (Art. 26) come on top.

Tiered by severity (Art. 99): up to €35m or 7% of global annual turnover for prohibited practices, up to €15m or 3% for violations of central duties such as those of Art. 26, up to €7.5m or 1% for incorrect information to authorities. The higher amount counts.

No. “Sufficient” literacy is an ongoing state: new tools, substantial system changes or new guidance require re-training; an annual refresher has established itself as the base rhythm. And every measure needs documentation, otherwise it counts as not having happened.

Art. 4 is the general literacy duty for everyone working with AI, regardless of risk level. Art. 26(5) adds a specific duty for high-risk systems: staff must be trained for the concrete system. Whoever deploys high-risk AI therefore fulfils both levels, foundational literacy plus system training.

The AI Act knows no explicit duty like the data protection officer. In practice, compliance still needs clear roles: someone maintaining the AI inventory, assessing risk classes, steering trainings and reporting incidents. The knowledge base (unit 107) recommends assigning this responsibility explicitly, as a joint task of IT, legal and business.

With the four-question heuristic on this page: prohibited practice? Annex I/III? Transparency case? Otherwise minimal. The biggest trap: the class follows the context of use, a language model is minimal-risk in marketing and high-risk in CV screening. For borderline cases the practice rule applies: when in doubt, assume the higher class.

No. The provider's conformity (CE marking, documentation) is a precondition but does not replace your operator duties: intended use, human oversight, training, logging and incident reporting stay with you. And whoever repurposes a system even becomes a provider themselves.

Next step

Turn the training duty into a competitive edge.

We build your Art. 4-compliant training programme: role-based, documented and on your real use cases, from foundation training to AI-champion development.

The platform

OneMachine: your AI, in your system.

Productive AI that runs securely in your organization: with your own data, permissions and approvals. Distilled from real project work into a licensable product.

Explore OneMachine
AI Literacy under the EU AI Act: the Art. 4 Training Duty