The AI Act turns AI literacy into a corporate duty: Art. 4 has applied since February 2025 to every business using AI. This page translates the requirements into practice, with an interactive risk check, the deployer duties under Art. 26 and a roadmap for meeting the training duty demonstrably.
2025Art. 4 applies since 2 February, no transition period
The essentials
What does the EU AI Act require in terms of AI literacy?
Art. 4 of the AI Act (Regulation (EU) 2024/1689) obliges providers and deployers of AI systems to ensure, to their best extent, a sufficient, role-based level of AI literacy among their staff, demonstrable and proportionate to the risk of the systems used. Deployers of high-risk AI additionally face a system-specific training and oversight duty under Art. 26.
Every company using AI professionally is covered, even without developing AI itself (deployer role).
There is no SME exemption from the literacy duty: Art. 4 and the Art. 5 prohibitions apply to all company sizes.
The duty scales with the risk class: minimal-risk tools require foundational literacy, high-risk systems add system-specific training (Art. 26(5)).
Without documentation, training counts as not having happened, records per person, content and date are part of the duty.
Violations of prohibited practices cost up to €35m or 7% of global annual turnover (Art. 99).
Status: July 2026 · deepens module 2 (units 15–18) of the AI knowledge base
Addressees
Provider or deployer, who carries which responsibility?
The EU AI Act distinguishes two central roles. A common misconception: if the provider is compliant, the user automatically is too. Wrong, deployers carry their own duties that no software contract takes away.
Provider
Whoever develops an AI system or places it on the market under their own name.
Conformity assessment and CE marking for high-risk AI
Technical documentation and instructions for use
Risk management across the lifecycle
Registration in the EU database (high-risk)
Deployer
Whoever uses an AI system professionally under their own responsibility, the role of most companies.
For high-risk: system-specific training (Art. 26(5))
Beware the role switch: whoever repurposes an AI system, using a system certified for area A in area B, or substantially modifying it, legally becomes a provider and assumes all provider duties.
Real people instead of legal theory: the MindsMachines team at the founding event in Düsseldorf.
Interactive risk check
Which risk class is your AI application in?
The four-question heuristic from the knowledge base (unit 16), answer three yes/no questions to get the classification with its duties. Question 4 is the conclusion: if none was answered yes, minimal risk applies.
Question 1 / 3
Does the system fall under one of the prohibited practices in Art. 5?
E.g. social scoring, subliminal behaviour manipulation, emotion recognition in the workplace, untargeted scraping of facial images.
Prohibited
Unacceptable risk. Art. 5
This practice is banned in the EU and must not be used, regardless of benefit or consent.
Stop or do not start the use. Violations: up to €35m or 7% of global annual turnover.
High-risk
High risk. Annex I / Annex III
Use is allowed but strictly regulated. The full deployer duties under Art. 26 apply, from human oversight to logging.
Check the provider's conformity documents, run a fundamental-rights impact assessment where required, set up human oversight, train system-specifically (para. 5), log operation.
Limited risk
Limited risk. Art. 50
Transparency duties apply: people must be able to recognise they are interacting with AI or seeing AI-generated content.
Ensure labelling (chatbot notice, content labelling, deepfake marking), plus the Art. 4 literacy duty.
Minimal risk
Minimal risk, question 4: none answered yes
No specific AI Act requirements. GDPR, trade-secret protection and general liability law of course still apply.
Art. 4 remains: all users need role-appropriate foundational AI literacy, documented.
Practice note from the knowledge base: the risk class follows the context of use, not the tool, the same language model is minimal-risk in marketing and high-risk in HR screening. When in doubt, assume the higher class. This heuristic does not replace legal advice on the individual case.
Art. 4 · AI literacy duty
Implementing Art. 4: from duty to demonstrable programme.
Art. 4 prescribes no curriculum, it demands “sufficient” AI literacy, oriented to role, risk level and prior knowledge. Precisely this openness unsettles many companies. The following roadmap turns it into a robust, audit-proof programme.
Key takeaway: Art. 4 has applied since 2 February 2025, with no transition period. Whoever cannot show documented measures in an audit risks being classified as non-compliant, even if all systems in use are harmless.
The 5-step roadmap to Art. 4 compliance
This is how you build the literacy duty systematically, each step produces exactly the evidence supervisory authorities expect:
1AI inventory
Record all AI tools in use, including shadow usage. Per application: purpose, data, user group, risk class (risk check above).
2Map roles & levels
Every role gets a target level: Foundation for all users, Intermediate for regular users, Advanced for AI owners and high-risk oversight.
3Set up the training programme
Blended instead of one-off seminars: self-paced foundations, live training on real use cases, supported practice. The 120-unit knowledge base provides the curriculum.
4Document without gaps
Per person: date, content, level, duration, trainer, result. Plus the organisation's competence matrix and risk-based system mapping.
5Update & refresh
Annual refresher; immediate re-training for new tools, system changes or new guidance from the Commission and AI Office.
This is what Art. 4 looks like in practice: a scenario workshop from our training programme.
The three competence levels (Foundation / Intermediate / Advanced) with contents and DigComp reference are covered in depth on the AI Academy overview page. To the three levels of AI literacy
Art. 26 · Deployer duties
High-risk in operation: the nine duty areas under Art. 26.
If your company deploys a high-risk system, such as AI-supported CV screening, the operator duties of Art. 26 kick in. Deployers are not passive users but active compliance owners:
01
Use per instructions
Operate the system only as documented by the provider (para. 1), deviation can trigger the role switch.
02
Human oversight
Qualified people must understand, monitor and be able to intervene in outputs (para. 1 with Art. 14).
03
Protection against misuse
Technical and organisational measures against unauthorised access and manipulation (para. 2).
04
Fundamental-rights impact assessment
Mandatory for public bodies and sensitive areas such as employment or education (para. 3 / Art. 27).
05
Logging
Keep and retain operating logs so decisions remain reconstructable (para. 6).
06
Informing affected persons
Inform people when AI takes or prepares decisions about them (para. 9 with Art. 50).
07
Incident reporting
Report serious incidents without delay, to the provider and the competent authority (para. 5).
08
Training the staff
System-specific training of all users, the bridge between Art. 26(5) and Art. 4.
09
Cooperation with the provider
Work with the provider on non-conformities and implement corrective instructions (para. 7).
The 7-step compliance roadmap for new high-risk systems
From unit 17 of the knowledge base, the structured approach before a high-risk system goes live:
1Identification
Determine the risk class with the four-question heuristic, is it really Annex III?
2Check provider documents
Conformity assessment, CE marking, technical documentation, no launch without them.
3Fundamental-rights assessment
If required under Art. 27: conduct and document it.
4GDPR review
Clarify the legal basis, run a DPIA if needed, sign a DPA with the provider.
5Configure human oversight
Define responsibilities, escalation paths and technical intervention options.
6Train & evidence
Train all users system-specifically, file the records (Art. 26(5) + Art. 4).
7Activate logging
Switch logging on and secure retention periods, before go-live.
The traffic-light approval model: AI governance that works day to day
Practice-proven from the knowledge base: instead of debating every tool request individually, classify AI applications into three approval stages, understandable for every department:
Green, free use
Usable without individual approval: non-critical tasks, no personal data, no trade secrets.
Approved writing assistants for drafts
Translation of public content
Brainstorming without internal data
Yellow, use with conditions
Only after review and with organisational measures: tools that could touch personal or confidential data.
AI analysis of internal documents
Meeting transcription
Customer communication with AI drafts
Red, blocked until approved
Only with explicit approval by compliance, data protection and, where relevant, the works council: high-risk applications and sensitive data situations.
AI in hiring (Annex III No. 4)
Employee performance evaluation
Unvetted tools with customer data
The traffic-light model operationalises Art. 4 and Art. 26 at once: it governs who may use what, and defines which competence level an approval requires.
Competence matrix: which role needs which level?
This is what the risk-based mapping from the knowledge base looks like in practice, your matrix will be more specific but follows the same pattern:
Role
Typical AI use
Risk class
Target level
Intern / assistant
Writing assistant for drafts
Minimal
Foundation
Case handling
Internal AI assistant, documents & e-mail
Minimal–limited
Foundation–Intermediate
Marketing / communications
Generated texts, images, campaigns
Limited (Art. 50)
Intermediate
HR / recruiting
AI-supported application pre-screening
High-risk (Annex III No. 4)
Advanced + Art. 26(5)
AI officer / compliance
Governance across all systems
All classes
Advanced
Key for the evidence: the matrix does not just record the status quo, it justifies the mapping: which system, which risk class, which level, when trained, when refreshed.
Deadlines and fines: where application stands
The AI Act phases in, for the literacy duty the key point is: it already applies, whatever systems you use.
1 August 2024Entry into force
Regulation (EU) 2024/1689 enters into force, the countdown of phased duties begins.
2 February 2025Art. 4 + Art. 5 apply
The literacy duty and the prohibitions have been applicable law for all providers and deployers since then.
2 August 2025GPAI duties
Rules for foundation models and the supervisory structure around the AI Office apply.
2 August 2026High-risk under Annex III
The deployer duties of Art. 26 and transparency duties of Art. 50 are fully applicable.
2 August 2027Annex I products
Final stage: high-risk AI in regulated products such as machinery or medical devices.
Fine system (Art. 99): up to €35m or 7% of global annual turnover for prohibited practices; up to €15m or 3% for violations of central duties, whichever is higher.
Self-test
How audit-proof is your company?
Eight statements, eight times yes or no. At the end you see your compliance score and know where you stand. No sign-up, the evaluation happens right in your browser.
1We keep a complete inventory of all AI tools used in the company.
2Every AI application is assigned to a risk class and the assignment is justified.
3All employees who use AI have received a documented basic training.
4Our training records contain date, content, level and duration per person.
5It is clearly regulated which tools may be used with which data.
6For high-risk applications, human oversight is assigned to named people.
7New AI tools pass an approval review before going productive.
8One responsible person steers AI compliance, trainings and incident reports.
0/8Your compliance score
Strong! You are on an audit-proof track.
Your organisation has the literacy duty under control. Keep the rhythm with annual refreshers and keep reviewing new tools before use.
Solid foundation, gaps in the evidence.
A lot is in place, but an auditor would find gaps. Prioritise documentation and role mapping now. Those are the fastest wins on the way to audit-proofness.
Starting phase: now is the right moment.
The most important building blocks are still ahead of you. The good news: with the 5-step roadmap above you build the basics within weeks. Start with the AI inventory.
Wissensbasis · Volltexte
Modul 2 in voller Tiefe: alle 14 Einheiten.
Jede Unterrichtseinheit als kompletter Lerntext aus der Wissensbasis, mit Übungen, Branchen-Anwendungen und Quellen. Frei zugänglich.
Frequent questions on the AI Act and the training duty.
The compliance questions managing directors and HR leaders ask us most often.
Yes. The literacy duty (Art. 4) and the prohibitions (Art. 5) apply to every company using AI professionally, with no size exemption. SME relief exists only selectively, e.g. simplified technical documentation for small providers, but not for literacy and operator duties.
Yes, that is exactly what the deployer role is for. Whoever uses an AI system professionally under their own responsibility is an operator under the regulation and must at minimum ensure staff AI literacy (Art. 4). Depending on the context, transparency (Art. 50) or high-risk duties (Art. 26) come on top.
Tiered by severity (Art. 99): up to €35m or 7% of global annual turnover for prohibited practices, up to €15m or 3% for violations of central duties such as those of Art. 26, up to €7.5m or 1% for incorrect information to authorities. The higher amount counts.
No. “Sufficient” literacy is an ongoing state: new tools, substantial system changes or new guidance require re-training; an annual refresher has established itself as the base rhythm. And every measure needs documentation, otherwise it counts as not having happened.
Art. 4 is the general literacy duty for everyone working with AI, regardless of risk level. Art. 26(5) adds a specific duty for high-risk systems: staff must be trained for the concrete system. Whoever deploys high-risk AI therefore fulfils both levels, foundational literacy plus system training.
The AI Act knows no explicit duty like the data protection officer. In practice, compliance still needs clear roles: someone maintaining the AI inventory, assessing risk classes, steering trainings and reporting incidents. The knowledge base (unit 107) recommends assigning this responsibility explicitly, as a joint task of IT, legal and business.
With the four-question heuristic on this page: prohibited practice? Annex I/III? Transparency case? Otherwise minimal. The biggest trap: the class follows the context of use, a language model is minimal-risk in marketing and high-risk in CV screening. For borderline cases the practice rule applies: when in doubt, assume the higher class.
No. The provider's conformity (CE marking, documentation) is a precondition but does not replace your operator duties: intended use, human oversight, training, logging and incident reporting stay with you. And whoever repurposes a system even becomes a provider themselves.
Keep learning
Deepen your AI literacy.
This page is part of the AI Academy, learning continues here:
We build your Art. 4-compliant training programme: role-based, documented and on your real use cases, from foundation training to AI-champion development.
Productive AI that runs securely in your organization: with your own data, permissions and approvals. Distilled from real project work into a licensable product.