The AI literacy requirement — Article 4, and what it asks of you now
Article 4 is short, easy to overlook, and already in force. It is also one of the few AI Act obligations that applies to almost every company using AI — regardless of risk category, and regardless of whether you build or buy.
First hour’s on us. No commitment.
What you get
- A mapping of who needs what — engineering, product, HR, legal, management and customer-facing staff need different levels, not the same slide deck
- Sessions delivered in plain language, pitched at each group and grounded in the systems you actually use
- A documented record showing what was delivered, to whom and when
- An onboarding routine so new starters are covered without a new project each time
How it works
- Intake, 45 minutes. Who uses AI in your organisation, and how. Free.
- Design. We map roles to levels and agree the content.
- Delivery and record. Sessions run, documentation produced.
Who you’ll work with
Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.
What Article 4 says
Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. The measures must take into account those people’s technical knowledge, experience, education and training, and the context the systems are used in — including the people the systems are used on.
The obligation has applied since 2 February 2025. Unlike the high-risk regime, it was not deferred.
What it does not say
It does not prescribe a course, a certificate, an hour count or a curriculum. There is no approved provider list and no examination. This is deliberate — the standard is proportionate to role and context.
That flexibility is helpful and slightly uncomfortable. There is no box to tick, which means the question is not “did we run training” but “can we show that our people understand the systems they use well enough for their role”.
Who is covered
“Staff and other persons dealing with the operation and use of AI systems on your behalf” reaches further than employees. Contractors, consultants and agency staff who operate your systems are in scope. Customers generally are not — but where you deploy a system that affects people, the context of use is something your own people need to understand.
What different roles actually need
Everyone using AI tools at work needs the basics: what the tools can and cannot do, that outputs can be confidently wrong, what must not go into a prompt, and when to escalate.
People operating systems that affect others — recruiters, credit officers, case handlers — need more: how the system reaches its output, what its known limitations are, what human oversight means in their specific workflow, and the authority to override it.
Product and engineering need the regulatory frame: risk categories, what makes a system high-risk, where provider obligations attach, and how design choices change classification.
Management needs enough to govern: which systems the company runs, which carry obligations, who owns them, and what the decisions in front of them actually are.
How to document it
The obligation is on measures, not outcomes — but a measure you cannot evidence is difficult to rely on. What holds up:
- A short written policy describing the levels and who falls into each
- Materials and dates, kept
- An attendance or completion record
- Onboarding built in, so the record does not decay
- A review point — the systems change, and so does what people need to know
A slide deck emailed once, with no record of who read it, is thin. It is also better than nothing, which is where many companies still are.
Frequently asked questions
We are a small company. Does this apply to us?
Yes. There is no size threshold in Article 4. What is proportionate for a ten-person company is different from a thousand-person one, but the obligation is the same.
Do we need a certified course?
No. There is no certification requirement and no approved provider list. What matters is that the measures fit the roles and that you can show what you did.
What if we only use tools like ChatGPT or Copilot?
Article 4 still applies — you are a deployer. The level needed is lower, but the basics matter: hallucination, confidentiality, and knowing when not to rely on an output.
Is anyone enforcing this yet?
National market surveillance authorities have been designated and the governance framework has applied since August 2025. In practice, the more common trigger is a customer or investor asking during diligence — which happens now.
Can you run the sessions for us?
Yes. We run them for engineering, product, HR and management, and produce the documentation alongside.
Where to start
Most companies can meet this properly in a few weeks. The first conversation is free and usually clarifies the scope within the hour.