Two things happened to Article 4 in the space of eight days
On 27 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force and rewrote the AI literacy duty in Article 4 of Regulation (EU) 2024/1689. On 3 August 2026, national market surveillance authorities began supervising that same duty. A good many businesses noticed only the first event and concluded the obligation had been watered down to nothing. The sequence points the other way. Article 4 has bound providers and deployers since 2 February 2025, and it has only now acquired someone whose job it is to look.
That combination is unusual, and it is why AI literacy is worth revisiting rather than filing away. The wording is more forgiving than it was. The supervision is real for the first time.
What does Article 4 actually require?
In its original form, Article 4 obliged providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account those people’s technical knowledge, experience, education and training, the context in which the systems are used, and the persons on whom the systems are used. Article 3(56) defines AI literacy as the skills, knowledge and understanding that let providers, deployers and affected persons deploy AI in an informed way and grasp its opportunities, risks and possible harms. Two features of the drafting matter commercially. It reaches beyond employees to contractors and consultants operating systems on your behalf, and it is explicitly contextual, so the standard for a compliance officer reviewing credit decisions is not the standard for a marketing assistant drafting copy.
What the Omnibus changed in the wording
Regulation (EU) 2026/1744 replaced the duty to ensure a sufficient level of AI literacy with a duty to take measures to support the development of one. It also puts the Commission and Member States under an obligation to support and facilitate that work, including by publishing practical examples of compliance. The practical effect is evidential rather than substantive. You are no longer answerable for whether every individual actually reached a given standard, which was always an awkward thing to guarantee. You are answerable for whether you took sensible measures. The underlying expectation that your workforce understands the AI it operates has not moved.
Who enforces it, and with what?
Supervision sits with national market surveillance authorities rather than the EU AI Office, and the Commission’s own questions and answers on AI literacy confirm that those authorities began enforcing from 3 August 2026. The penalty position is less familiar than elsewhere in the Act. Article 99(4) sets a harmonised ceiling of EUR 15 million or 3 per cent of turnover for a defined list of breaches, and Article 4 is not on that list. Penalties for AI literacy failures therefore come from national law under Article 99(1), which requires them to be effective, proportionate and dissuasive. The Commission’s guidance also points to private enforcement, meaning individuals may bring damages claims under national law. In Sweden the supervisory architecture is still being finalised, with the inquiry report Anpassningar till AI-förordningen (SOU 2025:101) proposing Post- och telestyrelsen as principal market surveillance authority.
A worked example
A Swedish accountancy firm with sixty staff rolls out a generative assistant that drafts client correspondence and summarises source documents. It runs a one hour all staff webinar and considers the box ticked. The gap is contextual. Partners signing off advice need to understand hallucination and verification duties, the finance team handling client data needs to understand confidentiality and what leaves the tenancy, and the two external consultants configuring the tool are covered by Article 4 as persons operating it on the firm’s behalf even though they are not employees.
Now change one fact. The same firm also uses a tool that ranks job applicants. That is an Annex III use case, so from 2 December 2027 Article 26(2) will require the firm to assign human oversight to people with the necessary competence, training and authority. Article 4 is the foundation that obligation is built on, which is why treating literacy as a soft duty tends to cost more later.
Common mistakes
The most common mistake is reading the Omnibus rewording as a repeal and quietly cancelling planned training. The second is running a single generic session and keeping no record of who attended or what was covered, which leaves nothing to show an authority that asks. The third is excluding contractors, agency staff and consultants who operate AI systems on your behalf, when the text reaches them expressly. The fourth is assuming the AI Office’s living repository of AI literacy practices is a safe harbour. It is a useful collection of what other organisations do, and the Commission is explicit that copying an entry does not create any presumption of compliance.
Recommended actions
Start by mapping who in the organisation actually touches AI, including people outside the payroll, and group them by what they do with it rather than by department. Set a different depth of training for each group, so that people making or reviewing consequential decisions get more than awareness. Write down what you delivered, to whom and when, because the softened wording shifts the question from outcome to effort and effort has to be evidenced. Refresh the material when you adopt a new tool or a tool changes materially, and fold AI literacy into onboarding rather than treating it as a campaign. Give one person responsibility for keeping the record current.
Frequently asked questions
Does the softened wording mean we can stop training staff?
No. The duty still applies and is now supervised. What changed is that you are judged on the measures you took rather than on whether every individual reached a given level, which makes documenting your training programme more important, not less.
Can we be fined for breaching Article 4?
Not under the Act’s harmonised tiers, because Article 99(4) does not list Article 4. Penalties instead come from national law under Article 99(1) and must be effective, proportionate and dissuasive. The Commission also points to possible private damages claims.
Do contractors and consultants need to be covered?
Yes. Article 4 reaches staff and other persons dealing with the operation and use of AI systems on your behalf. Agency workers, consultants and outsourced operators fall inside that wording, so your programme and your records should include them.
Conclusion
Article 4 is the cheapest obligation in the AI Act to satisfy and the easiest to be caught short on, because it produces nothing visible until somebody asks for the evidence. Since 3 August 2026 somebody can. The work is modest: know who uses AI, train them for what they actually do with it, and keep the paperwork. At Lawgent, we help companies build AI literacy programmes that match their real use of AI, document them so they stand up to supervision, and connect them to the human oversight duties coming in 2027. Get in touch if you would like yours reviewed.