Sofpact field note

AI Literacy: The AI Act Obligation That Is Already Live

Editorial diagram of five role groups receiving proportionate AI literacy measures

Of all the obligations in the EU AI Act, the one that already binds is the one least often discussed. It is not a high-risk requirement, it does not wait for a conformity assessment, and it applies whether an organisation builds AI or merely uses it. It has been in force since 2 February 2025.

It is also the obligation where most published guidance is now out of date, for a reason worth understanding before commissioning any training.

What the obligation is

Article 4 of the AI Act concerns AI literacy. It binds providers and deployers — that is, organisations that build AI systems and organisations that use them. It applies from 2 February 2025, and it is not tied to the high-risk timetable. An organisation that concluded it had nothing to do until the Annex III high-risk obligations apply on 2 December 2027 reached the wrong conclusion about this article.

The duty is to take measures on AI literacy among staff and others who operate AI systems on the organisation’s behalf, proportionate to their role, their existing knowledge and the context the systems are used in.

What changed, and why it matters

The Digital Omnibus on AI, in force since 27 July 2026, amended Article 4. The Commission’s own notice describes the change plainly: “the previous AI literacy requirement for companies is simplified, with the Commission and the Member States taking a stronger role in promoting AI literacy.” See the European Commission: AI Omnibus enters into force.

The obligation was not repealed. Its character changed: from a duty framed around a result to one framed around taking measures. In practical terms the organisation is judged on what it reasonably did, not on demonstrating an achieved standard across every employee.

That distinction matters commercially, because it changes what evidence is worth producing. A programme designed to prove a level across a workforce is expensive and brittle. A programme designed to show proportionate, role-appropriate measures — and to record them — is achievable and is what the current duty asks for.

Why most guidance still says otherwise

A first-hand observation, made on 16 September 2026: the European Commission’s AI Act Service Desk page for Article 4 still displays the pre-Omnibus text, under an explicit notice reading “This provision has been amended by the Digital Omnibus on AI. The text displayed on this page has not yet been updated to reflect those amendments.”

The official source is transparent about the gap. A great deal of secondary guidance is not, and continues to quote the superseded standard as though it were current. If a training proposal, policy template or compliance product quotes the old formulation back at you, that tells you when it was written and whether anyone has revisited it since.

This is the ordinary condition of a regulation still settling. It is also a reasonable test to apply to any adviser: ask what changed in July 2026 and what they updated as a result.

What “measures” look like in practice

Proportionality is the operative word, and it points at roles rather than headcount. Five groups cover most organisations.

  • People who decide. Executives and managers approving AI adoption need enough to ask useful questions: what the system does, what it is not for, what evidence exists that it works, what happens when it is wrong, and who owns the answer.
  • People who operate. Staff using AI in daily work need to know the boundaries of the tool, how to recognise a wrong or unsupported output, when to escalate, and what they may not put into it.
  • People who build or configure. Technical staff need evaluation practice, data handling, logging and change control — the working content of the NIST AI Risk Management Framework rather than an awareness session.
  • People who buy. Procurement and legal need to know which questions determine whether a system can be operated safely and exited cleanly.
  • People who advise or assure. Risk, compliance, audit and data protection need enough fluency to review a system without outsourcing judgement to the team that built it.

Two things follow. First, a single organisation-wide session cannot satisfy all five groups, because their questions differ. Second, none of this requires a certification scheme; Article 4 does not name one.

The evidence to keep

An obligation of effort is demonstrated by a record of the effort. Four artefacts cover it, and all four are things a well-run organisation would want anyway.

  • A role map showing which groups are exposed to which systems, which comes directly from an inventory of what the organisation actually runs.
  • A description of what each group received, with dates and content, however modest.
  • The material itself, versioned, so it is possible to say what people were told and when.
  • A review date, because a programme that is accurate once and never revisited is the thing that quietly stops being measures at all.

ISO/IEC 42001, the management-system standard for AI, treats competence and documented responsibilities as ordinary parts of a management system. An organisation borrowing that structure will produce the Article 4 evidence as a by-product rather than as a separate exercise.

The part that is not about compliance

There is a straightforward operational case for this that would hold if Article 4 did not exist.

The largest published field study of AI in service work, Brynjolfsson, Li and Raymond: Generative AI at Work, found that the benefit of an AI assistant concentrated among less experienced staff, at around 34%, while experienced staff gained close to nothing. The mechanism the authors describe is the spread of good practice. Whether that spread happens depends on whether people understand what the tool is doing and when to disagree with it.

Put the other way: the difference between a workforce that uses AI well and one that uses it badly is largely the difference Article 4 is asking you to address. The Stanford HAI 2026 AI Index Report puts organisational adoption at 88% while noting that results remain uneven — and unevenness of that kind is rarely a model problem.

Where to start

Start from the list of systems actually in use, not from a training catalogue. The exposure map falls out of the inventory, the role groups fall out of the exposure map, and the content follows from the roles. Doing it in that order produces a defensible programme in weeks; doing it in the opposite order produces a course that nobody needed.

If you would like the obligation mapped to your organisation and the programme designed around what you actually run, that is governance and assurance work, usually scoped as an assessment or delivered as a working session.