What AI literacy means
The AI Act defines AI literacy as the skills, knowledge and understanding that allow people to make an informed deployment of AI systems and to gain awareness of:
- their opportunities
- their risks
- the possible harm they may cause.
It does not mean that everyone must understand how a model is trained.
Nor does it mean that everyone must become a specialist.
The literacy required depends on the context.
Someone using an assistant to draft documents needs one set of knowledge.
Someone overseeing a system that influences decisions about people needs another.
And someone developing or validating a system needs a different level again.
AI literacy should therefore be connected to:
role + use + risk + responsibility.
What Article 4 currently requires
The current wording of Article 4 requires providers and deployers of AI systems to take measures to support the development of AI literacy among:
- their staff
- other persons operating AI systems on their behalf
- other persons using those systems on their behalf.
When deciding which measures are appropriate, they must take account of:
- technical knowledge
- experience
- education
- training
- the context in which the systems are used
- the persons or groups on whom the systems are used.
The obligation has applied since 2 February 2025. The supervision and enforcement provisions have applied since 3 August 2026.
It does not require a particular individual level to be guaranteed, nor does it prescribe a specific format.
Each organisation must therefore determine which measures are proportionate to its circumstances. This sits alongside the wider AI Act obligations for businesses, but it is not limited to one category of AI system.
Who the obligation applies to
Article 4 is directed at:
providers
and
deployers
of AI systems.
It is therefore not limited to companies that develop technology.
An organisation that uses AI systems in its activities may be a deployer.
Examples include:
- a company using generative AI
- an HR department using a recruitment system
- a bank using automated systems
- a company introducing an AI customer service assistant
- an organisation integrating AI into internal processes.
The level of exposure may vary considerably.
But the starting point is the same:
identify which AI exists and who uses it. The guide to AI governance roles and responsibilities helps distinguish internal functions from regulatory roles.
What changed in 2026
The original wording of the AI Act referred to ensuring, to the best extent possible, a sufficient level of AI literacy.
That wording was amended in 2026.
The current obligation focuses on:
taking measures to support the development of AI literacy.
It also clarifies that providers and deployers do not have to guarantee a specific level of literacy for each individual.
The change avoids treating Article 4 as a requirement to achieve a universal score or a particular certification.
It does not remove the obligation.
The organisation still needs to show that it has adopted reasonable, contextual measures.
Why generic training is not enough
One simple response to Article 4 might be:
“we gave everyone in the company a two-hour course”.
That may be a useful measure.
But it is not necessarily sufficient as a governance approach.
Different people:
- use different tools
- make different decisions
- access different information
- create different risks
- hold different responsibilities.
Someone using ChatGPT to summarise internal documents does not need exactly the same training as someone overseeing a scoring tool.
A developer does not need the same content as a business user either.
An effective programme should adapt its content to the context.
Start with AI roles and uses
Before designing training, establish:
who uses what.
The AI inventory can provide the starting point. A practical AI register and inventory can connect systems, people and responsibilities.
General user
Uses generative assistants for productivity tasks.
Training may need to cover:
- confidential information
- verification
- hallucinations
- intellectual property
- acceptable use.
Business owner
Owns an AI system.
May need knowledge of:
- risk
- classification
- controls
- decisions
- evidence.
Procurement
Buys AI-enabled solutions.
May need to understand:
- due diligence
- suppliers
- documentation
- contractual clauses
- changes.
Compliance or Legal
May need to understand:
- regulatory roles
- classification
- obligations
- documentation.
Technical team
May need deeper knowledge of:
- data
- validation
- testing
- monitoring
- robustness
- security.
Training should follow responsibility.
What every AI user should understand
Although the level will vary, certain basic areas may be useful to many users.
What AI is and is not
Understand that a generated answer is not automatically a correct answer.
Limitations
Recognise:
- errors
- hallucinations
- bias
- uncertainty.
Information
Know what information may be entered into a tool.
Verification
Understand when an output must be checked.
Responsibility
Understand that using AI does not remove human responsibility.
Escalation
Know what to do when there is:
- an error
- an incident
- uncertainty
- a prohibited use.
AI literacy should support better decisions and consistent application of the organisation's AI use policy.
What people with greater responsibility need to know
When someone takes part in significant decisions about AI systems, the knowledge required increases.
They may need to understand matters such as:
- intended purpose
- classification
- risk
- impact
- human oversight
- controls
- traceability
- suppliers
- monitoring
- change management
- incidents.
A system owner should be able to answer:
what could go wrong, and what are we doing to prevent or detect it?
AI literacy then becomes part of AI governance and may be supported by an AI Act classification process.
AI literacy and risk
AI literacy should not be managed in isolation.
It can be connected directly to AI risk management.
For example, where there is a risk of confidential information being entered into generative tools, measures may include:
- policy
- technical configuration
- targeted training.
Where there is a risk of automation bias, measures may include:
- oversight
- instructions
- practical training.
Where there is a risk of discrimination:
- training for accountable roles
- review criteria
- escalation mechanisms.
Training works best when it responds to real risks.
How to design an AI literacy programme
A practical approach can follow these stages.
Step 1. Identify AI systems
Use the inventory.
Step 2. Identify people and roles
Determine who:
- uses
- oversees
- develops
- purchases
- approves
- controls.
Step 3. Assess existing knowledge
Not everyone starts at the same level.
Step 4. Connect roles and risks
Identify what each group needs to understand.
Step 5. Create content
Measures may combine:
- training
- guidance
- practical sessions
- scenarios
- communications
- short resources.
Step 6. Practise
Practical scenarios are often more useful than theory in isolation.
Step 7. Record
Retain evidence of the measures adopted.
Step 8. Review
Update the programme when there are changes to:
- tools
- risks
- responsibilities
- regulation.
AI literacy should be a process.
Not a one-off activity.

What evidence should be retained
Article 4 does not prescribe a universal file of documents.
From a governance perspective, however, it is reasonable to retain evidence of the measures adopted.
For example:
- role analysis
- learning needs
- content
- materials
- invitations
- attendance
- communications
- guidance
- assessments where used
- updates
- reviews.
The evidence should answer one question:
what did the organisation do to support the development of AI literacy among the people operating or using AI on its behalf?
There is no need to create excessive bureaucracy.
But the organisation should be able to demonstrate the approach it followed.
How to integrate AI literacy into AI governance
AI literacy should not operate as a standalone Human Resources project.
It can be connected to an AI governance framework:
Inventory
Which systems exist.
Roles
Who uses them and who is accountable.
Risk
Which knowledge helps reduce it.
AI policy
Which rules people need to know.
Suppliers
Which training the supplier can provide and what remains the organisation's responsibility.
Incidents
Which lessons need to be incorporated.
Audit
Which evidence shows the measures exist.
Improvement
What needs to be updated.
AI literacy therefore becomes one of the organisational controls within AI governance.
How to measure whether the measures work
There is no single indicator.
Different metrics may be used depending on the context.
For example:
- percentage of roles covered
- people trained
- training completed
- internal assessment results
- incidents related to incorrect use
- enquiries received
- unauthorised uses detected
- reviews carried out
- new needs identified.
Attendance alone does not demonstrate competence.
It may be more useful to establish whether people:
- recognise risky situations
- know when to verify
- understand the rules
- know where to escalate
- understand their responsibilities.
Metrics should support improvement.
Common mistakes
Giving everyone the same course
Roles are different.
Treating AI literacy as prompt training
Prompting may form part of the training, but AI literacy is much broader.
Training only Technology teams
Many uses of AI emerge in business functions.
Forgetting senior leaders
Decision-makers also need to understand opportunities and risks.
Failing to connect training with real tools
Theory in isolation has limited value.
Failing to update content
Technology changes.
Not retaining evidence
It then becomes difficult to demonstrate which measures were adopted.
Turning it into bureaucracy
The aim is not to collect certificates.
It is to improve decisions.
What an organisation should do now
A reasonable starting point would be:
1. Review the inventory
Identify which AI is being used.
2. Identify users and accountable roles
Connect systems with people and roles.
3. Group profiles
Create groups with similar needs.
4. Identify risks
Determine which errors or uses need to be prevented.
5. Design measures
Do not rely only on courses.
Also consider:
- guidance
- policies
- communications
- practical sessions
- resources.
6. Implement
Prioritise uses with greater exposure.
7. Retain evidence
Record what was done.
8. Review periodically
Update measures as tools, people and risks change.
The aim is not simply to say:
“we delivered training”.
The more useful question is:
“do the people using our AI now know how to use it in a more informed and responsible way?”
AI literacy turns rules into everyday decisions
An organisation may have a sound AI policy.
It may have controls.
It may have an inventory.
But much of governance ultimately depends on the decisions people make every day.
What information they enter.
Which outputs they accept.
What they verify.
What they escalate.
What they challenge.
AI literacy helps connect:
people, knowledge, risk and responsibility.
This is where Article 4 stops being only a regulatory obligation.
It starts becoming a real part of AI governance.
References
- Regulation (EU) 2024/1689 — Artificial Intelligence Act.
- Article 3(56) — AI literacy.
- Article 4 — AI literacy, current version.
- European Commission — AI Literacy: Questions & Answers.
Does your organisation know how to use AI responsibly?
AI literacy starts with understanding which tools are being used, who is using them and what risks arise in each context.
Start the diagnostic →
Céntrika’s diagnostic can help identify your current level of governance and the main gaps.
