What Art. 4 AI Act requires
Art. 4 of the AI Act requires both providers and deployers of AI systems to “take measures to ensure, to their best extent,” that staff and other persons dealing with the operation and use of AI systems on their behalf have a “sufficient level of AI literacy”. The wording names four reference points to be taken into account when assessing this: technical knowledge, experience, education and training — each measured against the specific context in which the system is used and the persons or groups of persons on whom it is used.
The provision is deliberately drafted to be context-dependent: there is no fixed catalogue of hours or a prescribed certificate. What counts as “sufficient” depends on who works with which system in what role — someone configuring a high-risk system in HR needs a different level of competence than someone operating a chatbot front-end in customer service.
Since when the obligation applies
Art. 4 is one of the provisions that has already applied since 02.02.2025 — together with the prohibitions under Art. 5. This matters because the “Digital Omnibus on AI” has pushed back numerous other AI Act deadlines: the high-risk obligations under Annex III now apply only from 02.12.2027, high-risk systems under Annex I product legislation from 02.08.2028, and the transparency obligations under Art. 50 apply from 02.08.2026 (with a grace period until 02.12.2026 for systems already placed on the market). None of these postponements affect Art. 4. The obligation to ensure AI literacy has been running unchanged since February 2025 — regardless of whether your organisation currently operates any high-risk systems or systems subject to transparency obligations at all.
In concrete terms: anyone arguing that building AI literacy can wait until their own systems fall under the postponed high-risk or transparency regimes is overlooking the fact that Art. 4 already applies — to every AI system operated or used within the organisation, not only to high-risk applications.
What this means in practice
The wording “its staff and other persons dealing with” the operation and use of AI systems on its behalf covers not only permanent employees but also external service providers, freelancers or group companies, insofar as they operate or use AI systems on behalf of the deployer or provider. The obligation therefore applies equally to the department using a system on a daily basis, the IT function administering it, and management deciding on its deployment.
In practice, this means organisations need to map which role touches which system and how, and build a training concept on that basis covering technical fundamentals (how does the system broadly work? what are its limitations and sources of error?), legal fundamentals (which obligations under the AI Act apply to this particular role?), and the specific context of use. The legal text does not prescribe a particular format — in-house training, e-learning or external courses are all conceivable, provided the measure is proportionate to the actual risk and the person’s role.
Common gaps
Recurring patterns emerge in practice: organisations often train only the IT or data science teams that develop or configure systems — but not the business users who work with the outputs day to day and base decisions on them. Differentiation by context of use is often missing too: a one-off, generic “AI training” for all staff will typically not satisfy the requirement to address the “context in which the AI systems are intended to be used” when recruitment, credit decisions and internal text generation carry entirely different risks and competence needs.
Another frequent gap: the obligation is not documented. Without a record of who was trained on which system and when, it is difficult, if challenged, to demonstrate that sufficient competence was ensured “to the best extent”. External persons operating systems on the organisation’s behalf are also simply forgotten in many concepts.
Where to start
Before drawing up a training concept, you need to know which AI systems are actually in use in your organisation, which roles work with them, and how these systems are classified under the regulation. The free risk check at /einstufung gives you an initial structured overview that can serve as the basis for assigning AI literacy measures under Art. 4.