01
In one minute
Every provider and every deployer of an AI system has to take measures to support the AI literacy of the people who work with it on their behalf. That has applied since 2 February 2025, in every risk class, including a chat assistant in the browser. Since the Omnibus it is a duty of effort, not of result. National authorities supervise it since 2 August 2026. No certificate is required. What you will be asked for is a record of what you did.
- Applies since
- 2 February 2025To providers and deployers, in every risk class.1
- Reworded
- 27 July 2026“Take measures to support”, with no level to guarantee.2
- Supervised since
- 2 August 2026By national market surveillance authorities, not by the AI Office.3
- In Germany
- BundesnetzagenturMarket surveillance authority under the KI-MIG, in force since 29 July 2026.4
02
The wording, then and now
· original
“Providers and deployers of AI systems shall take measures to
ensure, to their best extent, a sufficient level of AI literacy oftheir staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.”1
· since the Omnibus, para. 1, excerpt
“Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf […]. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.”275
Three things changed. The duty moved from a result (a sufficient level) to an effort (measures that support). The Commission and the Member States now have to support companies, in particular SMEs, and the Commission publishes practical examples (new para. 2). The AI Board adopts recommendations based on European competence frameworks (new para. 3). What stayed: the same people, the same factors to take into account, the same date.78
In practice: you do not fail Art. 4 because one person still pastes customer data into a chatbot. You fail it by doing nothing, or by doing something that ignores who uses which tool for what.
03
On a timeline, to scale
Art. 4 applied for almost eighteen months in its first wording. The change, the German enforcement law and the start of supervision then landed within six days. The first chart shows the whole period, the second zooms into that week.
Art. 4, August 2024 to December 2026
- AI Act in forceReg. (EU) 2024/16891 August 2024
- Art. 4 appliesoriginal wording2 Feb 2025 – 26 Jul 2026
- New wordingReg. (EU) 2026/1744since 27 Jul 2026
- National supervisionmarket surveillance authoritiessince 2 Aug 2026
Zoom: 20 July to 6 August 2026, one day per tick
- Published in the Official JournalOJ L, 2026/174424 July 2026
- Omnibus in force, Art. 4 rewordedthird day after publication27 July 2026
- KI-MIG in force (Germany)Bundesnetzagentur29 July 2026
- Supervision startsArt. 50 applies the same day2 August 2026
04
Who counts
The article names “staff and other persons dealing with the operation and use of AI systems on their behalf”. The Commission reads it broadly. The test is not the employment contract but whether someone works with your AI for you.35
Counts
- Employees who use AI tools at work, including a chat assistant in the browser
- Managers who decide on AI or sign off its output
- Contractors, freelancers and service providers who operate or use AI for you
- Temporary staff, trainees and working students
- Clients who operate your system on your behalf, depending on the risk
Does not count
- People who are only affected by the AI, such as applicants it scores. Other articles protect them.
- The vendor’s own staff. That is the vendor’s duty as provider.
- Private use at home. That is outside the Act.
05
What measures look like
The Commission names a minimum: a general understanding of AI, your role as provider or deployer, the risks of the systems you use, and measures tailored to people’s knowledge and context, including legal and ethical aspects. The Bundesnetzagentur describes three steps: find the needs, design the measures, keep records and refresh them.35
Measures are more than training. A usage policy people can find, a list of approved tools, a named contact for questions, checklists inside the tools and a way to report problems all count.
The formats are our suggestions. The Act prescribes none.
06
Documentation
No certificate, no external audit and no AI officer are required. The Commission expects an internal record of trainings and other measures; the Bundesnetzagentur recommends keeping a good one. Keep it short and current:35
- 01Inventory
Which groups use which AI tools, for what.
- 02Measures
Per group: what, in which format, with which material and version.
- 03Participation
Who took part, and when. An export from your learning tool is enough.
- 04Policy
Your AI usage policy, with a date and an owner.
- 05Review
A review date, and the triggers for an earlier one: a new tool, a new use, an incident.
07
The planner
Pick who works with AI, which tools they use and how bad a wrong output would be. The planner suggests measures per group and the evidence to keep. Nothing leaves your browser unless you add it to your void.
Your plan
2 groups · 7 measuresEveryone who uses AI
- Basics: what your AI tools do and where they fail (invented facts, bias, outdated knowledge)
- Your AI usage policy: approved tools, data that must not go in, whom to ask
- How to report a problem or an incident
- Chat assistants: asking with sources, checking claims, no confidential data in tools that are not approved
- Office copilots: what the copilot can see through your permissions, and reading drafts before they go out
FormatA short session or e-learning, once, plus the policy
Management
- Everything under “Everyone who uses AI”, plus:
- Your role per system (provider or deployer), the risk classes and the dates; who decides on new AI tools
FormatA short session or e-learning, once, plus the policy
Keep as evidence
- Inventory: which group uses which tool, for what
- Material and version per measure
- Participants and dates
- The usage policy, with date and owner
- Next review date, and what triggers an earlier one
Our suggestions, not a legal checklist. The Act prescribes no format.
08
Questions
We only use ChatGPT or Copilot. Does Art. 4 apply?
Yes. Using an AI system at work makes you a deployer. The Commission is explicit that staff using such tools should at least know the specific risks, such as hallucination.3
Is a one-off e-learning enough?
For low-risk use it can be part of it. The measure has to fit the tools, the people and the context; one generic video for everyone rarely does. Refresh when tools or uses change.
Do we have to test people?
No. The Act requires no test and no level. A short check of understanding is still useful where people oversee systems that affect others.
Does it cover freelancers?
Yes, if they operate or use AI systems on your behalf. Put the briefing into onboarding and the contract.
Who checks this in Germany?
The Bundesnetzagentur, as market surveillance authority under the KI-MIG. It also runs an AI service desk for questions.4
Not legal advice Our reading of the law as of September 2026. It is not legal advice. For a binding view of your case, ask counsel.