The AI Literacy Duty: What Article 4 Requires and What Does Not Threaten

Since 2 August, market surveillance authorities have been monitoring compliance with the EU AI Act. In Germany, the implementing act that determines who holds jurisdiction came into force on 29 July. One of the obligations that becomes checkable as a result has already applied for a year and a half and is unknown in most companies: anyone deploying AI must ensure that the people working with it understand something about it.
At the same time, figures on fines circulate for this obligation that are simply wrong. Both belong in the same picture.
Key takeaway: Article 4 of the AI Regulation has obliged providers and deployers since 2 February 2025 to ensure a sufficient level of AI literacy among their staff. The obligation applies to every company using AI systems in its own name, including bought-in tools. It carries no fine of its own, however: Article 4 appears in none of the penalty lists in Article 99. It is still not without consequence, because missing competence counts as an aggravating factor when other violations are examined, and in a liability case it comes into play as organisational fault. The regulation prescribes no curriculum, but documentation is needed all the same.
What exactly does Article 4 require?
That providers and deployers take measures to ensure that their staff and other persons dealing with the operation and use of AI systems on their behalf have a sufficient level of AI literacy. That is what the regulation says, and it says nothing more.
What AI literacy means is defined in Article 3(56): the skills, knowledge and understanding that enable responsible deployment and create an awareness of opportunities, risks and possible harms.
What is notable about this wording is what it does not contain. No number of hours, no certificate, no examination, no prescribed provider. The regulation describes a goal and leaves the route to the company. That is both a relief and an imposition: you cannot go wrong by choosing a particular format, but you also cannot look up anywhere when it is enough.
The obligation is organisational in nature. It addresses the company, not individual employees. Nobody has to pass a test, but management must ensure the conditions are in place.
Who is affected, even when only using ChatGPT?
Practically every company deploying AI systems in its own name. The regulation distinguishes providers, who develop AI systems or supply them under their own name, from deployers, who use them under their own responsibility. The second case covers most mid-sized companies.
One point is frequently overlooked here: it makes no difference whether the system was developed in-house or bought in. Anyone using a third-party language model in the company is its deployer. That also covers cases nobody would call an AI project, such as using a chat assistant in administration or an AI tool when preparing quotations.
The circle of people is likewise wider than expected. It covers your own staff and other persons dealing with operation or use on the company's behalf. External service providers working on your behalf are included.
How widespread the exposure is can be seen in the Bitkom survey of April 2026: 41 percent of German companies actively deploy AI, a further 48 percent plan to. The obligation applies from the first system in productive use, not from a particular company size.
What does a breach of Article 4 cost?
Under the regulation itself: nothing. Article 4 carries no fine because it appears in none of the penalty lists in Article 99. That statement contradicts what many AI training offers claim, so here is the scale in detail.
| Violation | Range | Does it cover Article 4? |
|---|---|---|
| Prohibited practices under Article 5 | up to EUR 35 million or 7 % of worldwide annual turnover | no |
| Certain obligations for providers, deployers, importers, distributors and notified bodies | up to EUR 15 million or 3 % | no |
| False or misleading information to authorities | up to EUR 7.5 million or 1 % | no |
The frequently quoted EUR 35 million relate to prohibited practices under Article 5, such as social scoring or emotion recognition in the workplace. That has nothing to do with missing training. The EUR 15 million likewise cover different grounds.
Anyone selling you training with a reference to looming multi-million fines is therefore arguing with figures that do not apply to this obligation. That is no reason to ignore the obligation, but a good reason to read the offer critically.
Why the obligation is still not without consequence
Because it takes effect along three other routes, and all three matter more to a mid-sized company than a theoretical fine.
First, as an aggravating factor. When a supervisory authority examines another violation, the question of the participants' competence forms part of establishing the facts. In practice, authorities rarely pursue missing AI literacy in isolation, but treat it as an aggravating factor when something else is already at issue.
Second, in a liability case. If an AI deployment causes damage, the question of organisational fault arises. Anyone able to demonstrate that those involved were trained and knew the system's limits stands in a considerably better position than someone who cannot answer the question. The burden of proof here sits with the company.
Third, as an expectation of the member states. The Commission assumes that national market surveillance authorities can penalise breaches of Article 4 on the basis of national provisions. How this will be shaped in Germany is not yet settled; the implementing act governs responsibilities and penalty provisions, but no established practice exists at this point. In shaping it, the interests of SMEs and start-ups must be taken into account, and since 27 July 2026 also those of smaller mid-cap companies.
Who supervises this in Germany?
The Bundesnetzagentur. The Bundestag passed the act implementing the AI Regulation on 11 June 2026, and it has been in force since 29 July 2026. It names the Bundesnetzagentur as the central market surveillance authority, insofar as no other specialist authorities hold jurisdiction.
It is supported by the newly established coordination and competence centre KoKIVO, which bundles cooperation between the authorities involved, is meant to ensure consistent interpretation, and serves as the contact point for European institutions. BaFin, BSI, BfArM and BfDI remain responsible for their respective sectors.
For practice this means there has been a named addressee for a few weeks now. Anyone wanting to know who asks in case of doubt now has the answer.
What does a sufficient level mean?
Something that can only be determined in relation to the specific deployment. The regulation requires competence matching the role and the system in use. From that follows a graduation that limits the effort.
| Group | What they need to understand | Extent |
|---|---|---|
| Management | Legal framework, risks, responsibilities, approval decisions | Overview, once a year |
| Specialists using it daily | How it works in outline, the system's limits, handling errors, data protection | Detailed, with refreshers |
| Occasional use | What the tool may do, what it may not, when to escalate | Short, in writing |
| Staff with no AI contact | nothing | not applicable |
The last row matters because it clears up the most common misconception: the obligation covers people dealing with operation and use, not the entire workforce. Blanket training for all employees is not required.
For companies operating AI agents with customer contact, an additional substantive requirement arises: whoever looks after the assistant must know where its knowledge comes from and where it ends. How such a knowledge base is built is covered in the article on the knowledge base of AI agents.
How do you document compliance?
With records showing who was briefed, when, and on what. A certificate is not prescribed, but evidence is indispensable in your own interest, because in a liability case the company must prove compliance.
Four components are enough for a mid-sized company.
- An AI policy naming which tools are approved, which data must never be entered, and who decides on new tools.
- An attendance list with date, content and signature, even for a one-hour internal briefing.
- Role-based short documents, that is one sheet per group from the table above, rather than one training session for everyone.
- A repetition interval, usually annual, with an addendum for every newly approved system.
Anyone who has already produced a policy for AI use, for instance in the course of the transparency obligations, can extend it rather than create a second one. What has applied to disclosure since 2 August 2026 is covered in the article on the AI disclosure duty under Article 50.
What to do if nothing has happened so far?
The backlog can be cleared in half a day, and that is not an understatement. The obligation has existed since February 2025, but it does not require retroactive reconstruction, only a demonstrable state from now on.
A four-step approach:
- Take stock. Write down which AI tools are actually in use in the company. Experience shows the list is longer than expected, because tools were introduced individually in departments.
- Assign. For each tool, record who works with it and which of the four groups those people fall into.
- Brief. Produce one document per group and hold a session. For the largest group an hour is usually enough.
- Record. File the policy, the attendance list and the repetition date in one place that can be found in case of doubt.
Anyone taking this route meets the requirement in more than a formal sense. The real benefit is that in most companies someone knows for the first time, completely, which AI tools are in use. That list is also the basis for everything else, from the data protection review to the question of what exactly is being paid for.
Frequently asked questions
Since when has the AI literacy obligation applied? Since 2 February 2025. It is therefore one of the first provisions of the AI Regulation to take effect. Since 2 August 2026, market surveillance authorities have been monitoring compliance, in Germany on the basis of the implementing act in force since 29 July 2026.
Do fines apply if we have trained nobody? Not under the regulation itself. Article 4 appears in none of the penalty lists in Article 99. The frequently cited EUR 35 million concern prohibited practices under Article 5, the EUR 15 million other obligations. Missing competence becomes relevant as an aggravating factor in other violations and, in a liability case, as organisational fault.
Do we have to train all employees? No. The obligation covers people dealing with the operation and use of AI systems. Anyone not working with them falls outside it. A graduation by role makes sense: an overview for management, detail for daily use, short and in writing for occasional use.
Does the obligation also apply to bought-in tools? Yes. Anyone deploying an AI system under their own responsibility is a deployer within the meaning of the regulation, regardless of who developed it. Using a third-party language model in the company falls under this.
Which authority holds jurisdiction in Germany? The Bundesnetzagentur as central market surveillance authority, insofar as no other specialist authorities are responsible. It is supported by the coordination and competence centre KoKIVO. BaFin, BSI, BfArM and BfDI remain responsible for their sectors.
Do we need a certificate or a particular course? No. The regulation prescribes neither a curriculum nor a format nor a provider. Training courses are recognised, as are internal policies and multiplier programmes. What matters is that the competence fits the role and that compliance can be demonstrated.
Conclusion
The AI literacy obligation is an unusual case: a provision that has applied for a year and a half, is barely known, has been supervised for a few weeks, and carries no fine of its own. Precisely that combination leads to two opposite errors. Some ignore it because nothing threatens. Others buy expensive programmes against a fine that does not exist for this case.
The middle route is the appropriate one. For a mid-sized company the effort amounts to half a day and three documents. What exists afterwards is not only evidence for an authority that may never ask, but a complete list of the tools in use and a clear rule on who may do what with them. Both are missing in most companies, and both are useful regardless of any supervision.
This article reflects the state of knowledge as of 21 August 2026 and does not constitute legal advice.
Sources
- Regulation (EU) 2024/1689 (AI Act), Article 4 (AI literacy, applicable since 2 February 2025), Article 3(56) (definition), Article 5 (prohibited practices), Article 99 (penalties)
- German act implementing the AI Regulation, passed by the Bundestag on 11 June 2026, in force since 29 July 2026: Bundesnetzagentur as central market surveillance authority, coordination and competence centre KoKIVO, sector responsibility of BaFin, BSI, BfArM and BfDI
- Bitkom, AI study April 2026: 41 percent of German companies with active AI deployment, 48 percent planning
AI chatbot for sales & support
Answers customer enquiries in seconds, qualifies leads and hands over to your team - live in 2-4 weeks.
More Articles

AI Agents in Customer Service: Revolutionizing Digital Communication in 2025
Discover how AI agents are revolutionizing customer service in 2025, enabling 24/7 intelligent communication and boosting business efficiency.

AI Automation for SMEs: A Guide to Boosting Efficiency in 2025
Our 2025 guide for SMEs on using AI agents to increase efficiency, reduce operational costs, and overcome labor shortages. Calculate your ROI.
