Article 4: AI literacy, as amended
Article 4 was replaced in its entirety on 27 July 2026. The duty is now to take measures to support the development of AI literacy rather than to ensure a sufficient level: an obligation of effort rather than of result. It was softened. It was not removed and it was not deferred.
What changed
The amended Article requires providers and deployers to take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account those persons’ technical knowledge, experience, education and training, the context the systems are used in, and the persons or groups on whom the systems are used. It adds an express sentence that the obligation does not require providers or deployers to guarantee any particular level.
The European Artificial Intelligence Board is tasked with adopting recommendations setting common objectives to guide how the Commission and member states support the obligation.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
What the softening actually changes
Expert analysis. Less than the word “softened” suggests, and it changes the evidence question more than the workload.
| Under the old text | Under the amended text | |
|---|---|---|
| The question asked of you | Is your staff’s literacy sufficient? | What measures did you take? |
| Where you are exposed | A knowledge gap in your staff | Having taken no measures at all |
| Evidence | Competence assessment, arguably | A dated record of measures, mapped to roles and systems |
| Practical burden | High if read strictly | Modest, but not zero |
A lower bar is not an absent one
There is still no size exemption, it still binds at every risk tier including minimal risk, it still reaches contractors and outsourced operators acting on your behalf, and it has applied since 2 February 2025: two and a half years before the high-risk regime arrives.
For an organisation whose systems are not high-risk, Article 4 is the AI Act obligation most likely to be asked about first, precisely because it is live, universal and trivially easy for an authority to raise.
Article 4a: the new article next door
Regulation (EU) 2026/1744 also inserted a new Article 4a. It establishes a legal basis relevant to the processing of personal data, and the amended Article 2(7) expressly preserves Articles 4a and 59 when defining the AI Act’s relationship with the GDPR, Regulation (EU) 2018/1725, the ePrivacy Directive and the Law Enforcement Directive.
Recitals connect it to Article 10(2), points (f) and (g): examination for possible biases, and measures to detect, prevent and mitigate them.
What we are not asserting
Unsettled. We have confirmed that Article 4a exists, that it is a legal-basis provision, and that Article 2(7) preserves it in the GDPR relationship. We have not verified its full operative scope, and it should not be relied on as a processing basis without reading the consolidated text and taking advice. If you are considering it for bias-testing purposes, read it alongside Article 10(5), which sets its own conditions.
What to actually produce
Practical recommendation. Because the duty is now framed around measures, the record should be too:
- Who: by role, including contractors and outsourced operators.
- What measures: content mapped to the AI systems those roles actually deal with.
- When: dated, with a refresh cadence.
- Why it suits them: a short note on technical knowledge and context of use, which are named in the amended text.
- Affected persons considered: the limb most often skipped, and still in the amended text.
Half a page per role group. It is the cheapest obligation in the Regulation to close and the first thing that makes the rest of a programme look credible.
Status labels on this page
Verified fact: That Art. 1(5) of Reg. (EU) 2026/1744 replaces Art. 4 in full; the change from 'ensure a sufficient level' to 'take measures to support the development'; the express statement that no particular level need be guaranteed; the AI Board recommendations task; that Art. 4 was not deferred; and that a new Art. 4a exists and is preserved by the amended Art. 2(7).
Expert analysis: The comparison table, the assessment of what the softening changes in practice, and the five-element record.
Unsettled: The full operative scope of Article 4a. Confirmed to exist as a legal-basis provision; not verified in detail.
The cheapest gap on the list
A dated record of measures, mapped to roles and systems, closes an obligation live since February 2025. Days, not quarters, and it is the first artefact an authority is likely to ask for.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What does Article 4 of the EU AI Act require now?
Article 4 was replaced in its entirety by Article 1, point 5 of Regulation (EU) 2026/1744, in force since 27 July 2026.
Providers and deployers must take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, the context the systems are used in, and the persons or groups on whom they are used. The amended text expressly states that the obligation does not require providers or deployers to guarantee any particular level of literacy.
Was the AI literacy obligation removed?
No. It was softened, not removed, and it was not deferred. The standard changed from ensuring a sufficient level of AI literacy to taking measures to support its development. That is an obligation of effort rather than of result. It continues to bind every provider and deployer at every risk tier, with no exemption based on organisation size, and it has applied since 2 February 2025.
What is Article 4a of the EU AI Act?
Article 4a is a new article inserted by Regulation (EU) 2026/1744. It establishes a legal basis relevant to the processing of personal data, and the amended Article 2(7) expressly preserves Articles 4a and 59 when defining the AI Act's relationship with the GDPR, Regulation (EU) 2018/1725, the ePrivacy Directive and the Law Enforcement Directive. Recitals link it to Article 10(2), points (f) and (g), which concern examination for bias and measures to detect, prevent and mitigate it. Read the consolidated text before relying on its scope.
What evidence satisfies the amended Article 4?
The Regulation states an outcome and does not prescribe an artefact. Because the standard is now an obligation of effort, the evidence question shifts from what your staff know to what you did: a dated record of measures taken, mapped to roles and to the systems those roles deal with, with a note on why the content suits that group's technical knowledge and the context of use. The European Artificial Intelligence Board is tasked with adopting recommendations setting common objectives to guide how this obligation is supported.
Obligations, article by article
- Art. 5 prohibitions
- Art. 50 transparency
- Art. 9 risk management
- Art. 10 data governance
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- FRIA template (Art. 27)
- When Annex III does not apply →