There is an obligation in the AI Act that has been in force since 2 February 2025 and that a surprising number of organisations have not clocked. It is short, it is cheap to satisfy, and it applies to almost everyone using AI at work. It is Article 4, and it is about AI literacy.

What it actually says

The wording is broad on purpose. Providers and deployers of AI systems have to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other people who operate and use AI systems on their behalf. It tells you to account for people's technical knowledge, experience, education and training, and the context the systems are used in.

Notice what it does not do. It does not prescribe a curriculum, a certificate or a number of hours. That vagueness makes some compliance teams nervous, but it is also a gift: you get to decide what "sufficient" looks like for your people, as long as you can show you thought about it and did something real.

Why the EU bothered

The logic is that half the risk in AI comes not from the models but from the humans pointing them at the wrong problem. Someone pastes a client's personal data into a public chatbot. Someone trusts a confident answer that happens to be wrong. Someone automates a decision that should have had a person in the loop. None of that is fixed by better model weights. It is fixed by people who understand what the tool is and is not.

The cheapest compliance win in the whole AI Act is probably this one. A short, honest training module plus a record of who completed it covers most of what Article 4 asks for. Compare that to the machinery around high-risk systems and it is not close.

What "sufficient" looks like in practice

You do not need to turn your finance team into machine-learning engineers. Sufficient literacy for most staff means they understand a few things well enough to act on them. That the tool can be wrong and sounds equally confident either way. That some information should never go into it. That the output is a draft, not an oracle. That there are tasks where a human has to make the final call. And that the rules differ depending on whether the tool runs inside the company or sends data outside it.

That last point is where the shape of your deployment matters. If your assistant runs on your own hardware and nothing leaves the building, a big chunk of the "do not paste that here" anxiety simply goes away, and your training gets shorter and calmer. If staff are using a mix of external tools, the literacy programme has to spend real time on what is safe to send where. The EU AI Office has signalled it will publish living guidance and examples on literacy, so keep an eye there.

One practical note. Because Article 4 is already in force and enforcement of the broader Act is ramping up, "we will get to training later" is not a great position to be caught in. It is the one duty you can close out this quarter.

As always, this is general information rather than legal advice. Talk to a qualified adviser about what an adequate literacy programme looks like for your sector and your risk profile.