Article 4 EU AI Act — the 12-point checklist
What must be in place in every company that uses AI — under active market surveillance since 2 August 2026. Pragmatic, no fear-mongering — and not legal advice.
Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures supporting their staff’s AI literacy, proportionate to prior knowledge, experience and the context of use. Since the recast of 27 July 2026 they are expressly not required to guarantee any specific level. This checklist turns that duty into twelve documentable points.
As of 10 August 2026 · Legal status: Regulation (EU) 2026/1744, applicable since 27 July 2026, and the German KI-MIG, in force since 29 July 2026 · Sources: Official Journal of the EU, KI-MIG, BNetzA, Bitkom v2.0, Noerr, CMS, EU AI Office, IAPP
What Article 4 actually says — in plain terms
Providers and deployers of AI systems must take measures to support the development of AI literacy among their staff and anyone working with AI on their behalf. They are expressly not required to guarantee any specific level of AI literacy — the Digital Omnibus on AI clarified this with effect from 27 July 2026. The yardstick remains use-context, prior knowledge, and the persons affected.
“Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.”
What the Digital Omnibus changed
Article 4 was replaced by Article 1(5) of Regulation (EU) 2026/1744. The obligation has not disappeared — its intensity changed. Anyone still working from material that describes the position before 27 July 2026 is planning against the wrong norm.
| Aspect | Old version, until 26 July 2026 | Version in force since 27 July 2026 |
|---|---|---|
| Required action | take measures | take measures — unchanged |
| Purpose of the measures | ensure, to their best extent, a sufficient level of AI literacy | support the development of AI literacy |
| Link to an outcome | tied to a level of literacy, softened by the best-efforts qualifier | no reference to any level |
| Duty to guarantee | not expressly addressed | expressly excluded — paragraph 1, second sentence |
| Who is bound | providers and deployers of AI systems | unchanged |
| Persons covered | own staff and persons dealing with AI systems on their behalf | unchanged |
| Legal character | softened duty to achieve a result | pure best-efforts duty |
| Fines | not in the Article 99 catalogue | still not in the Article 99 catalogue — nor in § 15 KI-MIG |
What did NOT change matters just as much: the addressees, the persons covered and the penalty position are unchanged. Reading this as 'Article 4 is gone' is wrong.
What applies since when — and what is still to come
Most mistakes in practice come not from misreading the norm but from misfiling the dates. This overview separates what applies from what is still pending.
- Article 4 becomes applicablein force
Together with Chapters I and II of the AI Act, including the prohibited practices of Article 5.
- Penalties and governancein force
Chapter V (general-purpose AI models), Chapter VII and Chapter XII with Articles 99 and 100 — the penalty provisions therefore apply from 2025, not from 2026. National market surveillance authorities have been designated since then.
- Article 4 is replacedin force
The Digital Omnibus Regulation (EU) 2026/1744 enters into force and applies from the same day — no separate date of application was set.
- KI-MIG enters into forcein force
The German market surveillance and innovation act. The Bundesnetzagentur is the central market surveillance authority unless the act provides otherwise; sectoral authorities and BaFin remain competent alongside it.
- Transparency and market surveillancein force
Article 50 (marking of synthetic content, disclosure for chatbots), Chapter III Section 5, Chapters VI, VIII, IX and X, and Article 101. The high-risk obligations did not start on this date.
- New prohibited practicespending
Additions to Article 5, and Article 50(2) for generative systems placed on the market before 2 August 2026.
- High-risk obligations, Annex IIIpending
Chapter III Sections 1 to 3 for the Annex III use cases — postponed from the original 2 August 2026.
- High-risk obligations, Annex Ipending
For AI systems used as a safety component of regulated products under Annex I.
As of 10 August 2026. Source for all dates: Article 113 AI Act as amended by Regulation (EU) 2026/1744, and the KI-MIG.
Who counts as a “deployer”?
Any organisation that uses AI systems under its authority — even if it did not build the model. Practical examples:
- Microsoft Copilot for M365 (in your tenant)
- ChatGPT Team / Enterprise or Claude for Work
- AI features in CRM, HRIS, ticketing, code assistants
- Generative AI in marketing & recruiting tools
The provider carries the Article 4 duty for its own staff. As a deployer you carry it for your employees and contractors who use the system on your behalf.
The 5 typical gaps — what we find most often
Cross-section from BNetzA, Bitkom v2.0, Noerr, Travers Smith, IAPP, Delbion, Hogan Lovells.
The 12-point checklist — operational, not legal advice
Not an audit standard — a hands-on working list. You can mark the status per item locally (saved only in your browser).
- 01 · AI system inventory
Central register of every AI tool — including embedded AI in SaaS products, browser extensions and code assistants. Refreshed at least quarterly.
- 02 · Classification per system
Provider vs. deployer role, risk class per Annex III, use context, data class touched — documented per system.
- 03 · Role-to-system matrix
Who uses what, in which decision context, under whose authority? Mapping made explicit — not held in heads.
- 04 · Learning objectives per role
Basic users (prompting, risk awareness), power users (validation, hallucinations, prompt injection), oversight roles (Art. 14 / Art. 26(2)), executives (governance, accountability).
- 05 · Three-tier curriculum (BNetzA model)
(a) Foundational AI/data concepts and opportunities/risks; (b) advanced legal & technical along your value chain; (c) role-specific training (tech · law · ethics).
- 06 · Provider documentation reviewed
Instructions for use, system cards, model cards, DPIA/FRIA inputs from Microsoft, OpenAI, Anthropic & vendors — and staff trained to read them.
- 07 · AI Acceptable Use Policy
Written, approved by leadership, communicated. Rules on confidential data, customer data, prohibited use cases (Art. 5), disclosure duties (Art. 50).
- 08 · Training records
Name, role, date, modules, hours, assessment — retained as audit evidence. Bitkom certificate or equivalent is fine; certification is not mandatory.
- 09 · Refresher cadence
Annual minimum. Ad hoc on major tool rollouts or regulatory updates. Content reviewed every six months.
- 10 · Contracts with suppliers & contractors
Clauses requiring an Article-4-equivalent literacy commitment. Evidence requested at onboarding.
- 11 · Incident & escalation channel
Staff know how to report AI errors, hallucinations, bias, or prompt-injection attempts. Channel documented, incidents logged.
- 12 · Works council & works agreement on AI
Co-determination under §87 BetrVG (DE) for training and performance-related AI tools. “Betriebsvereinbarung KI” as the reference document.
Source aiactblog.nl: Can the responsible manager explain within 30 minutes which systems exist, who uses them, what each role was trained on, what gaps remain, and what management has done about it? If yes — you are enforcement-ready.
Walkthrough test (aiactblog.nl)Fine reality: Article 4 is NOT in Article 99
An important clarification we often have to repeat: Article 4 is not in the Art. 99 fine catalogue. The risk reaches you through three indirect channels.
- RFP / supplier-pool exclusion: public-sector and enterprise buyers ask for Article-4 evidence.
- D&O insurance: missing programme documentation is increasingly counted as a risk factor.
- ISO 42001 / SOC 2 / financial-statement audits: AI governance evidence becomes mandatory.
- Works-council friction: without a works agreement, Copilot rollout can be blocked.
Frequently asked questions
1. Are fines threatened specifically under Article 4?
2. We only use Microsoft Copilot — are we a “deployer”?
3. Is one-off training enough — checked-off and done?
4. Is there an official certification?
5. Must external service providers be included?
6. What about Switzerland?
Where does your company stand — today?
10 questions, 4 minutes. You receive a traffic-light score and a personalised PDF report with the five biggest gaps in your constellation. Free, no sign-up, GDPR-compliant.
Anonymous until the last question · no AI costs · no hidden sales pitch.
Sources & primary texts
- Article 4 EU AI Act, version applicable since 27 July 2026 (Official Journal)
- EU Commission · AI Literacy Q&A
- EU AI Office · Living Repository
- BNetzA · KI-Kompetenz (DE, as of June 2025, pre-Digital-Omnibus)
- BfDI · Die KI-Verordnung (DE)
- Bitkom · Umsetzungsleitfaden v2.0 (DE)
- Noerr · Article 4 EU AI Act (DE)
- Travers Smith · AI literacy key considerations
This checklist is not legal advice. It is an operational working document based on publicly available sources (BNetzA, Bitkom, EU AI Office, IAPP, German and international law firms) — as of 10 August 2026, legal status Regulation (EU) 2026/1744 and KI-MIG. For a legally binding assessment of your specific case, please consult a qualified lawyer.