Skip to content
Back to home
Operational compliance checklist

Article 4 EU AI Act — the 12-point checklist

What must be in place in every company that uses AI — under active market surveillance since 2 August 2026. Pragmatic, no fear-mongering — and not legal advice.

Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures supporting their staff’s AI literacy, proportionate to prior knowledge, experience and the context of use. Since the recast of 27 July 2026 they are expressly not required to guarantee any specific level. This checklist turns that duty into twelve documentable points.

As of 10 August 2026 · Legal status: Regulation (EU) 2026/1744, applicable since 27 July 2026, and the German KI-MIG, in force since 29 July 2026 · Sources: Official Journal of the EU, KI-MIG, BNetzA, Bitkom v2.0, Noerr, CMS, EU AI Office, IAPP

02/02/2025
Article 4 in force
Duty has applied since early 2025
2 Aug 2026
Market surveillance live
Chapter IX has applied since this date
27 Jul 2026
Article 4 recast
Digital Omnibus on AI, Reg. (EU) 2026/1744
BNetzA
Central authority (DE)
KI-MIG since 29.07.2026 · sectoral authorities remain competent alongside

What Article 4 actually says — in plain terms

Providers and deployers of AI systems must take measures to support the development of AI literacy among their staff and anyone working with AI on their behalf. They are expressly not required to guarantee any specific level of AI literacy — the Digital Omnibus on AI clarified this with effect from 27 July 2026. The yardstick remains use-context, prior knowledge, and the persons affected.

Verbatim, version in force since 27 July 2026:
“Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.”
Regulation (EU) 2026/1744, Article 1(5) (Official Journal)

What the Digital Omnibus changed

Article 4 was replaced by Article 1(5) of Regulation (EU) 2026/1744. The obligation has not disappeared — its intensity changed. Anyone still working from material that describes the position before 27 July 2026 is planning against the wrong norm.

AspectOld version, until 26 July 2026Version in force since 27 July 2026
Required actiontake measurestake measures — unchanged
Purpose of the measuresensure, to their best extent, a sufficient level of AI literacysupport the development of AI literacy
Link to an outcometied to a level of literacy, softened by the best-efforts qualifierno reference to any level
Duty to guaranteenot expressly addressedexpressly excluded — paragraph 1, second sentence
Who is boundproviders and deployers of AI systemsunchanged
Persons coveredown staff and persons dealing with AI systems on their behalfunchanged
Legal charactersoftened duty to achieve a resultpure best-efforts duty
Finesnot in the Article 99 cataloguestill not in the Article 99 catalogue — nor in § 15 KI-MIG

What did NOT change matters just as much: the addressees, the persons covered and the penalty position are unchanged. Reading this as 'Article 4 is gone' is wrong.

What applies since when — and what is still to come

Most mistakes in practice come not from misreading the norm but from misfiling the dates. This overview separates what applies from what is still pending.

  1. Article 4 becomes applicablein force

    Together with Chapters I and II of the AI Act, including the prohibited practices of Article 5.

  2. Penalties and governancein force

    Chapter V (general-purpose AI models), Chapter VII and Chapter XII with Articles 99 and 100 — the penalty provisions therefore apply from 2025, not from 2026. National market surveillance authorities have been designated since then.

  3. Article 4 is replacedin force

    The Digital Omnibus Regulation (EU) 2026/1744 enters into force and applies from the same day — no separate date of application was set.

  4. KI-MIG enters into forcein force

    The German market surveillance and innovation act. The Bundesnetzagentur is the central market surveillance authority unless the act provides otherwise; sectoral authorities and BaFin remain competent alongside it.

  5. Transparency and market surveillancein force

    Article 50 (marking of synthetic content, disclosure for chatbots), Chapter III Section 5, Chapters VI, VIII, IX and X, and Article 101. The high-risk obligations did not start on this date.

  6. New prohibited practicespending

    Additions to Article 5, and Article 50(2) for generative systems placed on the market before 2 August 2026.

  7. High-risk obligations, Annex IIIpending

    Chapter III Sections 1 to 3 for the Annex III use cases — postponed from the original 2 August 2026.

  8. High-risk obligations, Annex Ipending

    For AI systems used as a safety component of regulated products under Annex I.

As of 10 August 2026. Source for all dates: Article 113 AI Act as amended by Regulation (EU) 2026/1744, and the KI-MIG.

Who counts as a “deployer”?

Any organisation that uses AI systems under its authority — even if it did not build the model. Practical examples:

  • Microsoft Copilot for M365 (in your tenant)
  • ChatGPT Team / Enterprise or Claude for Work
  • AI features in CRM, HRIS, ticketing, code assistants
  • Generative AI in marketing & recruiting tools

The provider carries the Article 4 duty for its own staff. As a deployer you carry it for your employees and contractors who use the system on your behalf.

The 5 typical gaps — what we find most often

Cross-section from BNetzA, Bitkom v2.0, Noerr, Travers Smith, IAPP, Delbion, Hogan Lovells.

1 · No inventory (Shadow AI)
Only the obvious tools are identified — Copilot, ChatGPT. Embedded AI in CRM/HRIS/ticketing systems, browser extensions and code editors is missed. Delbion: typically 5–12 unlogged tools per company.
2 · Generic training instead of role-specific
“Intro to AI” for everyone. BNetzA explicitly recommends a three-tier model (foundational · advanced · role-specific). Travers Smith: simply reading instructions for use is not enough.
3 · Reasonable practice — but no documentation
IAPP finding: organisations often have sound practices but cannot demonstrate them. Attendee lists are missing, modules are not versioned, responsibilities are scattered across teams.
4 · One-off training treated as “done”
Article 4 implicitly requires an ongoing refresher cycle, because the AI landscape changes quarterly. Minimum standard: annual refresher, semi-annual content review.
5 · Contractors & freelancers forgotten
Article 4 also covers “other persons dealing on your behalf” with AI — recruiting agencies with CV screening, freelance developers with code assistants, marketing agencies using generative AI. Hogan Lovells lists third-party management as a top-three step.

The 12-point checklist — operational, not legal advice

Not an audit standard — a hands-on working list. You can mark the status per item locally (saved only in your browser).

0 of 12 done0%
  • 01 · AI system inventory

    Central register of every AI tool — including embedded AI in SaaS products, browser extensions and code assistants. Refreshed at least quarterly.

  • 02 · Classification per system

    Provider vs. deployer role, risk class per Annex III, use context, data class touched — documented per system.

  • 03 · Role-to-system matrix

    Who uses what, in which decision context, under whose authority? Mapping made explicit — not held in heads.

  • 04 · Learning objectives per role

    Basic users (prompting, risk awareness), power users (validation, hallucinations, prompt injection), oversight roles (Art. 14 / Art. 26(2)), executives (governance, accountability).

  • 05 · Three-tier curriculum (BNetzA model)

    (a) Foundational AI/data concepts and opportunities/risks; (b) advanced legal & technical along your value chain; (c) role-specific training (tech · law · ethics).

  • 06 · Provider documentation reviewed

    Instructions for use, system cards, model cards, DPIA/FRIA inputs from Microsoft, OpenAI, Anthropic & vendors — and staff trained to read them.

  • 07 · AI Acceptable Use Policy

    Written, approved by leadership, communicated. Rules on confidential data, customer data, prohibited use cases (Art. 5), disclosure duties (Art. 50).

  • 08 · Training records

    Name, role, date, modules, hours, assessment — retained as audit evidence. Bitkom certificate or equivalent is fine; certification is not mandatory.

  • 09 · Refresher cadence

    Annual minimum. Ad hoc on major tool rollouts or regulatory updates. Content reviewed every six months.

  • 10 · Contracts with suppliers & contractors

    Clauses requiring an Article-4-equivalent literacy commitment. Evidence requested at onboarding.

  • 11 · Incident & escalation channel

    Staff know how to report AI errors, hallucinations, bias, or prompt-injection attempts. Channel documented, incidents logged.

  • 12 · Works council & works agreement on AI

    Co-determination under §87 BetrVG (DE) for training and performance-related AI tools. “Betriebsvereinbarung KI” as the reference document.

Bonus: The 30-minute walkthrough test

Source aiactblog.nl: Can the responsible manager explain within 30 minutes which systems exist, who uses them, what each role was trained on, what gaps remain, and what management has done about it? If yes — you are enforcement-ready.

Walkthrough test (aiactblog.nl)

Fine reality: Article 4 is NOT in Article 99

An important clarification we often have to repeat: Article 4 is not in the Art. 99 fine catalogue. The risk reaches you through three indirect channels.

Fine-setting factor
Article 99(7) lists what authorities take into account when setting an administrative fine — alongside the nature, gravity and duration of the infringement, also “any other aggravating or mitigating factor applicable to the circumstances of the case”. The catalogue only bites where a fine is already on the table for a different infringement, such as under Article 26 or Article 5. How an authority weighs the state of AI literacy there is not settled by published practice.
Breach of duty of care
Noerr and CMS: failure to take Article-4 measures can be treated by German civil courts as a Sorgfaltspflicht-Verletzung in damages, employment, or shareholder claims following an AI-caused harm. The limitation clock has been running since 02/02/2025.
KI-MIG (Member-State penalties)
Since the Digital Omnibus, Art. 99(1) expressly requires Member States to provide penalties including administrative fines for any infringement of the Regulation. In Germany the KI-MIG implements this and has been in force since 29 July 2026. Its fine catalogue in § 15 lists the sanctioned infringements exhaustively — Article 4 is not among them, and the ceiling is 50,000 euros.
Non-monetary risks — these bite today
  • RFP / supplier-pool exclusion: public-sector and enterprise buyers ask for Article-4 evidence.
  • D&O insurance: missing programme documentation is increasingly counted as a risk factor.
  • ISO 42001 / SOC 2 / financial-statement audits: AI governance evidence becomes mandatory.
  • Works-council friction: without a works agreement, Copilot rollout can be blocked.

Frequently asked questions

1. Are fines threatened specifically under Article 4?
No — Article 4 appears neither in the fine catalogue of Art. 99 EU AI Act nor in § 15 KI-MIG. That does not make a breach consequence-free: where a fine is imposed for a different AI Act infringement, the state of AI literacy can feed into how that fine is set under Article 99(7). Add to that market-surveillance measures and the civil-law standard of care. Reputational and procurement consequences bite regardless.
2. We only use Microsoft Copilot — are we a “deployer”?
Yes. Anyone using an AI system productively under their authority is a deployer under Art. 3(4). The provider (Microsoft) carries the Article-4 duty for its own staff — you carry it for your employees and contractors.
3. Is one-off training enough — checked-off and done?
No. BNetzA and Bitkom v2.0 require a refresher cycle because tools and use cases change quarterly. Minimum standard: annual refresher, semi-annual content review.
4. Is there an official certification?
No. There is no mandatory certificate for Article 4. Bitkom certificates, in-house qualifications, or training records are all acceptable — what counts is verifiable documentation: name, role, date, modules, assessment.
5. Must external service providers be included?
Yes. Article 4 covers “other persons dealing with the operation and use of AI systems on your behalf” — contractors, freelancers, and external agencies working with AI on your behalf. Hogan Lovells lists third-party management as a top-three step.
6. What about Switzerland?
Switzerland has not enacted its own EU AI Act equivalent (Federal Council decision of 12 February 2025). Whether, and how far, the EU AI Act reaches a Swiss company depends on the Regulation's territorial scope in the individual case. We deliberately make no blanket statement here and clarify it in an initial consultation based on your actual setup. (As at 14 August 2026)

Where does your company stand — today?

10 questions, 4 minutes. You receive a traffic-light score and a personalised PDF report with the five biggest gaps in your constellation. Free, no sign-up, GDPR-compliant.

Anonymous until the last question · no AI costs · no hidden sales pitch.

Sources & primary texts

This checklist is not legal advice. It is an operational working document based on publicly available sources (BNetzA, Bitkom, EU AI Office, IAPP, German and international law firms) — as of 10 August 2026, legal status Regulation (EU) 2026/1744 and KI-MIG. For a legally binding assessment of your specific case, please consult a qualified lawyer.