AI Act for business

AI literacy for employees: what Article 4 requires

What AI literacy under Article 4 means, who needs preparation and how an SME can build a proportionate, documented, role-based programme.

AI ACT · PEOPLE AND SKILLS

AI literacy does not mean turning every employee into a machine-learning specialist. It means enabling people who use or operate AI to understand the system, its limitations, data and effects well enough to work responsibly in their role.

What Article 4 says after the 2026 amendment

Providers and deployers must take measures to support the development of skills among people operating and using AI systems on their behalf. Measures should take account of people’s technical knowledge, experience, education and training, together with the context in which the system is used. [EU-REG] [EU-LIT]

The amendment entering into force in mid-July 2026 keeps the obligation but clarifies that one uniform and “sufficient” level is not required of every individual. The focus is on reasonable organisational measures. The rules have applied since February 2025, with supervision and enforcement due from August 2026. [EU-LIT]

There is no standard course that solves everything

The Commission explicitly states that Article 4 does not require one formula, mandatory format or certificate. A company may combine training, guidance, workshops, scenario exercises, short materials and continuous support. Reading product instructions may form part of the programme but can be insufficient when people do not understand the risks of the concrete workflow. [EU-LIT]

The Commission’s practice repository includes e-learning, in-person sessions, bootcamps, internal communities and role-adapted programmes. These examples are useful, but copying them does not automatically create a presumption of compliance. A programme must start from the organisation’s own systems, people and risks. [EU-LIT-REP] [EU-LIT]

Who should be included

Not only developers. Article 4 concerns staff and other people operating or using AI on the organisation’s behalf. In an SME, this may include management approving the use, marketing generating content, sales preparing proposals, support summarising conversations, developers integrating APIs and contractors working under the company’s responsibility. [EU-LIT] [EU-A50]

The affected audience must also be considered. Someone using AI only to rephrase an email has different needs from a person configuring an agent that publishes to WordPress or a system recommending services to customers. The more directly an output reaches people and the more important its effects, the more specific the preparation should be. [EU-LIT] [EU-RISK]

The common foundation every user should know

Every professional user needs a common foundation: which AI systems are approved, what they may be used for, which data must not be entered, the fact that outputs may be wrong, how a claim is verified and where a problem is reported. The goal is not memorising legal definitions but avoiding foreseeable mistakes. [EU-LIT]

  • Systems and accounts approved by the company.
  • Rules for personal data, confidential information and client information.
  • Model limitations: errors, hallucinations, bias and loss of context.
  • Source verification and human approval before an important action.
  • User transparency and situations requiring disclosure of AI interaction.
  • Escalation channel and how to stop a problematic process.

Role-based preparation in an SME

Management should understand the system register, provider/deployer roles, escalation thresholds and who may approve a new tool. Marketing and editorial teams need rules for sources, copyright, claims, images, transparency and publication approval. Sales staff should know not to enter prospect data into an unapproved account or present model output as a verified fact. [EU-LIT] [EU-A50]

Developers and product administrators need more technical preparation: model and version, logging, permissions, prompt protection, boundary testing, fallback, content marking and change documentation. Support staff should recognise incorrect answers, transfer the conversation to a person and explain when the user is interacting with an AI system. [EU-A50] [EU-LIT]

How to document without unnecessary bureaucracy

The Commission clarifies that Article 4 requires neither a certificate nor a governance position such as an “AI officer”. An SME may keep an internal record with the date, audience, systems covered, objectives, materials, attendance and next review. For practical workshops, the scenarios discussed and resulting decisions can also be retained. [EU-LIT]

Evidence should not be separated from the process. When a new tool is approved, the register can trigger an update to guidance and a session for affected roles. When the model or functionality changes, the process owner checks whether existing preparation still covers the new risks. AI literacy then becomes operational maintenance rather than an annual box-ticking event. [EU-LIT-REP]

A 30-day programme

A proportionate programme can begin within a month. In week one, inventory systems and the people using them. In week two, define the common foundation and data rules. In week three, run short role-based modules and exercises using real situations. In week four, fix the processes discovered, publish internal materials and schedule review. [EU-LIT] [EU-LIT-REP]

For AYSA.RO, AYSA.AI or Web-Development.ro, real value appears when training uses the team’s actual workflows: briefs, research, WordPress access, generation, publishing, APIs and action approval. A general course on AI history may be interesting, but it does not replace an exercise in which people decide which data to enter, what to verify and when to stop automation. [EU-LIT]

Official sources and verification date

  1. Regulation (EU) 2024/1689 — Artificial Intelligence Act
  2. European Commission — AI Literacy Questions & Answers
  3. European Commission — repository of AI literacy practices
  4. European Commission — transparency obligations under Article 50
  5. European Commission — high-risk AI system classification