AI Training & EducationDeep DiveFreshLast reviewed: · 8d ago

    AI Literacy and EU AI Act Article 4: What Companies Must Do, and How Swedish Companies Meet It

    TL;DR

    Quick Answer
    Cited by AI
    Article 4 requires every company that uses AI to take role-based measures to build staff AI literacy. No certificate or set level is required. Keep a record.

    Article 4 of the EU AI Act has applied since 2 February 2025 and was rewritten by the Digital Omnibus in July 2026. This guide quotes the text, summarises what the European Commission's Q&A says about level, documentation and certificates, explains the Swedish supervisory situation, and sets out a role-based programme you can document.

    AI literacy under Article 4 of the EU AI Act is the obligation on providers and deployers of AI systems to take measures that support the development of AI skills, knowledge and understanding among their staff and others using AI on their behalf, adapted to each person's knowledge, role and context of use.

    Eric Lundberg - Author at Alice Labs
    Written by
    Linus Ingemarsson - Reviewer at Alice Labs
    Reviewed by
    Published ·Updated
    11 min read
    2 Feb 2025

    Article 4 AI literacy obligation applies to providers and deployers

    Regulation (EU) 2024/1689, Art. 113(a)

    27 Jul 2026

    Digital Omnibus on AI enters into force and rewrites Article 4

    Regulation (EU) 2026/1744

    2 Aug 2026

    National market surveillance authorities supervise and enforce Article 4

    European Commission, AI Literacy Q&A

    What you'll learn(5 points)
    • The exact wording of Article 4, before and after the Digital Omnibus (Regulation (EU) 2026/1744)
    • Who is covered: providers, deployers and the people who use AI on their behalf
    • What the European Commission's Q&A says about level, format, documentation and certificates
    • Who supervises Article 4 in Sweden in 2026, and what SOU 2025:101 proposes
    • A role-based programme for leadership, staff, developers and control functions, and how to document it

    Key Takeaways

    • Article 4 has applied since 2 February 2025 to every provider and deployer of AI systems, including a company whose staff only use ChatGPT, Copilot or Claude at work.
    • The Digital Omnibus, in force since 27 July 2026, changed the duty from ensuring a sufficient level of AI literacy to taking measures that support it. No individual level has to be guaranteed.
    • The Commission's Q&A says no certificate is needed. An internal record of trainings and other guidance is enough, and there is no duty to test employees.
    • Deployers of high-risk AI systems still have a separate duty under Article 26(2) to assign human oversight to people with the necessary competence, training and authority.
    • In Sweden, the interim government assignment of June 2026 does not name an authority for Article 4. SOU 2025:101 proposes PTS, and proposes no sanction fee for Article 4.
    • A defensible programme is role-based, uses the organisation's own AI tools and tasks, and leaves a dated record per group.
    01 / 10Chapter

    What does Article 4 of the EU AI Act say?

    Article 4(1) requires providers and deployers to take measures to support the AI literacy of staff and others using AI on their behalf. Since the Digital Omnibus, no specific level has to be guaranteed.

    Article 4 sits among the general provisions in Chapter I of the AI Act (Regulation (EU) 2024/1689), so it applies regardless of how risky an AI system is. As amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744), paragraph 1 reads:

    "Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."

    The original wording required providers and deployers to "take measures to ensure, to their best extent, a sufficient level of AI literacy". The Omnibus also added Article 4(2), under which the Commission and Member States must support providers and deployers, in particular SMEs, and the Commission must publish practical examples of compliance, and Article 4(3), under which the AI Board adopts recommendations based on European competence frameworks.

    Article 3(56) defines AI literacy as the "skills, knowledge and understanding" that allow providers, deployers and affected persons "to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause."

    02 / 10Chapter

    Who is covered: providers, deployers and people acting on their behalf

    In short

    Every organisation that builds or uses an AI system professionally, including companies whose staff only use ChatGPT, Copilot or Claude, plus contractors acting on their behalf.

    A provider develops an AI system and places it on the market under its own name. A deployer is, under Article 3(4), anyone "using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity." Almost every Swedish company becomes a deployer the moment staff use an AI assistant for work.

    The Commission's Q&A is explicit. Asked whether a company whose employees use ChatGPT to write advertising text or translate must comply, it answers: "Yes, they should be informed about the specific risks, for example hallucination."

    "Other persons" are people "broadly under the organisational remit", such as a contractor, a service provider or a client. Consultants who use AI on your behalf belong in the programme too.

    03 / 10Chapter

    From when, who enforces it, and what the Digital Omnibus changed

    In short

    Article 4 has applied since 2 February 2025. National market surveillance authorities enforce it from 2 August 2026. The Omnibus, in force since 27 July 2026, made it an obligation of effort.

    • 2 February 2025: Article 4 applies (Article 113(a)).
    • 27 July 2026: the Digital Omnibus enters into force, after adoption on 8 July and publication in the Official Journal on 24 July. The Commission's pages say "mid-July 2026".
    • 2 August 2026: national market surveillance authorities "start supervising and enforcing the rules", according to the Commission. The AI Office does not enforce Article 4.

    The obligation remains. The Commission states that "AI literacy remains an obligation for providers and deployers of AI systems, but no specific – or 'sufficient' - level is mandated", and that for deployers of high-risk systems "the obligation to ensure that their staff is trained to ensure human oversight remains in place." That duty is Article 26(2): deployers "shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support."

    Penalties follow national law and must be proportionate. The Commission notes enforcement "might, however, be more likely if there is proof of an incident due to lack of appropriate training and guidance".

    04 / 10Chapter

    What the Commission's AI Literacy Q&A says about level, format and documentation

    In short

    No certificate, no mandatory test, no fixed format and no required AI officer. Cover AI basics, your role, the risks of your systems and differences between staff, and keep an internal record.

    The Q&A sets out four minimum considerations for a programme:

    1. General understanding of AI: what it is, how it works, which AI the organisation uses, and its opportunities and dangers.
    2. The organisation's role: provider or deployer.
    3. The risk of the systems: what employees need to know about risks and mitigations.
    4. Tailored actions: based on staff knowledge and experience, and on the sector, purpose and affected persons.

    Legal and ethical aspects run through all four. On the practical questions:

    • Testing: Article 4 "does not entail an obligation to measure the knowledge of AI of employees."
    • Format: "no strict requirements or mandatory trainings are imposed", but "simply relying on the AI systems' instructions for use or asking the staff to read them might be ineffective."
    • Documentation: "There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives."
    • Governance: "no specific governance structure is mandated".
    • Levels: different levels for different groups "could be appropriate".

    Copying a practice from the Commission's living repository of AI literacy practices "does not automatically grant presumption of compliance".

    Linus IngemarssonEric Lundberg
    Alice Labs practitioner team

    Talk to the team behind 100+ AI implementations

    30-minute discovery call with a senior Alice Labs consultant. No slide deck, no sales pitch — just a scoping conversation.

    Book a Discovery Call
    05 / 10Chapter

    Risk-based AI literacy by role

    In short

    Train each group for the decisions it makes and the systems it uses. Leadership needs judgement and risk ownership, staff need safe everyday use, specialists need depth.

    The Q&A asks organisations to "adapt their AI literacy approach" to their role and the risk of their systems, with additional measures for high-risk systems. The table is the structure we recommend. It is our interpretation, not a format prescribed by the Act. For leadership, see AI training for executives and, in Swedish, AI-utbildning för ledningsgrupper. Procurement teams building a role-indexed vendor shortlist to deliver this risk-based literacy at scale should pair this table with our best AI training companies by persona 2026 comparison, which ranks providers specifically for each of the six Article 4 roles above.

    Article 4 AI literacy by role: what each group needs to know and how it is trained
    Role What they need to know How it is trained
    Board and leadership team What AI can and cannot do, where it changes the business, provider or deployer role, risk ownership, the AI Act at overview level Working session on real leadership tasks, ending in a decision on one bounded workflow and its owner
    All staff using ChatGPT, Copilot or Claude How the tool works, hallucination and verification, what data may be entered, the AI policy Hands-on basics in your own tool with your own tasks, plus a one-page policy
    Function specialists (sales, HR, finance, legal, support) Use cases and risks per function, such as personal data in HR or accuracy in finance Role workshops on the team's workflows, reviewing output against its quality standards
    Developers and technical staff Model and agent behaviour, evaluation, security, logging, provider obligations Technical sessions on the actual stack and briefing on AI Act classification
    Control functions (legal, compliance, DPO, risk, audit) AI Act Articles 4, 5, 26 and 50, GDPR interplay, classifying and auditing AI use Regulatory briefing and review of the AI inventory and training records
    Human overseers of high-risk systems The specific system, its limits, when to override, how to escalate System-specific training with competence and authority documented per person (Article 26(2))
    Contractors acting on your behalf Your AI policy and the risks of the tools they use for you Onboarding material and a contractual reference to the policy, scaled to risk

    Source: Alice Labs, based on the European Commission AI Literacy Q&A and Regulation (EU) 2024/1689

    06 / 10Chapter

    A practical AI literacy programme in six steps

    In short

    Inventory AI use, map roles to risk, write a short AI policy, train by role on real tasks, support use afterwards, and keep a dated record.

    1. Inventory AI use. Include AI features inside existing software and private accounts used for work. Flag anything that could be high-risk under Annex III.
    2. Map roles to risk. Group people by what they do with AI and decide depth per group.
    3. Write the AI policy. One page: approved tools, what may be entered, when output must be reviewed, who to ask.
    4. Train by role, on real tasks. People learn to judge AI output by producing it on their own work and checking it.
    5. Support use afterwards. Office hours, shared prompts and a follow-up session a few weeks later turn a course into habits.
    6. Record and review. Update when tools, systems or rules change, for example when the AI Board's Article 4(3) recommendations arrive.

    For programme scoping, see what corporate AI training is and our AI training for companies.

    If you are already at the supplier-comparison stage, our review of the best enterprise AI training companies for 2026 sets out the evaluation criteria that matter under Article 4.

    Linus IngemarssonEric Lundberg
    Alice Labs practitioner team

    Need an Article 4 programme you can document?

    Alice Labs runs practical, role-based AI training on your own tools and tasks, and delivers the policy and training record with it.

    See AI training
    07 / 10Chapter

    How to document Article 4 compliance

    In short

    Keep an internal record per group: systems used, measures taken, when, by whom, with what content, and the next review date. No certificate is needed.

    As an obligation of effort, your evidence is the effort itself. A record an authority, auditor or customer can read should contain:

    • The AI inventory and the role groups mapped to it
    • The AI policy, with version and date
    • Per group: format, date, trainer, content outline and materials
    • Attendance lists, including contractors where relevant
    • Follow-up measures such as office hours and refreshers
    • For high-risk systems: named overseers and their training under Article 26(2)
    • A review date and a named owner

    A shared folder or the HR learning system is enough. A short practical exercise is useful evidence that training was more than slides.

    08 / 10Chapter

    Article 4 in Sweden: PTS, IMY, Digg and AI Sweden

    In short

    Sweden's interim authorities, assigned until 31 December 2026, do not include an explicit Article 4 mandate. SOU 2025:101 proposes PTS for Article 4 and no sanction fee.

    On 4 June 2026 the Government (Fi2026/01365) assigned PTS, IMY, Finansinspektionen, Läkemedelsverket and Swedac as national competent authorities under the AI Act until 31 December 2026, pending complementary Swedish legislation. PTS is the single point of contact and covers certain prohibited uses, high-risk areas and parts of Article 50. IMY covers other prohibited practices, high-risk areas such as biometrics and law enforcement, and Article 50(3). The assignment does not explicitly allocate Article 4.

    The inquiry SOU 2025:101 proposes that PTS, as main market surveillance authority, take responsibility for Article 4, since much of the task is guidance, and that an Article 4 infringement should not lead to a sanction fee. As of September 2026 these are proposals, not law.

    • IMY supervises GDPR, which applies in full once personal data enters an AI tool.
    • Digg and IMY published national guidelines for generative AI in public administration in January 2025, including competence-raising measures.
    • AI Sweden, the national centre for applied AI, and the European Digital Innovation Hubs offer learning resources that complement internal training.

    Swedish readers: see AI-utbildning för företag. This article is a practical overview, not legal advice.

    09 / 10Chapter

    Common Article 4 mistakes

    In short

    Assuming the Omnibus removed Article 4, one generic module for everyone, buying certificates, forgetting contractors, and keeping no record.

    • "The Omnibus removed it." It did not. The duty is one of effort, but it applies.
    • One generic module for everyone. A CFO and a support agent need different content.
    • Buying a certificate as proof. None is needed. The record matters more.
    • Pointing staff to vendor documentation. The Q&A says this might be ineffective.
    • Forgetting contractors. People using AI on your behalf are in scope.
    • Confusing Article 4 with Article 26(2). High-risk deployers need system-specific oversight training on top.
    • Banning AI instead of training. Bans push use to private accounts, with no control and no record.
    Linus IngemarssonEric Lundberg
    Alice Labs practitioner team

    Build AI literacy that changes how people work

    Show live, try it yourself, review together. Training for leadership teams and staff in Sweden, with Article 4 documentation included.

    Explore AI training
    10 / 10Chapter

    How Alice Labs runs practical AI literacy training

    In short

    We train on the client's own tools and tasks: show live, try it yourself, review together, using a four-part working model of context, goal, draft and review.

    Alice Labs is a Stockholm-based AI consultancy and training provider. We start from the tools an organisation already has, whether ChatGPT, Copilot or Claude, and the tasks people actually do. Every module follows the same method: we show live, participants try it themselves, and we review the result together.

    Participants learn a four-part working model: give the AI context, state the goal, let it produce a draft, and review it before use. Review is where literacy shows: spotting ungrounded claims and invented sources. Leadership sessions focus on judgement: which work is worth changing, which data and risk conditions apply, and who owns the result. The policy, role-based content and training record are delivered with the training.

    About the Authors & Reviewers

    Published ·Updated
    Written by
    Eric Lundberg - Co-Founder, Alice Labs at Alice Labs
    Eric Lundberg

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.

    • AI automation & agent systems lead
    • Workflow design across 100+ deployments
    • Specialist in RAG, integrations & APIs
    Reviewed by
    Linus Ingemarsson - CEO & Co-Founder, Alice Labs at Alice Labs
    Linus Ingemarsson

    CEO & Co-Founder, Alice Labs

    CEO & Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.

    • 8+ years in AI strategy & implementation
    • Top-5 AI Speaker, Sweden (Mindley 2025)
    • 100+ enterprise AI engagements
    Published · Updated
    Reviewed for technical accuracy, methodology and source integrity.·All claims trace to public sources cited in-line.

    Frequently Asked Questions

    What does Article 4 of the EU AI Act require?

    Providers and deployers of AI systems must take measures to support the AI literacy of their staff and others using AI on their behalf, adapted to knowledge, experience and context. No specific level has to be guaranteed.

    When did the AI literacy obligation start to apply?

    On 2 February 2025. According to the European Commission, national market surveillance authorities supervise and enforce it from 2 August 2026.

    What did the Digital Omnibus change in Article 4?

    Regulation (EU) 2026/1744, in force since 27 July 2026, replaced 'ensure a sufficient level' with 'take measures to support the development of' AI literacy, and added support duties for the Commission, Member States and the AI Board.

    Does Article 4 apply if our employees only use ChatGPT or Copilot?

    Yes. Using AI professionally makes you a deployer. The Commission says such staff should be informed about specific risks, for example hallucination.

    Do we need an AI literacy certificate?

    No. The Commission's Q&A states there is no need for a certificate. An internal record of trainings and other guiding initiatives is enough.

    Do we have to test employees' AI knowledge?

    No. Article 4 does not entail an obligation to measure employees' AI knowledge, according to the Commission. A practical exercise is still useful evidence.

    Who supervises Article 4 in Sweden?

    As of September 2026, the interim assignment to PTS, IMY, Finansinspektionen, Läkemedelsverket and Swedac (until 31 December 2026) does not explicitly allocate Article 4. SOU 2025:101 proposes PTS.

    What are the penalties for breaching Article 4?

    Penalties follow national law and must be proportionate, and are more likely after an incident caused by inadequate training. SOU 2025:101 proposes no sanction fee for Article 4 in Sweden.

    Is a single e-learning course enough for Article 4?

    Rarely. Article 4 asks you to consider each group's knowledge and context, and the Commission warns that relying on instructions for use might be ineffective. Role-based training is easier to defend.

    Does Article 4 cover contractors and consultants?

    Yes. Other persons dealing with AI on your behalf, such as contractors or service providers, fall within the organisational remit and should be covered in proportion to risk.

    Previous in AI Training & Education

    AI Upskilling Program Design: A Framework for Building AI Capabilities

    Next in AI Training & Education

    Corporate AI Training: Programs, Costs & Formats 2026

    Further reading

    Related services

    Related reading

    Sources

    1. Regulation (EU) 2024/1689 (AI Act), Articles 3, 4, 26 and 113, EUR-Lex(accessed 2026-09-29)
    2. Regulation (EU) 2026/1744, Digital Omnibus on AI, EUR-Lex(accessed 2026-09-29)
    3. European Commission: AI Literacy, Questions & Answers(accessed 2026-09-29)
    4. European Commission: AI talent, skills and literacy(accessed 2026-09-29)
    5. Regeringen: Uppdrag att vara nationella behöriga myndigheter enligt AI-förordningen (Fi2026/01365)(accessed 2026-09-29)
    6. SOU 2025:101 Anpassningar till AI-förordningen, Regeringen(accessed 2026-09-29)
    7. IMY: Vilken myndighet kommer övervaka AI-förordningen i Sverige?(accessed 2026-09-29)
    8. Digg: Riktlinjer för generativ AI inom offentlig förvaltning (Digg and IMY)(accessed 2026-09-29)

    Next scheduled review:

    Linus IngemarssonEric Lundberg
    Alice Labs practitioner team

    Build AI literacy that changes how people work

    Show live, try it yourself, review together. Training for leadership teams and staff in Sweden, with Article 4 documentation included.

    Explore AI training
    Share

    Get in Touch!

    The lab usually responds within 24 hours.

    Need help with AI?Get in touch