← Blog.
ENRO
AI Act

AI Act Article 4: What SMEs Actually Need to Do About AI Literacy

A proportionate plan for AI Act Article 4, by role, with what to document, and the corrected dates after the Digital Omnibus: high-risk obligations for HR tools now apply from 2 December 2027.

A boardroom table at night with a stack of printed documents, an open binder and a laptop, lit in blue.

Yes. Since 2 February 2025, Article 4 of the EU AI Act requires every organisation that uses AI systems to take measures supporting the AI literacy of the people who use them. Since the Digital Omnibus (July 2026), no "sufficient level" is required, only proportionate, documented measures. High-risk obligations for HR tools apply from 2 December 2027.

Every employer in Europe knows the health-and-safety induction: a slide deck, a signature, a folder in a drawer. When I first read Article 4 of the AI Act, my worry was that it would become exactly that, one more form to sign. The version amended in summer 2026 makes that temptation stronger, so it is worth reading closely what it actually asks.

This is an operational guide, not legal advice. For your specific situation, talk to a lawyer.

Is AI literacy training mandatory in the EU?

Yes. Article 4 has applied since 2 February 2025, and it covers any organisation that uses AI systems (a "deployer" in the Act's language), not only those that build them. If your staff use ChatGPT, Copilot, Gemini or Claude for work, you are in scope.

What changed is the shape of the duty. The Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, rewrote Article 4 in full. Providers and deployers now "take measures to support the development of AI literacy" of their staff and others operating AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context of use. And the new text adds: "This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."

So the law moved from an obligation of result ("a sufficient level") to an obligation of effort, proportionate and provable. The same amendment tells the Commission and Member States to support organisations, SMEs in particular, and requires the Commission to publish practical compliance examples. The Commission's own AI literacy Q&A confirms the reading: AI literacy remains an obligation, but no specific or "sufficient" level is mandated.

Which AI Act dates apply now, after the Digital Omnibus?

A lot of pages, in Romania and elsewhere, still tell employers the HR deadline is 2 August 2026. It no longer is. The Omnibus moved the rules for stand-alone high-risk systems in Annex III, which include employment, to 2 December 2027.

DateWhat appliesRelevant if you…
2 February 2025Article 4 (AI literacy) and the Article 5 prohibitions, including emotion recognition in the workplaceuse any AI tool at work
27 July 2026The new Article 4 text (support measures, no "sufficient" level)as above
2 August 2026Most of the Act; supervision and enforcement start; Article 50 transparency obligationsrun a customer-facing chatbot or publish AI-generated content
2 December 2026New prohibitions (non-consensual intimate imagery, child sexual abuse material) and the end of the Article 50(2) marking transitionprovide generative AI systems
2 December 2027High-risk rules for Annex III systems, including recruitment, evaluation, promotion, terminationuse AI in decisions about candidates or staff
2 August 2028High-risk rules for AI embedded in regulated products (Annex I)make machinery, medical devices and similar

Sources: the text of Regulation 2026/1744 in the Official Journal and the implementation timeline published by the Commission's AI Act Service Desk, both read on 26 September 2026.

What counts as "measures to support AI literacy"?

Knowing which tools your people use, what the risks are in your context, and giving each group training that fits its role. The Commission's Q&A lists four things to consider:

  • a general understanding of AI in the organisation: what it is, how it works, what you use and what the risks are;
  • your role: whether you only deploy AI systems or also provide them;
  • the risk of the systems you use: what staff need to know to use them without causing harm;
  • tailored action: people's different technical levels and the context the tools are used in.

Three further points from the same Q&A matter for a small company. No certificate is needed; an internal record of trainings and other guidance initiatives is enough. There is "no one size fits all", and different levels of training for different groups can be appropriate. And simply relying on the instructions for use, or asking staff to read them, "might be ineffective". The Commission's own example is as ordinary as it gets: if employees use ChatGPT to write advertising copy or translate text, they should be told about specific risks such as hallucination.

The duty also reaches contractors: people working for a service provider on your behalf need the AI skills appropriate to their task.

What does a proportionate plan by role look like?

A good plan starts from what each person does with AI, not from the org chart. I suggest four groups, each with a different depth:

GroupWhoWhat they need to knowReasonable format
Everyoneany employee with access to an AI toolwhich tools are approved, what data never goes into a prompt, what a hallucination is and how to check, whom to tell when something goes wronga short session plus a one-page AI policy
Heavy usersmarketing, sales, support, legal, finance, anyone producing text or analysis with AI dailyprompting on their real tasks, checking sources, limits on personal and confidential data, when not to use AIa hands-on workshop on their own documents and tasks
People using AI in decisions about peopleHR, recruiters, managers who assess performancewhat a high-risk system is, bias, meaningful human oversight, what candidates and staff must be told, the emotion-recognition bandedicated training plus a written procedure per tool
Leadershipdirectors, ownerswhich tools are allowed and why, who owns the AI register, which risks the company accepts, the time budget for traininga leadership workshop, half strategy, half concrete decisions

A hypothetical example, to show the logic: imagine a distribution company of around 60 people. Finance uses Copilot on email, marketing writes with ChatGPT, and HR has started running CVs through a screening tool. Everyone gets the baseline session and the policy. Marketing and finance get a workshop on their own tasks. HR gets separate training, because the screening tool is precisely the kind of Annex III system that carries its own obligations from December 2027. Leadership decides whether to keep that tool at all. Nobody sits through a generic "AI for everyone" course.

If you are only starting with AI, the step-by-step guide to implementing AI in your company shows where to begin, and how to structure your company for AI covers who should own the register and the training.

How do I document compliance with Article 4?

With three short documents, kept current. There is no prescribed format, but these answer the questions any supervisor will ask:

  1. AI tools register. One table: which tool, who uses it, for what, what data goes in, which plan or contract you are on, who owns it. Without it you cannot say what your risk is. If you have not settled on the tools yet, start with ChatGPT vs Copilot for business.
  2. AI policy. One or two pages. Approved tools, data banned from prompts (customers' personal data, health data, trade secrets), the duty to check AI output, how to report a mistake.
  3. Training log. Who, when, what was covered, for which group, with which materials. Add what changed afterwards: an updated policy, a tool withdrawn.

This is where it differs from the safety induction. A log proves nothing if it is only a list of signatures. The evidence is the link between the tools register and the training: the people using AI in HR received something different from the people writing newsletters, and you can show why.

What does the AI Act require from employers using AI in HR?

Some of it applies already, the rest from 2 December 2027. Already banned since 2 February 2025: using AI to infer people's emotions in the workplace, except for medical or safety reasons. If a video-interview tool promises to "read" a candidate's enthusiasm, ask the vendor exactly what it does.

From 2 December 2027, the high-risk rules apply to Annex III point 4 systems of the AI Act: AI used in recruitment and selection (targeted job ads, filtering applications, evaluating candidates) and AI used for decisions on working conditions, promotion, termination, task allocation based on behaviour or personal traits, or monitoring performance. As an employer deploying such systems you carry deployer duties under Article 26: use them according to the instructions, with human oversight by trained people, keep the logs, and before putting such a system into service at the workplace, inform workers' representatives and the affected workers.

The delay is not a reason to wait. A screening tool you choose now will still be there in December 2027, and the GDPR already applies to automated decisions about candidates. Use the time to pick vendors who can give you the documentation you will need; independent AI consulting can help with choosing and auditing HR tools.

Who enforces Article 4, and what are the penalties?

The Commission says national market surveillance authorities, not the AI Office, oversee Article 4, with supervision and enforcement starting in August 2026. Penalties are set nationally, and the Commission stresses that any sanction must be proportionate, taking into account the nature and gravity of the breach and whether it was intentional or negligent. In Romania, the government designated ANCOM as market surveillance authority and single point of contact by a memorandum of 12 March 2026, alongside ASF and BNR for financial services and ANSPDCP for sensitive areas. National penalties are still being set in Romanian law: when I checked on 26 September 2026, the implementing law with the sanctions regime had not been adopted. If you operate outside Romania, check your own Member State.

None of that makes the obligation optional. The regulation applies directly. A well-kept register is exactly what shows you were not negligent.

So what?

Article 4 no longer asks for a result. It asks for an effort you can show. I would bet many companies will read "no need to guarantee a level" as "no need to do anything serious", and produce one more folder of signatures. I wonder whether the softer text is actually the harder test: nobody tells you any more how much is enough, so you have to decide, and be able to explain the decision.

If you want AI training built around the roles and tools in your company, the details are on the AI workshops for teams page, and for directors, the AI workshop for leadership teams.

Frequently asked questions

Is AI literacy training mandatory in the EU?

Yes. Since 2 February 2025, Article 4 of the AI Act requires organisations that use AI systems to take measures supporting their staff's AI literacy. It does not prescribe a course, a number of hours or a certificate. It requires measures suited to people's roles that you can document.

What changed in Article 4 with the Digital Omnibus?

Regulation (EU) 2026/1744, in force since 27 July 2026, replaced the duty to ensure "a sufficient level" of AI literacy with a duty to take measures supporting its development. The text states that organisations do not have to guarantee any specific level for any individual.

What do SMEs need to do under AI Act Article 4?

Keep a register of the AI tools in use, write a short AI policy, train people according to what they do with AI (everyone, heavy users, HR, leadership) and keep a training log. The Commission says an internal record is enough and no certificate is needed.

When do AI Act obligations for HR and recruitment apply?

From 2 December 2027 for high-risk AI in recruitment and workforce management, after the Digital Omnibus delay. The ban on emotion recognition in the workplace has applied since February 2025, and Article 4 literacy since the same date.

Do I need an AI officer to comply with Article 4?

No. The Commission's Q&A says no specific governance structure is mandated. In practice someone must own the tools register and the training log, and in a small company that is usually an operations lead or a director.
Work with me

Want to talk it through?

If your company is working out where AI fits, the first conversation is free. A few short questions, and the reply comes from me within 24 hours on working days.