AI Literacy Is Your Legal Obligation, Not Just A Good Intention

If your organisation uses AI tools it didn't build, you may not realise that you have a binding legal obligation under European law. Article 4 of the EU AI Act requires businesses to ensure their workforce possesses adequate levels of AI literacy. For most organisations, however, this has not been given much thought.

AI Literacy Legal Obligation

This article describes legal obligations in general terms. It is not legal advice. If the AI Act applies to your organisation, take proper advice on what it means for you specifically.

There is no automatic, multi-million euro fine for skipping AI literacy training on its own. But when a regulator is deciding whether to fine you for anything under the AI Act, they are legally mandated to look at the systemic safeguards you have in place. Under Article 99(7)(g), your AI literacy programme serves as evidence of organisational responsibility.

An auditor isn't going to knock on your door just to review your training records. The problem is the day something else goes wrong, an incident, a bias complaint, or an automated decision that harms an individual, and a regulator asks what you did to make sure the people running that AI system knew what they were doing. "Nothing" is not an acceptable answer at that point. It's an aggravating one.

This is how to frame the argument if you need to justify funding. The obligation isn't hypothetical; a lack of structured training weakens your legal defence and amplifies your exposure under the AI Act's formal penalty test.

The Digital Omnibus updated the literacy obligation to make it easier to meet, and pushed the enforcement timelines for high-risk AI back. Many legal experts have already published the breakdown on that, so I won’t repeat it. What none of them are asking is whether the softer wording changes your actual exposure. It doesn't, for the reason above, and that's why I'm calling it out here.

Most organisations skip right past Article 4 because it can be incorrectly interpreted as somebody else's problem. They didn't build the model; they simply bought a tool or paid for a service, and switched it on. That's the mistake. This obligation applies to deployers, not just to the companies that build AI. If you put an AI system to work in your business, you're a deployer. In Ireland, 64% of employees expect to reskill because of AI while only 5% of organisations train on AI at scale. That's not just a skills gap. It's a compliance gap.

The wording softened, the obligation didn't

The final text of the AI Act provides a realistic boundary: Article 4(1) no longer requires you to guarantee any individual's literacy level. The duty changed from a duty of result, ensuring a defined outcome "to your best extent," to a duty of effort: supporting the development of AI literacy. That sounds like a downgrade, and it is, but effort is still something you have to show.

Crucially, this bar rises depending on who your system impacts. Your training programme must actively account for the education, technical knowledge, and context of your staff, alongside the specific groups of persons on whom the AI systems are to be used. If your AI makes decisions about patients, job candidates, or borrowers, your literacy depth must scale up accordingly.

If your AI is classified as high-risk, a second, sharper obligation sits directly inside the heavier penalty tier: human oversight has to sit with people who have the necessary competence, training and authority to exercise it, and the support to do so. The Digital Omnibus pushed the enforcement timelines back, setting 2 December 2027 for independent high-risk systems under Annex III (like recruitment and credit scoring) and 2 August 2028 for embedded safety components under Annex I. However, building a defensible framework that proves your supervisors actually possess this competence is a multi-quarter operational lift, so starting sooner is better than scrambling later.

Why generic vendor training fails the compliance test

There are some key definitions outlined in a European standards document published in June 2026: CWA 18398 splits AI competence into three positions, and the split is more important than it looks at first glance.

The standard's own test is clean: a developer using an AI tool to build an ordinary app is a professional user; a developer building an AI application is an AI professional. The same split applies to a clinician using a diagnostic aid versus a data scientist who trained it, or a recruiter running a screening tool versus the vendor who built it.

Content vendors often sell training material to all three levels as one product, and organisations buy assuming they’re covered. A prompt-engineering workshop does not make a clinician safe to rely on an AI recommendation, because the risk in that job was never about prompting. It's about knowing when to overrule the machine, which is a professional-user skill, not a technical one. You cannot design proportionate training, the kind that would actually count as a measure in front of a regulator, until you know which of these three positions each of your people sits in.

None of this can be delivered centrally, either. You can publish an overarching AI policy, but you cannot centrally supply the judgement of the person deciding, at four on a Friday afternoon, whether to accept what the AI model just told them.

Someone still has to own the literacy programme itself. In most organisations that person already exists, unnamed, part-time, doing the work on top of their real job. Naming them is the first move.

Softer wording isn't a way out

The easy response to all of this is an e-learning module, a completion register and a screenshot for the auditor. The softer wording makes that easier to justify and no more likely to change how anyone actually uses AI day to day. It will read just as thin to a regulator weighing intent and mitigation as the box-ticking exercise. It also costs you trust that's already low, with 44% of workers reporting little or no confidence AI will be good for them. Measure how skills get used and how work actually changes, not whether learning videos were watched.

What to do next

  1. Map your users: Audit who uses AI and how, then group them against the lay user, professional user, and AI professional split.
  2. Target by role, not seniority: The most senior person in the room is often the least literate. Prioritise the professional users carrying judgement accountability, as they need far more depth than a lay user ever will.
  3. Flag high-risk systems now: Identify any systems that touch recruitment, credit scoring, or critical infrastructure. Formally name whoever will hold human oversight, and check that they have all four: competence, training, authority, and support.
  4. Identify a programme owner: Make it an official position and give them time to make it a real deliverable rather than a side project.
  5. Record what you did and why it was proportionate: This is what you'll show the regulator if something goes wrong.

None of that requires a consultant or a platform. It requires deciding this is something your organisation is accountable for, before a regulator makes that decision for you.

The wording may have softened, but what a regulator asks for on the day something goes wrong doesn't.

Further reading:

Last updated: 30 Aug 2026