Skip to main content

← All articles

AI literacy under Article 4 after the Omnibus

Article 4 of the AI Act after the Digital Omnibus: who is affected, what the Bundesnetzagentur expects, what is settled on fines and how to document your measures.

Sebastian LangSebastian LangOctober 5, 202617 min read
AI literacy under Article 4 after the Omnibus

The AI literacy requirement under Article 4 of the AI Act still exists, but since this summer it reads differently. On 27 July 2026 the Digital Omnibus on the AI Act entered into force, Regulation (EU) 2026/1744. Since then, Article 4 requires providers and deployers of AI systems to take measures to support the development of AI literacy, without mandating a particular level, compulsory training or a certificate. Since 2 August 2026, national market surveillance authorities have supervised the rule. In Germany, under the new KI-MIG, that is in principle the Federal Network Agency (Bundesnetzagentur).

This article consolidates our earlier pieces on Article 4 and brings them up to date after the Omnibus. Every legal statement rests on the text of the regulation, the European Commission's questions and answers, the KI-MIG or the Bundesnetzagentur's pages (as of October 2026). The sources are listed at the end. The text is not legal advice.

TL;DR

  • The obligation stays, the standard is softer. Providers and deployers of AI systems, including those who only buy and use tools, must take measures that support the AI literacy of their staff. They do not have to guarantee a particular level.
  • In Germany the Bundesnetzagentur is in principle the competent authority. Neither Article 99 AI Act nor the KI-MIG names a separate fine range for Article 4. According to the European Commission, penalties and other measures are still possible.
  • What matters is a traceable, documented approach. Inventory, roles, measures, record sheet, refresher. The Bundesnetzagentur expressly recommends documenting the measures well.

What Article 4 requires since the Digital Omnibus

Article 4 requires measures, not a guaranteed learning outcome. The Bundesnetzagentur quotes the amended paragraph 1 as follows:

"Die Anbieter und Betreiber von KI-Systemen ergreifen Maßnahmen, um die Entwicklung der KI-Kompetenz ihres Personals und anderer Personen zu unterstützen, die in ihrem Auftrag mit dem Betrieb und der Nutzung von KI-Systemen befasst sind, wobei ihre technischen Kenntnisse, ihre Erfahrung, ihre Aus- und Fortbildung und der Kontext, in dem die KI-Systeme eingesetzt werden sollen, sowie die Personen oder Personengruppen, bei denen die KI-Systeme eingesetzt werden sollen, zu berücksichtigen sind. Diese Verpflichtung verpflichtet Anbieter oder Betreiber nicht, für irgendeine Person ein bestimmtes Niveau an KI-Kompetenz zu garantieren."

Unofficial English translation: "Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee a particular level of AI literacy for any person."

Three points follow:

  1. The obligation stays with companies. In its questions and answers on Article 4 (as of 27 July 2026), the European Commission writes that AI literacy remains an obligation for providers and deployers. A particular or "sufficient" level, however, is no longer required.
  2. The yardstick is context. What has to be taken into account is the knowledge, experience, education and training of the people, the context of use and the persons on whom the systems are used.
  3. The EU and the Member States help. Under paragraph 2, the Commission and the Member States support companies, in particular SMEs. For this purpose the Commission publishes practical examples on a central information platform. Under paragraph 3, the AI Board adopts recommendations.

Article 3(56) defines AI literacy as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems and to gain awareness of the opportunities and risks of AI and of possible harm it can cause. The obligation is not new. Article 4 sits in Chapter I of the regulation and has applied since 2 February 2025 under Article 113(a). The Omnibus amended it in 2026.

Who the obligation applies to

Article 4 affects every company that offers AI systems or uses them professionally. The Bundesnetzagentur writes that this applies regardless of industry and organisation size and also covers general-purpose systems such as chatbots.

A provider is whoever develops an AI system, or has one developed, and places it on the market or puts it into service under its own name (Article 3(3)). A deployer is whoever uses an AI system under its own authority, except where the system is used in the course of a personal non-professional activity (Article 3(4)).

Bought-in tools count too

You do not have to build AI yourself to be affected. Anyone who uses a bought-in AI system at work uses it under its own authority and is therefore a deployer. The European Commission answers the question of whether a company whose employees use ChatGPT, for example for marketing copy or translations, has to comply with Article 4 with an explicit yes: people should be informed about the specific risks, for example hallucinations.

Who "other persons" are

This does not mean only employees. The Commission names persons in the organisational environment, for example contractors, service providers or clients. The Bundesnetzagentur names contractors and service providers. For service providers, the Commission writes that their people need AI skills suited to their task, just like the company's own staff. According to the Commission, whether you obtain contractual assurances of this depends on the system and its risk.

Exceptions

  • Purely private use: The regulation does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity (Article 2(10)).
  • Research: It does not apply to AI systems and AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development (Article 2(6)).

Article 4 contains no exemption for small companies.

High-risk AI: an additional obligation

For deployers of high-risk AI, the Commission says the obligation under Article 26 remains in addition: the staff working with the system must be trained well enough to handle the system and to ensure human oversight. For the high-risk cases in Annex III, such as AI for selecting applicants or assessing creditworthiness, these rules apply from 2 December 2027 since the Omnibus.

EU AI Act

AI literacy under Article 4: build it and document it

Go to the AI Act checklist

What changed with the Omnibus

The Omnibus weakened Article 4 but did not abolish it. A direct comparison of the two versions shows where the difference lies (the quotations in the table are unofficial English translations of the German wording):

2024 version (applies from 2 February 2025)Version after the Omnibus (since 27 July 2026)
Core obligationMeasures "to ensure, to their best extent, a sufficient level of AI literacy" of staff and other personsMeasures "to support the development of AI literacy" of staff and other persons
Levela "sufficient level" as the goalexpressly no particular level for any person
AddresseesProviders and deployersunchanged: providers and deployers
YardstickKnowledge, experience, education and training, context, affected personsessentially unchanged
Role of the EU and Member Statesnot regulated in Article 4Paragraph 2: support mainly for SMEs, practical examples; paragraph 3: recommendations of the AI Board

The Bundesnetzagentur quotes the old wording in its guidance paper of June 2025 and the new one on its current page on AI literacy.

The route to this result is instructive. In its proposal of 19 November 2025, according to its questions and answers, the Commission wanted to shift the obligation to the Member States and the Commission instead of imposing an unspecific obligation on companies. In the adopted text the obligation stays with providers and deployers, only without a fixed level. Anyone who reads that Article 4 was deleted is confusing the proposal with the outcome.

The timeline at a glance

  • 2 February 2025: Article 4 applies (Article 113(a)).
  • 19 November 2025: The Commission presents the Digital Omnibus.
  • 11 June 2026: The Bundestag adopts the act implementing the AI regulation, whose Article 1 is the KI-MIG.
  • 24 July 2026: The Omnibus is published in the Official Journal of the EU.
  • 27 July 2026: The Omnibus enters into force, and the amended Article 4 applies.
  • 29 July 2026: The KI-MIG enters into force, the Bundesnetzagentur takes up its role.
  • 2 August 2026: National market surveillance authorities supervise and enforce Article 4. On the same day the AI Office and national authorities begin enforcing the AI Act, and the transparency obligations under Article 50 take effect, more on this in our article on the transparency obligation under Article 50. Only for the machine-readable marking under Article 50(2) do systems placed on the market before 2 August 2026 have until 2 December 2026.
  • 2 December 2027: The rules for high-risk AI under Annex III apply.
  • 2 August 2028: The rules for AI in regulated products under Annex I apply.

Who supervises: Bundesnetzagentur and KI-MIG

Article 4 is a matter for the national authorities, not the EU AI Office. The Commission makes this clear in its questions and answers. In Germany the route usually leads to the Bundesnetzagentur.

The basis is the Act on Market Surveillance and Innovation Promotion of Artificial Intelligence (Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz, KI-MIG) of 22 July 2026, BGBl. 2026 I No. 223, in force since 29 July 2026. Under § 2(1) KI-MIG, the Bundesnetzagentur is the competent market surveillance authority unless the act provides otherwise. It does provide otherwise for AI systems directly connected with a regulated financial activity (BaFin, § 2(3)) and for AI in products under Annex I Section A, for which the existing product authorities remain responsible (§ 2(2)).

According to its press release of 29 July 2026, the Bundesnetzagentur is thus the market surveillance authority, central contact point and central complaints body: it receives complaints about infringements of the AI regulation and, where appropriate, forwards them to the competent authorities. For companies there is the AI Service Desk (KI-Service-Desk) with an online tool for a first assessment of the risk class, information on European guidelines and codes of practice, and tips on building AI literacy. There is also an AI regulatory sandbox (KI-Reallabor) aimed in particular at small and medium-sized enterprises.

For the Mittelstand, the Bundesnetzagentur also names free support on its AI literacy page: about 100 AI trainers are available through the Mittelstand-Digital Centres (Mittelstand-Digital Zentren) and support SMEs individually and vendor-neutrally, and there are also the European Digital Innovation Hubs.

Fines: what is settled and what is not

Neither Article 99 AI Act nor the KI-MIG names a separate fine range for Article 4. According to the European Commission, infringements can nevertheless lead to penalties or other enforcement measures. We can clearly distinguish what is settled from what remains uncertain.

What is settled:

  • Article 99 AI Act tiers the fines: up to EUR 35 million or 7 percent of worldwide annual turnover for prohibited practices under Article 5, up to EUR 15 million or 3 percent for the obligations named in Article 99(4) (including Articles 16, 26 and 50), and up to EUR 7.5 million or 1 percent for incorrect, incomplete or misleading information to notified bodies or competent authorities. Article 4 is on none of these lists.
  • The KI-MIG provides in § 15 for its own fines of up to EUR 50,000 for obligations under Articles 21, 27, 45 and 86. Article 4 is missing there as well. § 16 governs the procedure for infringements under Article 99(3) to (5) under the Administrative Offences Act (Gesetz über Ordnungswidrigkeiten).
  • The European Commission nevertheless writes that national market surveillance authorities could sanction infringements of Article 4 with penalties and other enforcement measures. Any penalty must be proportionate and take into account the nature, gravity and intent or negligence. It is more likely if an incident demonstrably goes back to a lack of appropriate training and guidance.
  • The Bundesnetzagentur writes that a lack of AI literacy can be regarded as a breach of the duty of care (Sorgfaltspflicht), in particular if damage results.

What is not settled:

  • An amount for Article 4. Neither Article 99 AI Act nor the KI-MIG names one. A euro sum that someone presents to you as an Article 4 fine is not covered by these provisions.
  • Practice. How the authorities use penalties and other measures for Article 4 in individual cases is not laid down by any of the texts cited.
  • Liability. According to the Commission, the AI Act itself creates neither criminal offences nor a separate claim for damages. Whether and how someone is liable for damage is governed by national law.

Is a webinar enough? What counts as a measure

A webinar can be a measure. Whether it is enough depends on who uses which systems for what, not on the format.

Neither the text of the regulation nor the authorities prescribe a minimum format. The Bundesnetzagentur names a range from self-study programmes through workshops and training courses to multi-stage further training programmes, organised in-house or externally. According to its account, guaranteed competence levels for individual persons, formalised or standardised training measures, external certifications and an AI officer (KI-Beauftragter) are expressly not required. The decision on the measures should, however, be plausible and traceable.

The Commission says the same in other words: there is no one-size-fits-all solution and no strict requirements or mandatory training. According to its interpretation, Article 4 contains no obligation to measure employees' knowledge. At the same time it warns that in many cases it may be ineffective merely to refer to the system's instructions for use or to ask people to read them. As minimum considerations it names:

  1. a general understanding of AI in the company: what AI is, how it works, which AI we use, which opportunities and dangers exist,
  2. the company's own role as provider or deployer,
  3. the risk of the systems in use: what people need to know, which risks they must be aware of,
  4. measures building on this, adapted to prior knowledge, experience and context of use, including legal and ethical aspects.

According to the Commission, different levels for different groups can be appropriate. The Bundesnetzagentur proposes a staged build-up: a basic understanding for everyone, advanced skills on the role, technology, risks and legal classification of the AI in use, then role-specific training. These contents are neither mandatory nor exhaustive. The Commission collects practical examples in a public repository with more than 40 initiatives, from e-learning through in-person training to bootcamps. Anyone who adopts one of these practices cannot, however, automatically infer from it that Article 4 is met, according to the Commission.

Our recommendation: Combine a general format for everyone with tool-specific exercises for the teams that use AI every day, and record both on the record sheet. We compared whether in-house or open courses fit better in the article In-house training vs. open AI courses.

If you work with Claude: our licence costs EUR 599 per licence, one-off, and includes the training with two courses, Cowork and Claude Code. The Claude Code course has 22 lessons in 7 modules, and what Cowork is about is explained in Claude Cowork explained. That is a measure you write on your record sheet, not a certificate that ticks off Article 4. The law does not require a certificate anyway.

How to document the measures

Article 4 prescribes no particular documentation, but the Bundesnetzagentur recommends documenting the measures well so that organisations can show at any time that they meet the requirements of Article 4. The Commission adds that a certificate is not necessary. Organisations can keep an internal record of training and other measures.

The following five steps follow the three building blocks the Bundesnetzagentur proposes: determine needs, design measures, document, evaluate and refresh.

1. Inventory: which AI runs where?

List all AI systems used in the company, bought-in tools included. For each system, record who uses it, for what purpose and which risks and opportunities are attached. This is how the Bundesnetzagentur describes the first building block, determining needs. For a first assessment of the risk class, its AI Service Desk offers an online tool. Also check whether a system falls into a high-risk area under Annex III, such as the selection of applicants.

2. Roles: who needs what?

Clarify for each system whether you are a provider or a deployer. Then form groups by activity, education and experience, because according to the Bundesnetzagentur these individual factors should shape the measures. Think of service providers and contractors who work with AI on your behalf. Set goals and designate the people responsible. The Bundesnetzagentur also includes this in designing the measures.

3. Measures: matched to group and risk

Assign measures to each group: basics for everyone, deeper training for intensive users, role-specific content for those in charge. Put the ground rules in writing, that is, which tools are approved and which data may go into them. For this we have our AI policy as a template. It contains a section on AI literacy under Article 4.

4. Record sheet: what, when, who

The Bundesnetzagentur recommends documenting, among other things, the type of measure, the content covered, its duration and the participants. We additionally recommend the date, the responsible person and the date of the next review. A test is not required. If you run one, you can add the result.

The record sheet does not replace a measure. It only shows which ones you have taken and why they fit your systems and people.

5. Refresher: review regularly

According to the Bundesnetzagentur, building AI literacy is a continuous process: skills should be refreshed regularly and adapted to technological developments. It recommends evaluating the measures regularly and refreshing them where needed, for example when systems or the context of use change. Our recommendation: Tie the review to fixed triggers, for example a new tool, a new use case or new employees, and additionally set a fixed date each year.

Where your company stands today is shown by our AI Act checklist with 12 questions, which you receive as a PDF by email. If you want to go through the five steps with us, book a 30-minute call.

FAQ

What does AI literacy under Article 4 of the AI Act mean?

Under Article 3(56), AI literacy means the skills, knowledge and understanding that allow providers, deployers and affected persons to use AI systems competently and to recognise opportunities, risks and possible harm. Article 4 obliges providers and deployers to take measures that support the development of this literacy among their staff and among other persons acting on their behalf. Since the Omnibus they do not have to guarantee a particular level.

Does the obligation also apply to companies that only buy AI tools?

Yes. A deployer is whoever uses an AI system under its own authority, and that includes a bought-in tool in everyday work. The European Commission expressly says yes for a company whose employees use ChatGPT for marketing copy or translations: they should be informed about risks such as hallucinations.

Is a one-off webinar enough to meet the obligation?

The law prescribes no format, so a webinar can be a measure. Whether it is enough on its own depends on the systems, their risk and the people's prior knowledge. The Bundesnetzagentur also recommends refreshing AI literacy regularly.

What counts as sufficient proof?

There is no prescribed proof. According to the European Commission, no certificate is necessary. Organisations can keep an internal record of training and other measures. The Bundesnetzagentur recommends documenting, among other things, the type of measure, the content covered, its duration and the participants.

Does the Digital Omnibus bring any relief?

Yes, on the standard: since 27 July 2026, Article 4 no longer requires a particular or "sufficient" level, but measures that support the development of AI literacy. The Commission and the Member States are to support companies, especially SMEs, among other things with practical examples. The obligation itself, however, stays with providers and deployers.

When does enforcement of Article 4 begin and who is competent?

Article 4 has applied since 2 February 2025, and since 2 August 2026 national market surveillance authorities have supervised the rule. In Germany, under § 2(1) KI-MIG, the Bundesnetzagentur is in principle competent, for AI systems directly connected with a regulated financial activity the BaFin (§ 2(3)) and for AI in products under Annex I Section A the existing product authorities (§ 2(2)). According to the Commission, the EU AI Office does not enforce Article 4 itself.

Sources

EU AI Act

AI literacy under Article 4: build it and document it

Article 4 asks for measures that build AI literacy, but no specific level and no certificate. The checklist shows in 12 questions where your company stands.

Sebastian Lang

About the author

Sebastian Lang

Co-Founder · Business & Content Lead

Co-Founder of Sentient Dynamics. 15+ years of business strategy (incl. SAP), MBA. Writes about EU AI Act compliance, ROI measurement and how Mittelstand CTOs actually adopt agentic AI.

Keep reading

Once a month. Only substance.

No motivational fluff. No tool lists. Only what CTOs, COOs and MDs in DACH really need to know about AI adoption.