The EU AI Act's widest-reaching duty is not the high-risk regime - it is two paragraphs most compliance calendars skipped. Article 4 requires every provider and deployer of AI systems, whatever their risk tier, to take AI literacy measures for the people operating those systems. It has applied since 2 February 2025, it covers a firm running nothing more exotic than a research assistant, and it is the duty a regulator or client audit can test with one question: show me the training records. This spoke of our EU AI Act timeline series unpacks what Article 4 demands, what the Digital Omnibus changed, and what a defensible programme looks like in a legal team.
Legal information, not legal advice - member-state implementation varies, and your own programme should be shaped with advice on your position.
What Article 4 actually requires
The direct answer: firms must take measures so that staff and anyone else operating AI on their behalf have the AI understanding their role requires - calibrated to their technical knowledge, experience, education, and training, the context the AI is used in, and the people it is used on (the full text is at the AI Act Service Desk). It is a proportionality standard, not a curriculum: a partner supervising AI-assisted drafting, an associate running research queries, and an HR manager evaluating an AI screening tool each need different literacy, and the duty is satisfied by measures matched to each.
Equally important is what Article 4 does not require. No certification, no standardised course, no AI officer, no regulator pre-approval - national guidance has said as much explicitly. The duty is real but administrative in shape: decide what each role needs to understand, deliver it, record it, refresh it.
Who is covered - and who counts as staff
Both roles in the AI value chain carry the duty: providers and deployers. For a law firm or legal department - a deployer in the ordinary case, per our deployer obligations guide - the covered population is wider than the payroll: "staff and other persons dealing with the operation and use of AI systems on their behalf" reaches contractors, paralegals from an agency, and secondees using the firm's tools. The trigger is using AI systems at all - not high-risk AI. A firm whose entire AI estate is a research assistant and a document-review tool is squarely inside Article 4.
The duty scales with context, and legal work supplies aggravating context: outputs feed advice, filings, and decisions about people. That is exactly the "context the AI systems are to be used in" the article tells firms to weigh - which is why a legal team's literacy bar sits higher than a marketing team's, whatever the tool.
The Digital Omnibus softening: effort, not guarantee
The original Article 4 required measures to "ensure, to their best extent, a sufficient level of AI literacy". The Digital Omnibus on AI - approved by the Council on 29 June 2026 and signed on 8 July 2026 - rewrites it as a duty to "take measures to support the development of AI literacy", adding expressly that no specific level must be guaranteed for any individual. The Commission and member states take on a supporting role, with practical examples to be published on the Commission's single information platform, and the AI Board is to adopt recommendations setting common objectives.
Read the change precisely. It converts an obligation of result into an obligation of effort - it does not delay the duty (which never moved from February 2025), and it does not repeal it. As of mid-July 2026 the amending regulation still awaited Official Journal publication, so the original wording remained the binding text. Either way, the compliance artefact is identical: a documented, role-appropriate programme. Firms that built one under the old wording are already compliant with the new.
What a defensible programme looks like
The workable pattern for a legal team is a role-tier matrix - who uses what, and what each tier must therefore understand.
| Tier | Who | What the training covers |
|---|---|---|
| All users | Everyone with access to any AI tool | What the tools can and cannot do; hallucination risk; confidentiality rules; the verification habit; the firm's use policy |
| Legal users | Fee-earners using AI in client work | Citation verification against sources; prompting and instruction discipline; when outputs may be relied on; documenting review |
| Supervisors | Partners and managers overseeing AI-assisted work | Oversight duties; spotting over-reliance; incident escalation; what competence review of AI output means |
| Tool owners | Those who select, configure, or administer AI systems | Classification basics; vendor documentation; logging and access controls; the governance policy's approval gate |
Content should be tool-specific where it matters - training on "AI generally" teaches nobody to verify a citation in the tool they actually use. Practical instruction discipline of the kind covered in our guide to prompting legal AI reliably makes a strong core module for the legal-user tier. Refresh annually and on tool changes, and benchmark proportionality against the Commission's living repository of AI literacy practices, which collects real organisations' measures.
Enforcement: no dedicated fine, real consequences
Article 4 has an unusual enforcement profile: the Act's fine tiers in Article 99 do not list it as a stand-alone fining category. That is not the same as toothless. National market surveillance authorities supervise the duty from 2 August 2026, and member-state penalty regimes fill gaps differently. A missing programme is the first aggravating fact examined when any other breach - a prohibited practice, a transparency failure - reaches an authority. And outside the Act entirely, an incident traced to untrained staff feeds negligence exposure and professional-conduct questions: the same failure, litigated under older law - a risk map we cover in AI malpractice risk for lawyers.
The asymmetry is the point: the programme costs days; its absence is discoverable in minutes and quotable in every later dispute.
Where Article 4 meets professional duty
For lawyers, Article 4 lands on ground professional regulators had already claimed. Bar guidance across jurisdictions converged on technological competence and supervision: lawyers must understand the tools they use well enough to catch their failures, and supervising AI-assisted work is supervision in the ordinary professional sense - our survey of bar guidance on competence and supervision maps the terrain. A firm can therefore run one programme serving both masters: the Article 4 evidence file and the competence file are the same records with two labels.
That double duty is also the budget argument. AI literacy spending is not an EU-compliance line item - it is the training the firm's own regulator, insurer, and clients already expect, with an EU statute now underneath it.
Building the evidence file
Five artefacts make the programme auditable: the role-tier matrix (who uses what, mapped to the AI inventory from your governance policy); the training content per tier, versioned; completion records with names and dates; the refresh cycle with its triggers (new tools, new uses, regulatory change); and a named owner. Store them where a client audit can be answered in a day - the test the whole file exists to pass.
Start small and real: one hour of tool-specific training for current users, recorded, beats a deferred e-learning programme. The duty has been live since February 2025; the enforcement machinery arrives in August 2026; the gap between those dates is credibility a firm either banks or forfeits.
Free raw material exists. The Commission's AI Act pages and the AI Act Service Desk publish plain-language explainers per obligation, the AI Office has run literacy webinars under the AI Pact since early 2025, and the living repository collects the measures other organisations actually took - a small firm can assemble a proportionate programme from public sources in a week. What cannot be assembled from public sources is the part that matters most in legal work: training on the specific tools your people use, with the specific verification steps those tools support.
How Judicio helps
Tools shape how easy literacy is to build. Judicio's outputs carry citations to the underlying sources, so "verify before you rely" is a workflow step rather than an aspiration - the single habit every literacy tier depends on. Role-based access means the tool-owner tier can scope who uses what, and the activity trail shows training took hold in practice. The feature set is documented plainly enough to train from, with methodology and security detail published for the supervisor and owner tiers.
Pair this article with the deployer obligations map and the governance policy template to put the programme inside a structure. To train on a live workspace, start a 7-day free trial - 500 credits, no card required - or talk to us; the EU backdrop is on the Europe hub.