Do employees need AI training under the EU AI Act?
Yes, the Article 4 AI literacy duty has applied since 2 February 2025 and was not deferred by the Digital Omnibus.
Yes, and the duty is already live. Article 4 of the EU AI Act requires providers and deployers to ensure a sufficient level of AI literacy in the staff who operate and use AI systems, and it has applied since 2 February 2025. It was not part of the Digital Omnibus deferral, so an organisation waiting for 2027 to start training is already late.
The question matters in 2026 because the deferral has bred a dangerous assumption. Many boards heard that the AI Act moved and concluded that everything moved. Only the high-risk obligations shifted, Annex III from 2 August 2026 to 2 December 2027 and Annex I embedded systems to 2 August 2028; the AI literacy duty and the Article 5 prohibitions have been in force throughout.
What does Article 4 actually require?
A sufficient level of AI literacy in the people who deal with the operation and use of AI systems on the organisation's behalf. The duty falls on providers and deployers alike, and sufficiency is judged in context: the technical knowledge, experience, education and training of the staff concerned, and the setting in which the systems are used. A claims handler relying on AI triage, a marketer using a drafting assistant and an engineer configuring retrieval face different risks, so the Act expects different literacy from each. Sufficiency is a moving standard, not a certificate.
Has the AI literacy duty been deferred to 2027?
No. The Digital Omnibus moved the high-risk Annex III obligations, once due on 2 August 2026, to 2 December 2027, with Annex I embedded systems following on 2 August 2028. It did not touch Article 4. AI literacy has applied since 2 February 2025, alongside the Article 5 prohibitions, and both remain live while the high-risk regime waits. Timeline confusion is not a defence a regulator is obliged to accept.
What counts as a sufficient level of AI literacy?
Three properties, each checkable.
- Role-appropriate: the training matches what each person actually does with AI, not a generic account of what AI is.
- Contextual: it covers the specific systems in use, their approved purposes, their limits, their failure modes and the data they may and may not see.
- Documented: the organisation can show who was trained, on what, when, and how that maps to the systems they operate.
An organisation that can evidence those three properties for everyone who touches an AI system has a defensible Article 4 position. One that cannot has a policy, at best.
Why is an annual slide deck not evidence?
Because it fails all three tests at once. A generic once-a-year deck is not role-appropriate, says nothing about the systems actually deployed, and usually leaves no record connecting a named person to a named system. Ensure is also an ongoing verb: systems change, staff change and uses change, and the literacy duty follows them. Training that predates the deployment of the system a person now uses is training about something else. The credible pattern is short, role-specific modules refreshed when the systems or their uses change, with completion recorded against the systems concerned.
What happens if you ignore Article 4?
Stated honestly, Article 4 carries no standalone penalty tariff. Its weight is indirect and real. Compliance with the rest of the Act runs through people who understand the systems they operate, and when something goes wrong the questions a regulator asks land on literacy: who used the system, what did they understand about it, and can the organisation show it. Weak literacy evidence undermines every other compliance claim the organisation makes, and it does so at the worst possible moment, after an incident.
Where should training records live?
Next to the usage records, because the practical question a regulator asks joins the two: who used the system, and did they understand it. Many organisations hold training records in an HR system and AI usage records, where they exist at all, in a vendor's cloud, so answering that question means manual reconstruction across silos. On Mickai, a Sovereign Intelligence Operating System that runs offline on operator-owned hardware, every AI action is sealed to a post-quantum signed audit ledger bound to hardware-attested identity, so the record already states who did what with which system, and it verifies offline, without trusting the operator's network or ours. Training evidence held alongside that record turns an Article 4 inquiry into a query rather than an archaeology project.
“AI literacy is evidenced by records that connect the person, the training and the use, not by a certificate on file.”
How the sealed audit architecture fits into the wider sovereign design is set out at /sovereign-ai, and the film at /film shows the interface, and the record behind it, in operation.
Frequently asked questions
Does the EU AI Act require AI training for all my employees?
Not all, but more than most organisations assume. Article 4 covers staff and other persons dealing with the operation and use of AI systems on the organisation's behalf, which reaches contractors and agency staff as well as employees. Anyone who touches an AI system in their work sits inside the duty, and the depth of training scales with the role.
Is the AI literacy duty deferred until December 2027?
No. The Digital Omnibus deferral applies to the high-risk Annex III obligations, which moved from 2 August 2026 to 2 December 2027. The AI literacy duty in Article 4 and the prohibitions in Article 5 have applied since 2 February 2025 and were not deferred.
What should I include in AI literacy training for my team?
The systems actually in use, what they are approved for, the data they may and may not see, their known failure modes, how to verify outputs before relying on them, and how to escalate concerns. Tie every module to a role, and record completion against the named systems, because contextual and documented is what sufficient means in practice.
Do UK companies have to comply with Article 4?
The EU AI Act is not UK law, but it reaches UK organisations that place AI systems on the EU market or whose systems produce outputs used in the EU, so many UK firms are inside the duty through EU operations or clients. UK-only organisations still face ICO expectations on staff competence around personal data and automated processing, so the training question does not stop at the border.
What records prove AI literacy if a regulator asks?
A register mapping each person to the systems they use, the training they received on those systems, the dates and the refresh cycle, together with usage records showing that the trained people are the ones actually operating the systems. Records that connect training to use are stronger than either set alone.