Since 27 July 2026, Article 4 of the AI Act no longer requires companies to reach a specific level of AI literacy. The Digital Omnibus replaced that binding obligation with simple encouragement. Training your teams is still strongly advised, and it remains required for high-risk uses. Here is what changed, what remains, and what you should actually do.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Since 27 July 2026, Article 4 of the AI Act no longer requires companies to reach a specific level of AI literacy. The Digital Omnibus replaced that binding obligation with simple encouragement. Training your teams is still strongly advised, and it remains required for high-risk uses. Here is what changed, what remains, and what you should actually do.
Article 4 is about AI literacy, not an imposed certified course. European Regulation 2024/1689, known as the AI Act, defines AI literacy in Article 3, point 56: the skills, knowledge and understanding that let providers, deployers and affected persons use AI systems on an informed basis, and weigh both the opportunities and the risks.
In its original version, Article 4 asked providers and deployers of AI systems to take measures ensuring a sufficient level of AI literacy among their staff and anyone handling those systems on their behalf. The text accounted for technical background, experience, training and the context of use. To place Article 4 within the wider regulation, our AI Act compliance guide for SMEs walks through each chapter in detail.
Short answer: the obligation was softened. The AI Omnibus, proposed on 19 November 2025 as part of the Digital Omnibus package, entered into force on 27 July 2026. It simplifies several parts of the AI Act, including Article 4. According to the European Commission, the previous AI literacy requirement on companies is now replaced by non-binding encouragement, with the Commission and the Member States taking a stronger role in promoting AI literacy.
In practice, no "sufficient" level of training is imposed anymore on a company that merely uses AI tools. The same text also pushed back other deadlines: rules on high-risk AI systems will apply from 2 December 2027, and those covering AI embedded in physical products (machinery, toys, lifts) from 2 August 2028.
| Article 4 | Before 27 July 2026 | Since 27 July 2026 |
|---|---|---|
| Nature | Binding obligation | Non-binding encouragement for companies |
| Required level | "Sufficient" level of AI literacy | No specific level imposed |
| Role of authorities | Checking companies' level | The Commission and Member States promote AI literacy |
| High risk | Training required | Training still required (Article 26) |
One point is often misread: most articles published before summer 2026 still describe a firm obligation backed by heavy fines. That framing has changed. If you read elsewhere that AI training is strictly mandatory for every company on pain of a 15 million euro fine, the information is out of date.
Almost every SME is a deployer, not a provider. The distinction matters, because the heaviest AI Act obligations fall on providers, meaning those who develop and place an AI system on the market. A deployer simply uses an AI system built by a third party.
An SME that drafts quotes with ChatGPT, summarises meetings with Copilot or handles emails with Claude is a deployer. It does fall within the scope of Article 4, as the Commission confirmed in its AI literacy questions and answers: a company whose staff use ChatGPT to write text must inform them of specific risks, such as hallucinations. To sort out the roles and who carries which responsibility, read who is affected by the AI Act.
Keep in mind that large language models, and generative AI in general, produce plausible answers that are sometimes wrong. That is exactly the kind of limitation AI literacy is meant to make clear to your teams.
Yes, in that specific case the training obligation remains. The lighter version of Article 4 does not touch Article 26 of the regulation, which requires deployers of high-risk AI systems to ensure that the staff running them have the skills needed for effective human oversight.
In other words, if your company deploys a system classified as high risk, for example to screen applications, assess creditworthiness or make certain HR decisions, training your teams remains a legal requirement. This is worth checking case by case, because high-risk classification drives a large share of your obligations. Our full AI Act timeline sets out the application dates by system category.
National market surveillance authorities, from 2 August 2026. Supervision of Article 4 does not sit with the European AI Office but with the authorities designated in each Member State. In France, depending on the field, this role falls to bodies such as the CNIL, ARCOM or DGCCRF.
Stay measured about penalties. Article 4 does not trigger an automatic fine. Breaches fall under the general penalty regime set out in Chapter XII of the regulation, applied proportionately: the nature, gravity and duration of the breach, and whether it was intentional or negligent, are all weighed. A penalty becomes plausible mainly where an incident stems from an obvious lack of training and supervision.
Beyond the letter of the regulation, AI literacy remains a real operational need. A lighter obligation does not make training pointless, for three concrete reasons.
First, responsibility does not disappear. An employee who sends sensitive customer data into a consumer tool, or reuses a wrong answer without checking, exposes the company to genuine risks: data leaks, invoicing errors, reputational harm. The GDPR still applies in full.
Second, there is the return on investment. Teams that know how to frame a request, check an output and spot a limit get far more value from the same tools. That is the gap between a licence paid for and a licence actually used.
Third, AI literacy prepares the coming deadlines. High-risk rules arrive at the end of 2027: companies that have already upskilled their teams will handle that step without rushing. To frame an internal effort, our corporate AI training starts from your teams' real use cases rather than a generic catalogue.
No certificate needed: an internal record is enough. The Commission states it plainly in its questions and answers: Article 4 requires neither a certificate, nor an AI officer, nor a dedicated governance board. It does not force you to formally measure staff knowledge either. What matters is being able to show a serious effort suited to your uses.
Here is a simple, proportionate outline for an SME:
That record can be a simple shared table. A preliminary AI audit helps set priorities, especially if your uses have grown without a clear framework. AI literacy fits into a broader path of building skills around AI in the workplace.
Is Article 4 of the AI Act still in force in 2026?
Yes. Article 4 still exists and has applied since 2 February 2025. Since the AI Omnibus entered into force on 27 July 2026, the requirement for a "sufficient" level of AI literacy on companies has been replaced by non-binding encouragement.
Is AI training mandatory for my SME?
Not in the strict sense, if you are simply a deployer of tools such as ChatGPT or Copilot. It does remain required if you deploy a high-risk AI system, under Article 26. In every case, it stays strongly recommended.
What level of training must be reached?
The regulation no longer sets a specific level. The good practice is to match your effort to the real risk of your uses and the profile of your teams, rather than aiming at a universal standard.
Who enforces Article 4 in France?
National market surveillance authorities, from 2 August 2026. Depending on the field, this may be the CNIL, ARCOM or DGCCRF.
Do we risk a multi-million euro fine?
That figure, often quoted, needs nuance. Article 4 does not lead to an automatic fine. Breaches fall under the general regime of Chapter XII, applied proportionately to the gravity and context.
Do we need a certificate or an approved body?
No. No certificate is required. An internal record of your upskilling actions is enough to show your effort.
GrowthPerf is a Qualiopi-certified training provider specialising in AI, no-code and automation for SMEs and nonprofits in the Paris region. We start from your tools and your real uses to build useful upskilling, not a theoretical programme detached from the field. The goal is not just to tick a compliance box, but to make your teams autonomous and careful with AI.
If you want to take stock of your position on Article 4, your current uses and the deadlines ahead, book a free 30-minute audit. We map your tools, assess your exposure and point out the concrete priorities. To go further, our AI Act compliance guide for SMEs and our corporate AI training give you the full picture.