Ensuring AI Literacy in Your Company: Obligations Under Article 4 AI Act

Since February 2, 2025, the mere use of ChatGPT and similar AI tools in the workplace is no longer enough: the EU AI Act requires that employees be sufficiently competent in handling AI systems, and that companies be able to prove this if in doubt. Anyone who ignores this obligation risks being accused of insufficient diligence in the use of AI in a dispute or liability case.
In brief: Article 4 AI Act has required, since February 2, 2025, all providers and deployers of AI systems, explicitly including sole traders and SMEs who use tools like ChatGPT in daily work, to ensure sufficient AI literacy among their employees, including awareness of hallucination risks. There is no dedicated fine provision, but errors from improper AI use risk liability and duty-of-care problems.
Who Is Affected by the AI Literacy Obligation?
This applies to all providers and deployers of AI systems, explicitly including small and medium-sized businesses as well as sole traders who use generative AI tools such as chatbots, text, image, or code generators in daily work. Company size or industry does not matter here; what matters is only whether and how employees work with AI systems. The obligation also does not only affect the IT department: marketing, support, and administration that work with generative AI count too, as soon as they incorporate AI output into their daily work. Whether you develop AI systems yourself (as a provider) or merely use them in your business (as a deployer) makes no difference to the obligation; both roles are explicitly covered. A tool like Company Audit shows which of these obligations specifically apply to your business.
What Exactly Do You Need to Do?
Article 4 AI Act requires companies to specifically enable their employees to handle AI systems and to document these measures in a traceable way. In practice, the following steps are recommended, which can also be implemented in small teams without a dedicated compliance department:
- Record the use of AI tools in the business (text, image, code generation, chatbots, analysis tools).
- Conduct training/awareness sessions for employees with AI access, including the limits and sources of error such as hallucinations.
- Put usage rules for AI tools in writing, for example on handling confidential data and the obligation to check AI output.
- Document participation in and content of the training.
- Retrain the competence level whenever new AI tools or new employees are involved.
A documented certificate creates reliable proof of due diligence in a dispute or liability case and can be presented at any time if needed, for example to customers, insurers, or as part of legal proceedings.
By When Must AI Literacy Be Ensured?
The obligation has applied since February 2, 2025; Article 4 AI Act does not provide a separate transition period for building this competence. Anyone using AI systems in their business should therefore ensure the AI literacy of employees from the very start of use, rather than trying to prove it only during an inspection. Because new AI tools keep emerging and the functions of existing tools keep changing, AI literacy is also not a one-time project but a recurring task: new employees with AI access and newly introduced tools each require renewed training or retraining. The longer AI systems are used without training, the harder it becomes to later demonstrate that the duty of care was observed from the start.
What Happens if You Violate the Rules?
The AI Act does not provide a dedicated fine provision for missing AI literacy. However, the obligation has an indirect effect through duty-of-care and liability questions: if improper AI use, for example undetected hallucinations in AI-generated text, images, or analyses, leads to errors, faulty advice, or damages toward third parties, the question of whether the company met its duty of care quickly comes into focus. This can affect not only contractual liability toward customers but also the fundamental question of whether the required diligence in using AI systems was organized within the company at all. This is exactly where clean documentation pays off: a training record or a certificate proves, in a dispute or liability case, that employees were made aware of how to handle AI systems.
Frequently Asked Questions
Is It Enough if Only the IT Department Is Trained?
No. AI literacy applies to all employees who work with generative AI, which means marketing, support, and administration too, not only developers.
Does the Training Have to Take a Specific Form?
The AI Act does not prescribe a specific training format, whether in-person training, an online course, or an internal briefing. What matters is that employees know the limits and sources of error of AI systems, especially hallucination risks, and that the measure is documented in a traceable way.
What Counts as an AI System for This Obligation?
This includes, among others, text, image, and code generators, chatbots, and analysis tools used in daily business operations, for example ChatGPT or comparable tools.
What Applies if the Business Does Not Yet Use Any AI Tools?
Without AI use, no obligation under Article 4 AI Act arises either. However, as soon as AI systems are introduced, the AI literacy of the affected employees should be planned in from the start, rather than caught up on later.
Does the Training Need to Be Repeated?
Yes. Whenever new AI tools or new employees with AI access are involved, renewed training or retraining is required so the team's competence level stays current.
Source: Article 4 AI Act. This article is general information and does not replace legal advice for individual cases. As of July 2026.
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Recapitulative Statement (ZM), OSS, and Intrastat in EU Trade
ZM due by the 25th of the following month, OSS filed quarterly, Intrastat from the threshold: EU reporting obligations explained compactly.
Ensuring Product Safety Under the GPSR
The GPSR and Germany's ProdSG require every seller of non-food products to carry out a risk analysis, appoint an EU responsible person, and provide warning notices, even for tiny quantities.
Product Liability: When Manufacturers Are Liable Without Fault
Manufacturers are liable without fault for defective products: product liability insurance protects against claims that could threaten a company's existence.
Ihre Unternehmerpflichten im Griff
Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.