The obligation that applied first
Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures to ensure, as far as they can, a sufficient level of AI literacy among their staff and anyone else operating or using AI systems on their behalf, taking into account those people's training and experience and the context the systems are used in. It applied from 2 February 2025, alongside the Article 5 prohibitions, which makes it one of the first two obligations in the Act to take effect and the one most organisations noticed last.
It is deliberately not a certification requirement. There is no prescribed course, no exam and no register of literate staff. What the Article asks for is proportionate measures, and what an organisation should be able to show is that it identified who uses or oversees AI, judged what they needed to know, and did something about it.
What literacy consists of, at three levels
The word suggests a single competence. In practice it is three, for three populations.
Everyone who uses an AI tool needs to know that outputs can be confidently wrong, that what they paste in may leave the organisation, that they remain responsible for what they do with the output, and where the organisation's rules on both are written. That is the level the shadow AI problem turns on.
People who oversee an AI system, the reviewers in a human-in-the-loop arrangement, need more: what the system is for, what its known failure modes are, what a wrong output looks like in their context, and what authority they have to override it. An overseer who cannot recognise a failure is not oversight; that is the point of inadequate human oversight design.
People who decide about AI systems, boards and senior managers, need to be able to ask the questions in this glossary's risk appetite entry and understand the answers. A board that approves an AI strategy it cannot interrogate has delegated its accountability without meaning to.
What evidence looks like
Because the duty is proportionate, the evidence is a record of judgement rather than a certificate. A defensible file holds:
- A mapping of roles to the AI systems they use or oversee, drawn from the AI inventory.
- For each role, what the organisation decided they needed to know and why.
- What was delivered: training, guidance, in-tool prompts, briefing, and when.
- How it is kept current as systems and staff change.
The EU's AI Office has published a repository of literacy practices from signatories to its AI Pact, which is useful as a source of examples rather than as a standard. Nothing in it is mandatory.
Beyond the Act
The obligation is European, but the need is not. The UK's financial regulators expect firms to understand the models they use under the PRA's model risk management principles and to be able to account for AI-enabled decisions under the Consumer Duty; that is a literacy expectation without the word. ISO/IEC 42001 asks for competence and awareness as part of the management system. And ASD's June 2026 position on AI in technical writing turns on the same point: a person who cannot judge a model's output cannot be the oversight the standard requires.
The common thread is that literacy is what makes every other control work. An acceptable use policy is only followed by people who understand why; a review step only catches what the reviewer can recognise.
Where it sits in the register
AI literacy gap in the deploying organisation is the register entry for the absence of it, and inadequate human oversight design is where the gap most often becomes harm. The AI literacy programme control describes the proportionate measures Article 4 has in mind, and the AI acceptable use policy is what those measures teach people to follow.