Kelias
← All posts

What Article 4 of the EU AI Act Means for Your Staff — and Why It Applies to Every Organisation

Article 4 of the EU AI Act places a legal obligation on every organisation deploying AI systems — public sector and private — to develop the AI literacy of their staff. Here is what that obligation means in practice.

What Article 4 of the EU AI Act Means for Your Staff — and Why It Applies to Every Organisation

"AI-ready Europe" sounds like policy language from a Brussels press release. For anyone working in an organisation that uses AI systems — a government agency, a bank, a hospital, a logistics company, a municipality — it translates into something more concrete: a legal obligation on the organisation, a set of competences that are becoming standard professional expectations, and a direct question about whether staff are prepared to work safely with the AI tools already in use.

This post explains what the obligation means at the individual level, why it matters now, and what the leading approaches in Europe look like.

Key points

  • Article 4 of the EU AI Act is the mechanism that makes AI literacy a legal obligation for any organisation deploying AI systems — public or private, across all 27 EU member states.
  • The obligation falls on the organisation, not on individual staff. But it directly shapes what organisations will require of the people working for them.
  • AI literacy is becoming a standard professional competence across both public administration and private sector roles involving AI-assisted decision-making.
  • The organisations leading on this have built their approach around measurable competence frameworks, not awareness campaigns.

From policy aspiration to legal requirement

The European Commission's Digital Decade 2030 programme set a target: at least 80 percent of the EU population to have basic digital skills by 2030. AI literacy features prominently in that programme alongside digital connectivity, business transformation, and digitalisation of public services.

But Digital Decade targets are policy goals. What converts them into legal obligations is the EU AI Act.

Article 4 of the EU AI Act (Regulation (EU) 2024/1689) places a direct legal obligation on organisations that deploy AI systems: they must take measures to support the development of AI literacy of their staff and others operating AI systems on their behalf. This obligation has applied since 2 February 2025, when Chapter I of the Regulation entered into force.

If your organisation uses AI tools in any operational capacity, it is a deployer under the Regulation. That applies whether you are a public authority, an SME, a healthcare provider, or a financial institution. There is no sector exemption. The policy aspiration and the legal obligation are pointing at the same thing.


What Article 4 means at the individual level

The Article 4 obligation belongs to the organisation, not to individual employees. It cannot be directly enforced against a staff member. The organisation is responsible for providing literacy support.

But the individual dimension is real.

Article 4 requires measures appropriate to each person's "technical knowledge, experience, education and training and the context the AI systems are to be used in." The compliance measure your organisation takes is tied to you specifically: your role, the AI systems you use, your starting competence level. Generic training applied uniformly to everyone does not satisfy this requirement.

What counts as sufficient for a case officer using an AI benefits tool is different from what counts as sufficient for a procurement officer evaluating AI vendor documentation, or a risk analyst using an AI-assisted fraud detection system in a private financial institution, or a digital transformation lead designing organisation-wide AI governance. The obligation is role-differentiated by design.

The practical consequence: organisations should be assessing current AI competence levels, identifying what each role requires, and providing training targeted at closing that gap. If yours is not doing this yet, Article 4 enforcement is the reason it eventually will.


The difference between what your organisation must do and what you can do proactively

Your organisation carries the legal obligation. But there is a direct personal interest in not waiting for the organisation to act.

When an AI system produces a wrong output and that output informs a decision affecting another person — a citizen, a customer, a patient — the question that arises is whether the person who acted on that output exercised appropriate human oversight. AI literacy is what makes oversight meaningful rather than performative. A professional who genuinely understands the limitations and failure modes of an AI tool is in a different position from one who does not, both in terms of the quality of decisions they make and in terms of accountability if something goes wrong.

GDPR Article 22 grants individuals the right not to be subject to solely automated decisions that significantly affect them. That right depends on a human being conducting a genuine, informed review. A staff member without AI literacy cannot provide that review. They can execute the motion without the substance.

AI literacy is also becoming a documented professional competence. DigComp 3.0 (JRC144121, November 2025) is the EU framework for measuring it. It is referenced in national AI strategies across EU member states as the benchmark for digital and AI competence. A DigComp 3.0 competence report is a portable record of your competence level: something you carry through your career, not just something your organisation files for compliance purposes.


Organisations leading on this

Estonia's approach is the most-cited model in the Baltic and Nordic context. Its public sector digital transformation infrastructure includes systematic competence development for civil servants, with formal assessment. AI literacy is an extension of that foundation, and Estonia's approach has influenced thinking across the region.

Denmark's AI skills initiative, run through the Danish government's digital agency, frames AI literacy as a professional standard rather than optional upskilling — for public servants and for private sector workers in AI-adjacent roles. It is mapped to competence frameworks and produces records that serve both compliance and career development purposes.

In both cases, and across the organisations in other member states that have moved early, the approach is built around measurable competence, not awareness campaigns. A staff member who completes a structured programme receives not just a certificate but a record of what they can do at a specific level. That record is usable for compliance, for performance management, and for professional development.


What staff stand to gain

Beyond compliance, AI literacy changes the practical quality of work.

A professional who understands how an AI case management or recommendation tool generates its outputs can use that tool more effectively: knowing when to trust the output, when to verify independently, and when the output is signalling something the tool is not equipped to handle. That competence reduces errors. It also reduces the time spent correcting errors that a less literate user would not have caught.

It changes the accountability picture. When an AI-informed decision is later questioned, a literate professional can document their reasoning: what the AI output showed, why they assessed it as reliable in this context, and what additional factors informed the final decision. That documentation is a professional protection — in public administration and equally in private sector roles where AI informs consequential decisions.

It changes career expectations. Across both public and private sectors in the EU, roles involving AI-assisted decision-making are increasingly expected to come with documented AI competence. The professional who can demonstrate measurable AI literacy is better positioned than one who cannot.

AI literacy is not a technical specialisation. DigComp 3.0 Intermediate level, Levels 3 and 4, describes competences that any professional using digital tools can develop with structured practice. That is the relevant target for most staff using AI tools operationally.


Where to start

The practical starting point for any staff member is understanding their current DigComp competence level. The JRC publishes a self-assessment tool aligned to DigComp 3.0 that takes about 20 minutes and gives a rough baseline against the framework's eight proficiency levels.

For organisations building a programme, the relevant resource is kelias.tech/organisations.


Kelias offers a free 6-month AI literacy programme mapped to DigComp 3.0 and built for Article 4 compliance — open to public sector institutions and private sector organisations across the EU. Access at kelias.tech.


Ikpong Joseph Alexander holds an MSc in Artificial Intelligence and is the founder of Kelias. Sources: Regulation (EU) 2024/1689, Article 4 (as amended by Digital Omnibus, July 2026); Regulation (EU) 2016/679, Article 22. DigComp 3.0: JRC144121, available from the JRC publications repository. This post does not constitute legal advice.

Written by Ikpong Joseph Alexander, founder of Kelias.

← All posts