Blog · 5 min read

AI literacy: the obligation 90% of companies haven't known about for a year and a half

Dušan Kníže · July 3, 2026

← Back to Blog

Ask ten small business owners whether they meet the "AI literacy" obligation under the European AI Act. Nine of them won't have a clue what you're talking about. And yet this obligation doesn't date from last year — it's been in force since 2 February 2025. It's been here longer than most of us realise, only nobody was really enforcing it until now.

That's changing. From August 2026, national supervisory authorities (in the Czech Republic, the forthcoming Czech Telecommunication Office) gain formal power to check and enforce the obligation. And unlike the rules on chatbots or AI content we wrote about last time, AI literacy doesn't only concern companies that offer AI to customers — it concerns absolutely everyone who uses AI in the company in any way.

Do you use ChatGPT for e-mails, Midjourney for graphics or Copilot in Excel at your company? Then you've been subject to the AI literacy obligation for a year and a half — regardless of company size or sector.

What AI literacy means under the law

Article 4 of the AI Act requires "providers" and "deployers" of AI systems to ensure a sufficient level of AI literacy among employees and other people working with AI systems on their behalf. In plain language: if someone in the company works with an AI tool, they must understand what they're doing — proportionate to their role, technical level and the context in which they use the AI.

What matters is what the law doesn't require. No certificate, exam or formal course is needed. No exact curriculum is set. The level of "literacy" depends on how risky the given AI use is — a receptionist using a chatbot to answer FAQs needs a different level of knowledge than an HR specialist using AI to screen applicants' CVs.

Why almost nobody knows about it

This obligation got lost in the shadow of the flashier parts of the AI Act — bans, fines for high-risk systems, mandatory chatbot labelling. Article 4 has no transition period or postponement of its own; it simply applies from February 2025 without much fanfare. On top of that, supervisory authorities in many countries are only now building capacity, so for the first year and a half nobody was actually checking anything.

But that's changing right now. The Digital Omnibus, which in June 2026 postponed the stricter parts of the AI Act to 2027, didn't touch Article 4 at all. AI literacy stayed unchanged — and with supervisory capacity gradually building, the risk grows that authorities will notice it sooner than the more complicated obligations.

The Digital Omnibus postponement applies to high-risk systems until December 2027. The AI literacy obligation isn't postponed at all — it's applied since February 2025, and oversight of it strengthens every month.

Who it actually concerns

The answer is uncomfortably simple: almost every company that has a computer. The obligation doesn't only target companies developing AI products. It applies to every "deployer" — that is, a company that uses an AI system as part of its activities. Typical cases include:

Marketing and copywriting. A team using ChatGPT or Claude to write text needs to understand the risks — hallucinations, the need for fact-checking, copyright in generated content.

Customer support. If a company has deployed an AI chatbot (even the simplest one for a few hundred euros), the staff who manage it or escalate inquiries must understand its limits.

HR and recruitment. Using AI to pre-screen CVs or evaluate candidates requires a higher level of understanding — here algorithmic bias is a risk, and it's also an area that falls under the stricter rules for high-risk systems.

Accounting and analytics. AI tools for invoice processing or cash-flow prediction — people who trust the outputs without verification are exactly the scenario AI literacy is meant to prevent.

In short: if AI exists in the company only as "that clever tool that writes it for us", you're not meeting the obligation.

What's at stake after August 2026

Breaching the main obligations of the AI Act — and Article 4 is among them — can mean a fine of up to €15 million or 3% of global turnover, with the lower of the two amounts always applying to small and medium businesses. Realistically, nobody will be mailing fines to small e-shops in September 2026 for a missing internal policy. But as the "quiet" phase ends, the likelihood grows that AI literacy becomes part of routine checks — much as inspectors today check GDPR or health and safety.

And there's a more practical risk than a fine: a company without clear AI rules has employees entering sensitive data into public AI tools, trusting unverified outputs, or not knowing when to disclose AI use. Those are real damages that happen well before any inspection.

How to comply in a single afternoon

Good news: for a small and medium business this is one of the cheapest obligations in the entire AI Act. No certificate, no external audit. All it takes is:

1. Map where AI is used in the company. List the tools — ChatGPT, Copilot, the website AI chatbot, image generators, anything. Without this overview you don't know who to train.

2. Write a one-page internal policy. What may and may not be entered into AI tools (personal data, trade secrets, passwords), how to verify outputs, who the contact person for questions is. It doesn't have to be a legal document — clear, understandable rules are enough.

3. Hold a short training. A half-day workshop or even a 90-minute presentation covering the basics: what AI can and can't do, how to spot a hallucination, why not to copy sensitive data into public tools. For more advanced roles (HR, analytics) add a specific section.

4. Record that you did it. The training date, who attended, what it covered. In case of an inspection, this is exactly what the authority wants to see — proof the company "took measures", not a perfect certificate.

5. Repeat once a year. AI tools change fast — what was true about ChatGPT last year may not hold today. A short annual update is enough.

This isn't bureaucracy for its own sake. Companies that do this properly also get clearer rules for using AI across the team — and that alone saves time and prevents embarrassing incidents with sensitive data.

The question to ask yourself today

If you've been waiting for a clear instruction "you must do this" — this is it. A year and a half old, legally binding, with the quiet phase ending soon. Most small businesses aren't dealing with it yet, because they don't know about it. That's exactly why to deal with it — while there's time for calm preparation, not firefighting after the first inspection.

Frequently asked questions about AI literacy

No. The AI Act requires no formal certificate, exam or accredited course. It's enough for the company to take reasonable measures — internal rules and training proportionate to how employees work with AI.
Yes. The obligation applies to every "deployer" of an AI system, including companies that merely use ready-made tools like ChatGPT, Copilot or AI chatbots — not only companies that develop AI.
The obligation applies from 2 February 2025. Formal oversight and enforcement by national authorities (in the Czech Republic, the forthcoming Czech Telecommunication Office) begins in August 2026. Unlike other parts of the AI Act, this obligation was not postponed by the Digital Omnibus.
Up to €15 million or 3% of global turnover, with the lower of the two amounts always applying to small and medium businesses. In practice, the first checks will likely focus on gross breaches, not formal shortcomings at small companies — but the legal risk exists from the first day of oversight.
Not sure exactly where your company stands with the AI Act?

As part of an AI audit I go through which AI tools you actually use, what of it falls under the AI Act, and what to do to be at ease — including a simple tailored internal policy.

Free non-binding consultation
DK
Written by Dušan Kníže
AI developer · Prague, Czech Republic

I build AI solutions for businesses — from chatbots to knowledge systems. I write about what actually works, no buzzwords. More about me →