Ask ten small business owners whether they meet the "AI literacy" obligation under the European AI Act. Nine of them won't have a clue what you're talking about. And yet this obligation doesn't date from last year — it's been in force since 2 February 2025. It's been here longer than most of us realise, only nobody was really enforcing it until now.
That's changing. From August 2026, national supervisory authorities (in the Czech Republic, the forthcoming Czech Telecommunication Office) gain formal power to check and enforce the obligation. And unlike the rules on chatbots or AI content we wrote about last time, AI literacy doesn't only concern companies that offer AI to customers — it concerns absolutely everyone who uses AI in the company in any way.
What AI literacy means under the law
Article 4 of the AI Act requires "providers" and "deployers" of AI systems to ensure a sufficient level of AI literacy among employees and other people working with AI systems on their behalf. In plain language: if someone in the company works with an AI tool, they must understand what they're doing — proportionate to their role, technical level and the context in which they use the AI.
What matters is what the law doesn't require. No certificate, exam or formal course is needed. No exact curriculum is set. The level of "literacy" depends on how risky the given AI use is — a receptionist using a chatbot to answer FAQs needs a different level of knowledge than an HR specialist using AI to screen applicants' CVs.
Why almost nobody knows about it
This obligation got lost in the shadow of the flashier parts of the AI Act — bans, fines for high-risk systems, mandatory chatbot labelling. Article 4 has no transition period or postponement of its own; it simply applies from February 2025 without much fanfare. On top of that, supervisory authorities in many countries are only now building capacity, so for the first year and a half nobody was actually checking anything.
But that's changing right now. The Digital Omnibus, which in June 2026 postponed the stricter parts of the AI Act to 2027, didn't touch Article 4 at all. AI literacy stayed unchanged — and with supervisory capacity gradually building, the risk grows that authorities will notice it sooner than the more complicated obligations.
Who it actually concerns
The answer is uncomfortably simple: almost every company that has a computer. The obligation doesn't only target companies developing AI products. It applies to every "deployer" — that is, a company that uses an AI system as part of its activities. Typical cases include:
Marketing and copywriting. A team using ChatGPT or Claude to write text needs to understand the risks — hallucinations, the need for fact-checking, copyright in generated content.
Customer support. If a company has deployed an AI chatbot (even the simplest one for a few hundred euros), the staff who manage it or escalate inquiries must understand its limits.
HR and recruitment. Using AI to pre-screen CVs or evaluate candidates requires a higher level of understanding — here algorithmic bias is a risk, and it's also an area that falls under the stricter rules for high-risk systems.
Accounting and analytics. AI tools for invoice processing or cash-flow prediction — people who trust the outputs without verification are exactly the scenario AI literacy is meant to prevent.
In short: if AI exists in the company only as "that clever tool that writes it for us", you're not meeting the obligation.
What's at stake after August 2026
Breaching the main obligations of the AI Act — and Article 4 is among them — can mean a fine of up to €15 million or 3% of global turnover, with the lower of the two amounts always applying to small and medium businesses. Realistically, nobody will be mailing fines to small e-shops in September 2026 for a missing internal policy. But as the "quiet" phase ends, the likelihood grows that AI literacy becomes part of routine checks — much as inspectors today check GDPR or health and safety.
And there's a more practical risk than a fine: a company without clear AI rules has employees entering sensitive data into public AI tools, trusting unverified outputs, or not knowing when to disclose AI use. Those are real damages that happen well before any inspection.
How to comply in a single afternoon
Good news: for a small and medium business this is one of the cheapest obligations in the entire AI Act. No certificate, no external audit. All it takes is:
1. Map where AI is used in the company. List the tools — ChatGPT, Copilot, the website AI chatbot, image generators, anything. Without this overview you don't know who to train.
2. Write a one-page internal policy. What may and may not be entered into AI tools (personal data, trade secrets, passwords), how to verify outputs, who the contact person for questions is. It doesn't have to be a legal document — clear, understandable rules are enough.
3. Hold a short training. A half-day workshop or even a 90-minute presentation covering the basics: what AI can and can't do, how to spot a hallucination, why not to copy sensitive data into public tools. For more advanced roles (HR, analytics) add a specific section.
4. Record that you did it. The training date, who attended, what it covered. In case of an inspection, this is exactly what the authority wants to see — proof the company "took measures", not a perfect certificate.
5. Repeat once a year. AI tools change fast — what was true about ChatGPT last year may not hold today. A short annual update is enough.
The question to ask yourself today
If you've been waiting for a clear instruction "you must do this" — this is it. A year and a half old, legally binding, with the quiet phase ending soon. Most small businesses aren't dealing with it yet, because they don't know about it. That's exactly why to deal with it — while there's time for calm preparation, not firefighting after the first inspection.
Frequently asked questions about AI literacy
As part of an AI audit I go through which AI tools you actually use, what of it falls under the AI Act, and what to do to be at ease — including a simple tailored internal policy.
Free non-binding consultationI build AI solutions for businesses — from chatbots to knowledge systems. I write about what actually works, no buzzwords. More about me →