
Blog Post
The AI Act Duty That Applies Regardless of Risk Tier
September 28, 2026
Almost every obligation in the AI Act is keyed to a risk classification. Work out which tier a system falls into and the duties follow.
Article 4 is not. It applies to providers and deployers of any AI system whatever it does, its subject is people rather than systems, and national authorities began supervising and enforcing it from 2 August 2026 while the high-risk regime moved to December 2027. It is the live one, and it sits outside the structure most governance programs are built on.
What Changed in July?
The character of the obligation rather than its existence, which is a bigger change than the wording suggests.
The Digital Omnibus replaced the article in full. The original required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy. The current text requires measures that support the development of AI literacy, with an added clarification that it does not require guaranteeing any specific level for any individual.
Which Moves It From Outcome to Effort
A sufficient level was a standard somebody could fall short of. Supporting development is a standard measured by what was done. So compliance is now evidenced by the measures taken rather than by what anybody knows, which is easier to satisfy and considerably harder to know you have satisfied.
Why Does It Have No Natural Evidence Artifact?
Because a control register records the state of systems and this duty attaches to the competence of people in relation to systems, which is a join rather than a field.

An outcome standard would at least imply a test. An effort standard implies records of what was provided, to whom, and why it suited them. Doing that requires knowing which people operate which systems, since the measures have to reflect technical knowledge, experience, education and the context of use.
Which Is an Inventory Problem First
The people list belongs to human resources and the system list belongs to technology. Neither holds the mapping between them, and the obligation is defined on the mapping. So the first task is not training design, it is establishing who operates what, which getting the unit right in an inventory addresses on the system side.
Who Does It Cover?
More people than the payroll, and the extra population is the one most likely to be missed.
.png)
The text reaches staff and other persons dealing with the operation and use of AI systems on the organization's behalf. Contractors, agency staff and outsourced functions all sit inside that phrasing where they operate a system for you, and none of them appears in a learning management system you control.
How Is That Discharged?
Contractually rather than through delivery. A requirement in the engagement that the supplier provides appropriate measures, with a record of the requirement, is the available mechanism. Attempting to deliver training directly to somebody else's employees is neither practical nor expected, and what a supplier arrangement has to specify is where the clause belongs.
Does the Relaxation Reduce the Work?
Some of it, and the part it removes is the part nobody was doing anyway.
Certifying individual competence is now expressly unnecessary, so no assessment, no pass mark and no per-person attestation. What remains is documenting programs and awareness measures and being able to show they were suited to the people and the context. The Commission is also required to publish practical examples of compliance, which will define the working standard in due course.
What Is the Risk of Over-Reading the Relaxation?
Concluding that nothing is owed. The duty was not repealed and it is being supervised now, so an organization with no measures at all has no defense in either version of the text. The change moved the standard rather than removing it.
What Is the High-Risk Position?
Separate and later, which is worth keeping distinct because the two get merged.
Deployers of high-risk systems carry a more specific competence and training requirement tied to human oversight, and its wording was not amended. It sits in the section the Omnibus deferred, so it applies from December 2027 for standalone systems while the general literacy duty applies today. Two obligations, two dates, one topic.
Which Argues for Building the General One Properly
Measures satisfying the general duty now form the base the specific one builds on, since the specific requirement adds oversight competence for named systems rather than replacing the general program. Building once with the later requirement in view is cheaper than twice, and what oversight competence has to include sets out what the harder version asks for.
Who Should Own It?
Somebody with the mapping rather than somebody with the training budget, which is the assignment most organizations get backwards.
Learning and development can deliver measures and cannot say who operates which system. Technology holds the system inventory and does not run training. The obligation is defined on the intersection, so ownership belongs wherever the intersection is maintained, and if nowhere maintains it the obligation is unowned regardless of who is nominated.
What Is the Minimum Viable Position?
A list of AI systems in use, a list of who operates each, a record of what measures each of those populations received, and a note of why those measures suited that population. Four artifacts, none requiring a platform, and the first two are the ones that do not exist.
What Would an Authority Ask For?
Records rather than results, which follows from the standard being effort-based and is worth anticipating while the Commission's examples are still pending.
An effort standard is examined by asking what was provided, to which population, when, and on what reasoning about their needs. None of that requires a competence score. All of it requires dating, which is the property most training records already have and most reasoning does not.
Which Field Is Usually Missing?
The reasoning. A record showing that a finance team received an awareness session in March establishes delivery, and it does not establish that the measure suited their knowledge and context, which is what the text asks for. One sentence per population recorded at the time answers a question that cannot be reconstructed later, and records that survive an audit turns on the same property.
Does the Absence of Guidance Help or Hurt?
Both, and the balance moves once examples are published. Until then there is no standard to fall short of, and equally no safe harbor to point at. An organization documenting reasoning now will map onto whatever the examples describe, and one documenting nothing will be reconstructing against a published benchmark.
What Should Be Established This Month?
Three things, and the third is the one that gets skipped.
Which AI systems are in operational use, including those arriving inside software already purchased. Who operates each of them, extending to contractors and outsourced functions. Then whether the measures provided to each population reflected that population's knowledge and context, since the text requires the fit rather than the delivery. An AI Interaction Data Fabric establishes the first two from observed activity, which is the only method that catches the systems nobody declared.
An Obligation About People, Enforced Now
The literacy duty applies to any AI system regardless of tier, binds providers and deployers alike, and national authorities began supervising it in August 2026 while the high-risk regime moved to December 2027. The July amendment replaced the article in full and changed its character, since ensuring a sufficient level was an outcome standard and supporting development is an effort standard with no individual level to guarantee. The change makes it easier to satisfy and harder to know you have. It has no natural evidence artifact because it attaches to the competence of people in relation to systems, which is a mapping neither human resources nor technology maintains. It also reaches contractors and outsourced functions, where the mechanism is contractual rather than delivered. Kovrr's AI Security and Governance Platform establishes which systems are in use and who operates them.
To see which AI systems are in operational use and which identities operate them, book a demo mapped to your own estate.
AI Literacy Duty FAQs
Speak to an ExpertDoes EU AI Act Article 4 apply to all AI systems?
Yes. Article 4 applies to providers and deployers of any AI system whatever it does, unlike almost every other obligation in the Act which is keyed to a risk classification. Its subject is people rather than systems, and national market surveillance authorities began supervising and enforcing it from 2 August 2026, while the high-risk regime in Chapter III moved to December 2027 for standalone systems.
What did the Digital Omnibus change about AI literacy?
It replaced Article 4 in full and changed the character of the obligation. The original required measures to ensure, to their best extent, a sufficient level of AI literacy. The current text requires measures that support the development of AI literacy, with an added clarification that it does not require guaranteeing any specific level for any individual. So the standard moved from an outcome somebody could fall short of to an effort measured by what was done.
Do you have to guarantee a level of AI literacy?
No, and that is now expressly stated. Certifying individual competence is unnecessary, so no assessment, no pass mark and no per-person attestation is required. What remains is documenting programs and awareness measures and being able to show they suited the people and the context. The Commission is also required to publish practical examples of compliance, which will define the working standard in due course.
Does Article 4 cover contractors and outsourced staff?
Yes. The text reaches staff and other persons dealing with the operation and use of AI systems on the organization's behalf, so contractors, agency staff and outsourced functions sit inside that phrasing where they operate a system for you. None of them appears in a learning management system you control, so the mechanism is contractual, meaning a requirement in the engagement that the supplier provides appropriate measures, with a record of the requirement.
Who should own the AI literacy obligation?
Whoever maintains the mapping between people and systems, rather than whoever holds the training budget. Learning and development can deliver measures and cannot say who operates which system, while technology holds the system inventory and does not run training. The obligation is defined on the intersection, so if nowhere maintains that intersection the obligation is unowned regardless of who is nominated.
How does Article 4 relate to the high-risk training requirement?
They are separate obligations with separate dates. Deployers of high-risk systems carry a more specific competence and training requirement tied to human oversight, and its wording was not amended, but it sits in the section the Omnibus deferred so it applies from December 2027 for standalone systems. Measures satisfying the general literacy duty now form the base the specific one builds on rather than being replaced by it.




