Blog Post

The AI Act Duty That Applies Regardless of Risk Tier

September 28, 2026

Table of Contents

Almost every obligation in the AI Act is keyed to a risk classification. Work out which tier a system falls into and the duties follow.

‍

Article 4 is not. It applies to providers and deployers of any AI system whatever it does, its subject is people rather than systems, and national authorities began supervising and enforcing it from 2 August 2026 while the high-risk regime moved to December 2027. It is the live one, and it sits outside the structure most governance programs are built on.

‍

What Changed in July?

‍

The character of the obligation rather than its existence, which is a bigger change than the wording suggests.

‍

The Digital Omnibus replaced the article in full. The original required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy. The current text requires measures that support the development of AI literacy, with an added clarification that it does not require guaranteeing any specific level for any individual.

‍

Which Moves It From Outcome to Effort

‍

A sufficient level was a standard somebody could fall short of. Supporting development is a standard measured by what was done. So compliance is now evidenced by the measures taken rather than by what anybody knows, which is easier to satisfy and considerably harder to know you have satisfied.

‍

Why Does It Have No Natural Evidence Artifact?

‍

Because a control register records the state of systems and this duty attaches to the competence of people in relation to systems, which is a join rather than a field.

‍

Monitoring view showing agent sessions attributed to named users with the business function each sits in and the systems each touched
Which named person operates which system is the join this obligation depends on, and it is usually the missing half.

An outcome standard would at least imply a test. An effort standard implies records of what was provided, to whom, and why it suited them. Doing that requires knowing which people operate which systems, since the measures have to reflect technical knowledge, experience, education and the context of use.

‍

Which Is an Inventory Problem First

‍

The people list belongs to human resources and the system list belongs to technology. Neither holds the mapping between them, and the obligation is defined on the mapping. So the first task is not training design, it is establishing who operates what, which getting the unit right in an inventory addresses on the system side.

‍

Who Does It Cover?

‍

More people than the payroll, and the extra population is the one most likely to be missed.

‍

Policy view showing enablement rules held separately per employee profile, with contractors appearing as a profile alongside finance, engineering and legal
Contractors held as a population with their own rules is the shape this obligation requires, since the duty reaches people acting on the organization's behalf.

The text reaches staff and other persons dealing with the operation and use of AI systems on the organization's behalf. Contractors, agency staff and outsourced functions all sit inside that phrasing where they operate a system for you, and none of them appears in a learning management system you control.

‍

How Is That Discharged?

‍

Contractually rather than through delivery. A requirement in the engagement that the supplier provides appropriate measures, with a record of the requirement, is the available mechanism. Attempting to deliver training directly to somebody else's employees is neither practical nor expected, and what a supplier arrangement has to specify is where the clause belongs.

‍

Does the Relaxation Reduce the Work?

‍

Some of it, and the part it removes is the part nobody was doing anyway.

‍

Certifying individual competence is now expressly unnecessary, so no assessment, no pass mark and no per-person attestation. What remains is documenting programs and awareness measures and being able to show they were suited to the people and the context. The Commission is also required to publish practical examples of compliance, which will define the working standard in due course.

‍

What Is the Risk of Over-Reading the Relaxation?

‍

Concluding that nothing is owed. The duty was not repealed and it is being supervised now, so an organization with no measures at all has no defense in either version of the text. The change moved the standard rather than removing it.

‍

What Is the High-Risk Position?

‍

Separate and later, which is worth keeping distinct because the two get merged.

‍

Deployers of high-risk systems carry a more specific competence and training requirement tied to human oversight, and its wording was not amended. It sits in the section the Omnibus deferred, so it applies from December 2027 for standalone systems while the general literacy duty applies today. Two obligations, two dates, one topic.

‍

Which Argues for Building the General One Properly

‍

Measures satisfying the general duty now form the base the specific one builds on, since the specific requirement adds oversight competence for named systems rather than replacing the general program. Building once with the later requirement in view is cheaper than twice, and what oversight competence has to include sets out what the harder version asks for.

‍

Who Should Own It?

‍

Somebody with the mapping rather than somebody with the training budget, which is the assignment most organizations get backwards.

‍

Learning and development can deliver measures and cannot say who operates which system. Technology holds the system inventory and does not run training. The obligation is defined on the intersection, so ownership belongs wherever the intersection is maintained, and if nowhere maintains it the obligation is unowned regardless of who is nominated.

‍

What Is the Minimum Viable Position?

‍

A list of AI systems in use, a list of who operates each, a record of what measures each of those populations received, and a note of why those measures suited that population. Four artifacts, none requiring a platform, and the first two are the ones that do not exist.

‍

What Would an Authority Ask For?

‍

Records rather than results, which follows from the standard being effort-based and is worth anticipating while the Commission's examples are still pending.

‍

An effort standard is examined by asking what was provided, to which population, when, and on what reasoning about their needs. None of that requires a competence score. All of it requires dating, which is the property most training records already have and most reasoning does not.

‍

Which Field Is Usually Missing?

‍

The reasoning. A record showing that a finance team received an awareness session in March establishes delivery, and it does not establish that the measure suited their knowledge and context, which is what the text asks for. One sentence per population recorded at the time answers a question that cannot be reconstructed later, and records that survive an audit turns on the same property.

‍

Does the Absence of Guidance Help or Hurt?

‍

Both, and the balance moves once examples are published. Until then there is no standard to fall short of, and equally no safe harbor to point at. An organization documenting reasoning now will map onto whatever the examples describe, and one documenting nothing will be reconstructing against a published benchmark.

‍

What Should Be Established This Month?

‍

Three things, and the third is the one that gets skipped.

‍

Which AI systems are in operational use, including those arriving inside software already purchased. Who operates each of them, extending to contractors and outsourced functions. Then whether the measures provided to each population reflected that population's knowledge and context, since the text requires the fit rather than the delivery. An AI Interaction Data Fabric establishes the first two from observed activity, which is the only method that catches the systems nobody declared.

‍

An Obligation About People, Enforced Now

‍

The literacy duty applies to any AI system regardless of tier, binds providers and deployers alike, and national authorities began supervising it in August 2026 while the high-risk regime moved to December 2027. The July amendment replaced the article in full and changed its character, since ensuring a sufficient level was an outcome standard and supporting development is an effort standard with no individual level to guarantee. The change makes it easier to satisfy and harder to know you have. It has no natural evidence artifact because it attaches to the competence of people in relation to systems, which is a mapping neither human resources nor technology maintains. It also reaches contractors and outsourced functions, where the mechanism is contractual rather than delivered. Kovrr's AI Security and Governance Platform establishes which systems are in use and who operates them.

‍

To see which AI systems are in operational use and which identities operate them, book a demo mapped to your own estate.

Or Amir

Product & Customer Growth Manager

AI Literacy Duty FAQs

Speak to an Expert

Does EU AI Act Article 4 apply to all AI systems?

What did the Digital Omnibus change about AI literacy?

Do you have to guarantee a level of AI literacy?

Does Article 4 cover contractors and outsourced staff?

Who should own the AI literacy obligation?

How does Article 4 relate to the high-risk training requirement?