Who Needs AI Literacy Training Under the EU AI Act?

Who needs AI literacy training under the EU AI Act? Article 4 covers staff and “other persons dealing with the operation and use of AI systems” on behalf of a provider or deployer. The obligation therefore extends beyond direct employees where other people are operating or using AI systems on the organization’s behalf. The measures taken should reflect each person’s existing technical knowledge, experience, education and training, as well as the context in which the AI system is used and the people or groups affected by that use. The amended Article 4 does not require providers or deployers to guarantee a specific level of AI literacy for any individual.

This article explains who falls into scope, how that differs for high-risk AI systems, and the role company size plays. For the full breakdown of what Article 4 requires, see our complete guide to AI literacy training under Article 4.

Not sure which of your teams or AI systems fall under Article 4?

AnnexOps AI Compliance Software helps you run an EU AI Act risk assessment across your AI inventory and identify exactly who needs AI literacy coverage.

The Two Core Categories: Providers and Deployers

Article 4 of the EU AI Act places the obligation on two categories of organizations: providers, who develop an AI system and place it on the market or put it into service under their own name, and deployers, who use an AI system under their own authority without having built it. Most businesses are deployers for at least some of their AI systems, and many are providers for others, depending on whether they built a given tool or bought it.

This distinction matters because the training and AI literacy measures attach to the organization’s staff and other persons dealing with the operation and use of AI systems on its behalf. A deployer using a third-party AI recruitment tool still has to support the AI literacy of the staff operating it, even though the deployer did not build the underlying model.

“Other Persons Dealing with AI Systems”: Who Else Counts

This is the part of Article 4 that can be overlooked when organizations define their training population. Article 4 expressly covers not only staff but also “other persons dealing with the operation and use of AI systems on their behalf.” The wording therefore extends beyond directly employed staff to others who operate or use AI systems for the provider or deployer.

In practice, this can include:

  • Contractors and freelancers using company AI tools as part of their work, where they are operating or using those systems on behalf of the organization
  • Third-party service providers operating or using AI systems on the organization’s behalf
  • Other external personnel whose role involves the operation or use of an AI system for the provider or deployer

The scope should be assessed from the person’s actual role and relationship to the AI system rather than simply from their employment status. A person who merely encounters an AI system as a customer or affected individual should not automatically be treated as falling within Article 4’s operational obligation. The Regulation separately defines AI literacy by reference to providers, deployers and affected persons, but that broader definition does not itself turn every affected person or customer into a person who must receive Article 4 training.

Does Someone’s Existing Technical Background Change What’s Required?

Article 4 explicitly requires providers and deployers to take account of each person’s technical knowledge, experience, education and training, as well as the context in which the AI system is used and the people or groups on whom it is used. This means the measures taken do not need to be identical for everyone in the organization.

A data scientist with formal AI training has a different starting point from a sales employee using an AI-powered CRM tool for the first time. Existing technical knowledge can therefore influence what measures are appropriate, but it does not automatically remove the need to address the organization’s specific AI systems, their intended use, relevant risks and the person’s role. The amended Article 4 focuses on supporting the development of AI literacy rather than requiring providers or deployers to guarantee a particular level for every individual.

Who’s In Scope: A Quick Reference

Group In scope under Article 4? Key consideration
Employees operating AI systems Yes Measures should reflect their knowledge, role, and AI use context
Contractors and freelancers Where operating or using AI on behalf of the organization Scope depends on their actual role and relationship to the AI system
Third-party service providers Where operating or using AI on the organization’s behalf Covered where their work involves operation or use on behalf of the provider/deployer
Clients/customers Not automatically Being a customer or affected person alone does not make someone subject to Article 4’s operational obligation
Technical staff with AI backgrounds Yes, where they fall within the Article 4 scope Existing knowledge and training should inform proportionate measures
Staff of a deployer using third-party AI Yes The deployer’s own Article 4 obligation applies to relevant staff and other persons acting on its behalf

High-Risk AI Systems: A Separate, Higher Bar

Article 4 applies broadly across AI systems handled by a provider or deployer, not just high-risk ones. But where an organization deploys a high-risk AI system, a separate requirement under Article 26 also applies: deployers must assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.

This means organizations identifying their exposure to high-risk AI systems under the EU AI Act obligations need to consider both requirements. Article 4 concerns AI literacy measures for relevant staff and other persons dealing with the operation and use of AI systems on the organization’s behalf. Article 26 focuses specifically on the competence, training, and authority of people assigned human oversight of high-risk AI systems. A proper EU AI Act risk assessment should therefore distinguish between the general AI literacy measures under Article 4 and the specific human oversight responsibilities under Article 26.

Do Affected Persons Need AI Literacy Too?

Article 3, point 56 defines AI literacy as skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations under the Regulation, to make informed deployment of AI systems and gain awareness of AI opportunities, risks and possible harm. Recital 20 similarly explains that AI literacy can have different content depending on the person’s role and context. For affected persons, this can include understanding how decisions taken with the assistance of AI may affect them.

This does not mean every customer, employee, applicant, or other affected individual interacting with an AI system needs formal training under Article 4. Article 4 places the operative obligation on providers and deployers in relation to their staff and other persons dealing with the operation and use of AI systems on their behalf. The reference to affected persons in the definition of AI literacy and Recital 20 provides the broader context for why AI literacy matters, but it does not create a general Article 4 training obligation for the public.

Does Company Size Change Who’s Covered?

The scope of Article 4 does not disappear for smaller organizations. Providers and deployers remain subject to the obligation, while the measures used to support AI literacy should take account of the relevant people, systems and context. The amended Article 4(2) specifically requires the Commission and Member States to support and facilitate the efforts of providers and deployers, in particular SMEs, in fulfilling the obligation.

For a five-person startup, this means the organization still needs to consider which staff and other persons are dealing with its AI systems on its behalf. The practical measures may be simpler than those used by a large enterprise with a larger AI estate, but the assessment should still reflect the systems in use, the people operating them, and the context in which they are deployed.

How to Work Out Who Is In Scope in Practice

Knowing the legal categories is one thing. Applying them across a real organization is another. A workable sequence starts with the AI inventory: list every AI system in use, then record who operates each one, including contractors and service providers where they are using or operating AI systems on the organization’s behalf, not just employees on the payroll.

From there, an AI risk classification tool for the EU AI Act can help identify which systems may fall into a high-risk category, which tells you where the separate Article 26 human oversight requirements also need to be considered. Some teams use an EU AI Act Compliance Checker at this stage as a first-pass screen, then move systems requiring closer review into a fuller assessment.

The output of this exercise should be a simple mapping: system, role of the organization (provider or deployer), people operating or using it on the organization’s behalf, and the AI literacy measures planned for each relevant group. This approach aligns with the Commission’s practical guidance and is easier to maintain in AI compliance software than in a spreadsheet that goes stale the next time a vendor, contractor, or team changes.

How AnnexOps Helps

Figuring out who actually needs to be covered gets harder as an organization’s AI footprint grows across departments, vendors, and contractor relationships. AnnexOps AI Governance Platform connects your AI inventory to the people operating each system, so identifying who falls under Article 4, and separately, who needs the more specific Article 26 human oversight training for high-risk systems, doesn’t depend on someone manually cross-referencing a spreadsheet of tools against an HR list. As part of a broader EU AI Act compliance platform, this keeps your EU AI Act readiness position visible as teams, vendors, and AI systems change.

Ready to map who needs AI literacy coverage across your organization?

AnnexOps helps teams connect their AI inventory to training obligations, documentation, and audit-ready evidence.

Sources referenced (accessed October 2026):

  • European Commission, Directorate-General for Communications Networks, Content and Technology, “AI Literacy – Questions & Answers”
  • Regulation (EU) 2024/1689 (EU AI Act), Articles 3(56), 4, 26, and Recital 20 – official consolidated text
  • Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 – Article 4 amendment

This article reflects the EU AI Act and its amended Article 4 as applicable in October 2026. Confirm your organization’s specific position with legal counsel before relying on this for a compliance decision.

Author: Nitin Grover

Nitin Grover is an AI compliance strategist and writer focused on EU AI Act compliance, AI governance, Annex IV documentation, AI risk management, and AI compliance operations for AI startups, SaaS companies, and enterprise AI teams across Europe.

Post a Comment

Your email address will not be published. Required fields are marked *

Analyse your AI exposure