2 February 2025 came and went without banners. While compliance teams tracked the AI Act's high-risk rules — the heavy obligations with 2026 and 2027 deadlines — a quieter provision applied that day, first in the queue. Article 4 made AI literacy a legal duty for anyone providing or using AI systems in the EU market. Not a duty for platform companies. Not a duty for model builders. A duty for anyone whose business touches an AI system — which, three years into the chatbot era, is close to everyone.

That includes UK and Irish firms. If your output reaches the EU market — clients, tenders, users — the literacy duty can reach you, and it has been live for well over a year. If nobody in your business has planned staff AI literacy training, you are not early. You are in remediation. This page is part of our full guide to the EU AI Act for UK and Irish businesses, and it covers the obligation most firms didn't know they had.

What Article 4 of the AI Act actually says

Strip away the legislative framing and three points remain.

  • Who it binds: providers and deployers. Providers build AI systems or put them on the EU market; deployers put them to use. If your team uses AI systems — a chatbot subscription, Copilot or Gemini inside Office and Workspace, AI matching in your ATS, "smart" fields in the CRM — you are a deployer. There is no size threshold, no SME exemption, and no grace period still running.
  • Who must be literate: everyone the work touches. Not just the IT team. The duty covers staff, contractors, and anyone acting under your authority who operates or uses AI systems on your behalf — or whose work is affected by one. The bid writer pasting tender responses into a chatbot is as in scope as the engineer wiring an API into production.
  • What "sufficient" means: proportionate, and evidenced. Literacy scales to context and role — technical depth for engineers, judgement-level awareness for client-facing staff. Nobody expects a 30-person firm to run a master's module. What regulators expect is evidence of action proportionate to your use: training matched to roles, records kept, refreshes scheduled.

That last word — evidenced — is where most SMEs stumble. The standard isn't perfection. It's demonstrable, proportionate action, which is a very different thing to audit for — and training records are part of your evidence shelf, alongside your inventory, logs and vendor documentation.

Why most SMEs missed it (the honest reasons)

"Missed it" is not negligence. The miss was designed into how the obligation arrived:

Reason 1

It arrived with no fanfare

Article 4 came with no fines schedule attached and no enforcement agency announcement. The headlines went to GPAI rules and €35M high-risk penalties. A duty with no number attached to it attached to nobody's attention.

Reason 2

The "we don't build AI" blind spot

Most SMEs never self-identified as deployers. But a chatbot subscription, AI features switched on inside Office or Google Workspace, matching in the ATS, enrichment in the CRM — each makes the firm a deployer of an AI system. You don't have to build it. You just have to use it.

Reason 3

Training was assumed covered

The e-learning bought in 2019 — data protection, phishing, acceptable use — was filed under "compliance training, done". AI literacy is not data protection. That module says nothing about models, prompts, hallucination, or what staff may safely paste into a tool. Different subject, different duty, different evidence.

The cost of waiting

Book this list — it is the section to bring to the next management meeting:

  1. Staff misuse triggers duties you also missed. Ungoverned AI use — shadow AI, the ungoverned layer training is meant to prevent — can trip transparency rules and data-protection spill-over long before anyone mentions Article 4.
  2. No evidence trail when someone asks. A client audit, a tender panel, a regulator's information request — all three increasingly ask what your staff are allowed to do with AI and what you have done about it. Without records, the honest answer is "nothing, in writing".
  3. Non-compliance compounds. An ignored Article 4 reads as a governance signal. If the cheapest, simplest duty went unaddressed, what does that suggest about your controls on everything else? Enforcement posture follows that logic.
  4. Procurement is already asking. Supplier questionnaires now carry AI literacy lines. A blank answer doesn't just look careless — it loses the deal to the firm that can attach an evidence pack.

Here is the asymmetry worth repeating: Article 4 is the cheapest AI Act obligation to fix and the most embarrassing to be caught without. AI Act staff training costs a fraction of any technical remediation — and it is the one duty a 20–250 person firm can close in weeks.

What compliant AI literacy training looks like

Here is the turn. The fix is not a certificate hunt — it is a small, structured system.

Three responses that reliably fail: the 20-minute generic video nobody watches and nobody can evidence a year later; the one-off slide deck with no record-keeping, no refresh, and a shelf life measured in weeks; and banning AI instead of training it — the ban that pushes usage underground, because the tools are free and one tab away.

What works instead:

  • Role-tiered literacy. Awareness for everyone, applied modules for active users, deeper training for the people who own or operate systems — tiers that follow how each role actually uses AI once you sort AI use into risk categories.
  • Records and a refresh cadence. Who was trained, when, on what — refreshed as the tools change, because the tools will change.
  • Tied to policy and inventory. Training that references every AI tool logged in an AI inventory and the usage policy that governs them, so literacy, policy and records reinforce each other instead of drifting apart.

The goal isn't certificates. It's demonstrable, proportionate competence — a system you can show, not a stack of PDFs.

How AI Literacy Training works

We built AI Literacy Training for exactly this duty, sized for 20–250 staff. Three steps:

  1. Baseline assessment. Who uses what AI, at what depth — including the tools nobody approved. The assessment doubles as discovery, so the training targets reality rather than an org chart.
  2. Role-tiered delivery. Awareness for all, applied for active users, deep for system owners. A few hours per person across a few weeks — not marathons.
  3. Evidence pack. Records of who was trained and when, links to your usage policy and inventory, and a refresh schedule: the artefact you hand to clients, auditors and tender panels.

Weeks, not quarters. The work sits in the assessment and the evidence, and the output is the difference between "we're looking into it" and "here's our programme".

The takeaway

Article 4 has applied since 2 February 2025, to providers and deployers alike, with no size exemption. If your team uses AI — a chatbot, Copilot, ATS matching, anything — the duty is live, and you are most likely already in remediation. The fix is proportionate, role-tiered staff training with records to show for it.

Close it properly: explore AI Literacy Training — or, if you are still mapping where the Act touches your business, start with AI Act Readiness or take the AI Act quiz (two minutes). Either rung leads to the same place: a defensible answer the next time someone asks what your staff are allowed to do with AI. (Practical guidance throughout — not legal advice.)