Artificial intelligence (AI) has, in a short space of time, become part of everyday work. Not only through well-known tools such as ChatGPT, Copilot and Gemini, but also through features in software for marketing, customer service, planning, recruitment and data analysis.
For many organisations that's useful, but also hard to keep track of. Teams experiment with AI, vendors add new features and processes change faster than policy or training can keep up with. That's precisely where the EU AI Act touches day-to-day practice.
Article 4 of the AI Act obliges organisations to ensure a sufficient level of AI literacy. That doesn't mean everyone has to become an AI specialist. It does mean employees need to understand what AI does, where the risks lie and when human oversight remains necessary.
For organisations that want to deploy AI seriously, this is more than a legal obligation. It's a good moment to get clear on what role AI may play within the organisation.
What does AI literacy mean?
AI literacy is about control. Employees need to know which AI tools they use, which information they may and may not enter and how to assess output.
That differs per role. A marketer using AI for content needs different knowledge than a developer connecting AI to a platform. An HR team deploying AI in recruitment has different responsibilities than a support team working with a chatbot.
The essence is that AI isn't used separately from the organisation. It has to fit the processes, the data, the users and the risks.
What does Article 4 of the AI Act require?
Article 4 obliges providers and users of AI systems to take appropriate measures for AI literacy. Appropriate is the key word here.
The law doesn't prescribe a fixed course. An organisation must determine for itself what level of knowledge is needed. That depends on the AI systems used, the experience of employees and the context in which AI is applied.
That's why this doesn't start with training, but with an overview.
- Which AI systems are in use?
- Which teams work with them?
- Which data goes into them?
- Which output is used in processes or decisions?
- Who owns the system?
Without that overview, AI literacy stays too general. Then everyone knows something about AI, but no one knows exactly how AI is used within the organisation.
Key deadlines
The AI Act is being introduced in phases. For organisations that use AI or have it developed, these moments are especially relevant.
| Date | What comes into effect |
|---|---|
| 1 August 2024 | The AI Regulation entered into force. |
| 2 February 2025 | The rules for prohibited AI practices are in effect. The obligation around AI literacy also applies from this moment. |
| 2 August 2025 | The provisions for general purpose AI models are in effect. This mainly affects providers of large AI models and organisations that build on them. |
| 2 August 2026 | Most of the remaining provisions come into effect. This is an important moment for high-risk AI systems and transparency obligations. |
| 2 August 2027 | Additional obligations apply to certain high-risk AI systems that are part of regulated products. |
| 2 August 2030 | A longer transition period applies to some high-risk AI systems at government organisations. |
The main conclusion is simple. AI literacy is not a topic for later. The obligation already applies and becomes more important as AI becomes more deeply embedded in processes and software.
The risk profiles of the AI Act
The AI Act looks at risk. The greater the potential impact on people, safety or fundamental rights, the heavier the obligations.
Prohibited AI practices.
These are AI applications with an unacceptable risk. Think of harmful manipulation, unjustified social scoring and certain forms of emotion recognition in education or the workplace. These applications have been prohibited since February 2025.
High-risk AI.
High-risk AI demands the most attention. This concerns applications that can influence important choices affecting people. Think of recruitment, education, biometrics, critical infrastructure, essential services, law enforcement and medical applications.
Stricter requirements come with this kind of system. Think of risk management, data quality, documentation, transparency, logging and human oversight.
Risk of deception.
AI that generates content or communicates directly with people must be clear about the use of AI. With a chatbot, it must be clear that someone is dealing with AI. With manipulated content or deepfakes, it must be visible that the content has been artificially created or altered.
Minimal risk.
Many AI applications fall into the minimal-risk category. Think of internal support, spam filters or productivity tools. Fewer specific requirements apply to these. Even so, good use remains important, especially when employees enter sensitive information or use AI output without checking it.
Why this matters strategically
AI literacy is often seen as compliance. That's too narrow. The questions you have to answer for it are the same questions needed for a good AI course.
- Where do we already use AI?
- Where does AI deliver value?
- Where does risk arise?
- Which processes deserve acceleration?
- Where is integration with existing systems needed?
- Which solution calls for bespoke development?
In this way, AI literacy directly touches the broader AI transformation of an organisation. Not as a large change programme without direction, but as a concrete translation of ambition into processes, software and measurable goals.
From standalone AI tool to working solution
Many organisations start with standalone AI tools. That's logical. It makes the possibilities tangible and gives teams room to learn.
The next step calls for more direction. As soon as AI becomes part of customer contact, internal workflows, analysis or decision-making, the solution has to align with the organisation. Think of data, permissions, roles, security, management and scalability.
That's why the choice between buying, integrating or bespoke development matters. In some situations, existing tooling is sufficient. In others, AI implementation is needed to get AI working well with existing systems. And sometimes bespoke is the best route, because the application is too specific or too strategic for a standard solution.
AI in software, apps and platforms
When AI becomes part of software, the responsibility changes. The user must understand when AI is being deployed. The organisation must be able to check what the system does. And the solution must keep fitting the purpose it was built for.
That calls for choices in design and technology. Think of clear interactions, logging, access rights, data security, human oversight and understandable output.
Within digital products, Artificial Intelligence can add value when it solves a clear problem. For example, by speeding up processes, making information easier to find, supporting users or preparing decisions.
With bespoke software in particular, these choices can be properly factored in from the start. Not afterwards as a repair, but as part of the strategy, architecture and user experience.
What organisations should do now
Start with an AI inventory. Map out which AI systems, features and tools are in use. Include software that already has AI built into it. Then classify the risk per application. Does AI only support internal work? Does it touch customer contact? Are personal data used? Does AI output influence assessment, advice or decision-making?
Next, determine what level of knowledge is needed per role. Not everyone needs the same training. Teams with sensitive data, customer impact or high-risk processes need more depth than teams that only use AI for internal support.
Finally, record what has been agreed. Think of an AI register, guidelines, ownership per system, role-based training and fixed evaluation moments.
From obligation to advantage
The AI Act forces organisations to deal with AI more consciously. That's not a brake on digital growth. It's an opportunity to organise AI more maturely.
Those who gain insight now into tools, risks and processes will see more quickly where AI adds value. Not as a standalone trial, but as part of software, apps and digital platforms that keep working reliably. This way AI literacy becomes not an end point, but a starting point. For better choices, safer application and digital solutions that contribute to sustainable growth.







