On 2 August 2026, national regulators across the European Union gained the power to enforce a requirement that has technically applied since February 2025: employers must build AI literacy in their people. That was two weeks ago. Most L&D teams I speak to have never heard of it.

What Article 4 actually says

Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures to support a sufficient level of AI literacy among their staff. It has applied since 2 February 2025. The European Commission's own policy page confirms that market surveillance authorities began supervising and enforcing it on 2 August 2026.

Two things about scope catch people out. "Deployer" means almost any organisation using an AI system in a professional capacity, not just companies building models. And "staff" is defined broadly enough to include contractors, service providers and in some readings clients.

What it does not say, which matters more

The AI Office published a questions and answers document on 27 July 2026, and it is refreshingly plain. There is no required level. No mandated curriculum. No certificate. In their words: "There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives."

But there is a floor, and it is the sentence L&D people should read twice: "simply relying on the AI systems' instructions for use or asking the staff to read them might be ineffective." Circulating a policy PDF and logging who opened it is explicitly called out as probably not enough.

What is required scales with context: whether you are a provider or a deployer, the risk level of the system, your sector, the purpose of use, and what your people already know. That is a proportionality test, not a checklist, which is harder to fake and easier to pass sensibly.

The obligation just got weaker, not stronger

If you are about to build a compliance-driven programme, know this first. On 27 July 2026 the Digital Omnibus on AI came into force and amended the wording. According to White & Case's analysis, the duty moved from "ensure a sufficient level of AI literacy" to "take measures to support the development of a sufficient level of AI literacy." They characterise it as a material weakening.

So the regulator is retreating while enforcement begins. I have found no reported penalties under Article 4 anywhere. If your entire argument for AI literacy is the threat of a fine, it is a weak argument and someone in the room will work that out.

The better argument is in the behaviour data

KPMG and the University of Melbourne surveyed 48,340 people across 47 countries for their global study on trust and use of AI. It is the best employee-level dataset available, and it is not comfortable reading:

These are self-reported answers to embarrassing questions, which usually means the real figures are worse, not better. The fieldwork ran from November 2024 to January 2025, so it is a pre-obligation baseline and now over eighteen months old.

Set that against the policy picture. ISACA's 2026 poll of 3,400 professionals found only 38% have a formal comprehensive AI policy and 25% have no active policy at all, while 90% acknowledge their employees are using AI. Universal AI training rose from 22% to 33% in a year, which is real progress and still means two-thirds of organisations are not doing it.

This is not only a European problem

In the United States, Illinois amended its Human Rights Act effective 1 January 2026. The covered employment decisions explicitly include "selection for training or apprenticeship." If you use an AI system to decide who gets development opportunities, that decision now sits inside employment discrimination law, and employers must notify employees when AI is used for it.

One honest note: the two official Illinois General Assembly URLs I tried both returned errors, so I verified the statutory language through two independent sources that match exactly. Confirm it with your counsel before acting, and note the state's Department of Human Rights still holds rulemaking authority over what notice actually requires.

What a proportionate response looks like

Write down which AI systems your organisation actually deploys and who touches them. Define what "sufficient" means for each group, because a finance analyst using a copilot and a recruiter using a screening tool are not the same risk. Train on real tasks rather than distributing a policy. Keep an internal record, since the regulator has said that is enough. Then revisit when the system or the role changes.

Do it because half your workforce is pasting confidential material into public chatbots, not because Brussels might send a letter. The first reason is true today and does not depend on a regulator's appetite.

On sourcing. Regulatory text and guidance link to the European Commission directly. The Digital Omnibus amendment is cited via a law firm's analysis because I could not retrieve the Official Journal text of Regulation (EU) 2026/1744, so verify that specific wording change with counsel before relying on it. No enforcement action under Article 4 has been reported anywhere I could find, and nothing here should be read as legal advice.