Free tool · EU AI Act Article 4
AI literacy policy generator
Answer four questions and get an AI literacy policy your auditors and market surveillance authority can read: what AI you use, who gets which training, what the rules are, and how you keep records. No signup, and nothing you type leaves your browser.
Your policy
AI LITERACY POLICY: [Company name] Version 1.0 · 2026-10-04 · Owner: [Role or name of the person responsible] 1. PURPOSE [Company name] is a deployer of AI systems (we use AI systems under our own authority). Article 4 of the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744) requires us to take measures to support the development of AI literacy of our staff and of other persons operating or using AI systems on our behalf, taking into account their technical knowledge, experience, education and training, the context in which the systems are used, and the people on whom they are used. This policy sets out those measures. It does not promise a specific competence level for any individual; it commits us to a reasonable, documented, proportionate programme. 2. SCOPE Everyone who uses, configures, supervises or builds AI systems for us, including employees, contractors and service providers. 3. WHERE WE USE AI AND WHAT CAN GO WRONG - Generative AI assistants (ChatGPT, Claude, Copilot…): Confidential data pasted into prompts, hallucinated output used as fact, unlabelled AI-generated content (Art. 50). Register every AI system in an inventory (name, purpose, owner, data used, risk tier). Review the inventory at least twice a year. 4. LITERACY MEASURES BY AUDIENCE - All staff: Foundations: what AI is and is not, approved tools, data rules, how to report a problem (about 60 minutes at onboarding, refreshed yearly). - Regular AI tool users: Practical: prompt hygiene, verifying output, handling personal and confidential data, disclosure of AI-generated content. Training is adapted to role and prior knowledge. Formats can include short courses, internal guides, workshops and supervised practice. 5. RULES EVERYONE MUST FOLLOW - Use only AI tools on the approved list; request approval before adopting a new one. - Never enter personal data, customer secrets or credentials into a tool that has not been approved for that data. - Check AI output before relying on it. A person remains accountable for the result. - Tell people when they are interacting with AI or receiving AI-generated content where the law requires it (Art. 50). - Report incidents, harmful or biased output and near misses to the owner immediately. 6. RECORDS We keep, for each audience: the content of the measures, dates, attendance or completion, and who delivered them. Records are kept for at least three years and made available to the market surveillance authority on request. 7. REVIEW [Role or name of the person responsible] reviews this policy at least once a year and whenever we adopt a new AI system, change the use of an existing one, or the law changes. Next review due: 2027-10-04. Approved by: ______________________ Date: ______________
Literacy is one duty of many
Find out which risk tier your AI systems fall into and which documents you need. The €49 Compliance Pack drafts them for you.
What the law asks for
Article 4 in plain terms
Article 4 of the EU AI Act asks providers and deployers to take measures to support the AI literacy of their staff and of anyone operating AI systems on their behalf, taking into account their knowledge, experience, the context of use and the people affected. It has applied since 2 February 2025. The Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) softened the wording from ensuring a “sufficient level” to taking measures that support literacy, and added a role for the Commission and Member States in helping, especially SMEs.
A defensible programme is proportionate, role-based and documented: an inventory of the AI you use, training matched to each audience, rules everyone follows, and records of who received what. The separate competence expected from people overseeing high-risk systems (Articles 14 and 26) is deferred with the high-risk rules, to 2 December 2027 for Annex III systems.
Next: classify your AI systems, build your AI system inventory, generate your Article 50 notices, or check your maximum exposure.
FAQ
Frequently asked questions
Is AI literacy still mandatory after the Digital Omnibus?
Yes. Article 4 has applied since 2 February 2025. Regulation (EU) 2026/1744, in force since 27 July 2026, rewrote it: providers and deployers must take measures to support the development of AI literacy, and no longer have to ensure a “sufficient level”. The duty to act remains.
Who has to comply?
Providers and deployers of AI systems, for their own staff and for other people operating or using AI systems on their behalf, such as contractors. Size does not exempt you, but the measures are judged against your context and risks.
Is there a fine for not training staff?
Article 4 has no dedicated penalty tier, and enforcement sits with national market surveillance authorities under national rules. In practice, missing literacy measures weigh heavily when an incident or another breach is investigated.
Do I need certificates?
No official certificate exists. What helps is a written policy, a record of what was delivered to whom and when, and content adapted to each role, which is what this template sets up.
Is this legal advice?
No. It is a well-formed starting point. Adapt it to your organisation and have it reviewed if you use high-risk systems.
General information about Regulation (EU) 2024/1689, updated 29 September 2026. Not legal advice.