EU AI Act and AI literacy
EU AI Act for Employees: Practical 2026 Guide
Updated
A practical explanation of what applies now, who owns which action, and how to make everyday workplace AI use safer without turning compliance into a box-ticking course.
If employees use ChatGPT, Copilot, Gemini, Claude or AI built into business software, the EU AI Act is already relevant. Article 4 does not ban everyday AI or require every employee to become a lawyer. It requires organisations that provide or deploy AI systems to take context-appropriate measures that support AI literacy among the people operating and using those systems on their behalf.
What applies on 23 August 2026: the AI literacy obligation has applied since 2 February 2025, and national market-surveillance authorities began supervising and enforcing Article 4 in August 2026. Regulation (EU) 2026/1744 changed the original wording in July 2026. Providers and deployers must now take measures to support the promotion of AI literacy, but they do not have to guarantee a specific level for every individual. That distinction matters: doing nothing is hard to defend, while a proportionate programme can be adapted to the organisation, role and use case.
Who is responsible: Article 4 places the direct obligation on AI providers and deployers. In ordinary workplace use, the employer or organisation will usually be the deployer; an employee using an AI system under its authority is not normally the deployer in their own right. The organisation should select approved tools, define ownership, assess use cases and provide suitable guidance. Employees should follow the policy, protect data, check AI outputs and report mistakes or unapproved tools. Employment duties and internal policy may still apply, but Article 4 is not a personal certification duty imposed on each employee.
What AI literacy should cover: a general user needs to understand what the approved tool can and cannot do, when an output needs human verification, what data may be entered, how bias or fabricated answers can affect people, and where to escalate a concern. Managers need additional knowledge about accountability, procurement and impact on staff or customers. Technical, legal, security and HR teams need role-specific depth. Training should therefore follow the actual systems and risks rather than giving everyone the same generic presentation.
Legal obligation versus good practice: taking appropriate AI-literacy measures is the legal obligation. The Commission says no particular certificate, AI officer or governance board is required solely for Article 4; an internal record of training and other guidance can help demonstrate what was done. A written AI policy, named owner, AI inventory, refresher cycle, prompt controls and short knowledge checks are practical ways to operationalise the duty, but Article 4 does not prescribe each of them. Other rules, including the GDPR and sector or employment law, may create separate requirements.
Start with an AI inventory: list both centrally purchased systems and AI features already embedded in office, CRM, support, recruitment and analytics tools. For each entry record the owner, users, purpose, data involved, vendor or model, integrations, whether outputs affect people, and the current approval status. Include employee-discovered tools and browser extensions. An inventory turns vague training into concrete instructions and makes shadow AI visible before it becomes an incident.
Treat sensitive data as a workflow question, not a memory test. Employees need examples of personal data, special-category data, customer secrets, contracts, credentials, unpublished financial information and source code that match their work. State which tools and accounts are approved, what must never be entered, when data must be minimised or anonymised, and who can approve an exception. Where possible, add preventive controls before submission: warnings, blocking, redaction or anonymisation reduce dependence on perfect recall.
This guide is practical information, not a legal opinion on a particular organisation. AI Act roles and obligations depend on how a system is developed, supplied and used, while data-protection and sector rules remain relevant. Organisations using AI for recruitment, worker management, access to services or other consequential decisions should obtain specialist advice and assess the additional rules for their specific system.
What the official guidance confirms
- The amended Article 4 requires providers and deployers to take measures supporting AI literacy, taking account of knowledge, experience, training, use context and the people affected; it does not require a guaranteed level for each person. Source
- The European Commission says no specific certificate or governance structure is mandatory for Article 4, while internal records of training or guidance can document the organisation’s actions. Source
- Denmark’s Agency for Digital Government recommends differentiating AI skills by role and system, combining technical, practical and ethical understanding, and keeping skills up to date. Source
- Spain’s data-protection authority provides a useful operational example: register generative-AI systems, limit them to approved purposes, supervise use and integrate AI incidents into incident management. Source
A realistic plan for this week
- Day 1 — appoint an accountable owner and ask each team which AI systems and embedded AI features they actually use.
- Day 2 — create a lightweight inventory with purpose, users, data categories, integrations, approval status and risk owner.
- Day 3 — publish a one-page policy: approved tools and accounts, allowed uses, prohibited data, human-review rules and an escalation route.
- Day 4 — deliver role-based training with real prompts from sales, HR, support, finance and engineering; record attendance and materials.
- Day 5 — add practical controls for sensitive prompts, test five common scenarios and log gaps, decisions and follow-up owners.
- Every quarter — review new tools, incidents and policy exceptions; refresh training when systems, roles or risks change.
A simple responsibility split
Leadership approves the risk appetite and resources. An AI or governance owner maintains the inventory and policy. IT and security configure approved tools and preventive controls. Legal, privacy and HR review the use cases within their remit. Managers translate the rules into team workflows. Employees use approved systems, minimise sensitive data, verify material outputs and raise concerns. This division is good practice rather than a governance chart mandated by Article 4, but it makes the required measures real and auditable.
Put guidance at the point where employees use AI
Policies and training are stronger when employees receive help before sensitive text reaches an AI tool. AIamigo can detect sensitive content at prompt time and help users anonymise it, supporting the organisation’s approved-use rules without stopping productive AI work. It complements an AI inventory, role-based training and legal review; it does not replace them.
Related practical guides
Frequently asked questions
Does the EU AI Act require employee AI training?
Article 4 requires AI providers and deployers to take context-appropriate measures supporting AI literacy among staff and others using AI on their behalf. Training is a common measure, but the law does not prescribe one identical course or format for every employee.
Do employees need an AI literacy certificate?
No specific Article 4 certificate is required. The European Commission says organisations can keep internal records of training and other guidance to document the measures they have taken.
Who is responsible for AI literacy: the employer or employee?
The direct Article 4 obligation is on the provider or deployer, usually the organisation in a workplace context. Employees still need to follow approved-use, confidentiality, security and review procedures.
Does Article 4 apply only to high-risk AI?
No. Article 4 is a general obligation for providers and deployers of AI systems. The appropriate measures vary with the system, use context, staff knowledge and people affected; high-risk systems may trigger additional obligations.
What should an employee never paste into an AI tool?
Unless an approved workflow explicitly permits it, avoid personal or special-category data, customer secrets, credentials, contracts, source code and other confidential material. Follow the organisation’s policy and minimise or anonymise data where appropriate.