Article 4 of the AI Act: What the AI-literacy duty actually asks of a company
Every company in the EU has been obliged since 2 February 2025 to develop the AI literacy of its staff. That sentence comes from Article 4 of the AI Act, it applies wherever people use AI at work, and it applies just as much when the entire AI estate is two ChatGPT logins and Microsoft Copilot. Most companies have not registered it, for a simple reason: Article 4 carries no fine of its own, so in practice it gets treated as advice.
That is a misjudgement with a delay built in.
What applies since the Digital Omnibus
The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and rewrote Article 4. The change sits in the wording:
| Original wording | Since 27 July 2026 | |
|---|---|---|
| Core duty | take best efforts to ensure sufficient AI literacy | take measures to support the development of AI literacy |
| Level | undefined, but framed as enforceable | expressly no guaranteed level for any individual |
| Who is addressed | providers and deployers | unchanged: any company using AI |
| Yardstick | technical knowledge, experience, training, context of use, people affected | unchanged |
This is a softening of the text, not a repeal. A duty of result became a duty of effort. Anyone who can show they did something is fine, with no certificate, no minimum hours and no AI officer. Anyone who did nothing still fails the duty; the argument merely shifts from fines to orders.
The dates where it turns concrete:
| Date | What applies |
|---|---|
| 02.02.2025 | Article 4 (AI literacy) and Article 5 (prohibited practices) apply |
| 02.08.2026 | Article 50 transparency duties, governance and penalties |
| 02.12.2026 | New prohibitions under Article 5; legacy content-generation systems must have met the marking duty under Article 50(2) for the first time |
| 02.12.2027 | Obligations for Annex III high-risk systems |
| 02.08.2028 | Obligations for Annex I high-risk systems inside regulated products |
Why a duty without a fine is still not free
Four levers work regardless, and none of them is in the penalty catalogue. The Omnibus in fact extended the catalogue in Article 99, just not with Article 4: obligations under Article 25 were added, and for small mid-cap companies the lower of the two amounts now applies.
- Information requests. Since August 2026, market surveillance can require a company to lay out what it did for AI literacy. An order is not a fine, but it costs money and attention.
- Combined effect. Article 50 carries up to EUR 15 million or 3% of worldwide annual turnover. In such a procedure the question of staff capability lands on the table by itself, and Article 4 turns into a side claim.
- Liability. This is where the point actually sits, and the RTR service desk says it itself: the AI Act provides no administrative sanction for Article 4, but missing staff training is attributable to the employer under § 1313a of the Civil Code. Article 4, in that reading, specifies the duty of care a company owes with regard to AI. If an AI-generated answer to a customer causes damage, missing capability then reads as an organisational failing in civil terms. That is the expensive route, not the authority.
- Proving the exemption. Publishing posts without a label means relying on the fact that a human reviewed them and someone holds editorial responsibility. Both are things you have to be able to produce. A sheet of paper that does not exist wins no argument.
Add a channel that has nothing to do with authorities: customers with their own obligations increasingly ask suppliers for an AI policy and a system inventory. The same sheet counts there, with a different audience. What the same question looks like from the data side, and why running your own model stack makes it easier, is in Why local AI answers the regulatory question.
Austria: same regulation, a different set of authorities
Work through the German guides and you mostly learn the German architecture: the Federal Network Agency as market surveillance authority, plus the BDSG and the Works Constitution Act as the law around it. None of those institutions exist in Austria. The AI Act applies directly and identically in every language version; the apparatus around it is national.
A contact point without teeth. For Austria the right first stop is the AI service desk at the RTR-GmbH, set up in early 2024 under § 20c KOG and § 194a TKG. It is an information hub and a contact point, explicitly not an enforcement body. What you get there is orientation, not a permit and not an order.
Nobody enforces it yet. The AI Act requires every member state to designate market surveillance authorities, with a deadline of 2 August 2025. The RTR states that there is currently no national transposition of those competences at all, neither for market surveillance nor for the notifying authority. A motion to finally name an AI authority has been sitting in the National Council since October 2025; the science committee postponed it in November 2025 and again in June 2026. What has been named are the fundamental-rights authorities under Article 77, such as the Parliamentary Data Protection Committee and the Ombudsboard for Equal Treatment. For an operator that means: in Austria there is currently nobody who would open a file over Article 4, and there is no administrative practice to orient yourself by either.
That is not an all-clear, only a different one. Anyone working with customer data or in a regulated setting is not hanging on an AI authority but on the supervision that already exists: the Data Protection Authority reviews the data protection side of AI use anyway and independently of this regulation, and a bank or insurer is closer to the FMA than to AI law.
The law next door. Co-determination in Austria does not work like the German model. § 96a of the Labour Constitution Act requires the works council to consent before introducing systems that process employees’ personal data beyond general personal details, and before systems used to assess employees. Without a works council that provision does not bite, and consent can be replaced by the conciliation board. On the legal basis for an internal register, look at your own data protection act rather than at a German template: the Austrian DSG has no employee-data paragraph, there is no Austrian counterpart to § 26 BDSG. The basis is Article 6(1)(b) or (f) GDPR, alongside § 1 and § 6 DSG. If image or video material lands in the same folders, § 12 and § 13 DSG apply on top.
One warning, because anyone who reads along will notice it: the FAQ of the RTR AI service desk still describes the Digital Omnibus as text agreed between the legislators but not formally adopted, while the timetable page from the same office already works with the Omnibus dates. That is normal when an authority maintains several pages at once, and it is still a trap. Regulation (EU) 2026/1744 has been in the Official Journal since 24 July 2026 and applies since 27 July 2026. If you rely on what an authority published, check the date and not the letterhead.
The three sheets that carry the evidence
One register for everything becomes unmaintainable. Three sheets with clean interfaces through IDs for person, system and content still work as a spreadsheet an apprentice can run.
Sheet A: literacy. We keep one row per person and per measure. Required columns: who, with role and function; which AI systems they use; in what context and with what outward effect; which measure with which learning objectives; when, and with what proof of attendance; and who owns the measure. A column for the next refresher is the one that answers the question when the last session was two years ago. Compare the columns with the recommendation from the RTR service desk and you end up in roughly the same place: type of training, provider, content and objective, date, repetitions. There are currently no certificates for any of it, and internal training by a qualified person in-house is expressly possible.
Sheet B: AI inventory. One row per system: tool name and version, use cases, the company's role as deployer or, rarely, provider, risk class, approved data categories, system owner. The data category is the most practical column in the whole inventory, because it answers the first question anybody asks: may a customer list go in there?
Sheet C: content log. One row per published item with any AI involvement: channel and URL, content type, tool and model, share of AI, topic with risk class, reviewer and approver with dates, labelling with its reasoning, and for image and video the rights and consent situation.
What deliberately does not belong there: certificates, exam results, minimum hours. What belongs there as a boundary condition: a literacy register shows individuals and their behaviour, so it runs on Article 6(1)(b) or (f) GDPR and not on an Austrian special provision, which does not exist. Where there is a works council, get the consent under § 96a of the Labour Constitution Act before the first entry. And no storage of prompts. Prompts contain trade secrets and personal data, and their wording proves nothing. You log the tool, the share of AI, the review and the approval, not the input.
The test that decides everything
The labelling debate usually gets hung on the topic, which is where it goes wrong. Two questions place any piece of content:
- Is the topic of public interest? Ordinary advertising, product copy, job ads and the typical social post are not. Law, health, economy, technology and security with general relevance are.
- Does the content show something real? A person who exists, a place that exists, an incident that never took place, in the look of a genuine recording.
That gives four fields instead of a fine-grained class scale:
| No resemblance to reality | Resemblance to reality | |
|---|---|---|
| No public interest | no label required, a visual check suffices | label required regardless of purpose |
| Public interest | label, unless reviewed on substance with named responsibility | label required, plus deeper review |
The top-right field is the one almost everyone misses: a photorealistic AI image inside an advertising post needs a label even though the text beside it would not. The reverse also holds, pure technique does not count as long as the statement stays the same. Colour correction, a crop or denoising does not turn a real photograph into an AI image. The exemption for editorially reviewed text also covers text only, never image, video or audio. And the review that carries the exemption has to be a substantive one: do the facts hold, is the account plausible, and is the reviewer actually allowed to kill the text? Correcting spelling is not a review.
The part almost everyone overlooks
Article 50(1) is not about content but about the interaction itself. A chatbot or a voice assistant that speaks with people has to make that clear itself, at the latest on first contact, and in a way people actually notice. A note buried in the terms and conditions does not do it, and a label such as “assistant” is too vague, since it could just as well be a person. The duty is built into the system by its provider. Anyone buying a ready-made assistant has to keep that information in their own interface and may not remove it. For every company currently rolling out a customer-facing or technician-facing assistant, this is the nearest and most frequently forgotten obligation in the entire regulation. It is topic-independent and has no editorial exemption.
What a thirty-person company concretely does
- Inventory in one afternoon. Collect every account some department is already using, twelve rows in a sheet. The inventory is almost always larger than the official approval list.
- Two pages of policy. What may go into a tool and what may not, who reviews, who approves, how labelling happens. One named person for editorial responsibility.
- One role-specific session. Two hours for administration, plus a separate hour for the inside-sales group with their actual use cases. Content should cover hallucinations, data protection, approval paths and labelling, and not merely how the tool works.
- One row per published item. Generating the log line where the post is written keeps it under a minute per piece.
- A quarterly sample. Pull five rows, open the posts, check label and approval, record the result in one line. This sample is the first thing anyone asks for.
- Ask the works council where one exists. A register showing who uses which system falls under the consent requirement of § 96a of the Labour Constitution Act, and that consent can be replaced by the conciliation board if needed.
- Choose retention deliberately. We start at three years after publication, which is easy to defend under the GDPR purpose limitation. It secures nothing: the ordinary limitation period under § 1478 of the Civil Code is thirty years, far above that, while the short damages periods sit well below it. Anyone who later wants to prove that a review took place should orient by the window in which they can be held liable, not by the shortest period data protection allows.
Where we stand
The scarce resource is not knowledge; the Commission's guidelines are free online. The scarce resource is the translation into something a twenty-person firm can finish on a Tuesday afternoon without founding a compliance department. That is exactly where the Article 4 questions sit: the regulation is not too complicated, most of the implementation offers are built for companies that barely exist in Austria.
Anyone starting a customer assistant or an AI assistant in order processing today should fill the three sheets before go-live, not afterwards. Writing a log after the fact that suggests a control which never took place is worse than no paper at all. We advise the opposite: fill the first sheet before the first post, not after.
This post is a practitioner's assessment, not legal advice. "Public interest" and "resemblance to reality" are matters of interpretation, and authorities may read them narrower or wider than set out here. For a specific case, take it to a lawyer.
Further reading
- Regulation (EU) 2024/1689, consolidated version: EUR-Lex
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, OJ of 24 July 2026, with the rewrite of Article 4 and the new dates of application: Official Journal text
- Commission, Guidelines on the transparency obligations under Article 50, final version C(2026) 5083 final of 20 July 2026: digital-strategy.ec.europa.eu
- Commission, Code of Practice on Transparency of AI-generated Content: digital-strategy.ec.europa.eu
- Commission, Questions and answers on AI literacy under Article 4: digital-strategy.ec.europa.eu
- RTR-GmbH, AI service desk Austria: overview, AI literacy with documentation advice, FAQ, penalties, timetable
- Digital Austria, fundamental-rights authorities under Article 77 of the AI Act: overview
- Austrian Parliament, motion to name an AI authority, 517/A(E): parlament.gv.at
- § 96a Labour Constitution Act (ArbVG): RIS, § 1478 Civil Code (ABGB), ordinary limitation: RIS
- Austrian Federal Economic Chamber, AI Act: obligations for companies: wko.at
- Practical guide with registers, risk matrix and prompts, German legal position: NxtLvlOrg, Article 4 of the AI Act
- Internal: the AI check to get started, AI consulting in Tyrol
Does a small company with a handful of staff have to meet the Article 4 AI-literacy duty?+
Yes. Article 4 of the AI Act sets no size and no sector threshold; it only asks whether AI systems are used at work, and that includes ChatGPT, Copilot and Claude. The standard is role-specific: for a twenty-person manufacturing firm that means one afternoon session, two pages of rules and one sheet to maintain, not a certification programme.
Is there a fine for failing to meet Article 4?+
A fine for missing AI literacy alone is not provided for; Article 4 does not appear in the penalty catalogue of Article 99. The duty bites through four other routes: information requests from market surveillance, the assessment of staff capability when an Article 50 or high-risk breach is examined, civil liability for an organisational failing, and the burden of showing that the labelling exemption for reviewed text actually applies.
Do AI-generated images and posts always have to be labelled?+
No, but the dividing line sits elsewhere than most people assume. For text the topic decides: material of general relevance must be disclosed unless a human reviewed it on substance and a named person carries editorial responsibility. For image, video and audio the criterion is resemblance to reality, so a photorealistic rendering of a real person or a real place always needs a label, advertising included.
senn-tech