What is AI Literacy (Article 4)?
The EU AI Act’s most widely applicable duty is not about models at all. It is about people. Article 4 asks organisations that provide or use AI systems to make sure the people operating them have a sufficient level of AI literacy, and it was among the first of the Act’s obligations to take effect. It is also the easiest to misread: as a training checkbox, an annual e-learning module, a certificate. Read properly, it is something more interesting, and more useful.
What Article 4 actually asks
In ordinary language: whoever uses AI on your behalf should understand it well enough to use it responsibly, and well enough is judged in context. The Act points at the factors that matter: the person’s technical knowledge, experience, education and training, the context the system is used in, and the people it is used on. Three things follow. It is broad: the duty attaches to the use of AI systems generally, not only the high-risk ones. It is proportionate: a consultant using a drafting assistant and a recruiter acting on match scores do not need the same depth, because the stakes and the affected people differ. And it is not prescriptive about form: the Act asks for measures that produce sufficient literacy, and leaves the how to the organisation. (This entry is orientation, not legal advice.)
Literacy is knowing what to challenge
The instinctive response is a course on how AI works: tokens, training data, neural networks. That teaches the model and misses the duty. The recruiter acting on a match score does not need to know how the model was trained. They need to know that the score is a prediction, not a finding; which inputs the system saw and, more importantly, which it did not; where this tool is known to fail; and what to do when they disagree, and with whom. The literate user’s working questions are small and sharp. What evidence did this see? How good was that evidence? What would make this answer wrong? Has it been wrong like this before? AI literacy is not knowing how the model works. It is knowing what the output rests on, and when it deserves a no. That framing also names the real adversary: automation bias, the well-documented human tendency to defer to a confident system. Literacy is the trained reflex that interrupts the deference.
Sufficient, for whom, for what
A workable literacy programme starts from an inventory, not a curriculum: which AI systems do our people actually use, and on whom do those systems act? For each, teach the things a responsible user must hold: what the tool is for and not for, what it sees and does not see, its known failure modes, and the route for challenging it. Then make challenge a normal act of work rather than an act of courage, because a workforce that is literate but not permitted to disagree has knowledge without a use. And treat literacy as perishable: systems change, models are swapped, failure modes move, and last year’s briefing describes last year’s tool.
One concrete example
Clearly illustrative, with no customer implied. A recruitment firm rolls out an assistant that ranks applicants. The first version of its training is an hour on how AI works: models, data, a diagram of a neural network. Weeks later, recruiters are approving shortlists wholesale, and when a hiring manager asks why a candidate ranked third, nobody can say. The training taught the model and not the tool. The second version is role-specific. It covers what the ranker reads (the written application, not the phone screen), what it cannot see, the patterns it handles badly (unusual career paths rank oddly), and the standing rule that a ranking is a proposal until a person confirms it, with a route to reorder and record why. Recruiters start disagreeing with the tool in the open, the disagreements get recorded, and the questions they now ask, what did it see and how sure is it, are precisely the literacy Article 4 was pointing at.
AI literacy and decision intelligence
Literacy has a dependency the Act can only imply: the system must be built to be challenged. The most literate reviewer in the world is a spectator in front of an unexplainable score, which is why literacy and human-in-the-loop design succeed or fail together. Decision intelligence supplies the other half of the bargain: evidence carried with its quality on the evidence hierarchy, so a literate user has something to read, and reasoning that can be traced, so a challenge has somewhere to land. It is the stance ONX takes with its own AI, keeping it explainable and challengeable, and treating candidate matching in Hiring as high-risk under the strict Annex III reading, with human review gates. The Act asks people to understand the AI they use. Decision intelligence asks the AI to be understandable. A workforce needs both, and only one of them can be trained.
Common questions
What is AI literacy under the EU AI Act?
AI literacy is the EU AI Act’s expectation, set out in Article 4, that providers and deployers of AI systems take measures to ensure the people operating and using those systems on their behalf have a sufficient level of AI literacy: enough understanding, given their role, their background and the context of use, to use the systems responsibly. It applies across AI systems generally rather than only to high-risk ones, and it is a duty about the workforce, not the technology.
Does Article 4 require formal AI training or certification?
The Act does not prescribe a format. It asks for a sufficient level of literacy, taking into account people’s technical knowledge, experience, education and training, and the context the AI is used in, including the people affected by it. For one role that might be a short briefing on what a tool can and cannot be trusted with; for another, deeper instruction. The measure of sufficiency is whether people can use the system responsibly in their actual work, not whether a certificate exists. This answer is orientation, not legal advice.
Do people need to understand how AI models work to be AI literate?
No. Mechanical understanding of model internals is neither required nor especially useful for most roles. Useful literacy is operational: knowing that an AI output is a prediction rather than a fact, what evidence the system did and did not see, where it tends to fail, and when its answer should be challenged or escalated to a human decision. A person who can answer those questions about the tools they use is literate in the sense that matters.
How does AI literacy relate to human oversight?
They are two halves of one requirement. The EU AI Act expects high-risk AI systems to be overseen by humans who can understand the outputs, stay alert to automation bias, intervene and overrule the system. That oversight is only real if the humans are literate: a reviewer who cannot tell what a score rests on cannot meaningfully contest it. Literacy is what turns a human presence into human oversight.