← Course outline
Aavistus Training · ai-act · AIA.11

AI literacy in practice: judgment under Article 4

What you'll learn

What the Article 4 AI-literacy duty requires of providers and deployers — a sufficient level of AI literacy for staff, matched to their technical knowledge, experience, education and the context of use — and what competent literacy means in practice: understanding AI capabilities and limits, hallucination and fabrication risk, deepfake-enabled fraud and social engineering, over-reliance on AI output, and a verification discipline (independent cross-checking of AI-generated claims before acting on them).

Regulation — cited to the current EU text

Who bears the duty

Article 4 imposes a positive obligation on two distinct categories of actors. Providers — defined in Article 3(3) as natural or legal persons, public authorities, agencies or other bodies that develop an AI system or a general-purpose AI model, or that have an AI system or a general-purpose AI model developed, and place it on the market or put it into service under their own name or trademark, whether for payment or free of charge 32024R1689 Article 3@2024-06-13 — must take active measures to ensure sufficient AI literacy 32024R1689 Article 4@2024-06-13. So must deployers: Article 3(4) defines these as natural or legal persons, public authorities, agencies or other bodies using an AI system under their authority, with a carve-out for personal non-professional activity 32024R1689 Article 3@2024-06-13.

Scope of the obligation

The duty extends beyond the organisations themselves to cover "their staff and other persons dealing with the operation and use of AI systems on their behalf" — language that deliberately encompasses employees, contractors, agents, and any other person handling a system on behalf of the provider or deployer. The obligation is qualified by the phrase "to their best extent," which introduces proportionality without making the requirement optional 32024R1689 Article 4@2024-06-13.

Contextual calibration

Article 4 does not demand uniform literacy training across all staff. It requires measures calibrated to four factors: the individual's technical knowledge, experience, education and training, and the context in which the AI system is to be used. A security analyst deploying a threat-detection model requires a different literacy baseline than a frontline worker using an AI-assisted scheduling tool. The duty also requires providers and deployers to consider the persons or groups of persons on whom the AI systems are to be used, meaning that the vulnerability or dependency of end-users can raise what counts as sufficient staff literacy in a given deployment 32024R1689 Article 4@2024-06-13.

What "sufficient" means in practice

Article 4 does not enumerate the specific competencies that constitute sufficient literacy; that determination is delegated to providers and deployers applying the contextual factors above. The Article 3(1) definition of an AI system — a machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from its input how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments — establishes the technical scope of what the Article 4 duty covers 32024R1689 Article 3@2024-06-13.

The specific content areas practitioners identify as constitutive of AI literacy — hallucination and fabrication risk, deepfake-enabled fraud and social engineering, over-reliance on AI output, and verification discipline requiring independent cross-checking before acting on AI-generated claims — are not enumerated in the EU corpus (ICAO-framework material). Article 4 creates the obligation; it does not specify the curriculum.

Nevertheless, the contextual factors in Article 4 point implicitly toward these risk areas. A deployer placing an AI system into a legal, financial, medical, or security-sensitive context cannot credibly claim a "sufficient" literacy programme that leaves staff unaware that AI systems can assert false information with apparent confidence, that synthetic media can be used to impersonate individuals at scale, or that uncritical reliance on AI recommendations does not transfer accountability away from the human decision-maker. The proportionality ceiling of the "best extent" qualifier rises with the stakes of the deployment context 32024R1689 Article 4@2024-06-13.

The provider/deployer distinction and its literacy implications

The Article 3 distinction between provider and deployer matters for how literacy programmes are designed 32024R1689 Article 3@2024-06-13. A provider's literacy obligation centres on the people who build and bring the system to market; the specific competencies involved — design choices, training data characteristics, known failure modes, proper scope of intended purpose — are not covered by the EU corpus (ICAO-framework material). A deployer's literacy obligation centres on operational competence; the specific competencies involved — recognising when AI outputs warrant scepticism, knowing when to escalate or override, maintaining accountability for decisions that AI has informed but not made — are likewise not covered by the EU corpus (ICAO-framework material).

An AI system as defined in Article 3(1) may exhibit adaptiveness after deployment 32024R1689 Article 3@2024-06-13.

Your operations manual

This block connects to your organisation's own AI governance policy. In the full product it shows, cited to your policy, how YOUR organisation implements the regulation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The following cases are labeled illustrative context only. They are not regulatory authority and do not represent the state of EU enforcement under the AI Act.

AI-assisted investment fraud — Australia, 2026 CASE-3

Australian police detailed the tactics used in a case where a woman lost over AUD 74,000 to a fraudulent cryptocurrency investment scheme in which AI tooling played a central role. The case illustrates two Article 4-relevant failure modes directly.

First, it demonstrates the social engineering potential of AI-generated content. Victims can be subjected to sustained, plausible interaction — synthetic voice, fabricated documentation, or manipulated imagery — that is materially harder to detect than traditional fraud. A literacy-competent staff member or user would approach such content with the awareness that its apparent authenticity does not establish its accuracy.

Second, the case illustrates the over-reliance failure mode. Targets of sophisticated AI-assisted schemes frequently fail to apply independent verification before committing funds because the generated material is convincing enough to suppress the instinct to check through a separate channel. This is exactly the behaviour that a functional Article 4 literacy programme must counteract: the default assumption that compelling output is correct output.

Staff in roles exposed to this threat — financial advisers, compliance officers, customer-due-diligence analysts, procurement managers — require the capacity to recognise that AI-generated content can be fabricated even when it appears authoritative, and the procedural discipline to cross-verify material claims through independent channels before acting. Neither capability is innate; both are the substance of what Article 4 requires deployers to actively cultivate CASE-3.

Check your understanding

1. On whom does Article 4 impose a positive AI literacy obligation?

2. Which activity is carved out from the Article 3(4) definition of a deployer?

3. Article 4 requires literacy measures to be calibrated to four contextual factors. Which set correctly reflects those factors?

4. What effect does the phrase "to their best extent" in Article 4 have on the literacy obligation?

5. According to the Article 3(1) definition, what may an AI system exhibit after it has been deployed?