The AI Act's AI literacy duty still applies to companies whose staff use ChatGPT
A support agent pastes a ChatGPT draft into a reply to a customer in Munich, and the draft promises a refund your terms have never offered. The customer complains. Nobody had told the agent that the tool makes things up, and under the EU AI Act that is now a question an authority can ask: Article 4 requires a company whose staff use AI systems at work to take measures that build their understanding of those systems, their limits and their risks. The Commission proposed dropping that duty for companies in November 2025, and the version adopted in July 2026 kept it, in a softer form: you no longer have to guarantee that anyone reaches a "sufficient" level, and the Commission says no certificate is needed.
If you read in early 2026 that the obligation was being scrapped, that was the proposal, and the proposal did not survive. If someone is selling you "AI Act certified" training, you do not need the certificate. What is left is a short, written piece of work: know which AI tools your people use, tell them what can go wrong with each, and keep a record that you did.
Does the AI literacy duty apply to a company that only uses ChatGPT?
Yes. Article 4 binds "providers and deployers of AI systems". A deployer is anyone "using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity" 4, so a company that gives its support team a chat assistant is a deployer of that assistant. The Commission's AI literacy Q&A, its official FAQ on Article 4, answers this exact case: a company whose employees use ChatGPT for writing advertising text or translating is covered, and "they should be informed about the specific risks, for example hallucination" 3.
Three details decide how far it reaches.
- Where you are, or where the work lands. The AI Act covers deployers established or located in the EU, and deployers elsewhere where the output of the AI system is used in the EU 7. A US team whose staff use ChatGPT for work that never reaches the EU is not plainly covered; one writing replies to EU customers with it is.
- Contractors count. The duty covers staff "and other persons dealing with the operation and use of AI systems on their behalf". The Commission reads that as anyone "broadly under the organisational remit", a contractor or a service provider for example 3.
- Shipping an AI feature makes you a provider too. A provider is the company that develops an AI system and puts it on the market under its own name, and it owes the same duty for the people who build and run that system. We build Lawcel, which uses language models to read pull requests against a company's legal documents, so we are both: provider of that feature, deployer of every assistant our team uses. The Act uses "provider" in a second sense too, for the maker of a general-purpose model; see when fine-tuning makes you a model's provider.
Tools your staff brought themselves are the grey area. In Microsoft's 2024 Work Trend Index, a survey of 31,000 knowledge workers in 31 countries, 78% of people using AI at work brought their own tools, and only 39% had received AI training from their employer. Neither the Act nor the Q&A says whether a personal account used for work is "under the authority" of the employer. My reading is that you should list those tools anyway: the work and the output are the company's.
Does your legal documentation match what you ship?
Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.
Get startedWhat did the July 2026 change do, and what counts as enough?
The Digital Omnibus on AI, Regulation (EU) 2026/1744, rewrote Article 4 with effect from 27 July 2026 1. The old text required measures "to ensure, to their best extent, a sufficient level of AI literacy" 2. The new one requires measures "to support the development of AI literacy", and says it "does not require providers or deployers to guarantee any specific level of AI literacy of any individual" 1. The Commission's own proposal would have moved the duty off companies altogether 3; Parliament and the Council did not follow it.
What counts as enough is less than a certified course. The Q&A settles four questions directly 3:
- No certificate. "There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives."
- No test of your staff. Article 4 "does not entail an obligation to measure the knowledge of AI of employees".
- No AI officer or governance board. "No specific governance structure is mandated."
- Different levels for different people are fine. An engineer who builds on a model and a salesperson who drafts emails with one need different things.
What the Commission does ask is that you think through which AI your organisation uses, whether you build it or only use it, what can go wrong with each system, and what each group of people already knows, and then act on the answers 3. It adds a warning: "in many cases, simply relying on the AI systems' instructions for use or asking the staff to read them might be ineffective". I would not count on a link to the vendor's help centre being enough on its own.
The mistake these briefings are meant to prevent already costs money. In October 2025 Deloitte Australia agreed to partially refund the Australian government for a report, written partly with Azure OpenAI, that cited sources that do not exist.
Who enforces the AI literacy duty, and what happens if you ignore it?
National market surveillance authorities, the bodies each Member State designates to police AI systems on its market. According to the Commission, they supervise and enforce Article 4 from August 2026 3.
The AI Act sets no EU-wide fine for Article 4. Each Member State decides the penalty, anywhere from a warning or a non-monetary measure to a fine 5 1.
The Commission ties the risk to incidents. Any sanction "must be proportionate", and it "might, however, be more likely if there is proof of an incident due to lack of appropriate training and guidance of employees or other persons" 3. My reading is that Article 4 is most likely to reach a small company after an AI mistake has reached a customer, when an authority asks what you told the person who made it.
What should you do about AI literacy?
If your company uses AI tools at work or ships an AI feature, and you are in the EU or your work reaches it, you need a written list of those tools, a note of what each group of users was told about them, and the date they were told. Otherwise the first AI mistake that reaches a customer leaves you with nothing to show the authority that asks.
- List the AI systems in use. Start from what you already have: the apps in your single sign-on, the subscriptions on the company card, and the AI features switched on inside tools you already pay for. Then ask each team what they use on their own. Note who uses each one and for what.
- Write down what each group needs to know. For most teams that is short: models invent facts and sources, so outputs that leave the company get checked; and which data never goes into which tool. If personal data flows into a model you call from your product, the three privacy policy changes an AI feature brings belong in the same conversation.
- If you ship an AI feature, brief the people who build and run it on the model underneath and how it fails. Training your customers' staff is mainly their employer's job as deployer; the Commission says briefing clients can be useful where the risk warrants it 3.
- Deliver it in a form that fits. A written guideline plus a session for the teams that use AI most will do for many small companies. Include contractors who work with your AI tools.
- If a system is high-risk, plan for more. For a tool such as one that screens job applicants, Article 26(2) will require its overseers to have "the necessary competence, training and authority" 6, from 2 December 2027 1. Check which AI features count as high-risk.
- Keep a dated record. What you covered, when, and who took part. Article 4 does not require one, but it is what the Commission suggests in place of a certificate, and it is how you answer an authority's question later.
Tags
FAQ
References
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Article 1(5) replacing Article 4 and Article 1(38) amending Article 99 of Regulation (EU) 2024/1689 - accessed 25 Sep 2026
- Regulation (EU) 2024/1689 (AI Act), Article 4: AI literacy (text as originally adopted) - accessed 25 Sep 2026
- European Commission, AI Literacy: Questions & Answers (updated 27 July 2026) - accessed 25 Sep 2026
- Regulation (EU) 2024/1689 (AI Act), Article 3: Definitions (page shows text before the Digital Omnibus; point (4) unchanged) - accessed 25 Sep 2026
- Regulation (EU) 2024/1689 (AI Act), Article 99: Penalties (page shows text before the Digital Omnibus; see reference 1 for the amendments) - accessed 25 Sep 2026
- Regulation (EU) 2024/1689 (AI Act), Article 26: Obligations of deployers of high-risk AI systems - accessed 25 Sep 2026
- Regulation (EU) 2024/1689 (AI Act), Article 2: Scope - accessed 25 Sep 2026
About the author
Kenneth Graupner
Co-founder, Chief Product Officer
Kenneth is Co-founder and CPO at Lawcel. He focuses on product strategy and on shaping workflows so legal, engineering, and GTM teams can ship continuously without treating compliance as a late-stage gate.
- Product strategy
- Compliance operations
- SaaS delivery
Related articles
Most SaaS AI features are not high-risk under the AI Act. Hiring and credit tools need a check.
Most SaaS features are not high-risk under the EU AI Act. Two things make a system high-risk: it is, or is built into, a product covered by EU product-safety law, or it sits in one of the eight areas in Annex III, such as hiring, education or credit scoring. If yours is, Article 6(3) can still take it out, but you then owe a written assessment and an EU database entry.
GDPRAdding AI to your app? Add these three disclosures to your privacy policy.
Calling an LLM API adds three things to what GDPR Article 13 makes you disclose: the model vendor becomes a recipient of personal data, wherever it runs the prompt is probably a transfer out of the EEA, and if the output decides something about a person you may owe the automated-decision disclosure too. AI Act Article 50 then adds two duties to the product itself.
AI ActThe EU KIDS Act would regulate general AI chatbots, not customer-support bots
The EU KIDS Act, proposed on 17 September 2026 and not yet law, would regulate AI chatbots that minors can reach and that can help across multiple domains. Chat limited to one task, such as customer service, is excluded. In scope, every user would get child-safe defaults, such as no memory between chats, until an age check that is not a tick box shows they are an adult.
AI ActFine-tuning rarely makes you a model's provider under the AI Act. The threshold is a third of the base model's compute.
The AI Act has two provider roles, and a fine-tune almost never moves the second one to you. Shipping an AI feature under your own name makes you the provider of that AI system. The provider of the model underneath is normally the lab that trained it, and the Commission's indicative criterion for whether your fine-tune changes that is compute greater than a third of what it took to train the base model.