← Back to Blog

Most conversations about the EU AI Act point to August 2026. But one obligation has already been in force since 2 February 2025 — and almost no small organisation has noticed. It's Article 4: the duty to make sure the people using AI in your organisation actually understand it.

This article explains what Article 4 requires, why it applies to your charity even if you feel far from "tech", and gives you a practical plan you can complete in an afternoon. It's written for people who run organisations, not for lawyers.

This article is general information, not legal advice. It does not constitute legal advice, and Vedomia does not provide legal services. For legal questions about your specific situation, speak to a qualified solicitor.

What Article 4 actually says

Article 4 of the EU AI Act is short, and its core is a single sentence in plain terms: if your organisation uses AI, you must take measures to ensure that the people operating it on your behalf have a sufficient level of AI literacy.

Two words carry the weight:

  • "Sufficient" — the level of understanding has to match the tools you use, the risks they carry, the roles of the people involved and the people affected by the AI. A volunteer using a chatbot needs a different level of understanding than a manager deciding to deploy an AI screening tool.
  • "Take measures" — you're expected to do something deliberate. Assuming staff will "pick it up" is not a measure.

Article 4 applies to both providers (organisations that build or supply AI) and deployers (organisations that use AI). Almost every charity is a deployer. It applies regardless of risk level — high, limited or minimal. It is, in fact, the broadest single obligation in the whole regulation, because it reaches every staff member, contractor and volunteer who operates an AI system for you.

The dates that matter

Two dates, and the gap between them is where the confusion lives:

  • 2 February 2025 — Article 4 already applies. The obligation to ensure AI literacy has been in force for over a year.
  • 3 August 2026 — enforcement machinery arrives. The supervisory and penalty framework of the AI Act steps up from this date. National authorities gain their full enforcement footing.

In other words: the duty is live now; the systematic checking is arriving. The sensible reading is not "we have until August 2026" — it's "the obligation already exists, and we'd like to be able to show we took it seriously from early on."

Article 4 is not asking you to become an AI expert. It's asking you to make sure the people using AI in your name aren't using it blind.

"We're a small charity — surely this isn't aimed at us?"

There is no size exemption and no charity exemption. What triggers the duty is not your legal form or headcount — it's whether AI is operated on your behalf. Ask yourself honestly:

  • Does anyone on your team use a chatbot, an AI writing assistant, or AI features built into your CRM, email or design tools?
  • Does a volunteer answer queries with the help of an AI tool?
  • Does a supplier run an AI system for you — an outsourced helpdesk bot, an AI-powered donor or grant platform?

If yes to any of these, Article 4 is speaking to you. And beyond the regulation, there's a plainer reason to care: a person who doesn't understand the tool they're using can't use it safely. They can't spot when it's wrong, can't tell a service user what it does, and can't protect the people you exist to serve. AI literacy isn't a compliance box — it's a safeguarding basic.

What "AI literacy" means in practice

You don't need to teach your team how neural networks work. The European Commission's own guidance frames literacy around a handful of practical understandings. For a charity, a sufficient baseline looks like this — every person operating AI on your behalf should be able to answer:

  • What is this tool, roughly, and what does it do? (It generates text / images / summaries / translations / recommendations.)
  • Where can it go wrong? (It can be confidently incorrect; it can invent facts; it doesn't know our organisation's specifics unless we tell it.)
  • What must never go into it? (Service users' personal or sensitive data, unless we've cleared that the tool is safe and lawful for it.)
  • Who reviews its output, and when? (Nothing goes to a service user or the public without a human check.)
  • How does this connect to our duties? (Transparency, data protection, and the fact that a person — not the AI — is responsible.)

The Commission has been clear about what literacy is not: it does not require you to formally test or measure staff knowledge, and a single onboarding video is not enough on its own. What matters is that the measures are real, proportionate to your tools, and — crucially — documented.

A five-step plan you can start today

You don't need a training budget or an external provider to begin. You need one focused session.

Step 1 — List where AI is used in your organisation

One row per use: the tool, who uses it, and what for. Include AI features hidden inside other software. This is the same inventory you need for transparency and human-oversight work, so it does double duty. You can't teach people about tools you haven't mapped.

Step 2 — Group people by how they touch AI

A few distinct groups usually emerge: staff who use AI daily to draft content; volunteers who use a limited tool; managers who decide which AI to adopt; and anyone whose AI touches service users directly. Each group needs a different depth of literacy. "Sufficient" is contextual — match the depth to the role.

Step 3 — Give each group a short, plain briefing

This can be a 30-minute team session or a one-page guide — it does not have to be a course. Cover the five questions above, using your own tools as examples. Concrete beats generic every time: "here's our chatbot, here's what it should and shouldn't do" lands better than an abstract lecture on AI.

Step 4 — Write a one-page AI use guideline for staff

Put the essentials in writing: which AI tools are approved, what must never be entered into them, that a human reviews output before it reaches a service user or the public, and who to ask when unsure. This single page is both a literacy measure and a reference people can return to.

Step 5 — Keep a simple record of what you did

This is the step almost everyone skips — and the one that matters most if you're ever asked. The Commission says there's no need for certificates; a simple internal record is enough. Note the date, who attended or received the briefing, what was covered, and where the written guideline lives. A single row in a spreadsheet per session is plenty. Without a record, even good training is invisible.

The one-line test: if someone asked today, "show me what your organisation has done to make sure your people understand the AI they use," could you point to something real? If the honest answer is "not yet", steps 3–5 are your afternoon.

A minimal documentation record

Here's the kind of lightweight record the Commission's guidance envisages. It's not a form you file anywhere — it's your own internal evidence that you took reasonable measures. Keep it wherever your other governance records live.

AI Literacy — Internal Record

Date Who took part What was covered Format & materials
[e.g. 14 Jul 2026] [e.g. All frontline staff and 2 volunteers] [Our approved AI tools; what not to enter; human review before publishing; who to ask] [30-min team session + one-page AI use guideline v1, stored on SharePoint]
[date] [e.g. New starter — induction] [Same one-page guideline as part of onboarding] [Read + short chat with line manager]

Review whenever you adopt, change or drop an AI tool, and at least once a year.

How Vedomia can help

Vedomia is an Irish company focused on one thing: helping organisations make their processes and their use of AI visible, explainable and auditable. We work mainly with charities, nonprofits and publicly funded organisations.

AI literacy under Article 4 rests on a foundation you also need for the transparency obligations arriving in August 2026: knowing exactly where AI lives in your organisation. That's where we start.

  • Transparency Self-Audit (free). Around 20 questions across four pillars — Visibility, Sequence, Justification, Auditability. It helps you surface where AI is used and where your organisation is thin on understanding, review and evidence.
  • Transparency Gap Report. A structured read-out of your gaps, which to close first, and what to document — including your AI literacy measures — in language your board and funders understand.

To be clear about what we do and don't do: Vedomia supports readiness, helps you document your AI use, and identifies transparency gaps. We do not certify compliance, and nothing we provide guarantees legal conformity. This is not legal advice.

Article 4 has been law for over a year. The good news is that catching up costs an afternoon, not a budget — and the record you keep today is the evidence you'll be glad to have tomorrow.

This article is general information about the EU AI Act and does not constitute legal advice.

Prepared with the help of an AI assistant, reviewed by Sandra Fedakova.

Want to see where AI is used across your organisation — and where the gaps are?

Take the Free Transparency Self-Audit