← Back to blog

What Does the EU AI Act's AI Literacy Duty Mean for a Small Firm?

If your firm uses AI tools at work, Article 4 of the EU AI Act applies to you. Since the digital omnibus took effect on 27 July 2026, it asks you to take measures that support the AI literacy of your staff and anyone else using AI on your behalf, matched to what they know and how they use it. It no longer asks you to reach a "sufficient" level, and it sets no particular level for any individual. For a small firm, a short policy, a session people actually attend, and a record of what was done will cover it.

The duty has applied since 2 February 2025. What changed this summer is the wording, and a lot of advice written in 2025 still runs the old test. We covered the wider Act, the risk bands and the dates in What the EU AI Act Means for a Small Irish Firm. This post is about the one obligation that reaches almost every firm using AI.

Does this apply to us if we only use ChatGPT or Copilot?

Yes. The Act puts the literacy duty on providers, who build AI systems, and on deployers, who use them under their own authority. A firm whose staff use ChatGPT, Copilot, or an AI feature inside its practice software is a deployer.

The Commission's own AI literacy Q&A deals with this case directly. Staff using a general-purpose chatbot should understand its specific risks, and the example it gives is hallucination: a fluent, confident answer that happens to be wrong.

The duty also reaches past your payroll. Article 4 covers "other persons dealing with the operation and use of AI systems" on your behalf. The Commission reads that as anyone broadly under your organisational remit, and names contractors and service providers as examples. If a freelance bookkeeper or an outsourced paraplanner uses AI on your files, they are in scope too.

What counts as "sufficient" literacy?

Nothing, any more. The original Article 4 required firms to ensure, to their best extent, a sufficient level of AI literacy. That phrase was hard to pin down, and it is gone.

The digital omnibus is Regulation (EU) 2026/1744. It entered into force on 27 July 2026, and it rewrote Article 4. You can read the amended text on the Commission's AI Act Service Desk. Paragraph 1 now says providers and deployers shall take measures to support the development of AI literacy. They take into account people's technical knowledge, experience, education and training, the context the systems are used in, and the people the systems are used on. It adds that the duty sets no specific level of literacy that any individual must reach.

In practice, the question has changed. It used to be "are your people literate enough?", which nobody could answer with confidence. Now it's "what did you do, and was it reasonable for how you use AI?" A small firm can answer that with a page of notes.

The Commission's guidance suggests three things to think about:

  • a general understanding of AI across the firm: what it is, how it works, and which tools you use
  • your role, provider or deployer
  • the risk of the systems you use, and what staff need to know when working with them

What would a proportionate programme look like for a 20-person firm?

Picture a 20-person advisory or accountancy practice using a business AI assistant for drafting, a meeting-notes tool, and an AI feature in its practice management software. Here is how we would set it up.

Start with who needs what, because the duty is tied to how people actually use the tools.

  • Everyone who touches an AI tool needs the basics. Which tools are approved. What data may go into them and what may not. How these tools fail, with real examples from your own work. Who checks any output before it reaches a client. An hour covers it.
  • The heavy users, the people drafting client letters or summarising files every day, need more depth on the tools they use. That means prompts that work, the failure patterns they'll see, and when to stop trusting a summary and read the source.
  • Whoever owns the tools, often an operations lead or a practice manager, needs to understand the settings. That covers data retention, whether the vendor trains on your data, and who has access. They also keep the record.
  • The partners or directors need enough to make decisions about which tools to approve, which uses to allow, and what to do when something goes wrong. That is usually a shorter conversation with sharper questions.

Then write a short policy. One or two pages, in plain language: the approved tools, the data rules, the review rule for anything client-facing, and who to ask. If you've read our post on putting client data into ChatGPT, the data rules are the tiers set out there.

Then keep a record. The Commission says plainly that an internal record of training and other initiatives is enough. A simple log does it: date, who attended, what was covered, and which version of the policy they were shown. Add new joiners as they arrive, and contractors when they start using AI on your files.

Finally, refresh it when something changes: a new tool, a new use, or an incident. Tie the refresh to tool approvals and it happens on its own.

That is a few days of effort in the first year for a firm this size, and a few hours a quarter after that.

Does it need a certificate or a course?

No. The Commission's Q&A says there is no need for a certificate. Nor does Article 4 require any particular course, provider or format.

The Commission keeps a living repository of more than 40 literacy initiatives from companies and public bodies, which is useful for ideas. It says itself that copying one of them gives no presumption of compliance. The amended Article 4 also commits the Commission to publishing practical examples of how to comply.

An off-the-shelf online module can be part of the answer. On its own, it rarely covers your tools, your data rules and your review step, and those are what your staff most need to know.

What changed with the omnibus?

The Commission proposed the digital omnibus on AI on 19 November 2025. The Council and Parliament agreed it in May 2026, and it entered into force on 27 July 2026. Beyond the softer wording above, it gave the Commission and the Member States their own duty to support firms' efforts, with SMEs named.

What did not change is that the obligation sits with you. The proposal was reported as shifting literacy onto governments. The final text gives governments a supporting role and keeps the duty on providers and deployers, and the Commission's Q&A, updated on 27 July 2026, says so. Article 4 has applied since 2 February 2025, and according to the Commission, national market surveillance authorities supervise and enforce the Act's rules from 2 August 2026.

Who enforces it in Ireland, and what are the penalties?

Ireland's Regulation of Artificial Intelligence Act 2026 was signed into law on 21 July 2026. It gives effect to the EU Act here and sets up the AI Office of Ireland as the central coordinating body and the single point of contact with Brussels. Supervision is spread across existing regulators, among them the Central Bank, the Data Protection Commission and the Competition and Consumer Protection Commission, each in its own field.

On penalties, here is what we can say from the texts. The EU Act sets fixed fine ceilings for the prohibited practices and for a named list of other obligations in Article 99, and Article 4 is not on that list. The Irish Act ties its fines and compliance notices to those same listed provisions, and as we read it, it makes no specific provision for Article 4. The Commission's Q&A says national authorities could impose penalties for infringing Article 4, proportionate to the nature and seriousness of the breach. As at 3 October 2026, we have not seen an Irish authority say how it will approach Article 4, or name which body leads on it for firms like yours.

Our view is that literacy is unlikely to be enforced on its own. It is more likely to come up when something else has gone wrong, when a client complains about an AI-drafted letter or personal data ends up in the wrong tool. A short record of what you did is a good thing to have on file at that point.

Where does this sit with the GDPR training we already do?

Next to it, and ideally in the same session. Most of what staff need to know about AI is a data protection question: what may go into the tool, where it is processed, and whether the vendor keeps it. The AI-specific parts are how these tools get things wrong, why a confident answer needs checking, and who reviews an output before a client sees it. Add those to the session you already run and log both together. We've written separately on what GDPR asks of a firm using AI.

More than a compliance box

The firms that do this well end up with more than a log. Staff who know what the tools are good at use them more, on better tasks, and spend less time correcting confident nonsense. The firm also finds out which tools are actually in use, and that inventory is the starting point for the rest of the AI Act.

We describe obligations and practical steps here. This is not legal advice, and a firm with an unusual use of AI should take its own.

Our method sets out how we build AI into firms that have to be able to defend it. A dploy.ai AI Operations Assessment covers your tool inventory, data rules and review steps, and maps where AI pays back for your firm, for a fixed fee agreed before we start. Or book a short call to talk it through first.

We draft our posts with help from AI tools. A person at dploy.ai reviews, edits and checks every one before it goes live.

Want to know where AI fits in your business?

We run a structured assessment that identifies your highest-value AI opportunities. Fixed price, agreed before we start, delivered within ten working days.

Book a free 15-minute call