Zum Inhalt springen
Marius Rieg.

AI

AI Literacy Duty Without a Fine: What Article 4 Actually Requires – and Why That's No Free Pass

By Marius Rieg · · 3 min read

Summary: The Digital Omnibus adjusted Article 4 of the EU AI Act as of July 27, 2026 – companies must train staff and management in AI fundamentals and risks, with the Bundesnetzagentur monitoring compliance since August 2nd. Notably, the regulation sets no direct sanction for simply lacking that training. A perspective from running an AI training program myself on why that gap is no reason to relax.

Since July 27, 2026, Article 4 of the EU AI Act applies in a tightened version, part of the so-called Digital Omnibus. The obligation itself isn't new – it's been in the law in essence since February 2025 – but enforcement is: since August 2nd, Germany's Bundesnetzagentur monitors compliance. Companies are supposed to train their staff and management in the fundamentals of artificial intelligence, particularly how it works and its risks. What's interesting is a detail that rarely makes headlines: for simply lacking such training, the current version sets no direct fine.

Why the missing penalty is no free pass

Reading that as toothless misses the actual construction. The training isn't an isolated requirement – it's the precondition for being able to meet other, genuinely sanctioned obligations under the AI Act at all, where serious violations carry fines of up to 35 million euros or 7 percent of global annual revenue. A company that has to prove it uses its AI systems responsibly but can't show a trained workforce is left, in a real dispute, without the foundation that responsibility is supposed to rest on. The missing direct penalty shifts the risk; it doesn't remove it.

The real gap sits elsewhere

From the practice of running my own AI training program – I founded Luftschloss Academy for exactly this need – I see a different problem than the fine. A rule that requires "training in AI fundamentals" without specifying quality or format can be satisfied just as well by a one-hour mandatory video as by a multi-day workshop built on real use cases. For the bare compliance requirement, either might suffice. For actual competence – the ability to recognize, in your own daily work, when an AI system is reliable and when it isn't – the difference is enormous. That's the same distinction between substance and merely satisfying a formal requirement I already drew regarding Article 50, the AI labeling obligation from the same Digital Omnibus. Article 4 asks the same question on a different level: not whether an image is labeled, but whether a workforce actually understands what it's using.

What an afternoon of mandatory training doesn't deliver

In our own workshops, the same point keeps showing up: the gap between "I know AI hallucinations exist" and "I can spot, in the concrete output of my own work, where a hallucination is likely" doesn't come from listening – it comes from hands-on practice on real tasks from your own daily work. Theory alone doesn't get you there. A mandatory training that ignores that distinction may satisfy the letter of the law and still miss the actual goal: a workforce that can independently judge AI output instead of adopting it company-wide without question.

What this means for companies that take it seriously

For companies that don't want to treat Article 4 as a formality, a clear consequence follows: training should start from the real tools and real tasks of your own teams, not a generic introduction that looks the same for every industry. That costs more time than a mandatory video – but it pays off twice over, because that same competence later becomes exactly the foundation a company can point to in a real dispute as proof it managed its AI risks responsibly.

Conclusion

Article 4 of the AI Act requires training with no direct fine for lacking it – that makes the obligation easier to ignore, not less important. The actual question was never whether a compliance box gets checked, but whether a workforce can ultimately judge when to trust an AI system. That competence can't be forced by law, but it can very much be secured by the standard you hold your own training to.