In one sentence
While everyone is talking about postponed high-risk deadlines, one duty under the AI Regulation has applied since 2 February 2025 — and it affects not only providers, but every company and every law firm that uses AI.
The overlooked duty
The debate about the EU AI Act revolves around dates: Art. 50 has applied since 2 August 2026, and the high-risk duties under Annex III have been postponed to 2 December 2027 by the “Digital Omnibus”. Art. 4 rarely features in it — yet it applied before either of them.
Its content is brief: providers and deployers are to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and among those dealing with AI on their behalf. The decisive word is “deployer”: it is enough to use an AI system professionally. Anyone in a firm who uses AI for research, drafts or document analysis is an addressee — without having developed anything themselves.
What “AI literacy” means in law
Art. 3 Nr. 56 defines it as the skills, knowledge and understanding that make it possible to deploy AI knowledgeably and to become aware of the opportunities, risks and possible harm. What is striking is what is not there: no certification requirement, no course length, no examination, no proof. What is required is a result, not a format.
Equally important is the standard: the Regulation looks to the knowledge, experience and training of the persons concerned and to the context of use. AI literacy is thus dependent on role. The secretariat that uses AI for appointments and draft texts needs a different understanding from the associate who transfers research results into a pleading — and a different one again from the partner who decides which tools may see client data. A one-size-fits-all training course meets the standard formally and misses it at both ends.
What a robust minimum implementation looks like
Providers are outdoing one another with courses and certificates. Less than that is needed, provided it matches actual use. As a rule three building blocks will carry the weight:
- A short, role-related briefing — what the tool does, where it typically goes wrong, which data may go into it.
- Documented participation — date, participants, content in keywords. Not a certificate, but a record.
- A written rule of use — which tools are approved, which outputs are to be double-checked, how that is documented.
The third point builds the bridge to professional conduct law: an AI output that has found its way into a pleading unchecked is a problem of due care even without the AI Act — see the KG Berlin case.
How enforceable is this?
Honesty belongs here rather than urgency. Art. 4 is not listed as a separate offence in the catalogue of fines in Art. 99; whether a breach can be sanctioned directly is therefore assessed differently, and there is as yet no settled supervisory practice. National enforcement, too, is in motion — which authority will be competent in Germany is something you should look up at the time of your own review.
The value of the documentation lies elsewhere in any event: not in fine proceedings, but in a liability case — when a client attributes a mistake to AI and the question is whether the firm put its people in a position to assess the tool. Anyone who can then produce a briefing, a rule of use and a checking routine stands differently from someone who points to general experience. Whether that suffices in the individual case is to be assessed under professional conduct law and clarified with a lawyer.
What this text does not do
This text explains a duty, it does not replace implementation. How deep the briefing has to go depends on your tools and your mandates. What a tool does and where its limits lie has to be disclosed by the provider — otherwise nobody can be briefed.
→ AI transparency · System limits · Compliance for firms · Labelling duty under Art. 50




