The AI Act's Quietest Duty: What Article 4 'AI Literacy' Means for Everyone Running Course-Evaluation AI
Article 4 of the EU AI Act is the one requirement that reaches every quality office deploying an AI evaluation tool, not just high-risk deployers. It is cheap to satisfy and easy to forget. Here is what it actually asks of you in 2026 - and what the Digital Omnibus changed.
Koji Education Team
Product ยท August 1, 2026
The short answer
If your institution uses any AI to run, moderate, or summarise course evaluations, Article 4 of the EU AI Act obliges you to make sure the people operating that system have a sufficient level of AI literacy. This duty has applied since 2 February 2025, it applies regardless of whether the tool is classed as high-risk, and it reaches your staff and anyone operating the system on your behalf. As of 27 July 2026, the Digital Omnibus reform softened the wording from an outcome obligation ("ensure a sufficient level") to an effort obligation ("support the development" of AI literacy), with the Commission and Member States taking a larger role. There is no standalone fine for breaching Article 4 - but that is not the same as it being safe to ignore.
For a sector that has spent two years debating whether AI-moderated evaluation is even permissible, Article 4 is the obligation almost nobody in the quality-assurance office has actually read. This piece fixes that.
What Article 4 says, precisely
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in staged phases. Two of the earliest to bite were the prohibitions in Article 5 and the AI-literacy duty in Article 4, both of which became applicable on 2 February 2025, per the European Commission's regulatory framework pages.
Article 4 is short. In its original form it required providers and deployers of AI systems to take measures to ensure, to their best extent, "a sufficient level of AI literacy" of their staff and other persons dealing with the operation and use of AI systems on their behalf. Crucially, this duty is horizontal: it does not depend on the risk classification of the system. A limited-risk chatbot that conducts evaluation interviews and a minimal-risk sentiment tagger both fall inside it. "AI literacy" itself is defined in Article 3(56) as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment and to be aware of the opportunities, risks and possible harms of AI.
For a university or college, the "deployer" is the institution. The "persons dealing with the operation" are the module leaders reading AI-generated theme summaries, the quality officers configuring the instrument, and the administrators exporting the reports. Article 4 says those people need to understand, proportionately to their role, what the system does, where it can go wrong, and how to interpret its output.
What the Digital Omnibus changed in July 2026
On 27 July 2026 the Digital Omnibus reform (published in the Official Journal as Regulation (EU) 2026/1744 and confirmed by the Commission's own announcement that the AI Omnibus entered into force) recalibrated several AI Act obligations. For Article 4 the change is one of emphasis: the duty shifted from ensuring a sufficient level of literacy toward supporting the development of that literacy, with the Commission and Member States taking a stronger promotional role.
Read carefully, this is a move from an outcome obligation to an effort obligation. You are no longer expected to guarantee that every operator has reached a defined competence bar; you are expected to take reasonable, documented measures to build it. That lowers the documentary and organisational burden - but the duty remains binding on every deployer, and national supervision of the AI Act framework begins on 3 August 2026. The softening reduces exposure; it does not remove the obligation.
"But there is no fine, so why bother?"
This is the strongest objection, and it deserves a straight answer. Article 4 has never carried its own penalty. The AI Act's administrative fines in Article 99 attach to prohibited practices and to high-risk and transparency breaches - not to the literacy duty. So an institution could, in narrow legal terms, breach Article 4 without a direct sanction.
Three reasons that framing is a trap:
- Literacy is the predicate for lawful high-risk use. If an evaluation deployment is ever treated as high-risk - for instance because AI output materially informs personnel decisions about teaching staff - the deployer duties in Article 26 (human oversight, monitoring, acting on instructions for use) become effectively impossible to discharge with operators who do not understand the system. Article 4 is the foundation those duties stand on.
- It is your cheapest credibility asset with sceptical faculty. The audience most hostile to AI in evaluation is academics who fear an opaque model judging their teaching. A documented literacy programme - what the model does, what it cannot do, how to challenge a summary - is precisely the transparency that earns their consent. We argue this in our piece on AI moderation disclosure and the AI Act.
- Regulators read effort obligations through documentation. After the Omnibus, compliance is judged on whether you took reasonable measures. An institution that can show a short, role-appropriate training record is compliant; one that cannot is exposed the moment a complaint, a data-protection review, or an accreditation audit asks the question.
The honest counter-counterargument: literacy programmes can become theatre - a slide deck nobody reads, an attestation clicked through. That risk is real. The fix is to make literacy specific to the tool and the decision, not generic "what is AI" content. An operator of an evaluation system needs to know how its thematic analysis can hallucinate, why a sentiment score is not an insight, and when to distrust a confident summary - not the history of neural networks.
Where Koji fits
Koji for Education is built so that the literacy bar is low to clear, because the system explains itself. Its AI moderation is standardised and bias-aware rather than a black box, so operators can be trained on a consistent, documented behaviour rather than the idiosyncrasies of a human moderator. Every thematic summary is traceable back to the underlying quotes, which means an operator can verify a claim rather than trust it - the practical core of provenance and traceability in AI-summarised feedback. And because Koji is explicit about what it does and does not claim - it mitigates and surfaces bias, it does not eliminate it - the training you build around it can be honest.
Concretely, an institution can meet its Article 4 effort obligation for the evaluation tool with a short, role-scoped briefing: what the six question types collect, how open-text is analysed, where the model can err, and how to challenge or override an output. That is a proportionate, documentable measure - exactly what the softened Article 4 now asks for. The same AI interview engine powers general user and customer research on the main Koji platform, so an institution's research office and its quality office can share one literacy baseline rather than maintaining two.
Article 4 will never make headlines the way high-risk classification does. But it is the one AI Act duty that touches every quality office running evaluation AI today. Treat it as a ten-minute training obligation, not a legal footnote, and it becomes the cheapest trust you will buy all year.
Frequently asked questions
Does Article 4 apply to my university if our AI evaluation tool is not high-risk? Yes. Article 4 is horizontal - it applies to providers and deployers of AI systems regardless of the system's risk classification. A limited-risk or minimal-risk evaluation tool is still covered.
Since when has the AI-literacy duty applied? Article 4 became applicable on 2 February 2025, the same date as the AI Act's prohibited-practices rules. It has been in force across the EU since then.
What did the Digital Omnibus change on 27 July 2026? It softened Article 4 from an obligation to ensure a sufficient level of AI literacy into an obligation to support the development of that literacy, with the Commission and Member States taking a stronger promotional role. It is now an effort obligation rather than an outcome one.
Is there a fine for breaching Article 4? No standalone administrative fine attaches to Article 4 specifically. However, literacy underpins the deployer duties that do carry penalties in higher-risk scenarios, and national supervision of the framework begins on 3 August 2026.
What counts as compliance for a course-evaluation tool? A proportionate, documented measure - typically a short, role-appropriate briefing for the staff who operate or interpret the tool, covering what it does, its limits, and how to challenge its output.
Does using an explainable tool reduce the literacy burden? Practically, yes. A system whose summaries are traceable to source quotes and whose moderation is standardised is far easier to train operators on than an opaque one, making the effort obligation cheaper to meet.