Direct answer
Does the AI Act also apply to small organisations?
This falls under Article 4: AI literacy. That obligation applies today. There is one exception you have to assess yourself.
This could go the other way
- The provision does not require a specific individual level to be guaranteed.
First step: Take role- and context-specific AI literacy measures.
You describe: You are an SME, start-up or small institution and wonder whether this regulation applies to you or only to large technology companies. Likely role: deployer (you use the system).
This applies now
- Article 4: AI literacyApplicable
- Article 50: transparencyApplicable
Coming up
- Annex III: high-risk AIfrom 2 December 2027
Then you are the deployer. Your vendor builds the system in conformity, you use it in conformity: according to the instructions for use, with human oversight that can genuinely intervene, and with the documents you should receive from them. Request the technical documentation and the declaration of conformity now; without them you cannot demonstrate your own duties later, and that is a contract question to raise before signing.
Your first actions
- Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
- Implement the applicable disclosure, marking or label. First determine which paragraph of Article 50 applies, then implement the specific transparency measure.
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
Record this
- AI literacy measures record
- Test report per touchpoint: disclosure visible, timely and accessible
- Article 49(2) registration record for the system assessed as not high-risk
biometrics and identification
Facial recognition at access control: the guard behind the camera counts too
An organisation secures the entrances to its buildings with facial recognition and uses that biometric access control to register visitors as well. When the system returns no match, a security officer reviews the camera images and decides personally whether someone may enter. The question is whose measures have to reach that officer: those of the supplier of the model, those of the department that deploys the system, or both.
Provenance: Article 4(1) provides that providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. In doing so they must take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, and consider the persons or groups of persons on whom the AI systems are to be used. The same provision states that this obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
We read the phrase about the persons on whom the system is used as the centre of gravity for biometrics: whoever stands in front of the camera is subject to the outcome and has little to set against it. That argues for equipping the officer who decides for himself when no match comes back more substantively than the colleague who merely switches the system on and off. The article itself names no sufficient level and expressly states that you need not guarantee one, so where the floor lies for each role stays open. In our assessment a record kept per role, stating the choice made and the reason for it, is easier to defend than one organisation-wide session backed only by an attendance list.
Editorial example. The rule above is in the Regulation. The situation was written by us to show how that rule plays out in this sector, and is not taken from a worked case in official guidance.
Artikel 4, lid 1
law enforcement
Police using AI in investigations: context sets how deep the training goes
A police force uses AI to search large volumes of investigation files and surface connections a detective would otherwise miss. The outputs feed into the choice of which suspect is pursued further and end up in documents that enter the criminal process. The question is whether one and the same basic instruction is enough for the analyst operating the model and for the detective who acts on its output.
Provenance: Article 4(1) requires providers and deployers of AI systems to take measures supporting the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The provision prescribes that they take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. It also states that this obligation does not require any specific level of AI literacy of any individual to be guaranteed.
Article 4 requires you to weigh the context of use and the people the system is applied to, and in law enforcement both factors run high on our reading. Whether a general introduction to what AI can do is then enough for someone carrying an output into a file that affects a person's position as a suspect, we doubt, but the provision expressly names no level you must guarantee, so that floor is yours to justify. We would record for each role what someone must be able to recognise, for instance that a discovered connection is not yet evidence, and revisit that choice periodically.
Editorial example. The rule above is in the Regulation. The situation was written by us to show how that rule plays out in this sector, and is not taken from a worked case in official guidance.
Artikel 4, lid 1
media and content
Newsroom with generative AI: do freelancers count within your measures?
A newsroom uses generative AI to prepare summaries, headlines and imagery, after which an editor finishes the piece and the desk decides to publish. Part of that work sits with freelancers, and an outside agency produces marketing content with the same tools. The question is whether your AI literacy measures must reach those freelancers and that agency, or only the people on the payroll.
Provenance: Article 4(1) is addressed to providers and deployers of AI systems and requires them to take measures supporting the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. The provision requires them to take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. It does not require any specific level of AI literacy of any individual to be guaranteed.
Alongside staff, the text expressly names other persons dealing with the operation and use of AI systems on your behalf, and we read that as a functional boundary rather than a contractual one. On that reading a freelance editor using your tool inside your workflow and on your instruction sits within your measures, employment contract or not. The outside agency is a harder case: if it works in your environment and on your instruction, the argument that it acts on your behalf holds up, but if it runs its own tools on its own account it is a deployer in its own right, and Article 4 does not say your measures must cover that work. In practice, in our assessment, that means recording in your agreements who works in which role and what instruction you give, rather than trusting the other side to arrange it.
Editorial example. The rule above is in the Regulation. The situation was written by us to show how that rule plays out in this sector, and is not taken from a worked case in official guidance.
Artikel 4, lid 1
government and public services
An induction call with the customer at the moment of go-live
Asimov AI is a micro organisation of at most fifteen people that supplies AI services for legislative work to government institutions and companies. With every new contract it holds one or more induction calls with the team leads and officials who will use the platform, explaining how the platform and the underlying models work and how hallucinations arise in this domain and can be mitigated.
Provenance: This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.
This practice puts literacy where the risk arises: with the people who will operate the system, at the moment they start. For a small provider that is also the only workable moment, because there is no training department to redo it later. Anyone adopting it should record who attended and what was explained, because otherwise the effort survives only in the participants memory a year on.
Levend repository van AI-geletterdheidspraktijken, ingediende praktijk van de betrokken organisatie
No mandatory course format, no certificate, no exam and no AI officer
The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.
Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)
Article 4 reaches beyond your own staff, and the national supervisor enforces it
The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.
Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)
AI agents must disclose both their AI nature and on whose behalf they act
Point (31) of the guidelines of 20 July 2026 states that AI agents are covered by Article 50(1) if they are capable of interacting with the persons instructing them or with other natural persons in the execution of their tasks, citing as examples making bookings, managing correspondence, negotiating or concluding contracts and executing purchases. That same point requires AI agents to be designed and developed so that they disclose both their artificial nature and the person on whose behalf they are acting, given the need for transparency of the origin and of the delegation of authority and accountability for the consequences of their actions. This also applies in complex multi-agent architectures in which other agents interact directly with natural persons. Where the provider cannot reliably determine before placing on the market or putting into service whether the agent will directly interact with a natural person, the agent should be designed at the architecture level and instructed to disclose itself in every situation where it is reasonably likely to interact with a natural person, including where that person represents a legal entity. Agents should also disclose themselves to the persons instructing them at key steps such as authorisation, reporting and validation, including where the agent receives, processes or relies upon outputs generated by other AI systems rather than by a natural person, and at every new interaction. Point (63) adds that Article 50(2) may apply to AI agents where the agent takes an action whose output is AI-generated or manipulated content perceptible by natural persons, while intermediate processing steps such as reasoning and chain of thought and non-perceptible actions such as a web request or browser action fall outside that scope.
Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)
Artistic or satirical work is not exempt but attenuated, and the informative character always prevails
Point (119) of the guidelines of 20 July 2026 describes an attenuated transparency obligation for deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works or programmes, where the obligation is limited to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work. Point (120) describes the categories: artistic works are created for the purpose of art, including music, cinematographic works and visual arts; creative works involve creative choices, while works mainly motivated by functional or technical considerations cannot be regarded as creative; satirical works are intended to criticise society, politics, business or public figures through humoristic techniques; fictional works involve persons, objects, places, entities or events in an imaginary but verisimilitude setting; analogous works share core traits with those categories without fitting neatly into one. Point (122) states that it must be evident to the natural persons exposed to it that the content falls within one of those categories, that the categories must therefore be interpreted strictly given the lighter disclosure regime and the interests of freedom of expression and freedom of the arts and sciences, and that content whose nature is potentially unclear or ambiguous to the audience falls outside this lighter regime. Relevant factors, per that same point, are whether the content displays formats or styles characteristic of the category, the context in which it is presented, and audience expectations. That same point excludes content whose nature is exclusively informative or commercial and recognisable as such, citing news reporting, notes that advertisements or documentaries may be regarded as evidently creative or fictional in certain specific situations but not in others because the assessment is case-specific, and states that where the deep fake combines multiple characters, for example informative and creative, the informative character should always prevail and the standard labelling requirements apply. Point (123) stresses that these deep fakes are not excluded from the obligation: the deployer must still disclose the AI origin or manipulation, but may do so in an appropriate manner, and must in any case comply with Article 50(5). Point (124) states that reliance on the attenuated obligation cannot justify failing to respect the fundamental rights of individuals or the rights of rightsholders under Union intellectual property or data protection law. As examples within the categories the document cites movies featuring AI de-aged existing actors or digital replicas of deceased actors, AI-generated music in the style of existing artists, and an AI-manipulated image of an existing politician in a scene clearly meant as humorous criticism. Outside the categories the document places among others an AI-manipulated video in the style of a teleshopping channel, AI-generated images of celebrities implying involvement in activities that never happened, and an AI-manipulated video featuring a realistic synthetic influencer focused solely on displaying a sponsored product's functionalities.
Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationExecution
Make AI literacy demonstrable per role
You demonstrate the Article 4 duty to take measures with a file per role: who received which training, guidance and assessment. LearnWize records that per employee, audit-ready.
See LearnWize