Article 4 of the EU AI Act is the most underestimated provision in the entire regulation. It requires providers and deployers to guarantee “a sufficient level of AI literacy” for the people operating these systems. Organisations have read it as a training requirement and passed it to human resources. That reading is wrong, and for senior leadership it is dangerous: the literacy of those who decide is not a course. It is a requirement of governing capacity.
What the provision actually says
The obligation has applied since February 2025, among the first provisions of the regulation to take effect (European Commission). A note for UK readers before anything else: the duty binds any organisation within the regulation’s reach — and UK organisations serving the European market fall within it (EU AI Act, Article 2). Domestically the logic arrives by another route: the Institute of Directors’ boardroom guidance presses directors to build AI competence as a matter of good governance, statute or no statute (IoD, 2025).
The provision prescribes no number of hours and no standard syllabus: it demands a level of understanding sufficient for the context, the role and the risks. It is a provision about outcomes, not procedure.
Precisely for this reason, wholesale delegation to HR is a design error. The level “sufficient” for someone approving an AI strategy is not the level of someone drafting emails with a conversational assistant. The heavier the decision, the higher the understanding required. At the top of the decision pyramid sits the board of directors — which is why the board’s accountability for AI is the context in which this duty must be read.
The paradox of adoption without understanding
The numbers of the gap are documented. Stanford University’s AI Index records organisational AI adoption at 88% among the entities surveyed (Stanford HAI, 2026). In the same period, the Institute of Directors’ survey of British boards finds a quarter of organisations without any AI policy or governance structure at all (IoD, 2025).
Adoption, by itself, does not produce understanding. It produces familiarity — which is a different thing, and often the more insidious one: those who use a tool every day stop asking how it works and where it fails.
Familiarity with AI grows faster than competence in AI. The gap between the two is where the worst decisions are made.
What decision-makers need to know
Boardroom literacy does not require knowing how to write code. It requires knowing how to interrogate. Four capabilities define it.
Understanding what the system does and does not do. Every AI system has a domain of validity: inside it performs, outside it improvises. Decision-makers must know where that line runs, because that is where the limits of algorithmic delegation are settled.
Recognising the typical error. Language models produce plausible answers, not necessarily true ones. The error does not present itself as an error: it presents itself as a well-written sentence. A literate decision-maker treats plausibility as a signal to verify, not as proof.
Reading the chain of responsibility. Who trained the system, who supplies it, who configured it, who uses it: each link carries different obligations. Confusing the roles means discovering late that duties assumed to be the vendor’s were yours.
Asking for evidence, not demonstrations. Demonstrations show the best case. Senior competence is measured by the ability to demand the worst: error rates, edge cases, behaviour outside the training distribution.
What literacy is not
It is worth clearing away the most common misunderstandings, because each one produces a useless compliance exercise.
It is not tool training. Knowing how to use a conversational assistant does not mean understanding when it fails, why it fails and what to do when it fails. Operational fluency grows on its own with use; critical capacity does not.
It is not general technology culture. Seminars on “understanding artificial intelligence”, with the history of the discipline and the prospects ahead, produce sparkling conversation and no governing capacity. Article 4 demands competence relative to the context of use: your organisation, your systems, your decisions.
It is not a one-off project. Systems change, uses spread, people rotate. A literacy exercise completed in 2025 and never refreshed describes tools that no longer exist — and its obsolescence is documented by the very training records that were meant to prove it.
How a serious programme is built
The architecture that works distinguishes three levels, with different objectives and different verification.
The board and senior leadership. Objective: capacity to interrogate and deliberate. Format: private sessions on the organisation’s real cases — the decisions AI already enters, the typical failures of the systems in use, the regulatory requirements read from the signatory’s point of view. Verification: can the board ask the right questions of the next investment proposal? The lecture-hall format always fails here: small numbers, confidentiality and real cases are required.
Senior executives. Objective: capacity to translate. Executives and heads of function must convert policy into daily choices: when human review is mandatory, what to document, when to stop and escalate. It is the level where literacy meets the boundary of algorithmic delegation — because they are the ones defending it, every day.
The operating population. Objective: informed use. Here scalable formats work, provided they are anchored to real use cases and closed by a test that can be failed.
The progression is not bureaucracy: it reflects the principle of the provision. The “sufficient” level rises with the weight of the decisions — so the leadership programme cannot be the abridged version of the operational one. If anything, the reverse.
How, then, to tell whether the programme has worked? Not with satisfaction questionnaires. Three observable signals: the questions asked in the boardroom about AI proposals change in quality — from “what does it cost” to “how does it fail”; requests to vendors include evidence of worst-case behaviour, not just demonstrations; and at least one decision in the year is altered or stopped for reasons the programme made visible. A literacy exercise that changes no decision was well-organised entertainment.
From obligation to advantage
There is a poor way and a rich way to satisfy Article 4. The poor way: a recorded course, a certificate, a line in the sustainability report. It survives an audit until someone asks a real question.
The rich way: treating literacy as decision-making infrastructure. A leadership team that understands AI negotiates better with vendors, sizes investments better, spots doomed projects sooner. Training stops being a compliance cost and becomes what we elsewhere call decision capital: the organisation’s capacity to choose well under uncertainty.
This is why serious programmes for boards and senior executives — such as our institute’s private masterclasses — do not teach people to use tools. They teach people to govern them: scenarios, failure cases, decision simulations, regulatory requirements read from the signatory’s point of view.
What this means for senior leadership
Three moves turn the obligation into an investment. First: distinguish the levels — operational literacy can be delegated; directional literacy cannot. Second: insist on verification — if no one can fail the programme, the programme certifies nothing. Third: make competence a condition of advancement for the roles that decide, as financial competence already is.
The objection of those with full diaries remains: time. But the account must be settled in full. The hours a leadership team does not invest in understanding will be paid back in longer vendor meetings, projects approved twice, incidents explained after the fact. Boardroom literacy does not compete with decision time: it returns it, with interest.
Article 4 sets a legal minimum. But the real stake is not compliance: it is who, in the room where decisions are made, understands enough not to be decided for.