Article 4 of the EU AI Act is three sentences long and creates one of the harder compliance questions in the instrument. Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf, having regard to their technical knowledge, experience, education and training, and the context of use.
It does not say what sufficient means. It does not prescribe a curriculum, a duration or an assessment. And it applies now.
Why generic training does not answer it
The obligation is explicitly relative to role and context. A clinician using an AI diagnostic aid needs to understand its failure modes on their patient population and the circumstances in which to override it. A procurement officer needs to understand what to ask a vendor. A developer needs something different again.
An organisation that rolls out one module to everyone has evidence that it delivered training. It does not have evidence that any particular person's level of understanding is sufficient for what they actually do, which is what the provision asks about. Blueprints that map literacy requirements to specific roles and their specific systems are answering the question as written.
The dependency between the three parts
Inventory, literacy and accountability are usually run by different functions and they fail as a unit. You cannot scope literacy without knowing which systems are in use and by whom, which is the inventory. You cannot assign accountability for a system nobody has registered. And an accountable owner who does not understand the system they own is accountable in name.
Integrating them is less a methodology than a recognition that separating them produces three programmes each waiting on the other two.
Watching the Dutch reading
Member states are standing up supervisory arrangements at different speeds and with different institutional homes, and early practice will shape how provisions like Article 4 are understood well beyond the jurisdiction that establishes it. The Netherlands has been comparatively quick, and its data-protection authority has taken an active role in AI supervision.
For multinational organisations, the practical consequence is that the first regulator to publish a view on what literacy means becomes the de facto standard for everyone, well before any formal harmonisation. Watching which regulator gets there first is a reasonable use of a compliance team's attention.