The European Commission keeps a public repository of AI literacy practices. Real programmes from real organisations, published so you can copy what works. There are forty-odd entries, filterable by sector.
Filter it for human health and social work activities, and the page comes back empty. Not one pharmaceutical company, not one medical device manufacturer. Europe's most training-documented industry has published nothing.
Across the EU, 30% of workers now use AI in their jobs (JRC, AIM-WORK survey, 2025). Ask how many have been trained for it and the picture thins. In the eleven Member States covered by Cedefop's AI skills survey, only 15% did any education or training to build their AI skills in the previous year. Two surveys, two populations, so the pairing gives you a roadmap and nothing more precise than that. The direction is uncomfortable enough.
You have probably already bought AI tools. Something in your QMS can triage a deviation, suggest a root cause, draft a first-pass SOP in half a minute, and classify a complaint and route it to the right person. The software arrived on schedule. The understanding didn't come with it.
That gap has a name, and regulators use it: AI literacy.
So what does the regulation actually want from you? What follows covers which tools in your QMS are even in scope, what Article 4 asks for after the July 2026 rewrite, and how to train five very different groups of people without putting 400 of them through the same slide deck.
Key takeaways
What is AI literacy?
The EU AI Act supplies a definition of AI literacy, and it is more useful than most legal text. Article 3(56) describes AI literacy as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, and to gain awareness of the opportunities, the risks, and the possible harm those systems can cause (Regulation (EU) 2024/1689, 2024).
You will notice the definition says nothing about coding, model architecture, or transformer mathematics. It asks for informed judgment about a tool you did not build.
Every QC analyst already recognises the shape of this. You don't need to build an HPLC to know when a chromatogram looks wrong. You need to know what the instrument does, which conditions produce inaccuracies, and what a suspicious peak means for the result you're about to sign.
That is interpretation, and it is exactly what Article 4 is asking of your people.
Technical AI expertise belongs with your data scientists and your vendors. Literacy has to reach everyone whose name goes on a decision the system influenced, and that population is a hundred times larger.
According to the AI Office's Q&A on AI literacy, a degree or professional experience in AI development usually counts, though not automatically. Those staff still need to know the specific systems your organisation runs, and the legal and ethical dimensions of using them. A brilliant model builder who has never read Article 26 is not the person you want signing off on human oversight.
Recommended learning:
Is the tool in your QMS even an AI system?
Before you train anybody, check whether the tool is an AI system at all. Article 3(1) does the scope-setting, and the Commission's guidelines on that definition help, though they are non-binding and deliberately not a list you can tick.
Tools that stay inside basic data processing fall outside it. Fixed-rule spreadsheets, database sort-and-filter, software used only for descriptive analysis, hypothesis testing or visualisation. In practice, that covers a lot of conventional quality statistics, as long as the tool is doing standard processing rather than learning, reasoning or modelling.
The label on the output will not settle it, because a recommendation or prediction can come from a system with no AI in it. What counts is whether the tool uses AI techniques to produce outputs that influence something, and whether those outputs get applied automatically or reviewed by a person first.
Do not file this under good news too quickly. The AI Act is more than a high-risk regime. It carries prohibited practices, transparency rules for certain systems, and separate obligations for general-purpose AI models. And Article 4 applies regardless of risk class. Any AI system counts.
Why AI literacy matters in life sciences
Every industry has a reason to care. Ours is sharper because we have to prove a competent human made the decision.
Imagine an audit. An inspector opens a closed deviation and sees that the root cause classification came out of an AI-assisted triage tool. The inspector will not ask which model you used. She will ask what your reviewer did with the output, and if the answer is that they accepted it because it appeared on screen, you have a people finding.
The Pistoia Alliance (2025) surveyed more than 200 life sciences professionals for its Lab of the Future report and found 77% of labs expect to use AI within two years. Respondents naming a lack of people as a barrier rose to 34%, up from 23% in 2024, while regulation as a barrier collapsed from 23% to 9%. In twelve months, the industry stopped worrying about what regulators would allow and started worrying about its own staff.
Then there is what it does to quality culture. Teams that don't understand a system tend to go one of two ways. Some reject it, and the €80,000 module gathers dust while people carry on copying and pasting from Word templates. Others accept everything it produces, which is worse, because now the errors are documented, approved and signed.
There is exposure too, though fines are the least of it. The Commission's Q&A describes two routes: public enforcement by national market surveillance authorities and private enforcement, in which someone who suffers harm sues under national law.
Standalone Article 4 cases are expected to be uncommon. The realistic scenario is that a documented literacy gap becomes an aggravating factor once a regulator is already looking at something else, since the nature and gravity of an infringement and whether it was negligent both feed the penalty. Which is why a training record you can produce beats a policy you can quote.
Recommended learning:
What Annex 22 means for AI governance in GMP-regulated environments
AI literacy and the EU AI Act: what article 4 asks for
Article 4 of Regulation (EU) 2024/1689, as replaced by the Digital Omnibus on AI in July 2026, says that if your organisation uses AI, you have to make a reasonable effort to help the people using it understand what they are doing. That covers your staff and anyone else operating the system on your behalf.
The depth should fit the person and the context, so someone drafting text with a chatbot doesn't need what a validation lead needs. And you are not required to certify anybody as an AI expert.
Start with who the duty lands on.
A provider builds an AI system, or has one built, and puts it on the market or into service under its own name or trademark, paid or free.
A deployer just uses one under its own authority. Most life sciences companies are deployers, and the bar is lower than people expect. If your QA team uses a commercial chatbot to draft training material, that is you, and your staff need to be told about risks like hallucination.
The line between the two is not fixed. Under Article 25, a deployer becomes a provider by putting its own name on a high-risk system, modifying one substantially, or changing a system's intended purpose. Fine-tune a vendor's model on your own batch data and you may have inherited the provider's obligations.
Then there is the word staff, which is not where the duty stops. It reaches other persons involved in the operation and use of AI systems on your behalf, so contractors and service providers are included. If a consultant runs your data integrity assessment with AI assistance, their competence is your exposure.
Scope also stretches in two directions that catch people out. Geographically, the AI Act applies wherever a system is placed on the Union market, used in the Union, or its use affects people in the EU, and the Commission confirms that this also applies to Article 4. A US-headquartered sponsor running EU trials is in scope.
And “other persons” can reach past contractors. Article 3(56) covers affected persons, and extends the reasoning to clients where the specific risk warrants it, which starts to matter once AI-assisted output reaches investigators or patients.
Last comes proportionality. The amended text drops the old phrase “to their best extent” and expresses the same idea by naming what you have to take into account: technical knowledge, experience, education and training, the context in which the system is used, and the persons or groups it is used on.
That last factor cuts both ways. Where a system's outputs land on vulnerable people, the standard for whoever operates it rises.
There is no one-size-fits-all benchmark and no external certification requirement. But the Commission has been clear that handing people the instructions for use and hoping is unlikely to count.
For once, the AI literacy requirements come with very little bureaucracy. No certificate to obtain, no AI officer to appoint, no governance board, and no duty to formally test what your staff know. An internal record of the training and guidance you have provided might do the job (AI Office Q&A).
Article 4 at a glance: What organizations need to do
Recommended learning:
How to conduct a supplier audit in the life sciences: Why continuous supplier oversight is critical in a risk-driven regulatory landscape.
AI literacy and the EU AI Act: what article 4
What moved in July 2026, and what didn't
The Digital Omnibus pushed the high-risk obligations back: standalone Annex III systems from 2 August 2026 to 2 December 2027, and AI embedded as a safety component in regulated products, including medical devices, to 2 August 2028. The Article 27 fundamental rights impact assessment moved with them.
Article 4 did not move, and neither did the Article 50 transparency obligations. So if your AI falls outside the high-risk categories, Article 4 is the only AI Act obligation enforceable against you in the near term. If it falls inside them, you have just been handed sixteen extra months for the documentation, and AI literacy is the cheapest part of that file to start on.
What should AI literacy training include?
A lot of what gets sold as AI literacy training is prompt engineering dressed up for compliance. Knowing how to write a good prompt does matter. But if that is all a team learns, they get answers faster without learning to question them.
The AI Office has published the closest thing to a minimum, and it is worth working through before you design anything. Its Q&A sets out four steps:
- Establish a general understanding of AI across the organisation, including what AI is, how AI works, which AI systems you actually use, AI opportunities and dangers.
- Decide whether you are a provider or a deployer.
- Assess the risk those systems carry, and what staff therefore need to know about it.
- Build your literacy actions on that analysis, adjusted for people's existing knowledge, experience, education, training, and the context of use.
It also says, twice, that relying on the AI system's instructions for use, or asking staff to read them, “might be ineffective and insufficient”.
Past that, real understanding shows up in five answers your people should be able to give about the tool in front of them.
What the system does. The task it was built for, the data behind it, and the point where it stops being useful. Someone should be able to explain it to a colleague in three sentences without reading from a vendor brochure.
How it fails. Hallucinated references, answers that sound right and aren't, bias carried over from historical data, and the slow drift that happens when the process changes and the model doesn't.
Where the decision sits. Which step is guidance, which one is the decision, and who has the authority to overrule the output.
What gets recorded. The prompt, the version, the output, the reviewer, the reason for the decision. The fact that the input came from a model does not change the basics of data integrity.
What happens when something looks wrong. People need a named route to escalate and a named person at the end of it. Without one they will work around the tool quietly, and the problem stays hidden.
How to build AI-ready teams without one-size-fits-all training
The most common mistake is the mandatory ninety-minute AI literacy session. You tick the box, file the attendance, and nobody remembers a thing afterwards.
Match depth to responsibility instead. For most organisations, five tiers are enough:
The AI Office imposes no sector-specific requirements. There is no pharmaceutical annex to Article 4, which means the depth you choose is something you will have to justify rather than look up. And where a system's outputs land on vulnerable people, patients included, the competence expected of whoever operates it rises accordingly.
Four things turn that table into a plan.
Start with an inventory of the AI systems people actually use
This is where the awkward silence usually starts in front of an inspector, because a lot of AI arrived inside software nobody ever labelled as AI. Until you know what is in use and who touches it, the training plan is guesswork.
Link every session to a real tool
People sit through broad awareness sessions and nod along politely. Fifteen minutes on the deviation triage module your team opens every morning lands better than an hour of abstract examples.
Cross-train in both directions
Let compliance, RA, and data protection focus on the technical side, and let the developers focus on the legal and quality side. Nobody needs to become the other. But the questions get sharper once each group knows where the other one is blind.
Put it on a real schedule
AI tools don't stay still. Review at least once a year, and treat a major model change as a reason to review sooner.
Where to start
You can't build trustworthy AI on top of people who don't understand it. Human oversight and risk management both assume someone on the other side of the screen notices when something looks off and says so.
For quality teams, the good news is that none of this is new work. You already run competence frameworks, keep training records, and think in failure modes. It’s the same discipline, with a different class of system.
The timing is the easy part to get wrong. The high-risk deadline slipped; Article 4 did not, and it has been enforceable since August 2026. For the many organisations whose AI never touches Annex III, it is the only AI Act duty that bites in the near term.
So pick one AI tool your team uses this week. Ask three people what it does, where it fails, and what they would do if the output looked wrong. Their answers will tell you more about your exposure than any policy document. And if the EU's repository still holds nothing from our industry a year from now, it won't be for lack of anything to teach.
If you want a place to start, Scilife Academy runs certifications for quality professionals building this foundation, including Fundamentals of Data Integrity and Data Governance. Our AI governance resources go deeper on oversight and documentation, and Scilife QMS Software keeps the training records, role mapping and audit trail in one place.
FAQs
Does the EU AI Act require AI literacy?
Yes. Article 4 has applied to providers and deployers of AI systems since 2 February 2025. The Digital Omnibus on AI rewrote the wording in July 2026, so organisations now take measures to support the development of that literacy among staff rather than ensure a sufficient level of it (Regulation (EU) 2026/1744, 2026). National market surveillance authorities began supervising Article 4 from 2 August 2026.
Did the Digital Omnibus delay the AI literacy obligation?
No. It deferred the high-risk obligations — standalone Annex III systems to 2 December 2027 and AI in regulated products such as medical devices to 2 August 2028 — and it left Article 4 and the Article 50 transparency rules exactly where they were. It softened the standard from ensuring literacy to supporting its development, which is a change of degree, not of duty. The enforcement date did not move.
Are all the tools in our QMS covered by the AI Act?
Usually not. The Commission's guidelines on the definition of an AI system exclude standard spreadsheets without AI features, database queries, linear and logistic regression, and systems used solely for descriptive statistics, hypothesis testing and visualisation. Control charts, capability indices and stability regression sit outside the definition. A tool comes into scope when it starts inferring, which means it recommends, classifies or predicts.
Do we need a certificate to prove AI literacy?
No. The European Commission's AI Office has confirmed there is no certification requirement and no obligation to formally measure employee knowledge. You can keep an internal record of the training and guidance provided. Deployers of high-risk AI systems face a stricter expectation under Article 26, where the people exercising human oversight need the necessary competence, training and authority.
Does Article 4 apply if we only use tools like ChatGPT, Copilot, Gemini or Claude?
Yes. Using a general-purpose AI tool for tasks such as drafting or translation makes your organisation a deployer, and the Commission's guidance says staff should be informed about the specific risks involved, hallucination among them.
Does the AI literacy obligation cover contractors and consultants?
It covers other persons dealing with the operation and use of AI systems on your behalf, which includes contractors, service providers and, depending on the risk, clients. People working for a service provider need appropriate AI skills for the task in the same way your employees do.
Does Article 4 apply to us if we're headquartered outside the EU?
Yes, if the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. The Commission states this explicitly for Article 4. A US or UK sponsor with EU trial sites, an EU affiliate, or EU-facing patient services is in scope.
What are the penalties for failing Article 4?
There is no single European figure, despite what some commentary suggests. Article 99's penalty tiers don't list Article 4; the Commission says national market surveillance authorities sanction infringements under the national laws Member States were required to adopt by 2 August 2025, and that any sanction must be proportionate to the nature, gravity and negligent or intentional character of the breach. In practice a literacy gap is more likely to aggravate another finding than to be pursued alone.
Our data scientists have AI qualifications. Are they already AI literate?
Normally yes, but the AI Office is careful not to make it automatic. It depends on the specific tool and qualification, and the organisation should still ask whether those staff know the systems it actually runs, the risks attached, and the legal and ethical dimensions of deploying them. Given how fast the technology moves, a qualification from three years ago is not a permanent exemption.
Where should a quality organisation start with AI literacy?
With an inventory of the AI systems already in use, including features embedded in tools you never classified as AI. Map who touches each one, then set the depth of training by decision weight rather than by job title.




