Independent reporting on data, AI and digital regulation in Luxembourg

AI Act · Explainer

AI literacy under AI Act Article 4: what Luxembourg organisations must do

Since 2 February 2025, every provider and deployer of AI in Luxembourg must take measures to build AI literacy among staff. What the rule requires after the 2026 Omnibus.

Key takeaways

  • Article 4 of the AI Act has applied since 2 February 2025 to every provider and deployer of an AI system, regardless of the system's risk level.
  • Since 27 July 2026, the Digital Omnibus on AI (Regulation (EU) 2026/1744) requires organisations to take measures to support AI literacy rather than to ensure a 'sufficient level' of it.
  • According to the European Commission's Q&A, no certificate is needed, but organisations can keep an internal record of trainings and other initiatives.
  • In Luxembourg, draft law No. 8476, which designates the CNPD as the main AI Act authority, was still in committee as of October 2026; the Conseil d'État issued its opinion on 10 July 2026.

Every organisation in Luxembourg that develops or uses an AI system has been subject to the AI literacy obligation in Article 4 of the EU AI Act since 2 February 2025. Since 27 July 2026, when the Digital Omnibus on AI entered into force, the rule requires providers and deployers to take measures that support the AI literacy of their staff, rather than to guarantee a “sufficient level”. The obligation was softened, not removed, and it applies regardless of how risky the AI system is.

What Article 4 says

Article 4 of Regulation (EU) 2024/1689 originally required providers and deployers to “ensure, to their best extent, a sufficient level of AI literacy” among their staff. Regulation (EU) 2026/1744, the Digital Omnibus on AI, replaced that wording. Providers and deployers now “shall take measures to support the development of AI literacy” of their staff and of other persons operating or using AI systems on their behalf.

The factors to take into account are unchanged: the technical knowledge, experience, education and training of the people concerned, the context in which the AI systems are used, and the persons or groups on whom they are used. A new second paragraph requires the Commission and the Member States to support providers and deployers, in particular SMEs, and the Commission to publish practical examples of compliance.

The AI Act defines AI literacy as the skills, knowledge and understanding needed to make an informed deployment of AI systems and to be aware of their opportunities, risks and possible harm.

Date What happened
2 February 2025 Article 4 starts to apply
27 July 2026 Digital Omnibus enters into force; Article 4 reworded
3 August 2026 Supervision and enforcement rules apply, according to the Commission’s Q&A
2 December 2027 Obligations for Annex III high-risk AI systems apply (postponed by the Omnibus)

Who is covered

The obligation applies to providers (organisations that develop an AI system or place it on the market under their name) and deployers (organisations using an AI system under their authority in a professional context). A bank using a generative AI assistant, a municipality using a chatbot and a software firm building an AI product are all covered.

According to the Commission’s AI literacy Q&A, “persons dealing with the operation and use of AI systems on behalf of” an organisation can include contractors, service providers and, depending on the risk, clients. The CNPD’s guidance adds temporary staff, trainees and apprentices to the list.

What “sufficient level” means now

Before the Omnibus, the Commission’s guidance treated “sufficient level” as context-dependent rather than a fixed standard. The Q&A, updated on 27 July 2026, now states that AI literacy remains an obligation for providers and deployers, “but no specific – or ‘sufficient’ – level is mandated.” Legal commentators describe this as a shift from an obligation of result to an obligation of means.

In practice, the Q&A still frames the minimum as a risk-based analysis covering four points:

  • a general understanding of AI within the organisation;
  • the organisation’s role (provider or deployer);
  • the risks of the AI systems it provides or uses;
  • the existing technical knowledge, experience and training of staff, and the context of use, including legal and ethical aspects.

The Q&A also indicates that relying only on the instructions for use of an AI system may not be enough. Separate rules apply to high-risk systems: deployers must assign human oversight to people with the necessary competence and training, an obligation that applies with the high-risk rules from 2 December 2027.

Enforcement in Luxembourg

Article 4 is supervised by national market surveillance authorities. The Commission’s Q&A says no certificate is required and that penalties must be proportionate to the nature, gravity and intent of an infringement. It also notes that individuals who suffer harm may seek redress under national law.

In Luxembourg, draft law No. 8476, deposited on 23 December 2024, designates the Commission nationale pour la protection des données (CNPD) as the default market surveillance authority and single point of contact. The Commission de Surveillance du Secteur Financier (CSSF) and the Commissariat aux Assurances (CAA) would be competent for the entities they supervise. The parliamentary dossier shows the bill still in committee as of October 2026; the most recent document is the Conseil d’État’s opinion of 10 July 2026. As long as the bill is pending, the national sanctions regime it provides for is not in force.

The CNPD has nonetheless been active on the topic. At the “AI Act en action” conference on 20 January 2026, it stressed that all organisations must train their staff to use AI systems safely and in compliance with the rules.

What to do now

  1. Build an AI inventory. List every AI system the organisation develops or uses, including generative AI tools bought as a service, and note whether the organisation acts as provider or deployer for each.
  2. Map the people. Identify who operates or uses each system, including contractors and service providers acting on the organisation’s behalf.
  3. Train by role. Combine a general awareness module for all staff with deeper training for those who configure, supervise or rely on AI output in decisions. Structured AI literacy training programmes for staff can be organised by role and risk level.
  4. Document. Keep an internal record of trainings, guidance notes and acceptable-use policies, as suggested by both the Commission and the CNPD.
  5. Review regularly. Update training when new systems are introduced, and track indicators such as completion rates, as the CNPD recommends.
  6. Watch the national law. Follow the progress of draft law No. 8476 and any updated CNPD guidance on the Digital Omnibus.

Questions & answers

Does the AI literacy obligation apply if a company only uses tools such as ChatGPT?

Yes. Article 4 covers deployers, meaning any organisation using an AI system under its authority in a professional context. The Commission's Q&A explicitly addresses staff using generative AI tools and points to risks such as hallucinations.

Did the Digital Omnibus abolish the AI literacy obligation?

No. Regulation (EU) 2026/1744 rewrote Article 4 with effect from 27 July 2026. Providers and deployers must still take measures to support AI literacy, but no specific or 'sufficient' level is mandated any more.

Is an AI literacy certificate required?

No. The Commission's Q&A states that no certificate is needed. Keeping an internal record of training and guidance initiatives is the recommended way to show what was done.

Who checks AI literacy compliance in Luxembourg?

National market surveillance authorities supervise the AI Act. Under draft law No. 8476, the CNPD would be the default authority, with the CSSF and the CAA competent for the entities they supervise. As of October 2026 the bill had not yet been adopted.

Sources

  1. Regulation (EU) 2024/1689 (AI Act) · EUR-Lex
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI) · EUR-Lex
  3. AI Literacy – Questions & Answers (updated 27 July 2026) · European Commission
  4. How do organisations ensure control over AI? (AI literacy) · CNPD
  5. Projet de loi 8476 – dossier parlementaire · Chambre des Députés
  6. L'AI Act en action (20 January 2026) · CNPD
  7. Article 4: AI literacy (consolidated text after the Digital Omnibus) · artificialintelligenceact.eu
  8. AI literacy: the Digital Omnibus rewrites Article 4 of the AI Act · Law and Technology

Written and fact-checked against primary sources.