From Obligation to Opportunity: Implementing an EU AI Act-Compliant AI and Data Literacy Programme 8 min read By Merve UgurluA practitioner's implementation guide for organisations navigating Article 4 of the EU AI Act and what boards need to know nowLegal BasisEU AI Act, Article 4 (Regulation EU 2024/1689)ScopeAll risk levels: no category of AI is excludedEnforcement Begins2 August 2026National Market Surveillance AuthoritiesWho Is CoveredStaff, contractors, service providers, andaffected clients Topics Risk Management and Regulatory Compliance Artificial Intelligence Why AI Literacy Is Now a Board-Level PriorityThe EU AI Act's Article 4 has been in force since 2 February 2025. It requires every provider and deployer of AI systems regardless of their size, sector, or the risk level of the AI they use to ensure that staff and other persons dealing with AI on their behalf possess a sufficient level of AI literacy.Enforcement begins on 2 August 2026, when national market surveillance authorities across EU Member States will be empowered to audit, penalise, and sanction non-compliant organisations.Yet despite these clear deadlines, the evidence of readiness is stark. Three independent studies published in 2025–2026 paint a consistent picture: 78 % of organisations have not taken meaningful steps toward EU AI Act compliance 60 % of enterprise leaders report an AI literacy skills gap in their organisation 42 % of enterprises actually provide foundational AI/data literacy training at scale The Vision Compliance EU AI Act Readiness Report (April 2026) found that [1] 78% of organisations surveyed have not taken meaningful steps toward AI Act compliance, this despite the Article 4 obligation having been in force for over a year. A parallel finding from the DataCamp / YouGov 2026 State of Data & AI Literacy Report [2] is equally sobering: while 72% of enterprise leaders acknowledge AI literacy as essential for day-to-day work, nearly 60% report a skills gap in their organisation and only 42% provide foundational training at scale.Meanwhile, McKinsey's 2025 Global Survey [3] confirms that 88% of organisations use AI, yet only one-third have scaled it effectively. The gap between AI adoption and AI understanding is not narrowing. Article 4 is designed to close it.The UK Government's DSIT AI Labour Market Survey 2025 reinforces the point from a workforce angle: 97% of respondents identified at least one skills gap in their organisation's AI capabilities, and 88% rely on informal on-the-job training rather than structured programmes yet only 13% of graduate schemes include any AI training at all.[4]For boards and executive leadership, this data is not abstract. It signals that most peers and competitors are exposed and that first-movers who build robust AI literacy infrastructure ahead of August 2026 will carry a meaningful compliance and reputational advantage. Understanding the Obligation: What Article 4 Actually RequiresArticle 4 of the EU AI Act does not prescribe a single mandatory training format. Instead, it establishes a principles-based, risk-proportionate obligation. Article 3(56) defines AI literacy as:Article 3(56) — Definition of AI Literacy“AI literacy means skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause.”The following key principles underpin the compliance obligation:No one-size-fits-all approach: Organisations must tailor AI literacy measures to the technical knowledge, experience, education, and training of their staff, and to the specific AI systems in use.Broad scope of persons covered: In scope are not just employees but also contractors, outsourced service providers, agencies, and in relevant cases clients and affected persons who interact with AI outputs.Risk proportionality: Where high-risk AI systems (as defined in Chapter III of the AI Act) are deployed, enhanced training and safeguards are required; no category of AI is excluded from the base obligation.No safe harbour for inaction: While there is no mandatory training format, regulators will treat the complete absence of an AI literacy programme as obvious non-compliance.From a board governance standpoint, this means that signing off on AI deployment without a corresponding literacy plan creates direct regulatory exposure. Boards should treat AI literacy programme oversight as part of their AI governance mandate alongside risk management, data governance, and algorithmic accountability. AI literacy is the foundation on which all other AI Act obligations rest. You cannot manage what you do not understand. A Structured Approach to Programme DesignThe following implementation framework, drawn from Protiviti's work with enterprise clients, provides a structured pathway from obligation mapping to programme governance. + EXPAND ALL Step 1 — Map Your AI Footprint and Role + The starting point is clarity about your organisation's role in the AI pipeline:Deployer: You integrate and operate AI systems built by third parties (e.g., an AI scheduling tool or a GenAI search engine).Provider: You develop AI systems in-house (e.g., a proprietary predictive pricing model). Many organisations are both. Your role determines the nature and depth of your training obligations. Providers carry heavier documentation and oversight obligations; deployers must ensure staff understand the system they are operating and its limitations. Step 2 — Conduct a Literacy Impact Assessment for Each AI Use Case + For every AI system in use, a structured assessment should determine:Which stakeholder groups interact with, oversee, or are affected by this system?What level of AI literacy is required for each group?Which delivery method is most effective given operational realities? This assessment should be a mandatory step in the AI project lifecycle which will be triggered every time a new AI system is introduced, a material change is made, or regulatory requirements evolve. Step 3 — Define Stakeholder Learning Profiles + Not all staff need the same level of AI literacy. An effective programme clusters individuals into learning profiles based on their exposure, responsibility, and rights impact:ProfileWhat They Must Know / DoWhat They Must AvoidC-Suite & BoardStrategic accountability; AI risk and regulatory exposure; programme governance oversightDelegating without overseeing; treating compliance as a one-time exerciseFrontline StaffInterpret AI outputs; know when to override; spot anomaliesBlind reliance on AI-generated decisions; bypassing escalation pathsManagersAccountability obligations; transparency requirements; high-risk system risksApproving AI-assisted decisions without validationTechnical TeamsModel lifecycle; data quality; monitoring; documentation standardsDeploying models without documented oversight proceduresRisk / Legal / HRRegulatory obligations; audit trail requirements; risk management processesTreating AI literacy as a technology-only responsibilityNote that the C-Suite and Board tier is explicitly in scope. Board members who approve AI strategy, oversee risk, or sign off on AI-enabled products must have sufficient literacy to discharge their governance duties. In simple terms,it is a practical accountability requirement. Step 4 — Define Minimum Training Content + Regardless of audience, Protiviti's guidance identifies five core content domains that should form the foundation of any EU AI Act-compliant literacy programme:1. Understanding AI Systems: How the AI system works conceptually, its intended purpose, limitations, and human oversight requirements.2. Data Literacy Fundamentals: Data quality, lineage, access controls, privacy, security, and responsible data handling; the baseline on which AI literacy depends.3. Ethical and Compliant Use: Transparency and explainability, bias avoidance, appropriate use of personal data, and safe use of GenAI tools.4. Safe Human–AI Interaction: When and how to override AI, understanding confidence levels and output limitations, and escalation paths for system concerns.5. Risk Mitigation Behaviours: Validating outputs, monitoring for anomalies, following governance processes, and maintaining records for regulatory evidence. Step 5 — Select Fit-for-Purpose Delivery Methods + Delivery must reflect operational realities. A large-scale enterprise with shift-based workers, multilingual teams, and high turnover faces very different constraints from a professional services firm. Key considerations include:Learning objective type: Conceptual knowledge suits e-learning; behavioural skills require scenario-based workshops; technical skills demand hands-on labs.Audience profile: Frontline staff need short-form, mobile-accessible content; executives need strategic briefings; technical teams benefit from peer learning and tooling sessions.Operational constraints: Device access, shift patterns, staff turnover, and language diversity all shape what is feasible and effective. For GenAI tools specifically, Protiviti recommends practical exercises on evaluating AI-generated outputs, safe prompting, data leakage awareness, and output validation. For predictive models, workshop-based training for managers and frontline teams covering model limitations, bias, and escalation procedures is advisable.AI literacy is not a training exercise. It is a governance obligationIn conclusion, organisations that view AI literacy solely as a learning and development initiative rather than a core risk and governance imperative expose themselves to risks at multiple levels.More importantly, they jeopardise the success of their broader AI adoption journey, as the lack of informed, accountable and risk-aware teams ultimately undermines both trust and value realisation. About Protiviti Protiviti is a global consulting firm that delivers deep expertise, objective insights, a tailored approach, and unparalleled collaboration to help leaders confidently face the future. Protiviti's AI/ML Assurance team supports organisations with AI governance frameworks, EU AI Act readiness, and the design and implementation of AI and data literacy programmes. References [1] 78% of Enterprises Are Not Ready for the EU AI Act — Vision Compliance EU AI Act Readiness Report, April 2026[2] The State of Data & AI Literacy in 2026: Definitions, Statistics, and the AI Skills Gap — DataCamp / YouGov[3] AI Adoption Insights from McKinsey's 2025 Global Survey[4] AI Labour Market Survey 2025 Report — UK Department for Science, Innovation and Technology (DSIT) Leadership Bernadine Reese Bernadine is a Managing Director within our Financial Services Industry (FSI) Regulatory practice in the U.K. Prior to joining Protiviti 17 years ago, Bernadine was a Director in KPMG’s Regulatory Services practice. A chartered accountant by training, Bernadine has over ... Learn more Nikunj Chadha Nikunj is a seasoned Data & AI leader with over 19 years of global experience across consulting, delivery, and leadership roles. He currently serves as Managing Director at the Data and AI practice at Protiviti UK. With a strong commercial focus, Nikunj has ... Learn more Michelle Moody Michelle is a Managing Director for the Data & Analytics Practice in the UK. She has 25 years of experience in data, analytics, and large programme delivery. Her experience is across sectors providing advisory and technical expertise.She has extensive international ... Learn more