AI literacy for law firms: a practical guide to Article 4 of the EU AI Act

A lawyer does not become AI-literate by learning a handful of prompts. In legal practice, literacy means knowing what a system can and cannot establish, which client material may enter it, how to verify every material source, when human review is becoming a rubber stamp, and when to stop. Article 4 of the EU AI Act now turns that practical competence into an organisational obligation for providers and deployers of AI systems.

Why AI literacy is the live compliance question in August 2026

Article 4 has applied since 2 February 2025. What changed in July 2026 is the legal test. Regulation (EU) 2026/1744 replaced an obligation to ensure, to the best extent possible, a “sufficient level” of AI literacy with an obligation to take measures that support its development. The amended text expressly says that a provider or deployer does not have to guarantee any specific level of AI literacy for an individual (1).

This is simplification, not deletion. The Commission's updated Q&A confirms that AI literacy remains an obligation, that national market-surveillance authorities take the enforcement role, and that supervision begins with the August 2026 application milestone (2). High-risk AI deadlines moved to 2027 and 2028 under the same Omnibus, but Article 4 did not move with them.

The timing matters for law firms because AI use is no longer confined to innovation teams. It appears in legal research, chronology building, contract comparison, document review, transcription, translation, drafting and business functions. A generic policy cannot teach a lawyer how to test whether a judgment supports a proposition, and a product demonstration cannot teach a paralegal where confidentiality is lost.

What Article 4 requires—and what it does not

Providers and deployers must take measures for staff and for other people dealing with the operation or use of AI systems on their behalf. In deciding what measures are appropriate, they must consider existing technical knowledge, experience, education and training; the context in which the systems are used; and the people or groups affected by that use.

For a law firm, five consequences follow.

  1. The duty is contextual. Training should follow the legal task, the system's permissions, the sensitivity of the information and the consequences of error.
  2. The duty extends beyond employees. Contractors, managed-service personnel and others using AI on the firm's behalf may fall within the relevant group.
  3. The duty is not limited to high-risk AI. The Commission gives the ordinary use of ChatGPT for writing as an example that still calls for awareness of risks such as hallucination.
  4. No single format is mandated. Training, guidance, supervised exercises, approved-use notes and other measures can work together.
  5. No certificate or AI officer is required. The Commission says Article 4 does not prescribe either, although a firm still needs clear ownership.

A small firm can therefore be proportionate without being informal. A concise programme tied to the tools it actually uses is more defensible than a costly library of generic courses that no one applies.

Do law firms and individual lawyers fall within scope?

A firm that uses an external AI system in its work will ordinarily be acting as a deployer: an organisation using an AI system under its authority. A firm that develops, substantially modifies or markets a system under its own name may need a separate role analysis. The label in the supply contract is not conclusive; the real function and control matter.

Article 4 is addressed to the provider or deployer, not to an employee as a standalone compliance unit. That does not mean every person needs the same course. It means the organisation should identify who encounters each system and give them enough, in context, to use or supervise it responsibly. A receptionist using no AI may only need the firm's basic escalation rule. A litigation associate using AI-generated research paths needs materially deeper source and confidentiality training.

Professional rules remain a separate and often stricter layer. The CCBE's guide connects generative AI use to confidentiality, competence, independence, transparency and conflicts (5). In the Netherlands, the NOvA likewise places final responsibility with the lawyer and calls for manual checking of facts, authorities and citations (7). Article 4 should be integrated with those duties, not taught as an isolated technology regulation.

The seven competencies a legal AI programme should build

1. Recognise the system and its role in the task

Users should know whether they are dealing with search, extraction, classification, generation or an action-taking agent. They should understand which sources the system can reach, whether it creates a draft or changes another system, and where uncertainty may be hidden by fluent output. The practical question is not “Is this AI?” but “What may this tool observe, infer and do in this matter?”

2. Protect confidentiality before entering the prompt

Legal AI literacy begins before generation. A user should be able to distinguish public material from client confidential information, privileged analysis, personal data and especially sensitive facts. They should know which tools are approved for each category, what minimisation means in practice, and when data location, retention, subprocessors or model-improvement terms require escalation. Our guide to secure AI use for lawyers addresses that decision in more depth.

3. Verify legal propositions against primary sources

“Check the answer” is too vague. A competent review asks whether the authority exists, whether the cited passage says what the draft claims, whether it governs the jurisdiction and date, whether its procedural posture matters, and whether later or contrary authority changes the proposition. The reviewer should reach the source itself rather than approve a citation because its format looks plausible. This is why source-grounded legal research is a working method, not a decorative feature.

4. Detect omission, bias and false agreement

A system can produce a factually tidy answer while omitting the inconvenient authority, qualification or document. Training should require an adverse search: ask what would defeat the proposed conclusion, which fact is assumed rather than established, which party's framing shaped the analysis and what has not been searched. Lawyers also need to recognise sycophancy—the system's tendency to follow the premise embedded in the user's question.

5. Apply meaningful human review

Human involvement is not meaningful when the reviewer sees only polished prose, lacks time to inspect the record or assumes that a colleague already checked it. The lawyer needs the underlying document or authority, a clear view of what the system contributed and the ability to reject the result. Review depth should rise for advice, pleadings, negotiation positions, rights-affecting decisions and irreversible actions.

6. Know the transparency and recordkeeping boundary

Article 4 is distinct from the AI Act's Article 50 transparency rules, professional disclosure duties and court-specific directions. A literate user need not memorise the whole regulation, but must know when AI interaction or content triggers a disclosure check, what the firm records about material use and who decides whether a client, court or counterparty must be informed. The Commission's final Article 50 guidance is the reference point for the 2 August 2026 transparency milestone (4).

7. Stop, preserve and escalate

Every user should recognise incidents: client material entered in an unapproved service, a fabricated authority, output sent to the wrong recipient, unexpected access across matters or a material supplier change. The immediate response should be known before the event—stop the workflow, preserve relevant facts without spreading sensitive data, notify the named owner and avoid silently “fixing” the record.

One foundation, five role-based learning paths

The amended Article 4 rewards differentiation. A credible firm programme can begin with one shared foundation and add modules by role.

External reviewers, contract lawyers and service providers should receive the parts that match their access and task. A contractual promise to “comply with AI policy” is not a substitute for giving them the usable guidance and controlled environment needed to do so.

Teach through legal scenarios, not slogans

Scenario work shows whether a rule survives contact with a matter. Four short exercises can reveal more than a long lecture.

  1. The persuasive but wrong citation. Give the team a fluent research paragraph containing one invented case, one real but irrelevant case and one outdated proposition. Require source-by-source correction.
  2. The over-shared dossier. Present a request to summarise a file containing privileged correspondence, health data and irrelevant identity documents. Ask what must be removed, which environment is permitted and whether a DPIA or further approval is relevant.
  3. The missing adverse fact. Compare an AI chronology with the original bundle and require the reviewer to identify omitted dates, uncertain inferences and conflicting documents.
  4. The almost-final pleading. Ask who checks facts, citations, procedural requirements, disclosure and the final version before filing. “A human looked at it” is not an acceptable control description.

Score the reasons, not just the answer. A user who rejects an output for the wrong reason may repeat the failure in the next matter. A good exercise reveals how the person reached the source, protected the client and decided when professional judgment was required.

What evidence should a firm keep?

The Commission says no Article 4 certificate is required and an internal record of training or other initiatives may be kept. The sensible evidence is therefore lean and operational, not an academy built for its own sake.

Do not collect personal performance data merely because it might look useful in an audit. Define a purpose, minimise what is recorded, set access and retention rules, and involve employee representatives where applicable. Evidence of literacy should not create an unnecessary second risk under employment or data-protection law.

Five common programmes that fail

  1. The annual inspiration session. It generates enthusiasm but gives no tool-specific instruction, matter examples or review method.
  2. The prompt-engineering course. It teaches people to obtain smoother output without teaching them to protect data or verify the law.
  3. The signed policy. Acknowledgement shows distribution, not understanding or application.
  4. The vendor demonstration. A supplier can explain features; the firm must explain professional limits, approved data and supervision.
  5. The expert exemption. Technical staff may understand models yet still need the firm's legal, ethical and matter-handling rules.

The failure behind all five is the same: they treat literacy as information received rather than judgment exercised. Article 4's contextual wording points in the opposite direction.

A practical 30-day implementation plan

Days 1–5: map real use

List sanctioned tools and known unsanctioned use. Identify the legal tasks, information categories, users, affected people and external actions. Do not wait for a perfect enterprise inventory; begin with the workflows that touch client material or legal conclusions.

Days 6–10: set the common foundation

Publish a short baseline covering approved tools, confidentiality, source verification, human responsibility, disclosure checks and incidents. Name the owner and make the route for questions practical.

Days 11–20: run role-based scenarios

Train through representative work from litigation, transactions, advisory and business services. Require participants to inspect sources and explain escalation, not merely watch a demonstration. Record material gaps in the workflow as well as mistakes by users.

Days 21–25: test supervision

Sample completed work. Can a supervisor see the source, distinguish fact from inference, understand what the tool did and identify who approved the result? If review is impossible under normal time pressure, redesign the process rather than repeating the instruction.

Days 26–30: record, correct and schedule refreshers

Finalise the training matrix, completion record and open remediation items. Set refresh triggers: new system, material model or permission change, new legal guidance, serious incident, repeated source failure or expansion into a higher-impact task.

Measure legal competence, not course completion

Completion rate is necessary administration, but it is a weak measure of legal readiness. A firm learns more by tracking whether users can find the primary source, catch unsupported propositions, avoid inappropriate data entry and escalate uncertain cases before external use.

Useful programme indicators include:

Do not reward a falling correction count without context: it may reflect better output, weaker checking or under-reporting. Combine numbers with sampled legal work and candid reviewer feedback.

How this fits the way LexVera supports legal work

Good AI literacy becomes visible in the work itself. The source remains close enough to inspect. Matter material stays within the right context. Uncertainty can be challenged. A qualified lawyer decides what becomes advice, correspondence or a filing.

LexVera supports that professional working method across research, documents and drafting. The objective is not to make lawyers trust an answer because it sounds assured. It is to help them reach relevant material, review the basis of a proposition and retain responsibility for the legal conclusion. That same distinction between sourced fact, professional interpretation and product context underpins our editorial policy.

Frequently asked questions

Does Article 4 of the EU AI Act apply to law firms?

Generally yes when a law firm provides or deploys an AI system. The obligation is not limited to high-risk AI. The firm should take context-sensitive measures for staff and others operating or using AI on its behalf.

Did the 2026 Digital Omnibus remove the AI literacy obligation?

No. It changed the standard. Firms must support the development of AI literacy but need not guarantee a specified level for each person. The distinction removes an uncertain outcome obligation; it does not remove the need to act.

Does every lawyer need the same AI training?

No. Everyone can share a basic foundation, but a research lawyer, supervising partner, legal-operations specialist and system administrator need different modules. The depth should follow the tool, role, data and possible consequence.

Do lawyers need an AI literacy certificate?

No specific certificate is required. Keep an internal record of relevant training and guidance, and be able to show why the programme fits the firm's actual use.

Is one annual AI webinar enough?

Not necessarily. It may establish a baseline, but higher-impact legal work calls for tool-specific guidance, role-based exercises and refreshers after meaningful changes or failures.

Do delayed high-risk AI deadlines postpone Article 4?

No. The Digital Omnibus moved certain high-risk-system requirements to December 2027 and August 2028. Article 4 already applies and was separately amended in July 2026.

Sources and methodology

This guide reflects legislation, Commission materials and professional guidance available on 1 August 2026. It distinguishes the binding text from non-binding Commission explanations and bar guidance. It provides general professional information, not legal advice on a particular firm's duties; national enforcement and professional rules must be checked in context.

  1. Regulation (EU) 2026/1744, Digital Omnibus on AI, especially amended Article 4
  2. European Commission, AI Literacy—Questions & Answers, updated July 2026
  3. European Commission AI Act Service Desk, repository and Article 4 resources
  4. European Commission, final guidelines on Article 50 transparency obligations, 20 July 2026
  5. CCBE, Guide on the use of generative AI by lawyers, 2 October 2025
  6. CCBE, Technical guide on the use of AI tools and models by lawyers, 27 March 2026
  7. Netherlands Bar, Recommendations on AI in legal practice
  8. European Commission, Governance and enforcement of the AI Act