Jump to

The AI Literacy Duty After the Omnibus: What a Turkish Company Must Document

The AI Literacy Duty After the Omnibus: What a Turkish Company Must Document

Article 4 of the EU AI Act is the one obligation that already applies to every provider and deployer of any AI system, whatever its risk class: since 2 February 2025, they must take measures on the AI literacy of their staff and of the other people who operate or use AI systems on their behalf. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) rewrote the wording. The duty is no longer to “ensure, to their best extent, a sufficient level” of literacy; it is to “take measures to support the development” of literacy, with the Commission and the Member States now obliged to support and facilitate those efforts, and with an express statement that no particular level has to be guaranteed. National market surveillance authorities have had enforcement powers since 2 August 2026. For a Turkish company selling into the EU, or deploying AI for EU users, the question is no longer whether Article 4 applies but what evidence of “measures” will satisfy a regulator, a customer’s procurement team or an investor. This article answers that with a documentation set that also serves Turkish obligations. The primary texts are collected in our AI Act document set.

Who is caught, and by which capacity

Article 4 applies to providers (those who develop an AI system or have it developed and place it on the market or put it into service under their own name) and deployers (those who use an AI system under their authority in the course of a professional activity). Most companies are both: a fintech that builds a credit-scoring model is a provider of that system and a deployer of the generative-AI assistant its support team uses. The territorial rule in Article 2 catches a Turkish company as provider when it places a system on the EU market or puts it into service there, and as deployer when the system’s output is used in the EU. A Turkish SaaS with EU customers is therefore a provider for Article 4 purposes even if every employee sits in Istanbul; a Turkish exporter using an EU-hosted AI tool for its own EU sales operations is a deployer. The literacy duty covers “staff and other persons dealing with the operation and use of AI systems on their behalf”, which includes contractors, agency workers and, for deployers, the outsourced teams that run the system.

What “measures” means after the Omnibus

The Commission’s Article 4 Q&A, updated on 27 July 2026, says three things that matter for drafting. First, no certificate or standardised course is required; the regulation does not prescribe a format. Second, the measures must be risk-based and context-specific, taking account of the technical knowledge, experience, education and training of the people concerned and the context in which the systems are used, including the persons or groups on whom they are used. Third, organisations may keep internal records of trainings and other initiatives, and those records are what an authority will look at. The Omnibus removed the argument that a company is in breach because some individual turned out not to be “sufficiently” literate; it did not remove the duty to act, and it did not remove the authority’s power to ask what you did. The practical standard is therefore documented, proportionate effort, differentiated by role.

Enforcement: what an authority can and cannot do

Article 4 is not in the list of provisions in Article 99(4) that carry the Regulation’s fixed fine ceilings, and the Commission’s Q&A confirms that authorities may nonetheless impose penalties and other enforcement measures under national rules, applied proportionately to the gravity and intent of the infringement. Since 2 August 2026, national market surveillance authorities have had jurisdiction. In practice the exposure is threefold: a direct enforcement action in a Member State where the company has a presence or a representative; an aggravating factor in an enforcement action about another obligation, since a company that never trained anyone will find it hard to show it took its high-risk or transparency duties seriously; and contractual exposure, because enterprise customers now write Article 4 compliance into AI procurement schedules and ask for evidence at onboarding and renewal. For most Turkish SMEs the third channel arrives first.

The documentation set: five documents

The first is an AI system inventory: every system the company provides or deploys, with its role (provider or deployer), its risk classification under the classification memo method, the people who operate it and the populations it affects. Article 4 measures are calibrated against this inventory, so it comes first. The second is a role-based literacy matrix: for each role that touches an AI system (developers, product owners, operators, customer-facing staff, management, and contractors), what they need to understand about the systems they touch, at what depth, and how that is delivered. The Commission’s guidance points to differentiation by technical knowledge, experience, education and context; a matrix is the simplest way to show it. The third is the training record: dates, content outlines, attendance and, where relevant, assessment results, kept per person, with onboarding and refresher cycles. The fourth is the human-oversight link: for any high-risk system, Article 26 requires deployers to assign oversight to natural persons who have the necessary competence, training and authority; the literacy record for those persons should be cross-referenced to the human oversight design. The fifth is a short Article 4 policy, one to two pages, that names an owner, describes the cycle, and states how contractors and agency staff are covered. Together these give a regulator or a customer a coherent answer in under an hour.

The Turkish overlay

Türkiye has no AI-literacy statute, but three domestic sources point the same way and can be served by the same record. The Personal Data Protection Authority’s Recommendations on personal data protection in AI ask developers and deployers to build competence and awareness in the teams that design and use AI processing personal data. The Authority’s data security guidance under Article 12 of Law No. 6698 lists staff training and awareness among the administrative measures a controller is expected to take, and inspectors ask for training records in breach investigations. And the Occupational Health and Safety Law No. 6331 (Article 17) requires employers to give workers health and safety training, in particular when new technology is introduced; whether AI-specific risks such as automation bias and over-reliance fall within it is a matter of interpretation, but the same training record serves both purposes. A single training programme, with a module for EU AI Act duties and a module for KVKK, satisfies all of them and avoids two parallel calendars. A Turkish company that also holds ISO/IEC 42001 certification or is working towards it will find the same records required by that standard’s competence clause.

How much is enough

Proportionality is the answer the Commission gives and the answer the Omnibus reinforced. A ten-person startup deploying a general-purpose assistant for drafting needs a two-hour onboarding module, an acceptable-use rule, a record, and an annual refresher. A company providing a high-risk system needs role-specific technical training for developers on the risk-management, data-governance and logging requirements, operational training for the people exercising human oversight, and management-level briefings, all evidenced. What both need is the same five documents, sized differently. What neither can afford is nothing: since the Omnibus, the literacy duty is easier to meet and harder to excuse.

Does a vendor’s certificate that its tool is “AI Act compliant” discharge our Article 4 duty?

No. The vendor’s compliance concerns the system; Article 4 concerns your people. A vendor’s training materials can be part of your measures, but the record of who was trained, on what and when is yours to keep.

Do we have to train employees who never touch an AI system?

Article 4 is addressed to staff and other persons dealing with the operation and use of AI systems. General awareness for everyone is good practice and helps with shadow-AI risk, but the legal duty is role-based; document the scoping decision.

Is the Commission’s “living repository” of practices binding?

No. It is a collection of voluntary examples from companies and public bodies, useful as a benchmark for what peers consider proportionate, not a standard against which you will be judged.

Related: AI literacy · human oversight · AI Act document set · AI Compliance Hub.

Sources. Regulation (EU) 2024/1689 (AI Act), Articles 2, 3, 4, 26 and 99, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI); European Commission, AI Literacy – Questions & Answers (updated 27 July 2026); European Commission, Living repository on AI literacy; KVKK, Recommendations on personal data protection in AI; Law No. 6698 (Article 12); Occupational Health and Safety Law No. 6331 (Article 17). Statute links open the official Turkish texts on mevzuat.gov.tr.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on AI and algorithm law, or book a call directly.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 25 September 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.