The AI literacy obligation: what Swiss companies must now train
There is an AI obligation that reaches almost every larger organisation and is still rarely discussed: not the classification of high-risk systems, but the competence of the people who operate AI. Since 2 February 2025, Article 4 of the EU AI Act requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff. It is the broadest single obligation in the entire regulation, because it applies regardless of the risk tier.
This article is a general explainer, not a legal opinion and not legal advice. As of July 2026. Check the current state of the relevant primary source before you act.
What the obligation requires
Article 4 of the EU AI Act (in force since 2 February 2025, source: EUR-Lex and artificialintelligenceact.eu/article/4) requires every provider and every deployer of an AI system, regardless of that system’s risk classification, to ensure a sufficient level of AI literacy among the people working with the system on their behalf. What counts, per the regulation, is those people’s prior knowledge, experience and training. The obligation covers not only permanent employees but also contractors and everyone who operates an AI system on the organisation’s behalf.
Enforcement sits with the national market surveillance authorities. Their competence for Article 4 applies from August 2026 (source: European Commission, “AI literacy Q&A”, digital-strategy.ec.europa.eu). Until then the obligation already applies, without a designated authority checking it systematically.
Who it hits in Switzerland
Switzerland has, as of July 2026, no dedicated AI law of its own. The EU AI Act does not apply here directly. It does have extraterritorial reach through its Article 2: a Swiss company falls within scope if it places an AI system on the EU market as a provider or deployer, or if the output of its AI system is used in the EU. That is a condition, not a blanket rule. A company operating solely within Switzerland and without any EU nexus is not caught by Article 4.
In practice: first check whether any of your AI applications touches the EU market, for instance through customers, products or data flows in the EU. If it does, the literacy obligation has applied since February 2025.
FINMA: an expectation, not a statute
For the supervised financial sector, a second thread comes into play. On 18 December 2024, FINMA published Supervisory Notice 08/2024, “Governance and risk management in the use of artificial intelligence” (source: finma.ch, News 2024/12/20241218). Important for framing: this is a supervisory expectation directed at supervised institutions, not a statute.
The notice follows a risk-based approach and names operational, data, IT and cyber, legal and reputational risks, along with dependence on third-party providers for models and cloud, and the allocation of responsibility when errors occur. FINMA expects institutions to identify, assess, monitor, manage and control AI risks, whether developed in-house or outsourced. Two concrete expectations stand out: maintain an inventory of all AI applications and classify them by risk, and document the decision paths of the models in a traceable way.
Competence is not an end in itself here. An institution can only manage AI risks if the people who operate and oversee these systems understand what they are doing. An inventory does not fill itself, and a risk classification is only as good as the judgment of the person who performs it.
What appropriate measures look like
Neither Article 4 nor the FINMA notice prescribes a specific curriculum. Article 4 asks for a level that is appropriate to the prior knowledge, experience and context of the given role. That means graduated rather than uniform measures. Three tiers hold up in practice:
- Foundations for everyone who operates AI. What an AI system can do, where it reliably fails, and which inputs and outputs are safe. This covers the breadth of the Article 4 obligation.
- Risk classification for the people responsible. Whoever adds an application to the inventory and rates it needs sound judgment about the risk a use case carries. This is the core of the FINMA expectation for supervised institutions.
- Safe and traceable use for teams that build AI into processes. This is where it is decided whether decision paths stay documentable or the system turns into a black box.
The mechanism behind this is simpler than it sounds. AI speeds up whatever you point it at. Point a competent team at a clean, understood process and quality compounds. Point an unprepared team at an unclear process and the problem compounds, faster and at greater scale. Competence is the difference between those two curves.
What you can do now
Three steps are feasible without a legal department. First, check whether any of your AI applications touches the EU market and whether you are under FINMA supervision. That decides which of the two threads applies to you. Second, build an inventory of your AI applications and assign a risk to each. For supervised institutions this is a named FINMA expectation; for everyone else it is the basis of any sensible literacy measure. Third, graduate your training by role instead of giving everyone the same thing.
Whether an organisation meets a specific regulatory requirement remains a question for its legal advisers and the relevant supervisory authority. The common denominator across all of these requirements stays the same: the competence of the people who operate AI.