AI literacy after the Digital Omnibus: from threshold to demonstrable measures
Since 27 July 2026 Regulation (EU) 2026/1744 amends Article 4 of the AI Act. AI literacy remains an organisation-wide duty, but as a demonstrable effort.
You must now document which AI literacy measures your organisation has put in place for each role that works with AI systems, and be ready to demonstrate those measures to supervisors and auditors. A general awareness campaign will not satisfy the requirement.
The prompt is an analysis of 24 August 2026 of the shift in Article 4 of the AI Act from outcome standard to effort standard, which argues that organisations no longer need to meet a measurable literacy threshold but must instead show they have taken deliberate, documented steps to support AI literacy across their workforce. The regulation entered force on 27 July 2026 as part of Regulation (EU) 2026/1744, the Digital Omnibus on AI. In our assessment, this change makes the duty harder to discharge, not easier: you now carry the burden of proof that your measures exist, fit your systems and roles, and are actually being followed.
What has actually changed in the requirement?
The AI Act has required organisations to ensure sufficient AI literacy since 2 February 2025. The amendment shifts the legal standard from an outcome — a measurable level of literacy — to an effort standard: you must take measures to support its development. This sounds like a relaxation, but the obligation itself remains in place and enforcement begins from 3 August 2026. What changes is what you must be able to show a regulator or auditor. You no longer have to prove your workforce has reached a particular competency threshold. You do have to prove you have designed, deployed and recorded training and awareness measures that fit the systems, the roles and the risks your organisation faces.
Which roles and workflows need different learning objectives?
The requirement is not one-size-fits-all. Those who configure an AI system, those who may include its output in a decision or document, and those who must oversee a high-risk system all need different competencies. A person who uses AI output in a high-trust workflow needs to understand the risks, recognise bias, interpret confidence signals and avoid automation bias. Someone who deploys or configures the system needs technical knowledge of its capabilities and limits. A general awareness campaign cannot meet these different needs.
The European data protection authorities have made clear that AI literacy is not a standalone training activity but a precondition for meaningful human oversight under Article 14 of the AI Act. Those who must oversee a high-risk system need the necessary competencies to do so properly. On that reading, literacy and oversight are inseparable.
What concrete measures must you be able to demonstrate?
- Record which AI competencies each role requires — define per job profile whether basic understanding, risk awareness, bias recognition, confidence interpretation, logging or oversight capability is needed.
- Link training to specific workflows — determine per workflow which training or exercise is mandatory before an AI system is deployed in that context.
- Document the measures taken — keep records showing that the training or preparation you identified has actually been delivered to the people who need it.
- Maintain audit visibility — be able to show during an internal or external audit which person completed which preparation for which AI system and when.
- Connect literacy to oversight tasks — demonstrate that those who oversee high-risk systems have received preparation that equips them to recognise and respond to the specific risks those systems pose.
What are the failure modes if you do not act?
- Undifferentiated training — running a single awareness campaign and assuming it covers all roles and workflows.
- No audit trail — having training in place but no records linking it to individual roles, systems or workflows.
- Disconnection from oversight — training people in AI literacy but not connecting it to the human oversight duties they must perform.
- Reliance on vendor materials — assuming that referring staff to a user manual or vendor documentation satisfies the requirement.
- No role-based design — treating all staff as needing the same level and type of AI competency regardless of how they work with systems.
How can you make this demonstrable without building a new system?
The hardest step is making the link between person, role, AI system and competence visible at the level of the individual workflow. Most organisations have training programmes but lack the visibility to show an auditor that a specific person received specific preparation before working with a specific system on a specific task.
A verification layer can help document and keep auditable which measures belong to which role and which workflows, and show that those measures have been recorded. It does not provide the training itself. What matters is that you can show the architecture: per high-trust workflow, who works with the AI system, which literacy measures belong to that role, and how that is recorded towards internal audit and supervisory authorities.
The professional judgement always remains with the human who works with the system. Precisely for that reason, that person must understand the language, the limitations and the risks of AI. In 2026, AI literacy is no longer a compliance checkbox but an embedded programme that enables your organisation to design and demonstrate high-trust AI workflows responsibly.
No tool can guarantee that your measures are sufficient or that your staff will apply them correctly. What a tool can do is make the measures visible, keep them auditable and help you show a regulator that you have thought through which competencies each role needs and how you are building them. The final accountability for whether your measures work remains yours.
Sources: This article draws on reporting and guidance from European Commission and EDPB.
Written by
Elena Kovač
Follows EU policy as it turns from consultation into enforceable requirement.