SecurityTechInsider AI security & governance
EN/ NL
Governance

AI Omnibus drops minimum AI literacy level

The AI Omnibus dropped the minimum AI literacy level from mid-July 2026, but left article 50 transparency in place from 2 August 2026.

23 September 2026 4 min
Illustration for this article: AI Omnibus drops minimum AI literacy level. The cut edges of a thick stack of blank paper, fanned slightly, raking light along the fibres.
Organisations must now tailor AI literacy measures to context and risk rather than meeting a prescribed standard, whilst meeting transparency obligations from 2 August 2026. Image: SecurityTechInsider — original editorial illustration

You must now demonstrate that your organisation's AI literacy measures are appropriate to the knowledge, experience, training, use context and persons affected by each system, rather than meeting a prescribed minimum standard. You have until 2 December 2026 for certain transparency markings on generative AI systems placed before 2 August 2026, but other article 50 transparency obligations took effect on 2 August 2026.

The prompt is an analysis of 23 September 2026 of the AI Omnibus and its amendment to article 4, which argues that the removal of a prescribed AI literacy level leaves organisations to substantiate context-specific measures instead. The European Commission confirmed on 27 July 2026 that the Omnibus entered into force and amended article 4 to remove the specified minimum competence threshold whilst retaining the obligation itself. In our assessment, the practical consequence is that you shift from demonstrating a measurable threshold to building a defensible case that your literacy measures fit the risk profile, sensitivity and personnel involved in each workflow—whilst simultaneously meeting transparency obligations that became enforceable from 2 August 2026.

What does article 4 now require you to do?

Article 4 remains in force. The amendment removed the prescribed "sufficient" level for individuals but did not withdraw the obligation itself. Providers and deployers must take measures that account for knowledge, experience, education, the context of use and the persons to whom systems are applied. The AI Office confirmed that this obligation does not require you to measure the knowledge level of every employee or to hold certificates. Instead, you must be able to show that the measures you have taken are tailored to the risk and the people involved.

Which failure modes does this create?

  • Undocumented or generic training — applying the same literacy programme to all staff regardless of their role or the sensitivity of the systems they touch.
  • Absence of context mapping — failing to connect literacy measures to specific workflows, data types or decision points.
  • No audit trail of substantiation — having training records but no documented reasoning for why those measures are appropriate to your risk profile.
  • Conflation of general literacy with high-risk oversight — treating the relaxed article 4 requirement as if it replaces the specific human oversight training that high-risk systems still demand.
  • Delayed or incomplete transparency marking — missing the 2 December 2026 deadline for machine-readable marking of certain generative AI systems placed before 2 August 2026.

How do you substantiate appropriateness?

  1. Document the system, its purpose and the data it handles — record which AI model each workflow uses, the lawful basis for the data it processes, and the persons or groups affected by its outputs.
  2. Map literacy measures to role and context — specify what training, experience or knowledge each person working with the system needs, and why that level is appropriate to the decisions or data involved.
  3. Keep internal records of training and accompanying initiatives — maintain evidence of the measures you have taken, including dates, content and participants.
  4. Connect literacy substantiation to AI governance controls — link your literacy measures to documented oversight procedures, particularly for high-risk systems, so that training and oversight form a coherent control framework.
  5. Review appropriateness when systems, roles or risks change — treat substantiation as a living record, not a one-time exercise, and update it when you deploy new systems or change how existing ones are used.

Do high-risk systems have separate requirements?

Yes. The removal of the prescribed minimum AI literacy level does not affect the obligation to provide appropriate training for human oversight of high-risk AI systems. That requirement stands independently. If you deploy high-risk AI, you must be able to demonstrate two separate but complementary tracks: general AI literacy measures tailored to your context and risk, and specific preparation for the humans who make or oversee high-risk decisions. The human oversight training requirement does not disappear because the general literacy threshold has been relaxed.

What guidance exists to help you comply?

The European Commission and member states are required to provide support and practical examples. The AI Board must develop recommendations with common objectives. Until those exist, the burden of substantiating appropriateness lies with your organisation. You should document the reasoning behind your literacy measures—why they are sufficient for the roles, systems and data involved—and keep that reasoning accessible to internal audit and to regulators if required. For work with sensitive information, connecting that substantiation to demonstrable control over AI use and a verification layer for sensitive workflows strengthens your position.

Tools can help you track training completion, map systems to personnel and maintain audit logs. What they cannot do is make the judgement about what is appropriate to your specific risk profile, data sensitivity and operational context. That remains your responsibility as the organisation deploying the system.

Sources: This article draws on reporting and guidance from Europese Commissie — Shaping Europe's digital future.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.