Javascript is required
logo-dastralogo-dastra

AI literacy: why Omnibus changed the rules without changing the date

AI literacy: why Omnibus changed the rules without changing the date
Zelie Aderic
Zelie Aderic
September 7, 2026·9 minutes read time

The “AI Omnibus” agreement, formally adopted by the Council on 29 June, has pushed back several milestones under the Regulation. For many organisations, this news has been welcomed as a broad relief: more time, less pressure.

However, that impression is only partly accurate. Several legally binding obligations have applied since February 2025, including one in particular that the AI Omnibus did not postpone.

Since 2 February 2025, the European Regulation on Artificial Intelligence (AI Act) has imposed an obligation that is still not widely known, but which is cross-cutting: AI literacy, as provided for in Article 4 of the AI Act. In practical terms, any organisation that develops or uses artificial intelligence must take measures to support the development of an appropriate level of AI literacy among its staff. This is often the first concrete obligation that companies encounter under the AI Act.

What is AI literacy?

AI literacy, also referred to as artificial intelligence literacy or AI literacy, refers to the set of skills needed to understand, use and supervise AI systems in an informed manner.

This is not about turning everyone into a data scientist capable of designing AI models or mastering machine learning, but about giving each employee the reference points needed to work with these new technologies knowingly, rather than treating them as a “black box”.

This literacy should in particular make it possible to understand the capabilities and limitations of an AI tool, identify the risks linked to an AI application, and know under what conditions AI can contribute to decision-making.

What Article 4 requires, as amended by the AI Omnibus

An obligation already in force

Article 4 of the AI Act requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff and any other persons dealing, on their behalf, with the operation and use of AI systems.

This obligation therefore concerns in particular operators and deployers of AI systems and applies regardless of the risk level of the system concerned. It has been in force since 2 February 2025.

What is too often overlooked is that this Article has already entered into force and was not postponed by the AI Omnibus. As a result, many organisations are delaying their compliance work on AI literacy and acculturation, even though it has already been in force since February 2025.

Moreover, from 2 August 2026, the national market surveillance authorities began monitoring organisations’ compliance with this Article, among others.

AI literacy after the AI Omnibus

The original text required organisations to “ensure a sufficient level” of AI literacy, which amounted to a result obligation.

The text as amended by the AI Omnibus, which entered into force at the end of July 2026, now requires them to “take measures to support the development” of that literacy, which amounts to an obligation of means.

The obligation has not been removed and the February 2025 application date has not changed, but its legal nature has shifted from a guarantee to a demonstrable effort.

It is easy to read this as an obligation quietly fading away. That is not the case. What changes is the standard against which an organisation’s efforts will be assessed, not the very existence of the obligation to make an effort.

Who is affected, and since when?

The obligation has applied since 2 February 2025 to all providers and deployers of AI systems, regardless of size or sector.

Unlike other obligations under the AI Act, it is not limited to high-risk systems: once an organisation uses AI, it must take appropriate measures to develop the AI literacy of the people who handle it.

This applies both to employees who use generative AI on a daily basis and to those involved in more technical AI projects involving AI models, machine learning, or specialised systems.

A risk linked to insufficient AI literacy: Shadow AI

Insufficient AI literacy generally produces a well-known side effect: Shadow AI, meaning the use of AI tools by employees without oversight from IT, legal or compliance teams.

This phenomenon is reminiscent of the older problem of Shadow IT, while also carrying risks specific to AI: leakage of sensitive data through unsecured external AI tools, unauthorised data transfers, increased exposure to data breaches, litigation and reputational damage.

Shadow AI should above all be read as an early warning signal: a sign that the pace of AI adoption within an organisation has outstripped the pace of its governance.

Two illustrative cases

  • An internal security incident at a major electronics manufacturer, where engineers shared proprietary source code with a public AI conversational agent, exposing that code outside the company.
  • A legal risk area identified within an international law firm, which had to issue internal guidelines on the use of AI after some lawyers proved unable to justify the sources underlying AI-assisted legal research.

A practical approach, grounded in the Commission’s guidance

The good news is that the level of requirement is genuinely proportionate, and organisations do not have to guess what regulators expect. The European Commission has published a permanent FAQ on AI literacy, which sets out a minimum approach without imposing a rigid model. It can be summarised in four steps.

  1. First, develop within the organisation a general understanding of what AI is, how it works, and the ways in which it is actually used. Many organisations are still unable today to answer this precisely.
  2. Second, identify the organisation’s role: does it develop AI systems, or does it merely use systems developed by third parties? AI literacy needs differ between a provider and a deployer.
  3. Third, assess the risk level of the AI systems concerned, since staff using a system in the context of HR decisions need a different level of understanding from those using a simple general-purpose writing assistant.
  4. Fourth, build concrete measures on the basis of that analysis, tailored to the technical knowledge, experience and usage context of each group. In practice, this usually translates into a short list of manageable actions: a documented training session for staff exposed to AI systems, differentiated between technical and non-technical audiences; a written internal policy describing acceptable uses, etc.

AI literacy according to risk level

The risk level should also guide the content of the training, not just its intensity.

The Commission’s guidance gives a telling example: employees using a general-purpose tool such as ChatGPT to draft marketing copy or translate content must still understand specific risks such as hallucination, even though the tool is not high-risk.

Deployers of high-risk systems also have an additional, related obligation under Article 26, namely to ensure that staff are trained to exercise human oversight. This obligation should be integrated into the same programme rather than treated separately.

How do you become compliant? A 5-step approach

  • Assess existing levels: map who uses AI and how well, by profile.
  • Segment needs: executives, technical teams, support functions and business users do not need the same skills.
  • Build training programmes covering the fundamentals: how AI and AI models work, capabilities and limitations, bias, prompt engineering, the regulatory framework (AI Act, GDPR) and ethical considerations.
  • Embed through practice: test real use cases — drafting, data analysis, automation of repetitive tasks — to understand AI’s strengths and limits. This approach also helps better understand how to support the development of AI literacy within teams.
  • Document and maintain: keep a record of actions taken (content, participants, dates) as evidence of compliance, and ensure regular updates in light of fast-evolving AI projects.

The Commission has clarified that no certificate is required, that no dedicated AI officer or governance committee is imposed, and that simply reproducing an already published training programme does not, by itself, guarantee compliance. What matters is that the measures are real, proportionate to the organisation’s actual use of AI, and sufficiently documented to be produced if requested by a regulator.

AI literacy and governance: a common foundation

Literacy is not limited to one-off training: it underpins the entire AI governance framework. Teams that are aware of the issues are better at identifying risky systems, feeding the AI systems register and applying the other obligations more easily (transparency, human oversight, impact assessments). They also foster better decision-making and responsible day-to-day use of AI. Dastra’s AI governance solution helps structure this approach across the organisation.

AI Literacy FAQ

What is AI literacy?

It is the set of skills that make it possible to understand, use and supervise artificial intelligence (artificial intelligence / AI) in an informed way: how models work, capabilities, limitations, bias, prompt engineering and ethical considerations. Article 4 of the AI Act makes it an obligation.

Since when has the AI literacy obligation applied?

Since 2 February 2025, at the same time as the prohibitions under Article 5.

Who is covered by Article 4 of the AI Act?

All providers and deployers of AI systems, regardless of size or sector, and not only high-risk systems.

How can compliance with the literacy obligation be demonstrated?

By documenting the training programmes implemented: content, participants, dates, and regular updates.

Does AI literacy concern only technical teams?

No. It concerns everyone who uses AI or supervises its use, at a level adapted to each role (executives, lawyers, support functions, business users).


See Dastra in action

In just a few minutes, schedule a personalized demo and discover how Dastra can adapt to your organization.

Ask for a demo
Subscribe to our newsletter

We'll send you occasional emails to keep you informed about our latest news and updates to our solution

* You can unsubscribe at any time using the link provided in each newsletter.