AI Literacy Training After the EU AI Act Omnibus
The Digital Omnibus rewrote Article 4 of the EU AI Act. Here is how to run a proportionate, role-based AI literacy program and keep a record that holds up.

Maya Chen is a fictional OkayLoop editorial persona representing the recurring perspective of compliance operations leaders. Articles are reviewed by the OkayLoop editorial team.
The EU AI Act’s AI literacy duty has applied since 2 February 2025. In July 2026, the Digital Omnibus on AI—Regulation (EU) 2026/1744—rewrote it. The amended Article 4 asks providers and deployers to take measures to support the development of AI literacy among their staff and others operating AI systems on their behalf. It also states that organizations are not required to guarantee a specific level of AI literacy for any individual.
Some teams have read that change as permission to stop. That is the wrong lesson. The duty remains, national market surveillance authorities are responsible for supervising it, and the European Commission’s AI literacy questions and answers notes that relying only on a system’s instructions for use is generally not enough. What changed is the shape of a good answer: a reasonable, documented effort matched to how your organization actually uses AI.
This article is practical guidance, not legal advice. Confirm your obligations with counsel and check the consolidated text of the AI Act on EUR-Lex before relying on specific wording.
What changed, and what did not
| Question | Before the Omnibus | After the Omnibus |
|---|---|---|
| Who is covered? | Providers and deployers | Providers and deployers |
| What is expected? | Ensure, to the best extent, a sufficient level of AI literacy | Take measures to support the development of AI literacy |
| Is an individual level guaranteed? | Implied by “sufficient level” | Expressly not required |
| Is a certificate required? | No | No |
| Do high-risk deployers have extra duties? | Yes, for human oversight | Yes, on the postponed high-risk timeline |
The practical shift is from an obligation of result toward an obligation of effort. Effort still has to be visible. If an AI-related incident occurs, the organization should be able to show what it did, for whom, and why that was proportionate.
1. Start with an AI use inventory
You cannot design proportionate literacy measures for AI use you have not identified. Before writing any training, list:
- approved AI tools and the business owner of each;
- the teams and roles that use them;
- the data each tool may and may not receive;
- whether your organization is acting as a provider, a deployer, or both;
- uses that influence decisions about people, such as hiring, performance, or access to services; and
- known unapproved use that needs a decision, not silence.
The inventory does not need to be perfect on day one. It needs an owner and a review date. Treat it as a controlled document in the same way you would treat an approved policy.
2. Segment audiences by exposure, not by job title
Literacy needs differ sharply between someone who occasionally summarizes a meeting and someone who reviews AI-assisted hiring recommendations. Group people by what they do with AI.
| Audience | Typical exposure | Literacy focus |
|---|---|---|
| All staff | General assistants, AI features in everyday tools | Approved tools, data boundaries, checking outputs, reporting concerns |
| Frequent users | Drafting, analysis, research, customer communication | Verification, disclosure, confidentiality, recognizing unreliable output |
| Builders and technical teams | Integrating models, prompts, data pipelines | Testing, logging, change control, documentation, security |
| Decision-influencing roles | HR, finance, eligibility, risk scoring | Bias, contestability, when human judgment must override |
| Human oversight roles | Assigned oversight of high-risk systems | Competence, authority, and support for the specific system |
The last row deserves separate attention. Deployers of high-risk AI systems have a distinct duty to assign human oversight to people with the necessary competence, training, and authority. Following the Omnibus, most stand-alone high-risk obligations now apply from 2 December 2027. That date is planning time, not a reason to defer the design.
3. Define outcomes as decisions
“Understand AI” is not a learning outcome. Write each outcome as a decision an employee should be able to make correctly.
- “Before pasting text into an assistant, I can tell whether it contains personal or confidential data and what to do instead.”
- “I can explain why an AI-generated summary must be checked against the source before it is sent to a customer.”
- “I know which AI uses in my team require approval and who grants it.”
- “If an AI-assisted recommendation about a person looks wrong, I know I can and should override it, and how to record why.”
Decision-based outcomes keep content short, make scenario questions easier to write, and produce results you can actually interpret. For scenario ideas, adapt the cases in AI acceptable-use policy training scenarios.
4. Build from your own policy, not a generic course
Generic AI awareness content explains what large language models are. Your employees also need to know what your organization allows. Anchor every lesson to an approved internal source: an AI acceptable-use policy, a data classification standard, or a procedure for a specific tool.
Use the same review discipline you apply to any policy learning:
- Extract one concept at a time from the approved source.
- Draft a short explanation and a role-specific scenario.
- Have the policy owner confirm the meaning has not changed.
- Record the approved version before assignment.
The workflow in turning dense policies into knowledge applies directly. If AI helps draft the lesson, the review step matters more, not less.
5. Keep a proportionate internal record
The Commission’s Q&A indicates that an internal record of training and other initiatives is generally sufficient and that no certificate is needed. A useful record answers the questions a supervisor, auditor, or internal reviewer is likely to ask:
- which AI use inventory version the program was based on;
- which audiences were defined and by what rule;
- which approved materials each audience received, and in which version;
- when assignments were made, completed, or remediated;
- which concepts produced repeated misunderstanding, and what changed as a result; and
- what triggers a refresh, and when the program was last reviewed.
Completion alone is weak evidence of effort. Concept-level comprehension results show that the organization looked for gaps and acted on them. See how to prove employees understood a policy for a fuller evidence chain, and from policy approval to audit evidence for the end-to-end workflow.
6. Refresh on change, not on the calendar
AI use changes faster than most annual training cycles. Define refresh triggers in advance:
- a new tool is approved or an existing one gains significant new capability;
- a new use case moves into decision-influencing work;
- an incident or near miss involves AI;
- the AI acceptable-use policy or data rules change; or
- comprehension results show a persistent gap in one audience.
Short, targeted updates respect employees’ time better than re-running a full course. They also produce a clearer record of responsiveness.
A 60-day starting plan
| Window | Focus | Output |
|---|---|---|
| Days 1–15 | Inventory and roles | Owned AI use inventory, provider/deployer determination |
| Days 16–30 | Audiences and outcomes | Audience rules, decision-based outcomes per audience |
| Days 31–45 | Content and review | Approved lessons and scenarios tied to source policies |
| Days 46–60 | Launch and record | Assignments, first comprehension results, documented refresh triggers |
After launch, review results with the policy owner and security lead. The first round will expose ambiguous rules as often as it exposes employee gaps; fix both.
The bottom line
The Omnibus lowered the bar from guaranteeing literacy to genuinely supporting it. A proportionate program—grounded in an inventory, segmented by exposure, built from your own rules, and recorded clearly—meets that bar and reduces real AI risk at the same time.
If you are building this alongside existing policy training, see how compliance teams use OkayLoop to run role-based policy learning, or book a demo with your AI acceptable-use policy in hand.
Reviewed by OkayLoop Editorial.