Skip to main content
OkayLoop
Compliance Operations

AI Literacy Training After the EU AI Act Omnibus

The Digital Omnibus rewrote Article 4 of the EU AI Act. Here is how to run a proportionate, role-based AI literacy program and keep a record that holds up.

Translucent blue and orange ribbons representing AI literacy spreading across different roles
By

Maya Chen is a fictional OkayLoop editorial persona representing the recurring perspective of compliance operations leaders. Articles are reviewed by the OkayLoop editorial team.

The EU AI Act’s AI literacy duty has applied since 2 February 2025. In July 2026, the Digital Omnibus on AI—Regulation (EU) 2026/1744—rewrote it. The amended Article 4 asks providers and deployers to take measures to support the development of AI literacy among their staff and others operating AI systems on their behalf. It also states that organizations are not required to guarantee a specific level of AI literacy for any individual.

Some teams have read that change as permission to stop. That is the wrong lesson. The duty remains, national market surveillance authorities are responsible for supervising it, and the European Commission’s AI literacy questions and answers notes that relying only on a system’s instructions for use is generally not enough. What changed is the shape of a good answer: a reasonable, documented effort matched to how your organization actually uses AI.

This article is practical guidance, not legal advice. Confirm your obligations with counsel and check the consolidated text of the AI Act on EUR-Lex before relying on specific wording.

What changed, and what did not

QuestionBefore the OmnibusAfter the Omnibus
Who is covered?Providers and deployersProviders and deployers
What is expected?Ensure, to the best extent, a sufficient level of AI literacyTake measures to support the development of AI literacy
Is an individual level guaranteed?Implied by “sufficient level”Expressly not required
Is a certificate required?NoNo
Do high-risk deployers have extra duties?Yes, for human oversightYes, on the postponed high-risk timeline

The practical shift is from an obligation of result toward an obligation of effort. Effort still has to be visible. If an AI-related incident occurs, the organization should be able to show what it did, for whom, and why that was proportionate.

1. Start with an AI use inventory

You cannot design proportionate literacy measures for AI use you have not identified. Before writing any training, list:

  • approved AI tools and the business owner of each;
  • the teams and roles that use them;
  • the data each tool may and may not receive;
  • whether your organization is acting as a provider, a deployer, or both;
  • uses that influence decisions about people, such as hiring, performance, or access to services; and
  • known unapproved use that needs a decision, not silence.

The inventory does not need to be perfect on day one. It needs an owner and a review date. Treat it as a controlled document in the same way you would treat an approved policy.

2. Segment audiences by exposure, not by job title

Literacy needs differ sharply between someone who occasionally summarizes a meeting and someone who reviews AI-assisted hiring recommendations. Group people by what they do with AI.

AudienceTypical exposureLiteracy focus
All staffGeneral assistants, AI features in everyday toolsApproved tools, data boundaries, checking outputs, reporting concerns
Frequent usersDrafting, analysis, research, customer communicationVerification, disclosure, confidentiality, recognizing unreliable output
Builders and technical teamsIntegrating models, prompts, data pipelinesTesting, logging, change control, documentation, security
Decision-influencing rolesHR, finance, eligibility, risk scoringBias, contestability, when human judgment must override
Human oversight rolesAssigned oversight of high-risk systemsCompetence, authority, and support for the specific system

The last row deserves separate attention. Deployers of high-risk AI systems have a distinct duty to assign human oversight to people with the necessary competence, training, and authority. Following the Omnibus, most stand-alone high-risk obligations now apply from 2 December 2027. That date is planning time, not a reason to defer the design.

3. Define outcomes as decisions

“Understand AI” is not a learning outcome. Write each outcome as a decision an employee should be able to make correctly.

  • “Before pasting text into an assistant, I can tell whether it contains personal or confidential data and what to do instead.”
  • “I can explain why an AI-generated summary must be checked against the source before it is sent to a customer.”
  • “I know which AI uses in my team require approval and who grants it.”
  • “If an AI-assisted recommendation about a person looks wrong, I know I can and should override it, and how to record why.”

Decision-based outcomes keep content short, make scenario questions easier to write, and produce results you can actually interpret. For scenario ideas, adapt the cases in AI acceptable-use policy training scenarios.

4. Build from your own policy, not a generic course

Generic AI awareness content explains what large language models are. Your employees also need to know what your organization allows. Anchor every lesson to an approved internal source: an AI acceptable-use policy, a data classification standard, or a procedure for a specific tool.

Use the same review discipline you apply to any policy learning:

  1. Extract one concept at a time from the approved source.
  2. Draft a short explanation and a role-specific scenario.
  3. Have the policy owner confirm the meaning has not changed.
  4. Record the approved version before assignment.

The workflow in turning dense policies into knowledge applies directly. If AI helps draft the lesson, the review step matters more, not less.

5. Keep a proportionate internal record

The Commission’s Q&A indicates that an internal record of training and other initiatives is generally sufficient and that no certificate is needed. A useful record answers the questions a supervisor, auditor, or internal reviewer is likely to ask:

  • which AI use inventory version the program was based on;
  • which audiences were defined and by what rule;
  • which approved materials each audience received, and in which version;
  • when assignments were made, completed, or remediated;
  • which concepts produced repeated misunderstanding, and what changed as a result; and
  • what triggers a refresh, and when the program was last reviewed.

Completion alone is weak evidence of effort. Concept-level comprehension results show that the organization looked for gaps and acted on them. See how to prove employees understood a policy for a fuller evidence chain, and from policy approval to audit evidence for the end-to-end workflow.

6. Refresh on change, not on the calendar

AI use changes faster than most annual training cycles. Define refresh triggers in advance:

  • a new tool is approved or an existing one gains significant new capability;
  • a new use case moves into decision-influencing work;
  • an incident or near miss involves AI;
  • the AI acceptable-use policy or data rules change; or
  • comprehension results show a persistent gap in one audience.

Short, targeted updates respect employees’ time better than re-running a full course. They also produce a clearer record of responsiveness.

A 60-day starting plan

WindowFocusOutput
Days 1–15Inventory and rolesOwned AI use inventory, provider/deployer determination
Days 16–30Audiences and outcomesAudience rules, decision-based outcomes per audience
Days 31–45Content and reviewApproved lessons and scenarios tied to source policies
Days 46–60Launch and recordAssignments, first comprehension results, documented refresh triggers

After launch, review results with the policy owner and security lead. The first round will expose ambiguous rules as often as it exposes employee gaps; fix both.

The bottom line

The Omnibus lowered the bar from guaranteeing literacy to genuinely supporting it. A proportionate program—grounded in an inventory, segmented by exposure, built from your own rules, and recorded clearly—meets that bar and reduces real AI risk at the same time.

If you are building this alongside existing policy training, see how compliance teams use OkayLoop to run role-based policy learning, or book a demo with your AI acceptable-use policy in hand.

Reviewed by OkayLoop Editorial.

Bring one policy and one training goal.

See how the policy-to-learning workflow fits your audience, review process, and program requirements.

Book a Demo