Blog

AI literacy after the Digital Omnibus: from threshold to demonstrable measures

Since 27 July 2026 Regulation (EU) 2026/1744 amends Article 4 of the AI Act. AI literacy remains an organisation-wide duty, but as a demonstrable effort.

· Victor Angelier

Since 27 July 2026 Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, has been in force. The regulation amends, among other things, Article 4 of the AI Act, the article that deals with AI literacy. According to the analysis by Licentium, the text shifts from an outcome standard — ensure a sufficient level of AI literacy — to an effort standard: take measures to support its development. That sounds like a softening, but the obligation itself remains in place. For organisations working with AI, what mainly changes is what they must be able to demonstrate.

This shift is relevant because the duty has already applied for some time. The official AI Literacy Q&A of the European Commission confirms that Article 4 has applied since 2 February 2025, that the text was amended after the Omnibus, and that supervision and enforcement begin from 3 August 2026. The Commission is clear about it: there is no one-size-fits-all, and merely referring to a user manual is not sufficient.

From an abstract threshold to concrete measures

The practical analysis by Casys sums up the essence clearly: whereas the old text asked for a result — a sufficient level — the new text asks for measures. This means that organisations no longer have to meet a measurable literacy threshold, but must demonstrably show which training and awareness measures they have put in place.

The analysis by PAICE confirms, after entry into force, that the duty affects all providers and users of AI systems and that it concerns a documentable effort obligation. The measures must fit the systems, the roles and the risks: aligned with knowledge, experience, level of training, context of use and the persons on whom the systems are used.

In practice this means that a general awareness campaign is insufficient. Those who may configure an AI system, those who may include output in a file, and those who may intervene in a high-risk system, all have different learning objectives. That differentiation by role and use case is precisely what the new text makes visible.

Why supervisory authorities see AI literacy as a governance layer

That the duty is not non-committal is also apparent from the joint opinion of the EDPB and EDPS. In their Joint Opinion 1/2026 on the Omnibus proposal, the European data protection authorities explicitly warned against deleting or weakening the AI literacy duty. They see literate employees and supervisors as a precondition for properly weighing the benefits and risks of AI — an accountability instrument, not a standalone training.

Casys and PAICE also make the connection with human oversight under Article 14 and Annex III. Those who must oversee a high-risk system need the necessary competencies for it: understanding risks, recognising bias, being able to interpret confidence signals and avoiding automation bias. On that reading, AI literacy is a precondition for meaningful oversight, not a separate activity alongside it.

Making AI literacy verifiable in high-trust workflows

For organisations working with sensitive or high-trust information, this translates into a concrete design. Recording per job profile which AI competencies are needed: basic understanding, risk awareness, bias recognition, interpretation of confidence, logging and oversight. Determining per workflow which training or exercise is mandatory before AI is deployed. And, during an audit, being able to demonstrate that those measures have actually been taken.

Making that demonstrable is the hardest step. Not because trainings are lacking, but because the link between person, role, AI system and competence is rarely visible at the level of the individual workflow. Here a verification layer such as IamVera.ai can support. Vera is not a chatbot and not its own language model; it is a verification layer for professionals working with confidential information. Vera can route a task through selected independent AI models and make verification steps, corrections, mutual differences and sources visible for inspection. This supports review and control, but does not guarantee correct output.

In the context of Article 4, the visibility around a workflow is especially relevant: per high-trust workflow it can be shown who works with the AI system, which AI literacy measures belong to that role and how that is recorded towards internal audit, supervisory authorities and clients. Vera does not provide the training itself, but can help document the organisational measures and keep them auditable. Anyone who wants to know more about that control architecture can find explanations of the verification steps and the privacy pre-processing.

That pre-processing and anonymisation take place on EU infrastructure and are designed to send only anonymised content to the selected AI models; when a privacy check fails, nothing is sent onward. That is an architectural choice, not a legal guarantee of full GDPR compliance.

What organisations can do now

The message from the sources is consistent: the Digital Omnibus does not relieve organisations of responsibility, but shifts the emphasis to demonstrable, role- and risk-related measures. Concretely, that means: defining learning objectives per role, linking them to human oversight tasks and recording per workflow which preparation is required. The professional final judgement always remains with the human who works with the system — precisely for that reason, that person must understand the language, the limitations and the risks of AI. In 2026, AI literacy is no longer an awareness campaign but an embedded programme that enables organisations to design and demonstrate high-trust AI workflows responsibly.

← All articles