EU AI Act Article 4 AI Literacy After the Digital Omnibus
What the Literacy Duty Requires Now, and What It Never Proved

This article is for educational purposes and does not constitute legal advice. Organizations subject to the EU AI Act should consult qualified counsel about their specific obligations.
The AI literacy obligation now says, in terms, that it does not require any individual to be AI literate.
The Literacy Duty Got Weaker in the Week Everyone Was Watching
August 2, 2026 was the date two years of readiness programs were built around. It arrived on schedule and delivered less than the calendars promised.
Six days earlier, the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force. Published in the Official Journal on July 24 and in force from July 27, it rescoped the AI Act's application timetable and replaced the text of Article 4.
Most compliance attention went to the deferrals. The Annex III high-risk block, including the human oversight duty in Article 14, moved from August 2026 to December 2, 2027. Annex I product-safety high-risk moved to August 2028. What actually became applicable on August 2 was narrower than the planning decks assumed: the Article 50 transparency tier, and the general application of everything not expressly deferred, including the Member State penalty framework.
Article 4 was already in force. It has applied since February 2, 2025. What changed in July is what it asks for.
What Article 4 Says Now
As replaced by the Digital Omnibus, Article 4(1) requires providers and deployers to take measures supporting the AI literacy of their staff and other persons operating AI systems on their behalf. Those measures must account for technical knowledge, experience, education and training, the context of use, and the persons or groups the systems are used on.
Then comes the sentence that was not there before. The obligation expressly does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
Article 4(2) puts a support duty on the Commission and Member States, particularly toward smaller organizations, with practical compliance examples to be published on the single information platform. Article 4(3) directs the AI Board to adopt recommendations that account for European competence frameworks.
Read plainly: the duty is to run the program. It is not a duty to produce a person who can do the thing.
What Moved and What Did Not
| Provision | Status as of August 2026 |
|---|---|
| Article 4, AI literacy | In force since 2025-02-02. Text replaced 2026-07-27 by Regulation (EU) 2026/1744 |
| Article 50, transparency | Applicable 2026-08-02. Marking duty for pre-existing generative systems from 2026-12-02 |
| Article 99, penalties | Applicable 2026-08-02 for the provisions then in application |
| Article 14, human oversight, and the rest of Annex III high-risk | Deferred to 2027-12-02 |
| Annex I product-safety high-risk | Deferred to 2028-08-02 |
Provision-by-provision status tracked at EveryAILaw, a free index of AI regulations and part of the PAICE Portfolio.
Two errors are easy to make here, and they run in opposite directions. Treating August 2026 as the moment high-risk duties began overstates the position by sixteen months. Treating the deferral headlines as a general delay understates it: transparency was not delayed, and the penalty framework is live.
Both errors were live the week the date landed. Signals & Subtractions episode 6, recorded with litigation attorney Michael Simon, walks the in-force position jurisdiction by jurisdiction and argues that for a US operator the December 2027 EU date deserves less weight than the state chatbot statutes already biting. That is a fair challenge to the emphasis here, and it is a challenge about priority rather than substance. The Article 14 duties still arrive, and the evidence they ask for still takes time to build.
A Completed Literacy Program Proves Attendance
Organizations that finished their literacy initiatives before August have a defensible record. Curriculum, delivery, attendance, assessment scores, role coverage, refresh schedule. Under a duty framed as taking measures, that record answers the question the regulation asks.
It does not answer the question the work asks.
A licensed professional receives a model output that is fluent, well structured, internally consistent, and wrong in one load-bearing detail. The relevant facts about that moment are whether they noticed, whether they checked the detail against a source, whether they rejected the output or corrected it, and whether anyone above them heard about it. A completion certificate is silent on all four.
This is the same gap that shows up whenever a training record is asked to serve as behavioral evidence, and it is not specific to Europe. Regulatory readiness is not AI literacy makes the general argument. The Omnibus amendment makes it concrete: the regulation itself now declines to require the individual outcome.
Why the Softer Duty Raises the Behavioral Question
The obvious reading is that a weaker Article 4 lowers the bar. The timetable says otherwise.
Article 14 becomes applicable on December 2, 2027. For high-risk systems it requires that oversight be exercised by natural persons who understand the system's capacities and limitations, monitor for anomalies and dysfunctions, remain aware of automation bias, interpret output correctly, decide not to use or to override or reverse an output, and intervene or halt operation. Article 26(2) requires deployers to assign persons with the necessary competence, training, and authority.
Those are behavioral descriptions. They are about what a named person can be shown to do while the system is running.
A literacy program completed in 2026 does not generate that showing. It generates a record that the program happened. Sixteen months from now, an organization with a strong training archive and no behavioral evidence will be asked how it knows the person assigned to oversight can actually detect an anomaly, and the archive will not contain the answer.
The Omnibus made Article 4 cheaper to satisfy and left Article 14 waiting. The gap between the two is where the next two years of governance work sits.
What Closes the Gap
Nothing in Article 4 requires behavioral assessment, and this piece is not claiming that it does. The literacy duty is a support-measures duty and can be met with support measures.
The claim is narrower and about evidence rather than law. If an organization wants to know, in advance of December 2027, whether the people it plans to assign to oversight roles can detect and escalate unreliable output under operational pressure, training records will not tell it. Behavioral evidence will.
PAICE (People + AI Collaboration Effectiveness) measures that one thing: what an operator does when the AI is uncertain, incomplete, or wrong. It observes verification, rejection, correction, and escalation behavior, and it produces scores rather than transcripts. It is not a literacy program, not a certification, and not a substitute for one.
The regulatory citation churned again this summer. The behavior it eventually asks about did not move at all.
Want to know whether your people hold verification under pressure? Take the PAICE assessment to see it firsthand, or learn about organizational baselines.
Recommended Reading
- Regulatory Readiness Is Not AI Literacy - Why training certificates and regulatory evidence are different artifacts
- Why AI Training Programs Aren't Working - What completion rates hide
- PAICE vs. AI Literacy Tests - Knowledge assessment compared with behavioral observation
- The Federal AI Framework Was Rewritten Twice - The same pattern in US federal guidance
- The EU AI Act on EveryAILaw - Provision status, dates, and duty holders as currently in force
Curious but short on time?
Take the 3-minute PAICE Pulse — a quick confidence check that maps how you see your own AI collaboration posture. No login required.