By Rafael Luque Ocaña

Article 4 AI Literacy after the Omnibus: the obligation softens, the diligence doesn't

The Digital Omnibus rewrites Article 4 in a less demanding tone. That doesn't mean AI literacy stops mattering. It means exactly the opposite of what alarmist messaging sells.

Update, 27 July 2026: Regulation (EU) 2026/1744 was published in the Official Journal of the EU (OJEU) on 24 July 2026 and has been in force since 27 July 2026. This article's references to the Omnibus as a proposal describe the situation as of its publication date. The new wording of Article 4 — an obligation of means: it “does not require providers or deployers to guarantee any specific level of AI literacy of any individual” — is the version in force from that date.

Article 4 of the AI Act has, for months, been the most-cited hook for talking to an SME about compliance: "if your team uses AI, you need to be able to show that it knows how to use it." That's still true. But the Digital Omnibus has touched the wording of this article, and the nuance deserves an honest explanation, because it marks the difference between serious governance and a fear-based pitch.

What Article 4 says, and since when

The AI literacy obligation has been in application since 2 February 2025. It isn't a future obligation. It requires providers and deployers to take measures to ensure their staff — and anyone operating the systems on their behalf — have a sufficient level of AI competence, taking into account their knowledge, the context of use, and the people the systems are used on.

In an SME, this translates into something concrete: the person responsible for making sure staff know how to use the AI they deploy is not the software manufacturer. It's the organisation itself. A clinic using an AI system to read X-rays, a distributor with an office-productivity copilot on every desktop: in both cases, the training and its evidence fall on whoever deploys the tool.

What changes with the Omnibus

The Digital Omnibus softens the language of Article 4. Where the original text speaks of ensuring a sufficient level of literacy, the new wording moves towards a mandate to promote and facilitate literacy institutionally, with measures proportionate to the organisation. In parallel, it strengthens the role of the Commission and the Member States in supporting and facilitating that effort.

It's a change of intensity, not of direction. The obligation of "result" (ensuring) moves closer to one of "means" (promoting with proportionate measures). The literal wording was settled with publication in the Official Journal of the EU on 24 July 2026 (Regulation (EU) 2026/1744, in force since the 27th): the Article “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”.

Why this doesn't let you off the hook for anything that matters

This is where I separate the analysis from the noise. The verb shifting from "ensuring" to "promoting" doesn't mean literacy stops mattering. It means three things:

First, the obligation still exists. A mandate to promote with proportionate measures is still a mandate. An organisation that cannot show a single measure — no policy, no training, no record — isn't promoting anything.

Second, the logic of diligence doesn't change. The value of having an AI use policy, a systems inventory, and evidence of training was never "because otherwise you'll be fined tomorrow." It was, and still is, being able to show that you acted with sound judgement the day someone — an authority, a client running an audit, an insurer renewing your policy — asks how you govern your AI.

Third, "proportionate" isn't "optional". The proportionality standard is measured against the risk of your systems. An SME that only uses low-exposure AI can meet the obligation with light-touch measures. A clinic processing health data with AI support, or a company starting to use AI in decisions about people, isn't in the same position. The softening of Article 4 benefits those with less risk, not those with more.

2 August is still on the calendar

One fact the softening of Article 4 doesn't touch: the supervision machinery has applied since 2 August 2025 (Chapter VII governance and the penalties regime), and 2 August 2026 brings the first obligation that reaches most deployers directly: Article 50 transparency. The literacy obligation has been in force since February 2025, and the scenario in which someone can ask you to demonstrate it is already open.

What to document, proportionately

For most SMEs, meeting Article 4 credibly looks like this:

  • An AI use policy adapted to the organisation: which systems are authorised, which are prohibited, what to do when a result looks anomalous.
  • An inventory of the AI systems actually in use (including AI that arrives through software updates without anyone registering it).
  • Evidence of training: who received what, when, on which systems. You don't need a master's degree; you need traceability.

None of this is a seal or a certification of anything. It's documentation that's reviewed and auditable, ready if an inspection ever arrives. And precisely because the Omnibus lowers the formal bar, it makes more sense than ever to do it properly and without dramatics: an organisation that documents its diligence proportionately is in a solid position, without needing to buy peace of mind.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.