By Rafael Luque Ocaña

AI literacy: what Article 4 requires now that the Omnibus rewrote it

Article 4 required measures to ensure a sufficient level of literacy. The Digital Omnibus replaced it: now the measures must support its development, and the article itself denies that anyone's specific level has to be guaranteed.

AI literacy is the first obligation under the AI Act that reaches any company using AI, whatever the risk level of its systems. It has been in force since February 2025 and doesn't depend on having anything classified as high-risk.

It's also the worst-described one, because the article that establishes it no longer says what it used to say.

What it used to say, and what it says now

The original text of Article 4 required providers and deployers to “take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”.

Regulation (EU) 2026/1744 — the Digital Omnibus — replaced the entire article. The wording in force reads:

“Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.

That last sentence wasn't there before, and it's unusual: the article itself expressly denies that this is an obligation of result. There's no need to interpret the change — the legislator wrote its scope into the text itself.

What actually changes, and what doesn't

The type of duty changes. From adopting measures to ensure a level to adopting measures to support development. The first is measured by the outcome in people; the second, by what the organisation does.

The subject doesn't change. It still reaches providers and deployers. If your company uses AI in its operations, it applies to you exactly as before.

The adequacy criterion doesn't change. The article still provides that the measures are taken “taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in” and the persons on whom the systems are used. It isn't generic training: it's proportionate to who uses what, and on whom.

And the obligation doesn't disappear. This is worth stating plainly, because the lazy reading of the change is "there's nothing left to do." The article still says “shall take measures”. What it no longer requires is proving a level reached by each person.

Why it was relaxed

The Regulation itself explains why: experience showed that a solution imposing “stringent obligations to ensure a sufficient level” of AI literacy was not suitable for all types of operators, and that imposing them created an additional compliance burden particularly for smaller enterprises — while AI literacy should be a strategic priority regardless of regulatory obligations.

In other words: it was relaxed because the previous formula asked a twenty-person company for something it could neither measure nor had any reason to measure. Not because the matter stopped mattering.

What this means in practice

The difference between the two wordings isn't cosmetic, and it shows in what you'd be asked to produce.

With the old formula, the natural question was “what level does your staff have?” — a question almost no SME could answer without setting up assessments.

With the one in force, the question is what measures the organisation adopted, for whom, and why those ones. That can be answered, and it's answered with a record: what was done, when, who took part, and what criterion was followed to decide those measures were the right fit for the context.

And that's exactly the kind of thing that separates ticking a box from having evidence: a certificate of attendance at a generic course proves there was a course. A record stating which systems each team uses, which measure was taken for each profile and on what criterion, proves there was a decision.

The error this change produces

There are two ways to describe Article 4 wrong today, and both are in circulation.

"It requires you to guarantee your workforce's training." It was almost true under the previous text, and today the article's own closing sentence contradicts it. It's the same kind of error as the Annex III date or the marking grace period: a statement that was accurate and stopped being so without the sentence itself changing.

"It no longer requires anything." That's the opposite error, and it comes from reading only the last sentence. The article still imposes the duty to adopt measures, on the same subjects, with the same proportionality criterion.

Between the two sits what the text actually says: an obligation of means — alive, enforceable, and adaptable to the size of the organisation.

What's worth having

Three things, and none of them is a corporate training plan.

Who uses what. You can't adopt measures proportionate to the context without knowing which systems each team uses. It's the same inventory that serves every other purpose.

Which measure was taken for each profile, and why that one. The "why" is what turns a list of courses into a defensible decision.

When it was reviewed. Because staff change, systems change and — as this very article shows — the rule changes too. A measure adopted two years ago for tools that are no longer in use proves nothing.

None of the three requires a training platform. They require the answer to be written down, dated, and kept somewhere it will still be when someone asks.

Content in line with Article 4 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.