Explainer
    Concepts
    Concepts

    Part of The company brain: where your organization's knowledge lives

    AI literacy: what the AI Act asks of employees, management and supervisors

    AI literacy is knowing what AI can do, what it can't and where the risks are. What the AI Act still requires after the Digital Omnibus, and how to approach it by role.

    Max van Genderen6 min read
    Share on
    AI literacy: what the AI Act asks of employees, management and supervisors

    AI literacy is the knowledge and skill to use AI responsibly: knowing what an AI application can do, what it can't, where the risks are and when you need to use your own judgement. Article 4 of the EU AI Act asks organisations to support AI literacy among everyone who works with AI on their behalf.

    This obligation has caused confusion. The Digital Omnibus softened the wording in 2026, and some conclude that AI literacy is no longer needed. That is a misunderstanding, both legally and practically. This article explains what applies now, why it matters more in practice than in law, and how to approach it by role.

    What the law requires now

    Article 4 has applied since 2 February 2025.1 Originally, organisations had to take measures to ensure a sufficient level of AI literacy among their staff.

    The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026)2 softened that wording. Organisations must now take measures to support the development of AI literacy. An obligation of result has become a best-efforts obligation. Member states and the European Commission also get a role in promoting it, for example through training and information materials.

    What hasn't changed:

    • The obligation still exists. You must demonstrably do something; only the level you reach is no longer prescribed.
    • High-risk AI carries heavier requirements. Anyone overseeing a high-risk system must have the necessary competence, training and authority to do so.
    • The transparency obligation still applies. People must know when they are dealing with AI. That requires your employees to recognise it themselves and be able to explain it.

    Read more about the timeline in What is the EU AI Act?.

    NIS2 also requires training. Under the Dutch Cybersecurity Act, the national implementation of NIS2, executives of organisations in scope must have enough knowledge to assess cyber risks and complete appropriate training.3 Combine it with AI literacy, because the risks overlap. See NIS2 and the Dutch Cybersecurity Act: what your data and AI layer must be able to prove.

    Why it matters more in practice than in law

    The legal wording has become softer. The risks have not. Four things go wrong when employees don't understand how AI works.

    They trust answers that sound right. A language model gives a convincing answer, even when it's wrong. Anyone who doesn't know AI can make things up checks nothing.

    They put sensitive data in a prompt. Pasting a customer contract into a public chatbot is a data breach. Anyone who doesn't know where a prompt goes doesn't see the risk.

    They use tools nobody knows about. Shadow AI doesn't come from bad intent but from helpfulness. Employees pick the tool that works, and nobody has explained which tools are allowed.

    They don't use it. The opposite happens too. People who don't understand AI distrust it or ignore it. Then an application delivers nothing and hits a stop rule. See Stop rules for AI.

    So AI literacy is not a compliance topic but an adoption topic. It determines whether your investment in AI pays off.

    What AI literacy means by role

    Not everyone needs the same thing. An employee who asks questions of company data needs different knowledge from a supervisory board member overseeing the AI register.

    RoleNeeds to knowNeeds to be able to
    EmployeeWhat the application does and doesn't do; that AI can make things up; which data not to put in a prompt; which tools are allowedCheck an answer against its source; report an error; recognise when their own judgement is needed
    Application ownerThe purpose and limits of the application; the stop rules; how quality is measuredAssess feedback; monitor thresholds; decide to pause
    Management and executivesThe AI Act risk categories; where AI runs in the organisation; what the business case promisesPrioritise applications; set stop criteria; decide on sensitive data sources
    Board and supervisory boardThe governance framework; the legal duties under the AI Act, NIS2 and GDPR; their own responsibilityAsk the right questions; assess a quarterly overview; probe a vague answer

    For executives and supervisors, AI literacy is mainly the ability to ask the right questions. See Five questions a supervisory board can ask about AI every quarter.

    What goes into good training

    A general course on "what is AI" is a start, but not enough. The best training covers the applications your organisation actually uses. Six topics belong in it:

    1. How it works, in plain language. A language model predicts text. It knows nothing unless you give it the right information, and it can be confidently wrong.
    2. Where an answer comes from. Can the user see which source and which definition an answer is based on? If not, it's advice, not fact.
    3. What you don't share. Personal data, confidential contracts and customer data only go into approved applications.
    4. When to use your own judgement. The system advises, a human decides. No decision about a customer or employee based on AI alone.
    5. How to report an error. A feedback button nobody uses is not a feedback mechanism. Show what happens with a report.
    6. What is allowed. Which tools may be used, for what, and where is that written down?

    An approach in five steps

    1. Start with the AI register. Which applications are running, and who uses them? That determines who needs which training.
    2. Write a one-page usage policy. Which tools are allowed, which data may go in and what is prohibited. Short enough to actually be read.
    3. Train by role, on the applications people actually use. An hour of practice with your own application is worth more than a day of theory.
    4. Record who has done what. Under a best-efforts obligation, you must be able to show what you've done. A simple record per employee and role is enough.
    5. Repeat it. AI changes quickly, and so do your applications. Plan an annual refresher, plus an extra session with every new application.

    Literacy starts with traceable answers

    You can teach employees to check AI answers. But that only works if they're able to. If an AI answer doesn't show which source it came from and which definition was used, there is nothing to check.

    That's why AI literacy is also a data question. A platform where every answer can be traced to its source and definition, and where AI never shows more than the user may see, makes critical use possible. Without that foundation, you are asking employees to check something that can't be checked. See Implementing AI: why it almost always fails on your data.

    Frequently asked questions

    Is AI literacy still mandatory after the Digital Omnibus? Yes. The obligation has been softened from ensuring a sufficient level to supporting its development. So you must demonstrably take measures, but there is no prescribed end level.

    Who does it apply to? Everyone who works with AI systems on behalf of your organisation. That includes employees, but also contractors and others who use AI on your behalf.

    Is an e-learning module enough? Perhaps as a start. Training on the applications people actually use, with a clear usage policy, is far more effective and easier to demonstrate.

    Do executives and the supervisory board need training too? Under the AI Act, it concerns people who work with AI. But anyone overseeing AI must be able to ask the right questions, and NIS2 already requires training for executives. A short annual session for the board and supervisory board is wise.

    Where do you start? With the AI register and a one-page usage policy. Then you know who needs which training. Request a foundation scan.

    Next step

    Want to see what's already inside your organization?

    Leave your details. We'll reach out and plan a scan. Within thirty days you'll see one concrete result.

    No newsletter, no reselling. Just this conversation.

    Comments

    Comments are reviewed by the editors before they appear.

    Use your Google or Apple account, or your business email address.

    Sign in to comment