AI Assurance Institute Logo AI Assurance Institute

AI Literacy under the EU AI Act:
Obligations, Competence and Quality Management Systems

AI Literacy and QMS Training Series

AI literacy is one of the earliest operational obligations under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). Article 4 has applied since 2 February 2025. It requires providers and deployers of AI systems to take measures that support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. The obligation is organisation-wide in scope, applies to AI systems of all risk levels, and is not limited to high-risk deployments.

The Digital Omnibus on AI (Regulation (EU) 2026/1744), which entered into force in July 2026, amended the wording of Article 4. Providers and deployers must still take measures to support the development of AI literacy, taking into account technical knowledge, experience, education and training, the context in which the AI systems are used, and the persons or groups on whom the systems are used. Critically, the amended text makes clear that organisations are not required to guarantee any specific level of AI literacy for any individual. Responsibility for fostering literacy is shared more explicitly with the Commission and Member States, which must support and facilitate efforts and publish practical examples.

This change softens the horizontal obligation. It does not, however, remove the need for structured competence where high-risk AI systems are concerned. EN 18286:2026 � the European standard on quality management systems for AI Act regulatory purposes � embeds concrete expectations around competence, awareness and training inside the Quality Management System required by Article 17. For organisations placing high-risk AI systems on the market, literacy and role-specific competence remain operational necessities, not optional extras.

What Article 4 Requires in Practice

Article 4 applies to both providers and deployers. It covers staff and any other persons who deal with the operation or use of AI systems on the organisation�s behalf. The measures taken should be proportionate to the context of use and to the knowledge and experience of the people involved.

The Regulation defines AI literacy as the skills, knowledge and understanding that allow providers, deployers and affected persons to make informed decisions about the deployment of AI systems, and to gain awareness of the opportunities and risks of AI and the possible harm it can cause. In practical terms this includes the ability to recognise when an AI system is being used, to understand its intended purpose and limitations, to identify potential risks to health, safety or fundamental rights, and to know how to escalate concerns or intervene where human oversight is required.

Supervision and enforcement of Article 4 fall to national market surveillance authorities. Formal supervisory powers apply from 2 August 2026 onwards. There is no general SME exemption. Smaller organisations remain in scope, although the measures they take can and should be proportionate to their size and to the nature of the AI systems they provide or deploy.

The Digital Omnibus Amendment and Its Limits

The Omnibus amendment was driven by practical concerns. Stakeholders argued that a rigid duty to ensure a �sufficient� level of literacy for every individual created disproportionate burden, particularly for smaller enterprises, and was difficult to demonstrate in a uniform way. The revised wording shifts the emphasis from guaranteeing individual outcomes to taking supporting measures, while placing a clearer supporting role on public authorities.

That shift should not be read as permission to abandon literacy programmes. The obligation to take measures remains. Organisations that can show no structured activity � no training, no awareness materials, no role-based guidance, no records of who has received what � will still struggle to demonstrate compliance. The change reduces the risk of being held to an undefined individual competency standard; it does not eliminate the expectation that providers and deployers actively support literacy development.

Competence inside the Quality Management System

For high-risk AI systems the picture is tighter. Article 17 requires providers to establish, implement, document and maintain a Quality Management System. EN 18286:2026 elaborates that system in detail. Competence, awareness and training form part of the support processes expected within a compliant QMS.

In a high-risk context, general AI literacy is the foundation. Role-specific competence sits on top of it. Personnel involved in risk management, data governance, design and development control, testing and validation, human oversight, post-market monitoring and serious-incident handling need knowledge and skills matched to their responsibilities. EN 18286 treats competence as a managed process: organisations must determine the necessary competence, ensure that people are competent on the basis of appropriate education, training or experience, take actions to acquire and maintain competence where gaps exist, and retain appropriate documented information as evidence.

This is where the softened horizontal Article 4 obligation and the more concrete QMS requirements diverge. An organisation may satisfy the amended Article 4 with proportionate supporting measures. The same organisation, if it places high-risk AI systems on the market, will still need documented competence management for the roles that operate the QMS and the AI systems themselves. Training records, competency matrices, effectiveness evaluations and continual improvement of competence processes become part of the evidence base for conformity assessment.

Role-Specific Literacy and Training Design

Effective programmes distinguish between audiences. Board and senior management need sufficient understanding to set direction, allocate resources and oversee residual risk. AI developers and data scientists need deeper technical and ethical literacy, including bias, data quality, robustness and documentation practices. Human oversight personnel need clear protocols for intervention, escalation and recording of decisions. Compliance, legal and Quality Management System managers need to understand how literacy and competence requirements interact with Articles 4, 9, 14, 15 and 17 and with EN 18286:2026.

Training should be contextual. Generic awareness modules are useful as a baseline; they are rarely sufficient on their own for people who design, operate or oversee AI systems that can affect health, safety or fundamental rights. Role-based scenarios, practical exercises linked to the organisation�s own systems, and periodic refreshers aligned with system changes or incident learning produce more durable capability than one-off generic courses.

Evidence, Records and Continual Improvement

Under both Article 4 and the QMS framework, records matter. Organisations should be able to show what measures they have taken, who was covered, how content was tailored to roles and context, and how effectiveness is reviewed. For high-risk systems these records form part of the documented information retained under the Quality Management System. They support internal audit, management review and, where applicable, external conformity assessment.

Continual improvement applies equally to literacy and competence. As systems change, as new risks emerge, and as regulatory expectations evolve, training content and competency requirements should be revisited. Lessons from post-market monitoring, serious incidents and near-misses should feed back into awareness and role-specific programmes.

Practical Implications for Organisations

Organisations should treat AI literacy as an ongoing operational responsibility rather than a one-time compliance project. A proportionate approach typically includes:

For providers of high-risk systems, alignment with EN 18286:2026 competence requirements provides a structured route that serves both Article 4 supporting measures and Article 17 QMS obligations. For deployers and for organisations operating only lower-risk systems, a lighter but still documented set of supporting measures remains necessary under the amended Article 4.

Conclusion

AI literacy under the EU AI Act is both a horizontal obligation and, for high-risk systems, a component of the Quality Management System. The Digital Omnibus softened the individual-level guarantee in Article 4; it did not remove the duty to take measures, nor did it dilute the competence expectations that sit inside EN 18286:2026 and Article 17.

Organisations that continue to treat literacy and competence as foundational elements of responsible AI management � supported by training records, role-based programmes, effectiveness evaluation and continual improvement � remain aligned with both the spirit of the original AI Act and the concrete requirements of the Quality Management System standard. Those that interpret the Omnibus change as a reason to scale back structured programmes risk falling short of what market surveillance authorities, conformity assessment bodies and, ultimately, the evidence demands of the wider regulatory framework will expect.

Content based on the EU AI Act (Regulation (EU) 2024/1689) as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744), EN 18286:2026, and official Commission guidance available as of mid-2026. Always consult the official texts and qualified legal advice for implementation. This article examines AI literacy as both a horizontal obligation and a competence requirement within Quality Management Systems for high-risk AI.