The Digital Omnibus has been overtaken on AI literacy by EN 18286 diluting its changes with concrete competence requirements.
In the EU AI Act (Regulation (EU) 2024/1689), Article 4 originally required providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. This was framed as a practical obligation: people involved needed the skills, knowledge and understanding to make informed decisions about AI deployment, recognise opportunities and risks, and handle harms appropriately. It applied broadly (with proportionality) and has been in force since 2 February 2025.
The Digital Omnibus on AI (the AI-focused part of the broader Digital Omnibus package proposed by the European Commission on 19 November 2025) set out to simplify implementation of the AI Act. After political agreement in trilogue on 7 May 2026, European Parliament approval in mid-June and final Council endorsement at the end of June, the package softens Article 4. Providers and deployers must now "take measures to support the development of AI literacy" of their staff and relevant people. Crucially, they are not required to guarantee any specific level of literacy for any individual. Responsibility for fostering literacy is shifted more toward the Commission and Member States, who must support and facilitate efforts and publish practical examples. The change moves the duty closer to an obligation of means than of result.
On paper this looks like meaningful deregulation or simplification. In practice, for AI literacy it is a damp squib, an anticlimactic fizzle. The real operational pressure for proper, documented competence has been overtaken and, in the areas that matter most, strengthened by a newly published European standard.
EN 18286 arrives at the decisive moment
EN 18286:2026, Artificial intelligence - Quality management system for EU AI Act regulatory purposes, was published on 22 July 2026 by CEN-CENELEC. It is the first major AI-specific harmonised standard designed to give providers of high-risk AI systems a clear, auditable pathway to meet Article 17 of the AI Act (the quality management system obligation). Once cited in the Official Journal of the European Union it will confer a presumption of conformity.
The standard is product- and lifecycle-oriented. It requires organisations placing high-risk AI systems on the market or putting them into service to establish, implement, maintain and continually improve a QMS covering regulatory compliance strategy, management responsibility, risk management, data governance, verification and validation, technical documentation, supplier management, post-market monitoring, serious incident reporting and change management.
Within the support processes (aligned with typical management-system structure, including elements corresponding to competence under Clause 7-type requirements), EN 18286 is explicit: providers must implement procedures that ensure core personnel competency through education, training and evaluation. Evidence of ongoing qualifications and the effectiveness of training must be maintained. Roles and responsibilities must be assigned only to personnel with relevant experience; a compliance manager (or equivalent) is designated; and all roles, authorities and reporting lines must be documented and communicated. Competence is defined in the standard's terms as the ability to apply knowledge and skills to achieve intended results.
This is not the vague, organisation-wide "AI literacy" of the original (or now softened) Article 4. It is targeted, role-specific, risk-proportionate competence for the people designing, developing, validating, overseeing, monitoring and maintaining high-risk AI systems-the very systems where inadequate literacy poses the greatest risk of harm to fundamental rights, safety and health.
Why the Omnibus changes are overtaken
High-risk AI systems are the core of the AI Act's protective regime. For these systems, Article 17 QMS obligations remain fully in force (subject only to the delayed application dates agreed in the Omnibus). Organisations seeking the practical benefits of a harmonised standard, streamlined conformity assessment, clearer auditability, reduced legal uncertainty, will implement EN 18286. That implementation necessarily includes robust, documented competence and training arrangements that go well beyond merely "supporting" literacy.
In short:
- The Omnibus dilutes the horizontal Article 4 duty that applied to all AI systems.
- EN 18286 operationalises a vertical, auditable competence requirement inside the QMS for the systems that regulators, courts and the market will scrutinise most closely.
- The standard therefore restores, and in many cases intensifies, the practical demand for proper AI literacy precisely where it is most needed.
Commentators and practitioners had already noted the complementarity: Article 4 builds broad organisational awareness; Article 17 and its supporting standard embed specialised, measurable competence into high-risk processes such as risk management, human oversight and data governance. With the standard now published, that complementarity becomes a compliance reality rather than an aspiration.
Organisations that treated the Omnibus as permission to scale back AI literacy programmes will find themselves out of step with the standard that will shape conformity assessments, notified-body expectations and, ultimately, market access for high-risk systems. Those that continue (or begin) treating literacy and competence as foundational elements of AI governance, supported by training records, competency matrices, effectiveness evaluations and continuous improvement, will be aligned with both the spirit of the original AI Act and the concrete requirements of EN 18286.
A damp squib, not a sea-change
The Digital Omnibus delivered useful timeline relief and some administrative simplifications. On AI literacy, however, its changes are largely symbolic. By the time the Omnibus text is fully in force, the technical specification that actually governs how providers must manage the quality of high-risk AI systems already contains a clear, enforceable expectation of proper competence. That expectation is harder to ignore than a softened horizontal obligation, because it sits inside the QMS that underpins presumption of conformity.
In the end, EN 18286 has rendered the Omnibus's literacy concessions largely moot for the AI systems that matter most. The Omnibus has been overtaken by a standard that insists on genuine capability. Organisations serious about trustworthy AI would do well to treat the new standard as the real benchmark for AI literacy.