← All articles
6 min read

AI literacy in your organisation: what the AI Act asks and how to show it

Regulation

In short

  • AI literacy is a legal duty for every organisation that uses AI, including teams that only use ChatGPT or Copilot. Since the Digital Omnibus, you must take measures that support your people's AI skills; you no longer have to guarantee a particular level.
  • No certificate is required. You do need to be able to show what you have done: which AI is in use, who needs what knowledge, and who has been trained.
  • Treat it as a four-step programme, as the Dutch Data Protection Authority suggests, rather than a one-off training.

AI literacy means that the people who work with AI in your organisation know enough to do so responsibly: what a model can do, where it goes wrong, and what you should never put into it. Article 4 of the EU AI Act requires organisations to work on this. That applies even if you only use off-the-shelf tools such as ChatGPT or Copilot (European Commission, 2026).

The key condition: the law asks for effort, not a result. Since the Digital Omnibus took effect on 27 July 2026, you must take measures to support the development of AI literacy. You are not required to guarantee that any individual reaches a specific level (Regulation (EU) 2026/1744). For an organisation with hundreds of staff, that is still real work. Below: what exactly is asked of you, how to approach it in four steps, and what to record.

This article is not legal advice. It is our translation of the rules into the day-to-day reality of organisations that want to use AI widely.

What does Article 4 still require?

The amended Article 4 says that providers and deployers of AI systems take measures to support the AI literacy of their staff, and of others who work with AI on their behalf, such as contractors and temporary staff. In doing so you take three things into account:

  • who they are: their technical knowledge, experience, education and training;
  • where it happens: the context in which the AI system is used;
  • who is affected: the people the system says something about or decides on.

Almost every organisation is what the law calls a deployer: you do not build the AI, you use it. So the duty also covers a team that uses Copilot to summarise emails. The European Commission explicitly mentions the risk that a model makes things up (European Commission, 2026).

Since 2 August 2026, supervision sits with national market surveillance authorities. They can sanction a breach, but according to the Commission any penalty must be proportionate to the case. So do not expect a wave of fines, and do not assume nobody is looking either. For the other changes in the Omnibus, read EU AI Act 2026: a delay for high risk, not for transparency.

Why a single training course falls short

An organisation that buys one e-learning module for everyone has done something. But it skips exactly what the law asks for: taking role, context and risk into account. A recruiter who uses AI to sort CVs needs different knowledge from a colleague who tidies up meeting notes with Copilot. The Dutch Data Protection Authority (AP) puts it plainly: not everyone needs to know the same, but anyone working with a system must understand its risks (AP, 2025).

There is a practical reason too. Knowledge without agreements fades. If people leave a course not knowing which tool they may use and with which data, they fall back on whatever they use at home. So the case for AI literacy is not only legal. It is the difference between scattered experiments and AI that is part of how work gets done.

A four-step approach to AI literacy

In its guide Aan de slag met AI-geletterdheid (in Dutch), the AP sets out a multi-year action plan in four steps. In a larger organisation it looks like this:

  1. Identify. List all AI in use, including tools people switched on themselves. Your GDPR record of processing activities is a good starting point. For each tool, record who uses it and what effect it has on customers, applicants or colleagues. Take a baseline of current knowledge, for example with a short survey.
  2. Set goals. Decide per group what people need to be able to do. A workable split is three levels: everyone (what AI is, what is and is not allowed), people who use it daily (using it well in their own field), and people who decide on or buy AI (risk, policy, trade-offs). The higher the risk of a system, the higher the level.
  3. Deliver. Run training per level and per role, and put the agreements in an acceptable use policy: which tools, which data, who checks the output. The AP also suggests naming an owner, such as an AI officer, so the topic does not fall between the cracks.
  4. Evaluate. Repeat the baseline, for instance once a year, and adjust the goals. AI moves fast, so what was enough last year may fall short now.

The AP adds four preconditions: the board adopts the plan, there is a budget, responsibility is assigned, and progress is reviewed at fixed moments. Without those, it remains the pet project of one enthusiastic department.

How do you demonstrate AI literacy?

You do not need a certificate. The European Commission says an internal record of training and other initiatives is enough (European Commission, 2026). In practice, a solid file contains:

  • the inventory of AI systems, with users and risk per system;
  • the split into levels: who needs to know what, and why;
  • the acceptable use policy, with its date and who approved it;
  • for each session: date, content and an attendance list;
  • the results of the baseline and of each evaluation;
  • the name of the owner, and when the board last discussed it.

This is not paperwork for its own sake. The same file shows internally what the effort delivers, and which departments are lagging behind.

E-learning or workshop?

Both have their place. The difference lies in what each achieves.

E-learningTailored workshop
Best forbasics at scaleapplying it to real work
Role and contextgenericper team or role
Recordautomaticattendance list
Behaviour afterwardsvariespractised on own work

In a large organisation a combination usually works best: short basics for everyone, and in-depth sessions in groups for those who use AI daily or make decisions about it.

What this is not about

AI literacy is no reason to slow AI down. The AP itself says it helps organisations seize opportunities as well as limit risks. If your organisation uses AI to assess people, for example in recruitment, credit or healthcare, the AI Act asks more than literacy from December 2027 onwards. This article covers the duty that applies to everyone.

Where to start this month

Start with step 1. An overview of which AI is used, and by whom, takes little time and shows straight away where the risks are. The rest follows fairly naturally.

Want to run it as a programme, from baseline to role-based training and agreements that stick? See our approach to AI literacy for organisations, or start with the Getting started with AI workshop for the basics, or the leadership session for the board.

Sources

Frequently asked questions

Do you need an AI literacy certificate?
No. According to the European Commission, an internal record of training and other initiatives is enough. A certificate can be useful, but the law does not require one.
Does AI literacy apply if we only use ChatGPT or Copilot?
Yes. You are still a deployer and must take measures. The European Commission gives the example that staff should know a model can make things up.

Let us begin

Want this in your own organisation?

We build it, or we teach your team to. Either works.