Skip to Content
OPINION

EU AI Act literacy changes may complicate, more than simplify, compliance

The EU AI Act's revised AI literacy requirements may actually increase compliance complexity by replacing a flexible best-efforts standard with external benchmarks.

Published
Subscribe to IAPP newsletters

Contributors:

Diogo Soares

CIPP/E, CIPM

Digital Advisory

BNP Paribas

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.

Remember earlier in 2026 when the European Commission's proposed Digital Omnibus on Artificial Intelligence prompted critics to assert that the EU was being irresponsible in deregulation while others claimed the proposal fell short of practical simplification?

Well, the provisional agreement reached in May 2026 by the European Council and Parliament brought significant changes that have, in their own right, caught the attention of the public. For providers and deployers, the initial focus on postponed high-risk deadlines has made sense. Largely overlooked, the edits to Article 4 of the EU AI Act on AI literacy may do more to reshape day-to-day compliance than the headline-grabbing reforms.

Recall how AI literacy got here. After a year of trilogues in 2024, literacy provisions were reduced from two distinct obligations and two definitions into a single paragraph. Originally, according to the European Parliament's first-reading negotiating position on the AI Act, the Commission and member states were to "promote measures for the development of a sufficient level of AI literacy" while providers and deployers were obliged to "take measures to ensure a sufficient level of AI literacy of their staff and other persons" under Article 4. To note that such sufficient level was one that contributed "to the ability of providers and deployers to ensure compliance and enforcement" of the AI Act.

We might never know why these versions never saw the light of day. But we do know that the former two were condensed into current-day Article 4; the latter was entirely deleted. In their place, Article 4 as enacted in 2024 entrusted only providers and deployers of AI systems with the obligation to take measures to ensure, to their "best extent," a sufficient level of AI literacy. 

Contrast this to the Commission's own proposal, which went further still. It replaced the binding organizational duty with a softer framework in which the Commission and member states would "foster" or "encourage" organizations to ensure AI literacy. The European Data Protection Board and European Data Protection Supervisor pushed back hard in their joint opinion, warning that promotion should complement, not replace, the existing obligation. The argument is nothing if not reasonable — hence, why it prevailed in the compromise text.

If the new Article 4 sounds familiar, that is why. Providers and deployers are again on the hook: They must now take "measures to support the development of AI literacy," while the Commission and member states "support and facilitate" their efforts.

On its face, the change can only be positive: simplification. Organizations that once were left alone in shouldering the education and training of their own staff now have institutional help and a growing official library of extensive documentation on AI literacy. Gone is the duty to ensure literacy. Gone, it seems, is the stringent compliance burden.

But look again at what was removed. Notice the sleight of hand? In an easy-to-miss edit, the revised Article 4 drops the words "best extent." 

Organizations were never answerable for the actual AI literacy of staff; they were answerable for documenting their best effort — an incredibly soft obligation of self-assessment. And while the new Article 4 does clarify that this obligation does not mean providers and deployers must measure the AI knowledge of specific employees, it is also true that the AI Act has more than one article.

Where high-risk systems are concerned, under Article 14, providers must design systems that can be effectively overseen by natural persons while deployers, under Article 26(2), must assign human oversight to natural persons who have the "necessary competence, training and authority, as well as access the necessary support." 

So, deployers must still guarantee a specific level of AI literacy in, at least, a few individuals. And how will these people perform their tasks? In increasingly multidisciplinary work environments, different teams must rely on each other's expertise in such a way that no one can effectively oversee AI systems alone. Can competent humans in the loop fulfill their role when surrounded by colleagues who lack the literacy to support them? 

If an organization's functions cannot back the overseer because they fall short of the literacy mark, then, it might not be in compliance with a more demanding Article 4. Yes, the organization must only "take measures to support the development of AI literacy." But what counts as a sufficient measure will be set by the practical implementation guidance which the Commission will issue. It's not as freeing as it first appeared.

The Council argues the opposite is true: that tying literacy to shared institutional instruments simplifies and harmonizes compliance by pulling the market toward a common standard, and that it even empowers human oversight by spreading the organizational competence a lone overseer needs. 

All the same, the argument refutes itself. You cannot praise a reform as simplification while in the same breath crediting it with raising the bar. An obligation to comply with a standard is, by definition, more demanding than one you could self-assess.

And, as the past few years of data protection guidance instruments teach us, an obligation tied to external instruments can often be more demanding than a self-assessed one. Soft-guidance filling gaps left by legislation often tends to produce more rigorous operational expectations. Indeed, EDPB guidelines became the floor and ceiling of compliant practice. There is little reason to expect a different result from the Commission- and member state-controlled instruments, which have yet to be written, named in the revised Article 4.

In practice, to know if an organization's conduct is enough, its leaders must now read, track and anticipate instruments that are diffuse, evolving and not yet written. Assessing sufficiency becomes harder and puts the Commission and member states in effective control of the benchmark. 

None of this changes the underlying reality that investing in AI literacy is a good business practice. Staff are already using AI; teaching them how to do it safely is a simple and effective way to hedge against existing risk while also promoting responsible adoption. 

The hard part is determining how much is enough. It is fairly challenging to find that sweet spot in a data processing operation. More complexity dressed as simplification will not make it easier.

So don't wait to be told. Organizations should begin to map current AI literacy initiatives and match them to existing best practices, move beyond one-size-fits-all approaches, document efforts with emerging requirements in mind and define their own "enough."

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Diogo Soares

CIPP/E, CIPM

Digital Advisory

BNP Paribas

Tags:

AI literacyLaw and regulationEU AI ActAI governance

Related Stories