Basic AI literacy will no longer be a compliance requirement in the future. Article 4 of the AI Act takes effect on February 2, 2025, simplified by an amendment under Article 4 of the Omnibus Regulation in July 2026, which means that providers and operators of AI systems should have already taken steps to promote basic AI literacy among their employees and others who operate or use AI systems on their behalf.

The AI Act, which entered into force in August 2026, amended the standard but did not eliminate the obligation. The new approach is more flexible and, in our view, better reflects how companies actually use AI.

What has changed?

Under the amended Article 4, providers and deployers must take measures to support the development of AI literacy. When deciding what those measures should look like, companies should consider the technical knowledge, experience, education and training of the people involved, the context in which they use AI and the persons who may be affected by that use.

The important change is that companies no longer have to guarantee that each individual reaches a specific or “sufficient” level of AI literacy. This distinction matters. There is no single level of AI knowledge that makes sense for everyone in an organization.

An employee using a generative AI tool to summarize documents does not need the same knowledge as an HR professional using AI to screen candidates or assess employees. Similarly, employees working with AI in credit, insurance, healthcare or safety-related processes may need considerably more specific knowledge.

The amended Article 4 therefore supports a proportionate and role-based approach: what people need to know should depend on what they actually do with AI.

What should companies do?

Check the 5 practical steps to get started on AI literacy: (link hategandigital.com)

A useful starting point is not necessarily an organization-wide AI course. Companies should first understand who uses AI, which systems they use, for what purpose and what risks arise from that use.

Employees using generally available generative AI tools may need practical guidance on confidentiality, personal data, intellectual property, hallucinations and verification of AI-generated outputs. Employees involved in more sensitive uses may require specific training on the limitations of the system, discrimination, automation bias, human oversight and applicable internal procedures.

AI literacy also does not mean training alone. Depending on the organization, appropriate measures may include internal AI guidelines, tool-specific instructions, restrictions on certain uses, verification procedures or targeted communications.

Article 4 does not require a specific certificate, AI officer or governance structure. Companies have flexibility in choosing their approach. However, they should be able to show what they have actually done. Internal guidelines, training materials, attendance records and communications to employees can provide useful evidence of the measures implemented.

The Commission and Member States must also support these efforts, particularly for SMEs. The Commission will publish practical compliance examples on the Single Information Platform, while the AI Board will develop recommendations and common objectives. Existing practices are already available in the Commission's AI literacy repository, although following them does not automatically create a presumption of compliance.

Who checks compliance?

The AI Office does not supervise compliance with Article 4. This responsibility belongs to the national market surveillance authorities. The European enforcement framework became applicable in August 2026, meaning that AI literacy has moved from an obligation on paper to one that authorities can supervise and enforce.

This makes documenting the measures taken increasingly relevant. If an authority asks how a company has addressed AI literacy, the company should be able to explain its approach and show how it reflects its actual use of AI.

What is the situation in Romania?

Romania is still completing the national framework needed to enforce the AI Act.

Through a Government Memorandum, ANCOM has been proposed as the national market surveillance authority and single point of contact, alongside other authorities that will supervise specific sectors. The national legislation currently under development must establish their respective responsibilities, cooperation mechanisms and the procedure and sanctions applicable to AI Act infringements.

ANCOM has clarified that Romanian authorities will be able to verify and sanction non-compliance with the AI Act only after the national implementing legislation enters into force.

Companies should not interpret this temporary enforcement gap as additional time for compliance. The Article 4 obligation already applies.

For organizations that have not yet addressed AI literacy, now is the time to identify how AI is actually used, determine who needs guidance and introduce proportionate measures. Building an AI inventory, defining internal rules and training different teams according to their real exposure takes time.

The standard may now be more flexible, but the obligation remains. And true compliance cannot be built overnight.