citiesabc, first_page
Why AI Literacy Is No Longer Optional: The Business Impact of the EU AI Act
07 Oct 2026

There is a date most compliance teams have in their calendar, and a date almost none of them do.
The first is 2 August 2026: the day national market surveillance authorities across the European Union acquired the power to supervise and enforce the AI Act.
The second is 27 July 2026: six days earlier, when the AI Omnibus entered into force and quietly rewrote Article 4, the AI literacy provision, from an obligation to ensure a sufficient level of AI literacy among staff to an obligation merely to take measures to support the development of such literacy.
Those six days contain the whole strategic problem, and most organisations have not noticed it.
The conventional framing says AI literacy is no longer optional because the law now requires it. That framing is correct in its conclusion but increasingly weak in its reasoning, because the law has required just a little less than it did a few months ago. The individual-level guarantee has gone. The European Commission has confirmed that internal records suffice and that no certification is required. Measuring literacy levels remains explicitly optional.
So if the legal floor is what moves you, the floor has just dropped. And every organisation that built its AI literacy programme to clear that floor is about to discover what it actually bought.
The argument of this article is simple: the regulation got lighter, and the problem got heavier. Those two facts are not in tension. Together, they are the entire story.

What Article 4 actually says
Precision matters here, because the detail is where the strategy lives.
Article 4 applies from 2 February 2025. It binds both providers of AI systems, those who develop and place them on the market and deployers, which is to say anyone using a system supplied by someone else. That second category catches almost every organisation in Europe, because deploying a third-party tool is sufficient. You do not need to build anything.
Its reach extends past employees. The obligation covers “other persons dealing with the operation and use of AI systems on their behalf”: contractors, outsourced service providers, agency staff, and potentially clients operating systems on an organisation’s behalf. It applies to all AI systems, not only those classified as high-risk. And it reaches extraterritorially, to any operation using AI systems in the EU on an organisation’s behalf, which means a company headquartered in London, New York or Singapore is squarely inside its scope the moment its systems touch European operations.
Article 3(56) supplies the definition. AI literacy means “the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems and to gain awareness of the opportunities and risks of AI.”
Read that twice, because it contains two halves, and the second is the one nearly every corporate training programme currently ignores.
Opportunities and risks. Not risks alone. The legislator was explicit that literacy means the capacity to see what AI can do for you as much as what it can do to you. Yet survey the market in Article 4 compliance training, and you find a genre built almost entirely around prohibition: what not to paste into a chatbot, which practices are banned, where the fines sit. All of it is necessary. All of it is radically incomplete, and, as I will argue, directly implicated in the most expensive failure in enterprise AI today.

What the Omnibus changed, and what it did not
On 27 July 2026, the AI Omnibus entered into force and amended the Act in several directions at once.
For Article 4, the obligation softened from ensuring a sufficient level of literacy to taking measures to support its development. The mandate to guarantee attainment at the individual level was removed and replaced with a duty to facilitate. The Commission and Member States, in turn, assumed an obligation to provide supporting materials and practical compliance examples.
Elsewhere, the high-risk timetable moved substantially. Stand-alone high-risk systems under Annex III were extended to 2 December 2027. High-risk systems functioning as safety components under Annex I were extended to 2 August 2028. Both had originally been due on 2 August 2026.
The overall direction is unmistakable: reduced compliance risk, lower liability exposure where staff lack knowledge, and a more collaborative regulatory posture. This is a reasonable and arguably sensible position. Brussels is trying not to crush smaller firms under a credentialing burden, and a prescriptive literacy mandate applied uniformly across all companies in the Union would be clumsy.
But notice what did not change.
The scope did not narrow. Providers and deployers, all AI systems, staff and third parties, extraterritorial reach, all intact. The definition in Article 3(56) stands. Enforcement powers commenced on schedule. And the commercial reality the obligation was responding to has, if anything, intensified.
What the Omnibus changed is the regulatory consequence of illiteracy. It changed nothing at all about the operational consequences. The risk did not disappear; it moved. It moved from the regulator’s desk to the balance sheet.
How this will actually be enforced
Penalties under Article 4 are set by individual Member States rather than fixed in the Act, and national authorities are required to weigh proportionality and the interests of smaller firms. There is no single headline number to frighten a board with, and anyone selling you compliance on the strength of one is inventing it.
Far more significant is a point that has received almost no attention outside specialist legal practice. Analysts examining enforcement expect that inadequate staff training will rarely be pursued as a standalone violation. Instead, it will be treated as an aggravating factor when something else goes wrong.
That changes the calculus entirely, and it is worth walking through what it means in practice.
An AI system produces an outcome that harms someone, a biased shortlist, a wrongful denial of service, a leaked dataset, a hallucinated figure that reached a regulator or a market. An investigation opens under a different article of the Act, or under GDPR, or under sector regulation. And at some point in that investigation, somebody asks what your people knew.
At that moment your training record stops being a compliance artefact and becomes evidence.
“We delivered a 45-minute e-learning module to 4,200 staff, with a 94% completion rate” is a defensible answer to Article 4 as currently drafted. It is a very poor answer to the question actually being asked, which is whether the specific person who deployed that specific system understood what they were deploying, and whether your organisation had any means of knowing whether they did.
The Commission’s own guidance anticipates this. It states that no particular training format is mandated; that role-based, risk-targeted programmes work materially better than generic courses; and in a line worth framing and circulating to whoever owns your learning function, that “relying only on an AI system’s instructions for use might be ineffective.”
The structural trap
Here is the issue, stated as plainly as I can manage.
Article 4 asks you to record inputs. Your business outcomes depend on measured outputs.
The Act wants evidence that training was delivered. It does not require evidence that competence was acquired, it makes measurement optional and certification unnecessary. Internal records suffice.
That is a defensible regulatory design. It is a catastrophic management strategy, and the distinction between the two is where a great deal of money will be wasted.
Strategy without tactics is the slowest route to victory. Tactics without strategy is the noise before defeat.
- Sun Tzu
Compliance training without a competence instrument is tactics without strategy. It generates activity, produces a record, satisfies an auditor, and leaves the organisation's underlying capability precisely where it was. The audit passes. The business does not improve. And the next time something breaks, the record proves only that you held a session.
The number that should worry your board more than the fine

Set the regulation aside entirely for a moment and look at the operating data, because it makes a sharper case than any statute.
Company AI adoption has risen from 20% in 2017 to 96% in 2026. Near-total penetration. And yet 41% of businesses still cannot demonstrate the business value of the AI they have deployed. More than 70% of professionals lack a foundational understanding of AI, according to OECD and World Economic Forum assessments. In the first quarter of 2026, 17.8% of the global working-age population was already using AI at work, 70% in the UAE, 63% in Singapore, 42% in the United Kingdom.

Ninety-seven million AI-adjacent roles are emerging, with a verified supply nowhere near enough to meet them. PwC sizes AI’s contribution to global GDP at USD 15.7 trillion by 2030.
Now look at what organisations themselves report as their obstacles to AI adoption. Measuring and proving business value leads at forty-one per cent. Lack of technological infrastructure follows at thirty-seven. A shortage of skilled AI talent at thirty-two. Lack of clean data at twenty-five. Lack of trust in AI-based decisions at twenty-two. Algorithm and model failure at eighteen. Inability to find the right data at sixteen. Legal, risk and compliance issues at fourteen.
Read that list as an operator rather than a policymaker. Only one of the top five obstacles is primarily a technology problem. The remainder are problems of people, measurement, judgement and confidence. They have literacy problems while wearing other clothes.
This is why the Article 4 debate is, in an important sense, the wrong debate. The regulation is a low floor beneath a very steep commercial cliff. You could achieve flawless Article 4 compliance, records filed, modules delivered, auditor satisfied, and remain squarely among the forty-one per cent who cannot demonstrate a return on the largest technology investment of the decade.
That is not a compliance failure. It is a capability failure, and no amount of compliance will fix it.

What “sufficient” has to mean if you intend to be serious
Translate the Commission’s guidance and the commercial data into an operational specification, and six requirements emerge.
Differentiated by role. A finance analyst using a forecasting model, a recruiter screening applications, a clinician reviewing imaging, and a director signing an AI investment case need four different literacies. One module serving all four produces a record, not a programme.
Calibrated to risk. Exposure should determine depth. What is required of someone deploying a system that materially affects people’s lives is not the same as what is required of someone drafting marketing copy, and pretending otherwise wastes the budget at both ends.
Covering opportunity as well as risk. Article 3(56) is explicit on this, and almost nobody honours it. A workforce taught only what it must not do will reliably deliver the forty-one per cent outcome, because nobody in it has been equipped to find value.
Measured, not merely delivered. The Act makes this optional. Your risk committee should not. If you cannot state what your people know, you cannot state what you are exposed to and you certainly cannot improve it, because you have no baseline to improve from.
Verifiable by a third party. Certificates today are siloed, easily falsified and unrecognised across jurisdictions, a structural trust deficit the World Economic Forum’s Digital Trust Initiative has named directly. An assertion of literacy that cannot be independently checked is worth roughly what any unverified claim is worth.
Continuous. The frontier moves quarterly. A credential earned once and never refreshed is a liability dressed as an asset, and a training record from 2025 describes a world that no longer exists.
Six requirements. Article 4, as amended, requires one of them. The gap between those two lists is simultaneously the exposure and the opportunity.
The third-party problem nobody is solving
One element of Article 4’s scope deserves separate attention because it is routinely missed in implementation.
The obligation extends to “other persons dealing with the operation and use of AI systems on their behalf.” Contractors. Outsourced providers. Agency staff. The managed service running your document processing. The consultancy configuring your CRM’s AI features. The offshore team handles first-line support with an AI assistant.
Most corporate learning infrastructure cannot reach these people. Your LMS does not have accounts for them. Your mandatory training completion reports do not count them. Your HR system does not know they exist. And yet, for the purposes of this obligation and of the aggravating-factor analysis above, they are operating AI systems on your behalf.
The architectural answer is a credential that travels with the individual rather than sitting inside your learning platform, portable, independently verifiable, and checkable by you without requiring you to have trained them yourself. That is a structural requirement, and it is one of the few places where a verifiable credential model is not merely better than internal training records but categorically different in kind.

What this means, by sector
For business. Your exposure extends beyond your payroll; your training record will one day be read as evidence, and your genuine commercial risk is the forty-one per cent problem rather than the fine. Seventy-eight per cent of Fortune 500 companies now prioritise AI literacy for entry-level roles, which tells you where the labour market has already moved, regardless of what Brussels requires.
For universities. The cost of inaction is now measurable: eroding graduate employability with employers who increasingly want verified capability rather than asserted exposure, loss of research-grant eligibility, and curriculum obsolescence relative to AI Act-era requirements. Universities also sit in an unusual position, they deploy AI systems in admissions, assessment,t and research, which places them within Article 4 as institutions, while simultaneously shaping whether the next generation arrives literate.
For the government and the public sector. Article 4 is the one obligation that applies to every public body deploying any AI system, immediately, regardless of risk classification and regardless of the high-risk deadlines pushed out to December 2027 and August 2028. Public bodies also face a trust burden no private firm carries: a citizen cannot choose another provider of justice, benefits or healthcare. Literacy in that context is not a measure of productivity. It is a condition of legitimacy.
For smaller firms. The proportionality provisions genuinely help, and the Omnibus genuinely reduced the burden. But SMEs are also the organisations least able to absorb the cost of an AI deployment that quietly fails, and most likely to be deploying third-party tools whose risks nobody internally understands. The regulation is lighter here; the operational case is heavier.

What to do in the next ninety days
Five steps, in order, none of which require waiting for further guidance.
One: inventory. Establish which AI systems are in use across the organisation, by whom, including shadow adoption and third-party-operated systems. Most organisations discover they have between three and ten times as much AI in production as their registers show.
Two: baseline. Measure what your people actually know, by role, against a structured framework rather than a satisfaction survey. You cannot manage an exposure you have not sized, and a baseline taken now becomes the evidence of improvement later.
Three: segment. Group the workforce by role and risk exposure, and design depth accordingly. Resist the pull toward a single universal module; it is cheaper to produce and almost worthless to rely on.
Four: build for competence, record for compliance. Design the programme to build capability, and let the compliance record fall out as a by-product. Doing this in the opposite order, designing for the record and hoping capability follows, is the error this entire article is written to prevent.
Five: make it continuous. Annual re-scoring, an upgrade path, and a refresh cycle aligned with the pace of the field rather than the audit calendar.
The real argument
AI literacy is no longer optional. That much is right.
But it is worth being clear about why, because the reason most commonly given has just become the weakest one available. Brussels has lowered the legal floor, removed the individual guarantee, confirmed that records suffice and that certification is unnecessary. If the mandate is what moves you, you will build to the mandate and the mandate will not protect you from the forty-one per cent problem, nor from the investigation that reads your training record as evidence, nor from a competitor whose workforce can genuinely do this.
The best way to predict the future is to create it yourself.
— Peter Diamandis
Diamandis’s abundance thesis holds that technology functions as a resource-liberator precisely when it is distributed rather than hoarded. AI literacy is the live test of that proposition. Concentrated in the hands of a handful of specialists, AI concentrates advantage and widens every gap it touches. Distributed across an organisation and verified, so that it can be relied upon, it becomes the largest expansion of institutional capability in a generation.
UNESCO warned in 2021 that the AI literacy divide risked becoming the defining inequality of the twenty-first century. Five years on, that reads less like prophecy and more like description.
The organisations that compound advantage over the next five years will not be the ones that complied earliest. They will be the ones that treated the regulation as a floor and built toward a ceiling, the ones that can state, with evidence, what every person touching an AI system in their organisation knows, what they can do with it, and what they would refuse to do.
Article 4 will never ask you for that. Everything else will.
Sources
- European Union — Regulation (EU) 2024/1689, Artificial Intelligence Act — official EUR-Lex text, including Article 3(56) on AI literacy and Article 4. Official EU AI Act — EUR-Lex
- European Commission — AI talent, skills and literacy — official Commission guidance on Article 4, the 2026 amendment, AI-literacy obligations, enforcement, and skills initiatives. European Commission — AI talent, skills and literacy
- White & Case — “EU AI Omnibus enters into force, amending the AI Act” — covers Regulation (EU) 2026/1744, which entered into force on 27 July 2026, including changes to Article 4 and delayed high-risk AI deadlines. White & Case — EU AI Omnibus enters into force
- Travers Smith — “The EU AI Act’s AI literacy requirement – key considerations” — useful for scope, tailoring literacy measures to roles and risks, record-keeping, and the enforcement framework. Note that this article predates the July 2026 amendment, so use it mainly for the Commission’s earlier implementation guidance rather than the current wording of Article 4. Travers Smith — EU AI Act AI literacy requirement
- Knowledge Foundry — “What does the EU AI Act require for AI literacy (Article 4)?” — updated explanation of the post-Omnibus Article 4 obligation, national enforcement, documentation, and the removal of a requirement to guarantee a specific literacy level for each individual. Knowledge Foundry — EU AI Act Article 4 AI literacy
- Gibson Dunn — “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes” — analysis of the Omnibus agreement and the revised timetable for high-risk AI requirements. Because this was published before final adoption, pair it with the later White & Case or EUR-Lex source when describing the law currently in force. Gibson Dunn — EU AI Act Omnibus Agreement
- Gartner — “AI Literacy Is No Longer Optional: The Business Impact of EU AI Act Article 4” — August 2026 webinar on the business, compliance, onboarding, partner, and market-access implications of AI literacy. Gartner — AI Literacy Is No Longer Optional
- UNESCO — Recommendation on the Ethics of Artificial Intelligence — UNESCO’s global AI ethics framework, adopted on 23 November 2021. UNESCO — Recommendation on the Ethics of Artificial Intelligence
- OECD — “Skills in the AI age” — 2026 policy paper covering AI literacy, workforce skills, complementary human capabilities, training, and labour-market adaptation. OECD — Skills in the AI age
- OECD — “AI and skills: What we know so far” — 2026 policy brief summarising research on skills needed to adopt and use AI effectively. OECD — AI and skills
- OECD / European Commission — “Empowering Learners for the Age of AI: An AI Literacy Framework for Primary and Secondary Education” — useful for definitions of AI literacy and competency-based education. OECD / European Commission — AI Literacy Framework
- World Economic Forum — “Measuring Digital Trust: Supporting Decision-Making for Trustworthy Technologies” — part of the WEF Digital Trust initiative, covering measurable trust, governance and trustworthy technology. World Economic Forum — Measuring Digital Trust
- PwC — “Sizing the prize: What’s the real value of AI for your business and how can you capitalise?” — source for the widely cited estimate that AI could contribute up to US$15.7 trillion to the global economy by 2030. PwC — Sizing the Prize report
Dinis Guarda is Founder and CEO of Ztudium Group and creator of the AI ID Passport, a blockchain-verified, gamified AI literacy certification programme delivered by Businessabc Academy and built on the ten-domain AI Readiness Wheel™. He is the author of AI for Business, EQ, IQ & AI, 4IR: Reinventing a Nation and The 5th Industrial Revolution, a Thinkers360 Top 10 and Edelman Top 50 AI thought leader.
Share

Dinis Guarda
Dinis Guarda is an author, entrepreneur, founder CEO of ztudium, Businessabc, citiesabc.com and Wisdomia.ai. Dinis is an AI leader, researcher and creator who has been building proprietary solutions based on technologies like digital twins, 3D, spatial computing, AR/VR/MR. Dinis is also an author of multiple books, including "4IR AI Blockchain Fintech IoT Reinventing a Nation" and others. Dinis has been collaborating with the likes of UN / UNITAR, UNESCO, European Space Agency, IBM, Siemens, Mastercard, and governments like USAID, and Malaysia Government to mention a few. He has been a guest lecturer at business schools such as Copenhagen Business School. Dinis is ranked as one of the most influential people and thought leaders in Thinkers360 / Rise Global’s The Artificial Intelligence Power 100, Top 10 Thought leaders in AI, smart cities, metaverse, blockchain, fintech.





