Regulation

AI literacy after the Omnibus: what Luxembourg and UK employers actually need to do

The EU softened Article 4 of the AI Act this summer. The duty to train staff did not go away. Here is what it now asks of you, how it reaches UK firms, and a proportionate way to meet it.

· 5 min read

Since February 2025, Article 4 of the EU AI Act has required organisations that use AI systems to do something about their staff’s AI literacy. For a year and a half, that sentence produced a lot of webinars and very little clarity.

Then, on 27 July 2026, the Digital Omnibus on AI (Regulation (EU) 2026/1744) came into force and changed the wording. Some commentary read this as “the AI literacy rule has been scrapped”. It has not. It has been made more realistic, which is arguably more useful for anyone trying to plan a training budget.

This article covers what changed, who it applies to (including UK businesses), and what a sensible response looks like for a 20 to 500 person organisation.

What Article 4 says now

The original text asked providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and others using AI on their behalf.

The amended text asks them to take measures to support the development of AI literacy of those people, and states plainly that this does not require anyone to guarantee a specific level of literacy for any individual.

In practice, that moves the duty from an obligation of result to an obligation of effort. You are not expected to certify that every employee is now “AI literate”. You are expected to be able to show that you took reasonable, proportionate steps to help them get there.

The question a regulator is likely to ask is no longer “is everyone trained?” but “what did you do, and does it fit the way your people actually use AI?”

Two things did not change:

  • It still applies to deployers. If your staff use ChatGPT, Copilot, Gemini, Claude or an AI feature inside your CRM, you are a deployer. This is not only a rule for AI companies.
  • High-risk systems still carry stricter duties. If you use AI in areas the Act treats as high-risk, such as recruitment, worker management or credit decisions, the people overseeing those systems need specific competence and authority. The Omnibus pushed the application date for most of those Annex III obligations back to 2 December 2027, which gives you time, not an exemption.

Who it covers in Luxembourg

Every organisation established in Luxembourg that uses AI systems in a professional context is in scope. Luxembourg has chosen to extend existing regulators rather than create a new one: the CNPD acts as the central authority and default market surveillance authority, with sector bodies such as the CSSF covering financial entities.

For a Luxembourg firm, the practical upshot is that AI literacy sits naturally next to the GDPR work you already do. If your data protection officer or compliance lead already keeps a record of processing activities, the AI literacy evidence can live alongside it.

Why UK firms should care too

The UK has no equivalent statute. Its approach so far relies on existing regulators (the ICO, the FCA, the CMA and others) applying their own rules to AI, plus UK GDPR as amended by the Data (Use and Access) Act 2025.

But the EU AI Act reaches beyond EU borders. A UK business can fall within scope if it places AI systems on the EU market, or if the output of an AI system it uses is used in the EU. A UK consultancy with Luxembourg clients, a UK software company selling into the EU, or a UK group with an EU subsidiary should all assume Article 4 is relevant.

Even where it does not strictly apply, it is a reasonable benchmark. If something goes wrong with an AI-assisted decision in the UK, “we trained our staff in proportion to how they use these tools” is a far better position than “we bought the licences and left them to it”.

A proportionate approach in four steps

The good news about an obligation of effort is that effort can be designed. Here is a structure that works for most small and mid-sized organisations.

1. Map who uses what

You cannot pitch training correctly without knowing the starting point. A short survey or a 30-minute conversation with each team lead should answer:

  • Which AI tools are in use, sanctioned or not?
  • What tasks are people using them for?
  • Which of those tasks touch personal data, client confidential information, or decisions about people?

Expect to discover tools nobody approved. That is normal, and it is useful information, not a disciplinary matter.

2. Tier your staff

Not everyone needs the same depth. A simple three-tier model:

Tier Who What they need
Everyone All staff with access to AI tools How these tools work and fail, what not to paste in, how to check outputs, your policy
Regular users People using AI weekly in their role Effective prompting for their real tasks, verification habits, when to escalate
Owners People who choose, configure or oversee AI systems Risk assessment, vendor questions, human oversight, documentation

3. Train on real work, not demos

Generic e-learning modules tick a box but rarely change behaviour. The training that sticks uses each team’s own tasks: the finance team drafting a variance commentary, the HR team summarising policy questions, the sales team preparing for a client call. People learn where the tool helps, where it invents things, and where it should not be used at all.

4. Keep light, honest evidence

Record what you did, when, for whom, and why you judged it proportionate. A one-page summary per year plus attendance records is usually enough for a small organisation. Revisit it when you adopt a significant new tool.

What not to do

  • Do not wait for enforcement guidance. National authorities gained supervisory powers in August 2026. Waiting to see what they ask for first is a strategy, but not a good one.
  • Do not buy a certificate and call it done. A course nobody applies to their work is weak evidence of “measures to support the development of AI literacy”.
  • Do not treat this as only a compliance exercise. The same training that satisfies Article 4 is the training that gets people using the tools you are already paying for.

This article is general guidance, not legal advice. If you deploy AI in an area the AI Act treats as high-risk, take specific advice.