
Issue #2 · August 2026
A commercial pilot’s license doesn't make someone qualified to fly a Boeing 737.
The license establishes a baseline; the aircraft requires its own preparation, procedures, and type rating. And don't forget time spent flying the plane. In the U.S., pilots log flight time throughout training, long before earning a commercial pilot certificate. In fact, the logged experience is a prerequisite for certification.
The same operational logic applies to AI literacy: the system being used, the role using it, the decision it influences, and the person accountable for the outcome determine what someone needs to know. A universal course can establish vocabulary, but it can't establish readiness.
Readiness means knowing whether a tool is approved for a specific use, what information may be entered into it, when an output requires independent verification, and which decisions should never be delegated. Course completion can't answer those questions on its own.
AI literacy is therefore not primarily a learning-and-development initiative. It's an operating capability that connects systems, roles, decisions, accountability, and risk. The standard is not whether people attended training; it is whether they can use a particular system, in a particular context, without outsourcing their judgment to it. That's the responsibility leadership must now operationalize.
Article 4 changed the requirement, not the responsibility
Article 4 of the Artificial Intelligence Act has applied since February 2025, and national authorities began supervising and enforcing it in August 2026.
The article was amended in July. Providers and deployers of AI systems must now take measures that support the development of AI literacy among employees and others using AI on their behalf. However, they don't have to guarantee that every individual reaches a prescribed level, and there's no single required course, certificate, or governance structure.
That gives leaders some flexibility, but it also means there's an expectation that employers will tailor their AI literacy based on roles and risk.
The measures an organization takes should reflect:
The AI systems it provides or uses
The knowledge and experience of the people using them
The context in which the systems operate
The people who may be affected by the systems
The risks associated with those uses (though not explicit in Article 4, this is important)
A generic course for the entire company won't meet the standard. A system drafting internal meeting notes doesn't require the same preparation as a system influencing hiring, lending, healthcare, safety, legal, or customer decisions.
Context determines what people need to know. Risk determines how much they need to know before they act.
The executive question is therefore not, “Have our employees completed AI training?”
It is:
What must each person understand before they can use or oversee AI responsibly in this organization?
That question turns AI literacy from a compliance activity into an operating decision.
Start with the uses that can change an outcome
You can't design a useful literacy program without knowing how AI is being used in practice.
The first step is to understand the actual work:
Which approved AI systems are available?
Which teams use them?
What decisions or work products do they influence?
What data do they handle?
Who could be affected if an output is wrong?
Where are employees using unapproved tools?
Don't wait for a perfect enterprise inventory. Begin with the most consequential uses and expand from there. The goal is not to create a static catalog that looks complete in a governance meeting. The goal is to identify where AI is already shaping execution, decisions, and exposure.
This is where many organizations lose clarity. They discuss AI literacy as if “AI” were one tool with one risk profile. It isn't. A summarization assistant, a coding system, a customer-service agent, and a model used in employment decisions create different requirements for users and different responsibilities for leaders.
The more important question is what the output is allowed to influence.
If an employee uses AI to brainstorm language, the required judgment is different from the judgment required when an output determines who receives an interview, how a claim is assessed, or whether a customer is denied a service. The system may be technically similar, but the operational context changes the stakes.
AI literacy begins when an organization stops talking about tools in the abstract and starts mapping systems to consequences.
Each role needs a different form of judgment
AI literacy should not mean turning every employee into a technical specialist. It should mean giving people the knowledge required for the decisions they actually make.
Most organizations will need several levels of preparation.
All users should understand approved uses, data-handling rules, common system limitations, verification expectations, and escalation paths. They should know what the tool is for, what it is not for, and what to do when the output is incomplete, biased, misleading, or simply wrong.
Managers and business owners should understand when AI is appropriate, who remains accountable, what human review is required, and how system performance will be monitored. They also need to recognize when a productivity gain creates second-order effects for quality, privacy, customer trust, or employee experience.
Technical, legal, risk, security, privacy, and procurement teams need deeper knowledge tied to their responsibilities for evaluating systems, vendors, controls, documentation, and organizational exposure. Their role is not merely to approve or reject a tool. They must be able to translate technical behavior into business and regulatory implications.
People responsible for human oversight need system-specific preparation. They must be able to recognize problems, interpret outputs appropriately, challenge the system when necessary, and intervene when the operating conditions no longer support safe use.
The relevant question is not whether everyone received the same information. It is whether each group received the information needed for its role.
That distinction is central to responsible scale. Uniform training feels efficient, but role-specific judgment is what protects execution when systems move from experimentation into enterprise workflows.
“Human in the loop” is not an operating model
Organizations often describe their safeguards with a familiar phrase: human in the loop.
The phrase sounds reassuring until someone asks what the human is actually expected to do.
Leadership must define:
Which outputs require review
Who performs that review
What the reviewer is expected to check
Which decisions cannot be automated
When use must stop
Where concerns are escalated
Who owns the final decision
A review step without a defined standard is a formality. A person may technically approve an output while lacking the time, authority, context, or expertise to evaluate it. That is not meaningful oversight. It is a control that exists on paper but fails during execution.
Training cannot compensate for unclear accountability.
If employees do not know what authority they have, or where their responsibility begins and ends, more instructional content will not solve the problem. Leaders need to establish the decision rights first, then prepare people to operate within them.
This is also where organizational culture becomes part of the infrastructure. In high-trust teams, employees need a clear path for challenging an output without being treated as obstructive. They need to know that escalating a concern is part of responsible execution, not evidence that they lack confidence in the technology.
AI can accelerate work, but acceleration without decision clarity increases the speed of error. Human oversight matters because a named person owns the consequence.
Evidence should show the reasoning, not just attendance
Article 4 does not require a particular certificate. The European Commission says organizations can maintain internal records of training and other guidance.
That evidence might include:
The AI systems and uses considered
The roles or groups affected
Training, guidance, policies, and practical exercises provided
Participation or completion records
System-specific instructions
Changes made after incidents or employee questions
Dates and triggers for refreshing the material
Documentation should show the reasoning behind the program, not merely that a course was assigned.
A completion report can tell you that, say, most employees watched a module. It cannot tell you whether a manager understands when human review is mandatory, whether a developer knows which code may be entered into a system, or whether a customer-service team knows when to stop using an agent and escalate to a person.
The stronger evidence is practical. Can people apply the guidance to the systems they use? Can they identify a prohibited or high-risk scenario? Can they explain what they checked before relying on an output? Can they show where a questionable result was escalated?
AI systems, organizational uses, and risks change quickly. Literacy cannot be treated as an annual event that remains valid regardless of what changes around it. New tools, new data flows, new vendors, new regulations, and new incidents should all be potential triggers for review.
The program should evolve with the environment it governs.
The real gap is operational, and leaders own it
Your leadership team should be able to answer six questions:
What AI systems are people using on our behalf?
In what contexts are they using them?
What must each role understand?
What guidance, training, or practice have we provided?
How do we know people can apply it?
What triggers an update?
If those answers are unclear, the organization has more than a training gap. It has an operating-control gap.
The distinction matters because AI literacy affects more than regulatory posture. It affects the quality of decisions, the resilience of processes, the credibility of leadership, and the organization’s ability to scale AI without creating hidden exposure.
The best literacy programs connect four things that are often managed separately: the system being used, the role using it, the decision being influenced, and the person accountable for the outcome. That connection gives employees practical clarity and gives leaders measurable evidence that the organization is prepared.
AI literacy is not about making everyone an AI expert. It is about ensuring that people know enough to use a particular system, in a particular context, with the right constraints and the right escalation path.
That is a leadership responsibility, even when someone else delivers the training.
So what? Treat AI literacy as part of your operating infrastructure. Map the consequential uses, define role-specific expectations, establish meaningful human oversight, and keep evidence that shows how the program responds to changing systems and risks. The payoff is not a better completion rate. It is the ability to accelerate adoption while preserving judgment, accountability, and trust.
Where is the biggest AI-literacy gap in your organization today: basic awareness, role-specific judgment, or evidence that the right preparation occurred?
Reply and tell me what you're seeing.
Sources
This briefing is a regulatory and operating-risk analysis, not legal advice.