Editorial by Gianmarco Gori
In November 2025 the European Commission has published the proposal for a Digital Omnibus on AI (hereafter, AI Omnibus), a regulation that aims to introduce a set of “targeted amendments” to the AI Act with the goals of addressing “certain implementation challenges”[1].
While, at the time of writing, the legislative train of this proposal is still in motion and thus its fate is uncertain,[2] one of the amendments thereby proposed concerning the requirement of AI literacy deserves particular attention. While modest in appearance, the amendment of AI literacy reveals broader trends in EU AI policy and law.
After briefly introducing the AI literacy requirement and its proposed amendment, I will examine the rationale behind the proposed changes, arguing that they reflect a growing concern within EU AI policy about the burden AI operators face in ensuring legal compliance. I will then discuss this concern and outline some of the challenges it raises.
AI literacy
Entering the trilogue negotiations in 2023 on the initiative of the European Parliament,[3] AI literacy was included as a legal requirement in the final text of the AI Act, becoming applicable in February 2025. Article 3(56) of the AI Act defines it as the
skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause.[4]
Under Article 4, providers and deployers of any AI systems (that is, not only high-risk AI systems) are required to:
take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.[5]
The Commission has repeatedly emphasised the importance of AI literacy through various initiatives, including a dedicated Q&A online page[6] and a “Living repository to foster learning and exchange on AI literacy”.[7] Consistent with this emphasis, the AI Omnibus itself describes AI literacy as a “strategic priority”, acknowledging that its development is “crucial to equip AI operators and affected persons with the necessary notions to make informed decisions regarding AI systems deployment”.[8]
Yet, the Commission simultaneously proposes to soften this obligation by remodulating both its addressees – not longer AI operators, but the Commission and the Member States instead – and, consequently, its content – not anymore ensuring a sufficient level of AI literacy, but encouraging AI operators to develop AI literacy.[9]
The AI Omnibus justifies this amendment on the basis of three claims concerning Article 4: that it imposes a “one-size-fits-all solution”, that it generates an “additional compliance burden” for AI operators, and that it constitutes an “unspecified obligation”. Each of these claims deserves closer examination.
A “one-size-fits-all solution”?
The claim that AI literacy constitutes a “one-size-fits-all solution” is both surprising and difficult to reconcile with the text of Article 4.
First and foremost, the Commission itself has explicitly affirmed that “[t]here is no one size fit all when it comes to AI literacy”.[10]
Second, Article 4 establishes a best effort obligation: AI operators are required to take AI literacy measures “to their best extent”.[11]While this means that any AI operator must make their best effort, what counts as “best effort” clearly varies for different AI operators. For instance, the effort expected from a small enterprise with limited resources will not be the same than that expected from a large technology company.
Third, AI operators are asked to make their best effort to ensure a “sufficient” level of AI literacy.[12] Sufficiency is inherently a context-dependent normative standard and therefore necessarily allows for differentiation. As Article 4 makes explicit, what qualifies as “sufficient” must be determined in light of circumstances and factors specific to both the AI operators’ organisation and the AI system provided or deployed. These include the “technical knowledge, experience, education and training” of the AI operator’s staff, “the context the AI systems are to be used in”, and “the persons or groups of persons on whom the AI systems are to be used”.[13]
An additional compliance burden?
According to the Commission, compliance with the AI literacy obligation entails an average a cost of around 1000 euros per company, thus representing “an additional compliance burden” that is deemed particularly taxing for smaller enterprises. [14]
Since it is a truism that legal obligations generate compliance burdens, the relevant question is whether the burden imposed by AI literacy is necessary and proportionate in light of the goals this obligation pursues. These include providing “all relevant actors in the AI value chain with the insights required to ensure the appropriate compliance and … correct enforcement” of the AI Act.[15] In this respect, Article 4 does not require AI operators anything additional to what is arguably already implied by other obligations.
For providers and deployers of high-risk AI systems, AI literacy is effectively a precondition for complying with their obligations under the AI Act.[16] For AI operators not subject to those specific obligations, possessing a level of “skills, knowledge and understanding” sufficient to use AI in an informed manner and with awareness of its potential risks and harm is nonetheless necessary to comply with general duties of care and obligations stemming from other areas of law (e.g., data protection law, antidiscrimination law, etc.).
The AI literacy requirement creates an autonomous legal basis for this otherwise implicit obligations and makes compliance with it subject to administrative monitoring and enforcement. The practical burden this generates for AI operators lies primarily in the need to use the language of AI literacy to account for the (best) efforts they undertake to ensure that their organisation possesses the expertise required to use AI in accordance with applicable obligations and duties of care.
Importantly, the AI Omnibus does not dispute the necessity of AI literacy,[17] nor that its developing entails a cost. What it proposes is to partially externalise such cost, shifting it from AI operators to public authorities[18] and thus, ultimately, taxpayers. Whatever its merit and effectiveness as a policy choice, such a shift requires a stronger justification than the AI Omnibus currently provides.
An “unspecified obligation”?
Perhaps the most significant criticism raised against the AI literacy obligation concerns its allegedly “unspecified” nature.[19] In this respect, the proposed amendment seeks to address stakeholders’ concerns about the uncertainty surrounding what constitutes a “sufficient level of AI literacy” and the “considerable margin of discretion” [20] that this leaves to Market Surveillance Authorities, thereby creating “a deterrent effect for businesses and public authorities”.[21]
These concerns are mitigated by the considerations discussed above regarding the multiple circumstances that, under Article 4, both guide AI operators and constrain Market Surveillance Authorities’ discretion in determining what counts as sufficient AI literacy.
One may even argue that an AI operator who is insurmountably uncertain as to what “skills, knowledge and understanding” their staff require to “make an informed deployment of AI systems, become aware of AI’s “opportunities and risks”, and appreciate the “possible harm” AI can cause,[22] should indeed be deterred from entering the AI market or making use of AI. Undertaking activities that may generate risk without possessing the knowledge and skills necessary to exercise due control over them would in fact be contrary to duties of diligence that exist independently of the AI Act.
Furthermore, if compared to many other legal obligations, AI literacy does not appear particularly “unspecified”. Before and beyond being AI operators, providers and deployers are, for instance, product manufacturers, employers, public authorities, data controllers, etc. In all these roles, they are routinely required to determine the scope and content of partially “unspecified” obligations. Yet, with respect to AI literacy and other AI Act provisions targeted by the AI Omnibus, the issue of legal uncertainty and its deterrence effect appear to raise exceptional concerns.
To avoid sliding in a form of AI exceptionalism, an important distinction must be drawn between, on the one hand, concerns with the necessity and proportionality of the compliance burden borne by AI operators and, on the other hand, treating any “normative work” that AI operators may need to undertake to determine their legal obligations as an obstacle to be removed.
The AI Omnibus proposal seems largely underpinned by the latter narrative. In particular, the proposal to postpone the implementation of rules on high-risk AI systems until harmonised standards or “other support tools” become available partly adheres to this logic.[23] Undoubtedly, delays in the standardisation process frustrate the implementation of the “New Approach” architecture of the AI Act and increase AI operators’ compliance burden, namely by requiring them to determine how to comply with legal requirements without the guidance of technical specifications.[24]
Yet, more than two millennia of debate on legal (in)determinacy teach us that no normative text, neither a refined AI Act, nor technical specifications such as harmonised standards, will unambiguously resolve every question that AI operators will face when providing and deploying AI systems in day-to-day scenarios. Although, hopefully, standards will provide more “specified” guidance and help asymptotically reduce the gap between normative requirements and what constitutes their correct implementation, AI operators will always be required to engage in a “normative work” to determine what the law requires in concrete circumstances.
Standards will not spare providers such work, at the very least because they will still be required to determine whether, and to what extent, certain technical specifications actually cover relevant requirements,[25] and to consider any additional measures necessary to fully implement them, keeping in mind that conformity with standards creates only a presumption of conformity, not an automatic guarantee of compliance.
Additionally, the requirements that harmonised standards are meant to specify not only apply to products as diverse as toys integrating AI and crime prediction systems, but are also formulated in such a way that their proper implementation requires careful consideration of AI systems’ intended purpose and context of use, as well as of the persons on which they will be used and the potential consequences for their fundamental rights. The protection of fundamental rights, in particular, is essentially incompatible with full standardisation and ex ante specification, requiring the exercise of a situated capacity of judgment. AI operators will always need, as it were, a sufficient level of “skills, knowledge and understanding” to appreciate what technical and organisational measures are necessary to ensure compliance with the law and safeguarding fundamental rights in specific circumstances.
Treating this normative work as a compliance burden that could or should be preempted or avoided is misleading and raises concerns as to the understanding of what fundamental rights protection entails.
[1] Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). Brussels, 19.11.2025 COM(2025) 836 final 2025/0359 (COD), Recital 3.
[2] The Council has produced a compromise text and Members of the European Parliament 450 amendments proposed by. See, respectively, Interinstitutional File: 2025/0359 (COD), 23 January 2026. https://www.europarl.europa.eu/committees/en/imco/documents/latest-documents
[3] Paolini e Silva, Manuela and Tamò-Larrieux, Aurelia and Ammann, Odile, ‘AI Literacy Under the AI Act: Tracing the Evolution of a Weakened Norm’ (January 16, 2025). Available at SSRN: https://ssrn.com/abstract=5099834 or http://dx.doi.org/10.2139/ssrn.5099834.
[4] Article 3(56) AI Act. See also Recital 20.
[5] Article 4 AI Act.
[6] https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers
[7] https://digital-strategy.ec.europa.eu/en/library/living-repository-foster-learning-and-exchange-ai-literacy
[8] Recital 5, AI Omnibus.
[9] Article 1(4), Recital 5, AI Omnibus.
[10] https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers
[11] Article 4 AI Act.
[12] Article 4 AI Act, emphasis added.
[13] Article 4 AI Act. Cf also Recital 20, stating that “the necessary notions to make informed decisions regarding AI systems … may vary with regard to the relevant context.
[14] Significantly, the AI literacy cost represent more than half of the costs that the AI Omnibus aims to reduce (i.e., 222.75 millions of euros out of a total of 429.5 millions). For more information on how these costs are calculated, see Commission Staff Working Document Accompanying the documents Proposal for a Regulation of the European Parliament and of the Council Amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus) Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) {COM(2025) 837 final} – {COM(2025) 836 final}, Brussels, 19.11.2025 SWD(2025) 836 final, pp. 78, 135.
[15] Recital 20, AI Act.
[16] Cf Articles 26(1),(2),(4),(5), 27, 86, AI Act, for deployers, and Articles 9(5)(c), Recital 65, 10, 13-15, 17, 72, Annex IV, AI Act, for providers.
[17] Recital 20 AI Act.
[18] Recital 5 Omnibus on AI.
[19] Explanatory Memorandum, p. 2.
[20] Commission Staff Working Document, p. 72.
[21] Ibid.
[22] Article 3(56) AI Act.
[23] AI Omnibus, Explanatory Memorandum, p. 2.
[24] Recitals 2 and 22, AI Omnibus.
[25] Cf Articles 40(1) 17(1)(e), Annex IV(7), AI Act.
