Back to blogCompliance

    AI literacy and ISO 42001 competence: one training plan, two obligations

    A legal duty and a voluntary requirement reach the same people. What the Digital Omnibus actually changed, why the relief doesn't apply to oversight roles, and how to map each module to the obligations it meets.

    ZeroFive.AI September 18, 2026 9 min

    In short. The AI literacy obligation in Article 4 of the AI Act and the competence requirements in clause 7 of ISO/IEC 42001 largely reach the same people, and running them as two separate projects means paying twice for the same training base. The Digital Omnibus rewrote Article 4, turning it from an obligation of result into one of effort, while leaving untouched the competence requirements covering anyone exercising human oversight over high-risk systems. A single role-based plan, stating which obligation each module covers, answers both.

    In companies dealing with the AI Act and ISO/IEC 42001 certification at the same time, training often starts from two different offices: the legal team works from Article 4, the quality manager from clause 7. The two tracks end up with separate vendors, budgets, and calendars, and nobody checks how much they overlap until someone compares the programs.

    Two obligations with different origins

    Article 4 of the AI Act has applied since 2 February 2025 to providers and deployers alike. It is a legal provision, enforced by national market surveillance authorities, and it binds organizations that pursue no certification at all.

    Clause 7 of ISO/IEC 42001 comes from a voluntary standard instead, and asks organizations to determine the competence needed for each role within a documented management system, ensure it, evaluate the effectiveness of the actions taken, and keep evidence of all of it. Those who apply it do so because they chose to certify, or because they want a method that holds up in a due diligence.

    What changed on 27 July

    Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and has been in force since 27 July. Article 1, point 5, replaces Article 4 of the AI Act in full.

    The original wording required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff. The new wording requires measures supporting the development of AI literacy, and adds an explicit clarification: the provision does not require guaranteeing any specific level of AI literacy for any individual.

    The technical shift is from an obligation of result to an obligation of effort. The criteria for calibrating those measures are unchanged: technical knowledge, experience, education, and the context in which the systems are used.

    The relief that doesn't apply to everyone

    Read quickly, the new Article 4 looks like it takes pressure off everyone. It moves the plane on which measures get judged rather than removing it, and for some organizations it changes almost nothing.

    The obligations covering people assigned to human oversight of high-risk systems were not touched. An organization assigning someone to oversee a system of that kind must ensure they have adequate competence, training and authority, and that requirement is not an obligation of effort. A company with systems falling under Annex III therefore faces a lightened general duty alongside an intact specific one, precisely for its most exposed staff.

    The practical consequence is that the relief mainly concerns the wide perimeter, meaning the base of staff using lower-risk tools. On critical roles, the distance between Article 4 and clause 7 narrows rather than widens.

    The comparison

    AspectAI literacy (AI Act, Art. 4)Competence (ISO/IEC 42001, cl. 7.2 and 7.3)
    NatureLegal obligation, of effort after the Digital OmnibusRequirement of a voluntary standard
    Who it coversStaff of providers and deployers and others using the systems on their behalfPeople working under the organization's control who affect AIMS performance
    ContentSupport measures calibrated to skills, experience, education, and context of useCompetence determined by role, acquired and verified
    Individual levelNeed not be guaranteed for any one personDetermined for each role
    EvidenceNot prescribed in detailDocumented information required by the standard
    EffectivenessNot explicitly requiredEffectiveness evaluation mandatory
    Who checksNational market surveillance authoritiesInternal audits and the certification body
    RefreshTied to the context of useTied to changes in the AIMS and the systems

    Who falls inside the perimeter

    Both provisions look beyond the payroll, and in similar terms. Article 4 covers staff and other persons dealing with the operation and use of the systems on the provider's or deployer's behalf. Clause 7.3 speaks of people working under the organization's control.

    In both cases that takes in consultants, temporary staff, contractors and personnel of suppliers operating inside your processes. The external agency running customer service with an AI-assisted tool sits inside both perimeters, and in both cases the only instrument for governing it is the contract, because you have no training plan covering those people.

    This is also where the two obligations align best: an organization that has already mapped its perimeter for clause 7 knows its extended perimeter already, and doesn't need to redo the exercise for Article 4.

    Why "contextual" changes what to buy

    The rewriting of Article 4 leaves the reference to context of use standing, and removing the individual level effectively shifts the centre of gravity onto it. Measures get judged against the systems actually in use, the roles working around them, and the risks they carry.

    That makes the best-selling training product of the moment, the generic AI Act course, of limited use. Knowing how the regulation is structured doesn't help an operator recognise when the tool they use every day is getting something wrong. One hour on the system that person has in front of them is worth more than four hours on the regulation, and answers both obligations better.

    Where they meet

    Both ask for training calibrated to role and context of use, and both end up reaching the people who decide on adoption, use the tools, or assess their risks. A plan built on the roles-competence matrix already covers much of what Article 4 requires.

    Which framework does your company actually need?

    AI Rating measures maturity across the four areas of the model and shows where to start, with priorities and estimated effort.

    Start your AI Rating

    The differences that remain

    AI literacy is a floor, which applies even to organizations that have no management system and do not plan one, while ISO 42001 competence requires verifiable evidence linked to the risks of inventoried systems. An organization can meet Article 4 while staying far from clause 7; the reverse is hard, because meeting clause 7 in practice already covers the literacy of the staff involved.

    Two clause 7 requirements have no equivalent in Article 4. The first is evaluating the effectiveness of training actions, which forces measurement of the outcome and not just of delivery. The second is the update mechanism triggered by changes to the management system or to the systems in use. Anyone building a plan for Article 4 alone tends to skip both, and those are exactly what make a plan useful beyond the audit date.

    Mapping modules to obligations

    The method is to map each module of the plan to the obligations it satisfies. In practice the structure that works has three layers.

    A base layer for everyone touched by an AI system, short, centred on what the system they use does, where the system's responsibility ends and theirs begins, and who to flag an anomaly to. It answers Article 4 and, for non-critical roles, the awareness requirement in clause 7.3.

    A role layer, built on the matrix, answering the competence requirement in 7.2 and covering Article 4 for operational roles in more depth than strictly needed.

    A specialist layer for those running risk assessments, exercising human oversight over high-risk systems, and accountable for decisions. Evidence here has to be individual and verifiable, because this is where the specific human oversight obligations and the clause 7 requirements ask for the same thing.

    Keep the mapping, because during an audit or an inspection it shows quickly how the company addressed each requirement.

    What to keep if you're not certifying

    An organization not pursuing ISO/IEC 42001 has no detailed documentary obligations under Article 4, which is not the same as having nothing to show. An authority asking about the measures adopted expects more than an assertion.

    The reasonable minimum is a document describing which measures were adopted and for which groups of staff, the list of AI systems in use those measures relate to, a record of when they were delivered and to whom, and a review date. Four items an HR function produces in a week, and which turn a statement into a defensible position.

    A hypothetical example

    An industrial group runs two AI training projects with different vendors and separate budgets, one launched by the legal team for Article 4 and the other by the quality function for ISO 42001 certification. Mapping the modules to roles shows that much of the content overlaps and that the two vendors use different definitions of a high-risk system. The group merges the plan, keeps one vendor for the general part, and gives the other the specialist modules. The example is illustrative and does not describe a real case.

    Questions before signing with a vendor

    • Which modules address Article 4 and which address clause 7?
    • Is the evidence produced linked to each person's role?
    • Does the content use the AI Act definitions as amended by the Digital Omnibus?
    • How much of the program covers the systems actually in use here, and how much covers the regulation in general?
    • How is effectiveness measured, beyond a satisfaction survey?
    • Who updates the content when the systems in use change?
    • Does the new plan account for what the company has already delivered?

    The most frequent mistakes

    The first is reading the Article 4 amendment as a postponement. The obligation has applied since February 2025, national supervision is operational, and an organization that has adopted no measures at all is in no better position after the Digital Omnibus.

    The second is buying the course on the regulation rather than on the system, which produces staff able to cite Article 6 and unable to notice that a tool is returning anomalous outputs.

    The third is treating Article 4 and clause 7 as though the former were a subset of the latter at every point. For the wide perimeter that's nearly true; for oversight roles it's less true than it looks, because the AI Act's specific obligations on those people remain in full.

    The last is building the plan without knowing which AI systems are actually in use. Without the system inventory, context of use is a hypothesis, and training calibrated to context becomes training calibrated to an idea of the context.

    Next step

    Before splitting the budget, compare existing programs against the role matrix. The full requirements are in ISO/IEC 42001 clause 7, explained without jargon, and the levels are built in a roles-competence matrix for AI.

    Our approach to training tracks is described on the AI Training page. To check the overlaps in your plan, book an assessment meeting.

    Want to discuss this for your company?

    30 minutes with us to figure out where to start, or an AI Rating to measure your starting point.

    #AI literacy#AI Act#ISO IEC 42001#AI training#AI compliance
    Share

    Keep reading