Back to blogCompliance

    The mandatory AI course: what it covers after the Omnibus and what ISO 42001 still needs

    What a standard course cannot contain by construction, the three sales promises to recognise, what it costs to add the missing part, and the questions to ask a vendor before signing.

    ZeroFive.AI September 23, 2026 7 min

    In short. A standard AI course bought to answer Article 4 of the AI Act covers a useful base, and stays far from what clause 7 of ISO/IEC 42001 requires. After the Digital Omnibus, the AI literacy obligation consists of adopting measures that support literacy, and a general course can count among them. Clause 7 instead asks for competence determined by role, documented evidence, and updates tied to the systems in use. Below: what a standard course cannot contain by construction, what it costs to add, and what to ask a vendor before signing.

    With a large part of the AI Act applicable from 2 August 2026, many companies are asking whether the mandatory course they bought months ago is enough to consider themselves in order. For Article 4, after the Digital Omnibus amendments, the answer depends on how the course fits into the measures the company adopted. For anyone heading toward ISO/IEC 42001 certification, the answer is almost always no.

    The market for standard courses

    Since the AI literacy obligation became applicable on 2 February 2025, a wide offering of standard courses has grown, short and identical for every client, often presented as a complete answer to Article 4. The course itself is a legitimate instrument. The problem starts when it gets treated as the last step rather than the first.

    Three sales formulations deserve attention because they promise more than a course can deliver. The first is guaranteed AI Act compliance, which no training vendor can provide, because compliance depends on the systems you run and how you govern them. The second is a course valid for ISO/IEC 42001 certification, a formula confusing training content with the evidence a certification body will assess. The third is the recognised certificate, where the recognition often comes from the same entity delivering the course.

    None of the three makes the course useless. All three signal that the vendor is selling reassurance rather than competence, and it's worth knowing that before treating the matter as closed.

    Article 4 after the Digital Omnibus

    The amendment to the regulation, in force since 27 July 2026, made the obligation less rigid than many vendors continue to suggest: organisations must adopt measures supporting staff literacy, without guaranteeing any specific demonstrated level for each person.

    For anyone organising training at scale that's a concrete simplification, and a well-chosen general course can form part of those measures, especially when paired with guidance on the systems present in the company. The criteria for calibrating those measures stand, among them the context in which systems are used, and that criterion is precisely what a one-size-fits-all course doesn't satisfy on its own.

    One limit the relief doesn't touch is worth adding. Competence obligations for those exercising human oversight over high-risk systems remain in full, and for those roles attending a general course isn't sufficient even against the AI Act.

    What a standard course covers

    ContentStandard courseISO/IEC 42001 clause 7
    Basic concepts on models and risksCoveredUseful as a base
    Principles of responsible useCoveredUseful as a base
    Role-specific competenceUsually absentRequired (7.2)
    Reference to inventoried systemsAbsentRequired for roles affecting the AIMS
    Awareness of the AI policy and one's contributionPartialRequired (7.3)
    Evidence tied to the person and the roleGeneric certificateDocumented information (7.5)
    Effectiveness evaluationSatisfaction surveyRequired (7.2)
    Refresh when systems changeAbsentExpected by the management system

    The five elements no vendor can write

    One point gets lost in the discussion and is worth stating plainly: some things are missing from standard courses not through vendor laziness, but because content identical for every client cannot contain them by construction.

    Your AI policy, which is your document and which clause 7.3 requires people to know. The list of systems actually in use at your company, with what they do and which decisions they support. The name of the person to flag anomalous behaviour to. The internal procedure describing what happens after that report. The edge cases observed on your systems, which is the single most useful piece of information for whoever uses them daily.

    Five elements no external vendor can write on your behalf, and also the ones turning generic training into training that changes how people behave. The good news is they're cheap: thirty or forty minutes per system, prepared by whoever already knows it.

    Where clause 7 goes further

    The standard course covers models, risks in the abstract and general principles, and rarely enters the role of whoever attends. A risk owner and a warehouse operator walk out with the same certificate, with no connection to the systems they'll use, and in an audit that certificate demonstrates attendance more than competence.

    Even an organisation in order with Article 4 therefore stays distant from clause 7, which asks for competence determined by role, evidence retained, and a plan refreshing itself when systems change, as described in the roles-competence matrix.

    There's also a requirement standard courses almost never address, the effectiveness evaluation required by clause 7.2. The satisfaction survey handed out at the end measures how much people enjoyed it, not how much stayed, and doesn't cover that obligation.

    Which framework does your company actually need?

    AI Rating measures maturity across the four areas of the model and shows where to start, with priorities and estimated effort.

    Start your AI Rating

    What the certificate actually says

    The typical certificate carries the person's name, the course title, its duration and the date. Useful information for showing something was delivered, insufficient for showing a competence was acquired.

    To work as evidence, a certificate should let someone answer three questions without opening other documents: which competence from the matrix that person covered, against which role, and with what verification of learning. Almost no standard certificate answers all three.

    The fix doesn't require redoing the course. It takes an internally produced document linking the certificate to the role and the competence, kept alongside the certificate itself, which is exactly what the documented information in clause 7.5 asks for.

    A hypothetical example

    A distribution company bought an online AI course for all employees and is preparing for ISO/IEC 42001 certification. During gap analysis it emerges that the course covers the general part well but touches neither of the two inventoried systems, and that certificates don't state people's roles. The company keeps the course as an introductory module, adds a workshop for risk owners and short modules for operators of the two systems, and links every certificate to the role matrix. The example is illustrative and does not describe a real case.

    The course and the evidence

    There is a further reason, outside the technical standard, why a standard course doesn't settle the matter. Since 30 September 2026, Legislative Decree 160/2026 allows a court to order disclosure of the human oversight arrangements adopted, and in that forum a certificate of attendance at a generic course says little about what competence the person who should have caught the error actually had.

    The relief the Omnibus brought to Article 4 concerns the level of literacy required in general, and leaves untouched the competence obligations for those exercising human oversight over high-risk systems. For those roles the evidence has to stay individual and tied to the specific system, which is what clause 7 asks for as well. The procedural picture is set out in the article on evidence and causation under Legislative Decree 160/2026.

    How to extend the course you already bought

    Starting over is the most common waste when the gap appears, and it's hardly ever needed. The course you paid for remains valid for what it covers, and works as the first of three layers in a plan.

    • Record the course as the plan's introductory module, listing the content it genuinely covers.
    • Link every certificate to the person's role in the matrix, through an internal document acting as the bridge.
    • Add a short module for each inventoried system, aimed at whoever uses it and whoever owns its risk. Half an hour per system, prepared internally, covers what the course couldn't contain.
    • Plan a session for top management, centred on the decisions they have to take rather than on technical concepts.
    • Define the effectiveness check, at least for critical roles, through a practical case or a review of real work.
    • Set the refresh trigger, typically a new system being adopted or a person changing role.

    The additional cost concentrates in the internal hours of whoever prepares the specific modules, who are also the people who know the systems. Buying those externally rarely pays, because the vendor would first have to learn from you what it's meant to teach your people.

    Questions to ask before buying

    Anyone still choosing a course can avoid much of the later work with five questions during selection.

    • Can the program be extended with content on our systems, and on what terms?
    • Can certificates state the role and the competences covered, or are they standard?
    • Is there a learning check distinct from the satisfaction survey?
    • Is the content current with the AI Act as amended by the Digital Omnibus of July 2026?
    • Who updates the program when the rules change, and how often?

    A vendor answering vaguely on the first and the third is offering a product rather than a path, and should be assessed as such.

    Next step

    The course already paid for is a base to extend. The coordination between the two obligations is described in AI literacy and ISO 42001 competence, the construction of the levels in the roles-competence matrix, and the most frequent audit findings in the mistakes that make an AI training plan fail an audit.

    Our approach to building role-based tracks is described on the AI Training page. To assess what your plan is missing, you can book an assessment meeting.

    Want to discuss this for your company?

    30 minutes with us to figure out where to start, or an AI Rating to measure your starting point.

    #AI literacy#AI Act#ISO IEC 42001#AI training#Digital Omnibus
    Share

    Keep reading