For leaders operating in the European Union, AI literacy stopped being a development topic on 2 February 2025. Article 4 of the EU AI Act requires providers and deployers to "take measures to ensure, to their best extent, a sufficient level of AI literacy" among staff and anyone else operating AI systems on their behalf. It applies to every provider and deployer, at every risk tier, whether or not the organisation runs anything classified as high-risk. Commission supervision and enforcement of the literacy rules began on 2 August 2026.
Most organisations have responded by buying tool training and calling it literacy. That satisfies a procurement line rather than the obligation, and more importantly it does not produce the thing the obligation exists to produce.
What the Article actually says, and what it deliberately does not
The text is short. Measures must be taken "to their best extent", judged against "technical knowledge, experience, education and training and the context the AI systems are to be used in", and taking account of "the persons or groups of persons on whom the AI systems are to be used."
Three things follow, and the third is the one that gets missed.
It is proportionate, not uniform. There is no prescribed curriculum and no certificate. A radiographer, a recruiter and a board director need different things, and a compliance approach that gives all three the same ninety-minute module has satisfied nobody's actual need.
It is contextual. Literacy is defined relative to the systems being used and the setting they are used in, which means it cannot be bought off the shelf and cannot be finished. It changes when the tools change.
It extends to people affected, not only people operating. The final clause pulls in the persons on whom systems are used. For an employer that includes candidates screened by a system and staff whose work is allocated by one. Very few AI literacy programmes have noticed this clause exists.
What leaders specifically need, which is not what staff need
The obligation covers staff. But a leader's literacy failure is more consequential than a user's, because leaders decide what gets deployed, what gets cut, and what gets measured. Four capabilities matter more than any tool knowledge.
Knowing what these systems are bad at, not just what they are good at. The competence boundary is jagged rather than smooth: in the Dell'Acqua field experiment with 758 consultants, those working just outside it were 19 percentage points less likely to reach a correct answer than consultants with no AI at all. A leader who cannot describe where their systems fail is authorising deployments blind.
Reading a claim about AI performance. Distinguishing a randomised trial from a vendor survey, noticing when an average conceals opposite effects on different people, asking what a study does not support. In the radiology evidence, the effect of AI assistance ran from strongly positive to strongly negative between individual readers and was not predicted by experience. An average is not a finding, and leaders are shown averages constantly.
Understanding what deployment does to capability. Automating a task removes the practice that built the judgement for it. Someone has to be accountable for whether the organisation can still do the work if the system fails, and that person is not in the IT function.
Knowing what you personally can no longer verify. The most useful question a leader can ask themselves is which decisions they are now approving rather than making. That is not a governance question. It is a personal one, and nobody else can answer it for them.
The SuperSkills view
"AI literacy" is a weak frame for a strong obligation, and the weakness is predictable. Literacy language invites a training solution: a course, a completion rate, a dashboard. But completion is not capability, and an organisation can reach 100 per cent completion while its actual ability to judge machine output stays exactly where it was. That is usage theatre with a compliance certificate attached.
The stronger frame is judgement. Article 4 does not ask whether people know how to use the tools. It asks whether they have a sufficient level of understanding for their context and for the people affected. That is a question about competence to decide, not familiarity with an interface. Read that way, the obligation and the capability argument point the same direction, and Article 14 confirms it by requiring that overseers of high-risk systems can detect anomalies and remain aware of automation bias.
There is a real risk worth naming. Because Article 4 says "to their best extent" and prescribes no curriculum, it is unusually easy to comply with cheaply and badly. The likely equilibrium is a market of certificates that satisfy auditors and change nothing. An organisation that wants the capability rather than the certificate has to measure something other than completion, which almost nobody currently does. See how should leaders respond to AI.
Where this is uncertain
Article 4 has been in force since February 2025, but enforcement only began this month, and no guidance yet defines what "sufficient" means in practice. There is no case law and no penalty precedent. Reasonable organisations will interpret the standard very differently for at least the next year, and anyone stating confidently what compliance requires is going beyond what exists.
This page describes the obligation and offers an interpretation of what it should mean. It is not legal advice, and organisations should take their own.
What to do
- Segment by decision rights, not by seniority. The people who need most are those whose judgement the organisation relies on and who are now working with machine output. That is rarely the same list as the training budget's.
- Measure capability change, not completion. Can people identify a plausible-but-wrong output in their own domain? That is testable, and it is the only measure that means anything.
- Cover the affected, not only the operators. The final clause of Article 4 is the one most programmes miss.
- Write down what each role must be able to detect. The Delegation Boundary Map turns this into a stage-by-stage record with a named owner.
- Resource the practice, not just the training. Literacy that is never exercised depreciates, and the depreciation is invisible until something fails.
Related SuperSkills research
On the oversight duty that follows from this, meaningful human oversight. On why completion is not capability, usage theatre and the AI readiness lie. On the leadership response, how should leaders respond to AI and the CHRO guide. On what erodes underneath, capability debt.
Key sources
- Article 4, AI literacy, Regulation (EU) 2024/1689. In force 2 February 2025.
- Article 14, Human Oversight. In force 2 August 2026.
- Dell'Acqua, F. et al. (2023). Navigating the Jagged Technological Frontier. Harvard Business School and BCG.
- Yu, F. et al. (2024). Heterogeneity and predictors of the effects of AI assistance on radiologists. Nature Medicine, 30(3).
About this research
Rahim Hirji is the author of SuperSkills: The Seven Human Skills for the Age of AI (Kogan Page, 2026) and founder of The SuperSkills Intelligence Company. AI literacy is a term from the regulation and the wider field, not a coinage from this work. The regulatory position is quoted from the primary text and dated; the interpretation is the author's and is kept separate. Not legal advice. On a 90-day review cycle while enforcement practice develops.
Cite this
Hirji, R. (2026). What does AI literacy mean for leaders? The SuperSkills Intelligence Company. Last reviewed 26 August 2026. thesuperskills.com/research/what-does-ai-literacy-mean-for-leaders