Which AI does our company actually use today?
Hardly anyone asks that question. Instead, the AI Act is treated as a compliance topic: a deadline, a folder for the auditor. I think that is the wrong discussion — because it starts at the wrong end.
The real problem
In most organisations, AI was never introduced. It seeped in.
Marketing writes copy with ChatGPT. HR screens applications with a tool that carries "AI-powered" in its name. Development uses Copilot, support runs a chatbot, project management has its status reports generated. Every department on its own, often without approval, almost always without a central overview.
The numbers are clear. Depending on the study, 71 to 80 percent of employees use AI tools their IT never approved. According to an ESCRIBA survey from June 2026, almost every second person works with AI without authorisation — around 13 percent of them with customer data.
This is not rebellion. People reach for these tools because they get their work done faster — not to dodge the rules. Shadow AI is not an edge case; it has long been everyday work.
The risk therefore does not sit in any single tool. It sits in the fact that nobody can say which systems are running in the organisation, which data they see and which decisions they influence. The lack of transparency is the risk.
And it has consequences even without any regulation. Where nobody knows what is running, nobody can check quality — errors in AI-generated results surface, if at all, at the customer's end. Responsibility cannot be clarified after the fact, because it never existed. An organisation can spend months producing results that nobody stands behind when it matters.
What the AI Act has to do with it
Against this background, the AI Act looks less like a bureaucratic monster and more like an imposition of the useful kind. Its risk-based approach presupposes something that has little to do with regulation: knowing where AI is in use at all.
The EU has just postponed the obligations for most high-risk systems by 16 months to the end of 2027 via the "Digital Omnibus", some even further. The postponement removes the time pressure — it does not remove the problem. A company that does not know which AI it uses still will not know at the end of 2027.
One obligation has applied all along, since February 2025, independent of any risk class: AI literacy. Whoever deploys AI must make sure their own people understand what they are working with — because those who do not understand how a system arrives at its results can neither judge nor supervise its risks.
Three questions instead of twenty checklist items
Whether an organisation is prepared is not decided by the volume of its documentation. It is decided by three questions:
Do I know which AI systems are actually used in our organisation — including the ones that were never approved?
Do I know who is responsible for each of these systems?
Do I know which decisions are still taken by people — and which, in practice, no longer are?
Whoever can answer these three questions reliably has the foundation for everything else. Whoever cannot had a governance problem long before the AI Act — it just did not have that name yet.
What remains
I do not believe the AI Act changes companies. Regulation rarely changes anything an organisation does not want to change anyway.
But it exposes which companies understand their own AI usage — and which have spent years using tools they never inventoried, never assessed and never assigned to anyone.
This test is not graded in Brussels but inside your own company. Most just do not know their result yet.
If you want a first read without standing up an inventory first: the AI Readiness Check asks 18 questions and scores them across five dimensions — strategy, data, competence, processes, governance. It does not evidence competence in the sense of Article 4. It shows where the gap is widest.
Sources: Digital Omnibus decision (EU Parliament, 16 June 2026; Council, 29 June 2026); the AI Act's AI-literacy obligation, in force since February 2025; shadow-AI surveys by WalkMe (2025), UpGuard (2025) and ESCRIBA (June 2026).
Frequently asked questions
Does the AI literacy obligation apply to small companies too?
Yes. Article 4 of the EU AI Act addresses providers and deployers of AI systems and sets no threshold by company size. A deployer is anyone using an AI system under their own authority — that covers a five-person team using a language model for proposals as much as a corporation. The scale of the measures may follow the use case; the obligation itself does not.
Since when does Article 4 apply — and did the Digital Omnibus change that?
The AI literacy obligation has applied since 2 February 2025 and remains in force unchanged. The Digital Omnibus postponed the obligations for most high-risk systems by 16 months, in parts into 2028 — Article 4 is not among them. Reading the postponement as a general reprieve confuses two separate rules.
What does AI literacy mean in practice?
That the people working with an AI system, or supervising it, understand how it arrives at its results and where its limits lie — proportionate to their role and to the context of use. This is not a certification requirement. It is the ability to judge an output rather than adopt it.
Is a one-off training session enough to meet the obligation?
The regulation prescribes no format, so formally perhaps. In practice it rarely holds: tools, models and use cases change faster than an annual cycle, and the obligation is measured by what people can actually do, not by an attendance list. Anyone who wants to evidence compliance needs a record of which role understood what.
Where do you start when nobody knows which AI is in use?
With exactly that question. An inventory precedes any classification: which systems are in use, by whom, with which data, and which decisions they influence. Without that list every risk rating is guesswork — and experience shows the answers come from the business units, not from IT.
Related offering
AI literacy under Article 4 of the EU AI Act
Workshops for teams that have to meet the obligation — plus team licences for the online courses, so the capability outlasts the session.
Learn more →
Philip Müller
Trainer and consultant for project management, agile methods and AI in day-to-day project work.
About the author →Newsletter
What actually works in day-to-day projects — every other week.
New articles, tools, and what has held up when using AI on real projects. No sales talk, no roundup of news you have already seen.
I would like to receive occasional emails from Agile Forge about courses, new content and offers. You can unsubscribe at any time with one click. I never pass your address on. Read the privacy policy
