August 31, 2026
The shift of artificial intelligence from technological curiosity to operational tool has opened a gap in the business world between those who use these capabilities maturely and those still building trust in them. Pew Research Center points to accelerating adoption: 49% of American adults now use AI chatbots, a significant jump from roughly a third in 2024. Even so, maturity hasn't caught up with the sheer scale of adoption.
The Skillsoft Workforce Readiness Report (2026) highlights a systemic gap: while 77% of managers believe their employees are set up for success with AI, only 24% of employees confirm they actually have the skills they need. It's a real disconnect — one that shows leadership frequently confuses granting access to software with building real organizational capability.
The skills shift: critical thinking as a control mechanism
Defining AI literacy as prompt-writing is a strategic mistake. Writing prompts is just the syntactic interface — the ability to phrase textual instructions; the analytical skills that follow are the ones that truly matter. In an extensive SHRM (2026) study of nearly 6,000 employees, 71% of respondents said critical thinking has become considerably more important with AI's integration, and a similarly high share noted that its absence leads directly to flawed operational decisions.
So despite the sense of lacking technical know-how, how AI output gets evaluated is the core competency now becoming formalized into work methodologies. The functional definition of AI literacy, then, sits in the ability to assess that output: spotting plausible hallucinations, understanding the epistemic limits of language models, and recognizing the exact point where automated processing needs to give way to human judgment. Original thinking becomes essential in an AI-dominated landscape — not as a secondary soft skill, but as an internal control function needed to validate assumptions, catch logical errors, and manage ambiguity.
The other side of the same coin — the trap of unguided adoption and the Shadow AI phenomenon
Individual efforts to adapt can't make up for the absence of an institutional framework. Per UNLEASH's analysis of BCG's "AI at Work 2025" report, based on comments from Nick South, BCG Managing Director and Senior Partner, employees who complete at least 5 hours of structured training show a regular-use rate of 79%, compared to 67% for those with less training. The same analysis finds that 54% of employees are willing to turn to unauthorized AI tools (Shadow AI) when their company doesn't provide adequate solutions — companies that skip formal training don't just miss out on optimization, they actively expose their information infrastructure to major vulnerabilities.
The SME sector's structural vulnerability
This governance gap is felt most acutely among small and medium businesses. According to Founder Reports (2026) data, 59% of employees at companies with fewer than 10 people say their organization has no AI usage policy. Meanwhile, although 89% of employees already use AI at work (38% daily), 44% of them operate in a complete regulatory vacuum. This lack of internal governance produces real operational risks:
- Erosion of interpersonal trust: 77% of employees say they audit colleagues' work with heightened suspicion when they know an AI tool was used.
- The cost of unowned errors: 45% of workers report having had to redo or directly correct tasks completed by colleagues who relied uncritically on AI-generated output.
Without internal policies, the theoretical speed AI offers turns into a multiplier for redundant work and execution errors — a luxury no SME can afford.
And last but not least, we've already moved from optional practice to regulatory obligation: Article 4 of the AI Act
From a legal and governance standpoint, informal use of AI technology is no longer optional. Article 4 of the European AI Regulation has, since February 2, 2025, imposed a legal obligation: providers and deployers of AI systems must take measures for the AI literacy of staff responsible for operating or using these technologies. Worth noting: the EU's "Digital Omnibus on AI" (in force since July 2026) softened this obligation's wording — from requiring providers to "ensure" an adequate level of AI literacy, to merely "support the development of" it. The legal bar is more permissive than when the obligation first took effect, but the underlying duty remains.
Taken together, all of this makes clear that a robust governance structure goes beyond user manuals; it requires setting rigid safety guardrails, defining human-in-the-loop verification steps across the operational flow, and, above all, continuous workforce training.
The action list
Right now, for businesses in Romania and the CEE region, integrating AI means, beyond buying software, an organizational maturity test built on four fundamental pillars:
- Minimum training: moving past passive formats through at least 5 hours of applied training, focused on the specific use cases within each department.
- Clear usage standards: explicitly defining permitted data classes, authorized applications, and security protocols for confidential information.
- Checkpoints and accountability: inserting formal human validation steps for any deliverable generated with the help of algorithms.
- Developing technological judgment: training teams to recognize the limits of mathematical models and logical errors.
AI already operates inside organizations, but we need to make sure this presence generates direct, measurable value — which is a management responsibility.