AI literacy is the next big compliance challenge for your business

AI For Business


Companies can no longer resort to simply deploying AI responsibly and need to prove that people understand how to use it


No one's reading Computing We need to persuade AI to grow. The figures reveal that 78% of global companies use AI and 71% deploy Genai with at least one feature. The spread of AI is also combined with a lack of understanding of basic technical principles, and is at the heart of changes in regulations, along with new focus from lawmakers on AI literacy.

As usage rises, regulatory expectations rise too. The EU AI Law on AI Literacy – a new small discussion provision in Article 4 – places an organization on a clear duty to ensure that all people (including contractors and suppliers) understand the tools they are using.

This provision, effective February 2, 2025, creates new compliance risks and operational challenges, especially for UK companies trading in the EU. Regulations will begin in August 2026, but we have seen private lawsuits threatened to enforce literacy obligations.

IT teams aren't the only knowledge of AI

According to Article 4, users and users affected by AI systems must: “AI literacy sufficient to make informed decisions.” That doesn't just mean a team, developer, or data scientist. It expands HR staff using AI in hiring, marketing teams using Genai, and even third-party contractors.

It's easy to assume that some organizations don't apply to AI literacy regulations just because they aren't in the tech industry. However, it also includes deployment of AI systems. This could catch many organizations that don't think they're dealing with AI at all.

The European Commission issued additional guidance this spring, defining AI literacy as “skills, knowledge, understanding” and required the use or exchange of AI systems responsibly. This includes:

  • Understand how AI systems work and the data they use.
  • Recognise the risks of hallucinations, discrimination, bias, and more.
  • Know when and how human surveillance is applied.
  • It recognizes legal obligations under EU AI law and other related frameworks.

It's time for businesses to have a full grasp of AI and train staff to prevent misuse.

Who do the rules apply to?

Article 4 is broad. It applies to organizations using AI in the EU, even if they are based elsewhere. This includes British companies deploying AI tools within EU operations and providing AI-enabled services to the EU market.

Importantly, non-compliance does not only affect technical teams. Business may be liable if a customer service chatbot misleads users or if the hiring algorithm perpetuates bias.

As regulators sharpen their focus, so are risks associated with shadow AI. An AI ban will not work on personal devices that switch AI usage at its best and can increase the risk of harm. According to a survey by McKinsey, 90% of employees use AI and 21% are heavy users. Therefore, staff training and clear policies are essential.

There is also a generational risk. Digital natives are more likely to find the tools they need to work on social media or search. Without proper guidance, this can open the organization at risk. Including everyone in a well-thought AI literacy program can reduce misuse and enhance compliance.

Consequences of non-compliance

The AI ​​literacy obligation came into effect on February 2, 2025, but enforcement by national authorities across the EU will begin on August 3, 2026. EU countries determine their enforcement strategies and penalty levels. The European Commission emphasized that enforcement is based on individual cases. Factors such as gravity, intention, and negligence should be taken into consideration.

The European AI Office exists to provide expertise, promote innovation and coordinate regulatory approaches, but does not directly enforce Article 4.

While a new EU regulatory regime is now in shape, the main risk for organizations that do not meet AI literacy requirements is civil litigation, with various pressure groups actively monitoring the use of AI. You can also file a complaint with the GDPR regulator if the use of your personal data is not legal, fair and reasonable. Such complaints have already been made to several social media companies and UK businesses involved in popular online dating apps that used AI on “icebreakers” in their first referrals.1.

Practical steps to prepare

All of this indicates that businesses cannot afford to wait until 2026. National regulators have already developed audit and enforcement plans. Practical preparation means working on both governance and culture.

Here are five steps that the legal and compliance team should consider:

  1. Map AI Estates
    Perform a comprehensive audit of AI systems used throughout your business. Include tools used to make decisions, interact with customers, or generate content.
  2. Develop and deliver targeted AI literacy training
    Training should not be common. It should be tailored to your role and risk exposure. For example, HR teams using AI for employment should understand issues relating to bias, data protection, and accountability.
  3. Check the relationship between the contract and the third party
    If your vendor or service provider uses AI systems on your behalf, you may need to meet AI literacy standards. Make sure these obligations are reflected in the contract.
  4. Create internal policies for AI usage and governance
    Establish clear policies regarding acceptable AI use, approval processes, and human reviews. It deals with this with the same rigour as data protection and anti-bribery frameworks.
  5. Engage the board and embed a culture of responsible AI use
    AI is currently a board-level issue. Leadership needs to set expectations for responsible innovation, transparency and compliance.

The whole picture

The introduction of Article 4 indicates clear regulatory changes. Companies cannot rely on responsibly deploying AI. They also have to prove that people understand how to use it. Just as GDPR has changed the way organizations process data, EU AI law reshaping how AI is implemented, monitored and explained across employees. What used to be good practice is now a legal obligation.

Jonathan Armstrong is a partner at Punter Southall Law



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *