AI LITERACY

The law demands competence, not certificates.

Article 2 of our EU AI Act campaign

Every day, AI systems in German organizations make decisions — or prepare them. Forecasts are adopted, texts signed off, prioritizations confirmed. Routines that work. Until they don't.

Right now, a question is on the table that nobody used to ask: Does anyone in your organization actually know what the AI system is doing? Not in theory. Not according to the documentation. But in the moment that matters — when a recommendation becomes a decision that no one can explain.

In the first part of our campaign, we showed that the EU AI Act has been in force since February 2, 2025 — quietly, without alarm, but with consequences. Now we go deeper: What does the law actually require? Who is especially affected? And what happens if nothing happens?

What does Article 4 of the EU AI Act require?

AI Literacy sounds like professional development — a seminar, an e-learning module, a checkbox in the annual plan. Article 4 of EU Regulation 2024/1689 sees it differently: providers and deployers of AI systems must ensure that everyone working with AI systems has a sufficient level of AI competence.

Three terms define the standard: Sufficient does not mean basic knowledge, but sound judgment in concrete use. Demonstrable means documented, verifiable, auditable. Organizationally embedded means not optional, not limited to individual teams, but applying to everyone who works with AI.

Good to know: The EU does not require a certificate — but it does require demonstrable competence. According to the official EU Q&A on AI Literacy, internal documentation can also serve as sufficient evidence. What matters is not the format but the substance: can the competence withstand scrutiny if a supervisory authority asks?

But Article 4 is only the regulatory framework. Behind it lies an economic fact: the gap between AI adoption and actual AI competence keeps widening — in the private sector as much as in public administration. The numbers make that clear:

40% of all employees will need to be reskilled by 2027, according to the IBM Institute for Business Value — the equivalent of 1.4 billion people worldwide. Organizations that successfully implement this reskilling report an average revenue growth advantage of 15%. (IBM IBV, "Augmenting Potential," 2023)

78% of organizations already use AI according to McKinsey — but only about a third have begun scaling it company-wide. The majority remain stuck in pilot projects, while 51% of respondents have already experienced negative consequences from AI use. (McKinsey, "The State of AI in 2025")

68% of employees who use generative AI at work access public AI tools through personal accounts. 57% enter sensitive company data while doing so. Shadow AI incidents raise the average cost of a data breach by $670,000. (Menlo Security Report, 2025; IBM Cost of a Data Breach, 2025)

What this means in practice is illustrated by one scenario: an AI system prioritizes cases, grant applications, or procurement decisions. The human role is reduced to confirming the recommendation. But what if the model systematically favors certain patterns — and no one notices? AI Literacy means knowing that formal oversight is not the same as substantive responsibility.

Why are public authorities and operators of critical infrastructure especially affected?

For companies, AI Literacy is a compliance obligation. For public authorities and operators of critical infrastructure, it goes further: here, decisions are made that directly affect people's lives. That makes AI Literacy a matter of public accountability.

Public authorities decide about people — grant applications, building permits, security classifications, personnel actions. When AI systems prepare these decisions, the requirement for traceability is especially high — not only legally, but democratically. The EU AI Act explicitly classifies such systems as high-risk: increased documentation obligations, mandatory human oversight — and AI Literacy as a basic prerequisite. An authority that uses AI without demonstrable AI competence among its staff does not meet the requirements of the EU AI Act.

At the same time, Germany's Online Access Act (OZG), digital strategy, and register modernization are accelerating AI adoption in public administration. According to a Deloitte study, 73% of surveyed public institutions in the DACH region plan to integrate generative AI into operational processes within the next two years. The pace far outstrips competence-building.

Operators of critical infrastructure — energy, water, transport, healthcare, digital infrastructure — are already subject to strict requirements under Germany's BSI Kritis Regulation and NIS2. The EU AI Act adds another layer: AI systems in operationally relevant processes are almost automatically high-risk, staff need documented AI competence, and shadow AI is an acute security risk in critical infrastructure environments. The gap between usage and governance is already alarming today: according to ISACA, 60% of employees use AI tools at work, but only 18.5% are aware of an official company policy on AI use. Fewer than a third of organizations have a mature AI governance framework, according to Gartner. AI Literacy is not an IT topic — it is a governance topic.

What happens if nothing happens?

Picture a routine audit. The supervisory authority asks: how do you ensure your employees use AI competently? Pointing to a training session from two years ago isn't enough. The question about documented proof of competence goes unanswered. The record states: no demonstrable AI governance.

Or: an AI system produces a faulty result. Damage occurs. The legal question isn't whether the system failed — it's whether the organization can demonstrably show that the person responsible knew the system's limits. Without that proof, the question of liability remains open.

Timing: Article 4 has been in force since February 2, 2025. Monitoring and enforcement rules take effect from August 2026 — from then on, market surveillance authorities begin active enforcement. (European Commission, AI Literacy Q&A)

The M2 AI License — AI Literacy that creates more than a paper trail

90 minutes of e-learning, a PDF certificate, business as usual — that's the market standard. But a checkbox on a compliance list won't protect any organization when a supervisory authority asks whether employees can actually assess AI outputs.

The M2 AI License is not a short course and not a legal seminar. It is a structured learning journey across three days and four progressively building modules — with one clear goal: employees who can legally assess AI, critically evaluate outputs, and act in the organization's interest. Anyone who truly understands AI recognizes risks before they arise, uses data responsibly, and strengthens trust in every AI-supported decision. Documented, auditable, ready to use immediately.

3 days. 4 modules. On-site or remote.

Module 1 — Fundamentals & safe use: How AI works, where its limits lie, why public AI tools are a risk in regulated environments, and how enterprise AI differs. The foundation for all further competence.

Module 2 — Effective use of AI: Prompting techniques, systematic quality assurance of AI outputs, and recognizing hallucinations. Employees learn to use AI as a tool — not as an oracle.

Module 3 — Risks & governance: Data protection, intellectual property, compliance, and organizational responsibility. This is where awareness of shadow AI takes shape, along with the ability to assess AI risks before they become problems.

Module 4 — Workflow & certification: Integration into real workflows, practical scenarios from the relevant industry, a knowledge test for the AI Driving License. The result: documented proof of competence that can be presented during audits and inspections.

The M2 AI License is scalable and adaptable to industry-specific requirements. For public authorities and operators of critical infrastructure, it delivers exactly the depth of documentation that Article 4 of the EU AI Act requires. We deliver the competence the law actually demands.

Explore the AI License

FAQ: The most common questions about AI Literacy and Article 4 of the EU AI Act

This section answers the questions most frequently asked by public authorities, IT leaders, and executives.

❓ What exactly does Article 4 of the EU AI Act require from companies and public authorities? Article 4 obliges all providers and deployers of AI systems to ensure that employees working with AI have sufficient AI competence. This includes a basic technical understanding, sound judgment when assessing AI outputs, knowledge of data protection and compliance, and the ability to assess risk. The obligation has applied since February 2, 2025.

❓ Does the AI Literacy obligation also apply to public authorities and administrations? Yes, explicitly. Public authorities and administrations are deployers of AI systems within the meaning of the EU AI Act. Many administrative AI systems also fall into the high-risk category, which means increased requirements for documentation and human oversight. AI Literacy here is not just a compliance obligation but a democratic responsibility.

❓ What is shadow AI, and why is it especially dangerous in regulated environments? Shadow AI refers to the uncontrolled use of unauthorized AI tools by employees — for example, public chatbots used for internal documents. In regulated environments, this is an acute data protection and security risk. AI Literacy builds awareness of why enterprise AI should be preferred over public tools.

❓ How can a public authority document and demonstrate AI Literacy? Through structured qualification programs with formal completion, documented participation, and proof of competence — such as the M2 AI License. It provides verifiable evidence of AI competence that can be presented during audits and inspections by supervisory authorities.

❓ Are operators of critical infrastructure more affected than other companies? Yes. Operators of critical infrastructure are already subject to increased requirements under Germany's BSI Kritis Regulation and NIS2. The EU AI Act adds to this: AI systems in critical processes are almost automatically high-risk, employees need demonstrable AI competence, and regulatory audits are increasingly including AI governance.

❓ What's the difference between an e-learning course and genuinely building AI Literacy? E-learning modules convey knowledge about AI. Genuinely building AI Literacy creates the ability to act in concrete situations: When should I question an AI result? What do I do if something seems wrong? How do I document my use of AI? The M2 AI License relies on practical scenarios rather than abstract knowledge.

❓ What does an initial consultation with M2 cost — and what do I get out of it? The initial consultation is free and non-binding. In 45 minutes, our experts work with you to analyze: Where does your organization use AI today? What risks arise from insufficient AI Literacy? What measures would help immediately? The conversation is not a sales pitch — it's an honest assessment of where you stand.

Sources and References
*IBM Institute for Business Value (2023): „Augmenting Potential: How AI and automation are transforming the workforce.“
*IBM (2025): CEO Study — „CEOs Double Down on AI While Navigating Enterprise Hurdles.“
*McKinsey & Company (2025): „The State of AI in 2025: Agents, Innovation, and Transformation.“
*Menlo Security (2025): Report on GenAI Usage and Data Exposure.
*IBM (2025): Cost of a Data Breach Report 2025.
*ISACA (2025): Survey on AI Usage and Governance Frameworks.
*Stanford HAI (2025): AI Index Report 2025 — 233 dokumentierte AI-Incidents in 2024.
*EU-Kommission: Q&A zu AI Literacy (digital-strategy.ec.europa.eu/de/faqs/ai-literacy-questions-answers)

 

Related News