Frameworks @ Srna SEO

The AI Literacy Framework: Why Adoption Without Understanding Is Just Exposure

The AI Literacy Framework: Why Adoption Without Understanding Is Just Exposure

In This Article

    You bought the tools. Copilot is rolled out, ChatGPT Enterprise is on half the laptops, someone in HR is piloting an AI recruitment screen, and the board deck says “AI-enabled” in three places. And you still don’t know, with any precision, whether your organization understands what any of it is actually doing.

    That gap is what this Framework is about.

    AI literacy is the ability to understand, question, verify and act on what an AI system produces, at the level appropriate to your role. That’s the working definition I use, and it’s close to the one the EU AI Act settled on when it wrote Article 4 into law back in February 2025. Not “can you use the tool.” Not “can you write a good prompt.” Whether you understand what happens when the system’s output becomes part of a decision, a workflow, a customer interaction, or a policy.

    Most companies never get past prompt training. That’s not AI literacy. That’s tool usage with a certificate attached.

    This Framework isn’t a training curriculum. It won’t tell you which LMS module to buy or how many hours your compliance course needs to run. It’s a way of measuring whether the people making decisions with AI, from the employee typing into a chatbot to the minister approving a national data center, actually understand what they’re accountable for. If you’re looking for a checklist to hand your legal team, this will get you partway there. If you’re trying to work out whether your organization is genuinely capable of operating AI or just renting the appearance of it, this is the tool.

    Two Different AI Literacy Problems

    There’s an enterprise version of this problem and a national one, and they rhyme more than people notice.

    The enterprise problem

    A company can buy every AI product on the market. ChatGPT, Copilot, Claude, Gemini, an AI-powered CRM, an AI recruitment platform, AI customer service. None of that is the hard part anymore, procurement can move fast when the budget’s approved.

    But if the people using those systems don’t understand what the AI is actually doing, what data they’re feeding it, when the output can be trusted and when it needs to be verified, what must never be entered into it, how the output affects a customer or a colleague, and who’s accountable when it’s wrong, then the company hasn’t adopted AI. It has distributed an unknown decision-making capability throughout the organization, and nobody signed off on that, because nobody framed it that way.

    The national problem

    Zoom out and the same shape reappears at country scale. A government can own GPUs. It can build data centers, stand up a sovereign cloud, even train a national model. I’ve sat in Geneva session and hear this pitched as the finish line.

    It isn’t. If the civil servants, judges, doctors, teachers, regulators and citizens who interact with those systems can’t understand, question or challenge them, the country doesn’t have AI sovereignty. It has AI infrastructure with nobody home. Case study I keep coming back to when I make this point in client workshops.

    The EU has started treating this as a lifelong learning problem, not a one-off training tick box, folding AI literacy into reskilling, upskilling and the broader labour market conversation. In May 2026 the EU Council went further and explicitly tied AI literacy to critical thinking, media literacy and data sovereignty in education policy. That’s the compliance question widening into a capability question, and it’s the widening this Framework is built to track.

    Where Article 4 Actually Stands Right Now

    Because the legal ground has shifted under this topic twice in the last few months, and most of what’s published about it is already stale.

    Article 4 of Regulation (EU) 2024/1689 has technically applied since 2 February 2025. But national market surveillance authorities gained formal supervisory powers to enforce it as of August 2026, which means the obligation stopped being theoretical this summer. Breaches sit at the intermediate penalty tier under the AI Act, up to EUR 7.5 million or 1% of global annual turnover, whichever is greater.

    There’s a second change worth flagging, because it changes how you defend a compliance program if it’s ever challenged. Following the Digital Omnibus, the standard shifted from an obligation to ensure a sufficient level of AI literacy to an obligation to support its development, which in legal terms is a move from an obligation of result to an obligation of effort. In plain terms, regulators can no longer demand proof that every employee reached some fixed literacy bar. What they can demand is evidence that you built a real program aimed at getting them there, and kept building it.

    That’s not a loophole. It’s actually a harder standard to fake, because “effort” has to be demonstrated with documentation, cadence and follow-through, not a single training event you can point to once and move on from. A screenshot of a completed e-learning module is not evidence of effort. A programme with levels, audiences, review cycles and escalation paths is. Which is exactly what the rest of this Framework builds toward.

    AI Literacy Is Not AI Skills

    I want to be precise about this distinction because I see it collapsed constantly, usually by vendors selling training.

    A developer needs AI skills. A lawyer doesn’t need to know how to fine-tune a model. A CEO doesn’t need to understand gradient descent. A civil servant doesn’t need to build an LLM from scratch.

    But all of them need to be able to answer nine questions about any AI system they touch or rely on:

    1. What is this system actually doing?
    2. What does it know, and what doesn’t it know?
    3. What data does it use, and where does that data go?
    4. What happens when it’s wrong?
    5. Who remains accountable for the outcome?
    6. Can I challenge its output?
    7. Can I verify its output independently?
    8. Can I replace it if I need to?
    9. Can I operate without it, even badly, if it fails?

    That list is literacy. Everything else is training.

    The AI Literacy Maturity Matrix

    Not everyone needs the same depth, and treating a call centre agent and a board member as equivalent literacy targets is where most corporate programs waste their budget. I use two axes: how deep the understanding needs to go, and who needs it.

    Depth (0 to 5):

    LevelNameWhat it means in practice
    0UnawareDoesn’t know where AI is being used in their own workflow
    1AwareKnows AI exists in the system, can identify AI-enabled touchpoints
    2UserOperates the tool correctly, follows basic prompting and safe-use rules
    3Critical UserRecognizes hallucination, bias and uncertainty, verifies before acting
    4Responsible OperatorUnderstands data flow, risk exposure, human oversight duties
    5StrategistCan evaluate dependency, architecture and organizational or national exposure

    Audience (who needs which floor, not ceiling):

    LayerWhoMinimum functional level
    CitizenEveryone interacting with AI systemsLevel 1-2
    WorkerAnyone using AI tools day to dayLevel 2-3
    ProfessionalDomain specialists (legal, medical, financial, technical)Level 3-4
    Decision-makerManagers, executives, procuring officialsLevel 4
    StrategistBoards, governments, national leadershipLevel 5

    Cross those two tables and you get something you can actually audit, not just a poster on the intranet. A manager sitting at Level 2 while accountable for Level 4 decisions isn’t a training gap, it’s a governance failure waiting for an incident to expose it. I’ve written before about what that looks like when it reaches an audit committee.

    The AI Dependency Gap

    This is the single most useful number I’ve built into this Framework, and it’s the one I’d lead with if you only take one thing from this article.

    Picture an organization where 90% of employees use AI daily, 10% understand roughly how it works, 5% understand its actual risk profile, 1% could evaluate the underlying system if asked, and effectively 0% could replace it on short notice. That organization looks highly AI-enabled on every dashboard that measures adoption. Strategically, it’s dangerously exposed.

    So define it plainly:

    AI Dependency Gap = AI Adoption − AI Literacy

    The wider that gap, the more the organization has outsourced not just a tool but its own judgment, without anyone deciding to do that on purpose. It’s the same exposure I’ve described in competitive displacement scenarios, except here the threat isn’t a competitor moving faster, it’s your own workforce moving faster than your understanding of what they’re relying on.

    Adoption should never outrun literacy for long enough to become permanent. In practice, when I score this gap across a client’s functions, the widest gaps rarely sit where people expect. It’s not the front-line staff, who tend to get whatever training exists. It’s the decision-makers one or two levels up, who adopted AI-assisted reporting and procurement tools early, assumed competence because they were early, and never actually closed the loop on Level 4 questions like accountability and audit trail.

    For example, in two big international organizations I was supporting recently, everyone was using AI daily, but none of them provided the training on it’s usage, there were no any guidelines on what and how to do, and there was not clear strategy on it’s usage. This is not lack of knowledge, this is lack of initiative, understanding and corporate responsibility.

    This is also, not coincidentally, exactly what the assessment I built alongside this Framework measures. If you want to see where your own organization’s gap actually sits rather than estimate it, that’s the starting point, get in touch and I’ll walk you through it.

    The Right to Escalate

    AI literacy isn’t only about knowing how to use a system. It’s about knowing when not to, and having a legitimate, understood path to say so.

    Can the employee recognize when an AI recommendation needs a human check before it goes further? Can a manager recognize when an AI-generated report shouldn’t be treated as evidence in a decision? Can a government official recognize when an automated classification needs to be escalated rather than accepted?

    A properly literate organization doesn’t just teach people to use AI. It teaches them when to stop, question, override and escalate it, and it makes that a protected action rather than a career risk. That maps directly onto the human oversight duties already written into the AI Act, and it’s the piece most training programs skip entirely because it’s harder to put in a slide.

    Institutional AI Memory

    Here’s a question I ask clients that usually produces a long pause: if the five people who actually understand how your AI systems work all left tomorrow, what would remain?

    For most organizations, the honest answer is a vendor contract and a support ticket queue. Knowledge lived in five heads, not in documentation, procedures or institutional capability. That’s a sovereignty problem, just at company scale instead of country scale, and it connects to something I flagged in a piece on what security audits routinely miss: the risk isn’t only that data leaves the building, it’s that understanding never gets written down in the first place.

    The Institutional AI Memory Principle: critical AI knowledge must remain inside the institution, even when the technology itself is externally supplied. If your AI knowledge only exists as tribal knowledge in a few people’s heads, you’re not just dependent on a vendor. You’re dependent on those five people who left you.

    AI Literacy for Procurement

    The people buying AI systems need a different literacy from the people using them day to day, and this is the layer most compliance programs never touch because procurement doesn’t usually sit in the training budget conversation.

    Before signing, procurement should be able to get straight answers to:

    • Where is our data processed, and under which jurisdiction?
    • Who owns the model, and can the vendor train on our inputs?
    • Can we export our data in a usable format if we leave?
    • What happens to our data and our access if the vendor disappears or is acquired?
    • What documentation do we receive, and is it enough to survive an audit?
    • Can the system be independently audited?
    • What happens, contractually and operationally, when the underlying model changes?
    • Can we replace this system, and how long would that actually take?

    Answer those eight honestly and you’ve turned AI literacy into a supply-chain capability instead of a training slide, which is where it belongs. I’ll go deeper on building this into an actual procurement checklist in a follow-up piece, this Framework is the diagnostic layer, the Blueprint would be the operational one.

    AI Sovereignty and the Human Capability Layer

    This is where the enterprise and national threads I opened with tie back together.

    I’ve argued elsewhere that sovereignty isn’t one thing, it’s a stack:

    AI Sovereignty = Infrastructure + Data + Models + Governance + Human Capability

    Most national strategies I see stop at the first three. GPUs, data centres, a domestic model. Governance gets a mention. Human capability, the layer where AI literacy actually lives, is treated as an afterthought or an education ministry problem to solve separately.

    But a country cannot be sovereign over systems its own people cannot understand. Ownership of the infrastructure without the capability to interrogate what runs on it is possession without control. That’s true whether the “country” in question is a nation-state or a business unit that bought its way into AI without building the judgment to run it.

    How to Actually Test Literacy

    The honest answer is that certificates don’t measure this. A three-hour AI compliance course completed by 100% of staff tells you almost nothing about whether those staff would catch a bad output before it reached a customer.

    What actually measures literacy is behavior, tested against a simple sequence: recognize, question, verify, decide, escalate, document. Can the person recognize an AI-influenced decision point, question the output rather than accepting it by default, verify it against something independent, decide with that verification in hand, escalate when the decision exceeds their level, and document enough that the next person doesn’t have to start from zero?

    Test that, even informally, in a handful of real scenarios per role, and you’ll learn more about your actual exposure than any completion rate ever will.

    Where to Start This Week

    You don’t need the full national scorecard to begin, that’s a separate, deeper piece I’m building next. Start smaller and closer to home:

    1. Map where AI actually touches decisions in your organization, not where IT thinks it does, where it actually does.
    2. Score your Dependency Gap for the three functions with the highest AI adoption. Adoption minus literacy, function by function.
    3. Identify who sits above their literacy level for the decisions they’re accountable for. That’s your highest-risk group, not your least trained one.
    4. Build one escalation path that people will actually use, tested, not theoretical.
    5. Document what five key people know. If you can’t write it down, you don’t have institutional memory, you have institutional luck.

    In my experience running this kind of assessment with enterprise clients, closing even one level of the gap for the decision-maker layer, moving managers from Level 2 to Level 3, is usually where the exposure drops fastest, well before you touch the front line. It’s a smaller group, the decisions carry more weight, and the fix is faster than a company-wide rollout.

    FAQ

    Article 4 defines it as the skills, knowledge and understanding that let people who provide, deploy or are affected by AI systems make informed decisions about them, at a level appropriate to their role and context.

    It applies to every organization that provides or deploys any AI system in the EU, regardless of size or risk classification. High-risk systems carry additional obligations, but the literacy duty itself is universal.

    The obligation moved from ensuring a sufficient level of AI literacy to supporting its development, an obligation of effort rather than result. The underlying duty and the enforcement timeline weren’t changed.

    Skills training teaches someone to operate a tool. Literacy is the ability to question, verify and take accountability for what that tool produces. You can complete every skills module available and still lack literacy.

    It’s AI adoption minus AI literacy, measured per function or per organization. A wide gap means an organization looks AI-enabled while actually being highly exposed to failures it can’t recognize or correct.

    By observed behavior against a sequence: recognize, question, verify, decide, escalate, document. Completion certificates measure attendance, not capability.

    This article was researched and drafted with the assistance of AI tools and reviewed and edited by the author prior to publication. Images are AI generated.

    Ready to see where your own organization’s AI Dependency Gap actually sits? That’s the starting point for the advisory work I do with enterprise teams, get in touch and I’ll walk you through the assessment.

    Share in 𝕏
    Ivica Srncevic
    Author

    Ivica Srncevic is an independent AI strategist, researcher, framework author, and international speaker focused on AI sovereignty, knowledge infrastructure, governance, AI retrieval, and the evolving relationship between organizations and intelligent systems. His work examines what AI systems can see, retrieve, infer, and reconstruct from organizational information, and how organizations can retain greater control over their data, knowledge, and AI infrastructure. In 2026, he spoke at the AIFOD Geneva Summit at UN Geneva on what nations must own and what they can safely share, with a particular focus on data ownership, control, and sovereign AI infrastructure.

    Articles: 156