Skip to content

AI literacy evidence — prove effort, not scores

The June 2026 amendments to the EU AI Act rewrote Article 4: the duty to ensure a “sufficient level” of AI literacy became a duty to take measures that support its development. That sounds like a relaxation, and legally it is. But it has a consequence most commentary skips: when the obligation is effort, the record of your effort is the entire compliance artifact. There is no score threshold to point at. There is only what you did, for whom, and whether you can show it.

The question changed shape

Under the old wording, an organization could imagine defending itself with an outcome: “our people passed.” Under the amended wording, the only meaningful question a supervisor, auditor, customer, or court can ask is: what measures did you take, and were they appropriate to your context? National market surveillance authorities supervise Article 4 from 2 August 2026, per the European Commission’s AI literacy Q&A — and the same Q&A points to the artifact that matters: an internal record of your trainings and initiatives.

What you should be able to show

Five answers, each backed by a record rather than a recollection:

  1. Which AI systems your people actually use — approved or not — and what data and decisions those systems touch. An inventory is the foundation; measures for tools you don’t know about don’t exist.
  2. What measures ran for which group. Baseline for everyone; specific measures for the roles where AI touches consequential decisions — HR, support, engineering, management.
  3. Why the measures fit. The Act’s definition of literacy (Article 3(56)) is about informed deployment — so your rationale should reference what each role does with AI, not an off-the-shelf module.
  4. Per-person records. Who worked through what, when, and what they demonstrated — not who was invited, or who clicked play.
  5. A refresh trail. Tools and policies change; a measure from spring doesn’t cover the workflow you adopted in autumn. Records should show the program moved when reality did.

Attendance is not evidence

A sign-in sheet proves a room was booked. It says nothing about what anyone can now do differently — which is what “supporting the development of literacy” means. The strong version of evidence is produced by the learning itself: the scenarios each person worked through, how they responded, where they struggled, what they went back to. That is also the version that holds up outside compliance — in an incident review, an insurance conversation, or a customer’s vendor assessment.

Copying best practice is not evidence either

The Commission publishes a living repository of AI literacy practices — useful for ideas, and worth reading. But the Commission is explicit that replicating a repository practice does not grant a presumption of compliance. Someone else’s program, however good, is evidence of their effort. Yours has to be yours: your tools, your policy, your roles, your records.

Keep the effort real

An effort-based duty invites paperwork theater — a folder of PDFs nobody read. Resist it, for a practical reason: every audience that will ever look at your evidence (a market surveillance authority, a judge, a buyer’s procurement team) is allowed to ask the follow-up question. Records of measures that plausibly work — adapted to roles, current, in the language people actually work in — survive follow-up questions. A completion export from a generic module does not. If a vendor promises compliance by certificate, that’s one of the five claims that stopped being true.

This is the shape our readiness program produces by default: role-based measures where the evidence accumulates as people learn — per person, per role, per topic — ready to export when someone asks. To see what your record could look like by the end of Q3, book a walkthrough.

Ulern builds readiness and evidence. This post explains the obligation in plain terms — it is not legal advice.

← All posts