Can your staff recognise when they should not trust AI?
AI literacy is not a general awareness course. Staff need the knowledge, authority and practical judgment required for the systems they actually use.
In today’s governance note, I want you to consider what your staff must understand before they are permitted to use AI in their work.
Many organisations begin with access. They purchase a tool, make it available and provide introductory training on prompts, features and approved uses. Staff may leave knowing how to generate a summary or improve a document. That does not necessarily mean they are ready to use the system responsibly.
AI literacy should help someone recognise when an output is unreliable, when information must not be entered, when a decision exceeds their authority and when the matter needs to be escalated. It must prepare them not only to operate the tool, but to exercise judgment around it. This question belongs much earlier than rollout. Before purchasing or approving an AI system, identify the people who will use it, the decisions it may influence and the consequences of foreseeable mistakes. That assessment should determine the literacy required. Training designed after deployment is likely to explain the product. Training designed before deployment can still influence whether the product is suitable.
I would avoid giving everyone the same AI course. A communications officer using AI to develop a first draft needs to understand verification, disclosure, copyright and the risk of inventing authoritative-sounding information. A caseworker using an AI-generated summary needs to recognise missing context and understand that compression can change meaning. A manager receiving predictive analysis needs to understand uncertainty, inappropriate comparison and the limits of the underlying data.
Technical staff require different knowledge again. They may understand models well while knowing less about the legal duties, service context or institutional consequences surrounding a particular use.
Role-based literacy should answer five questions:
What can this system do?
Where does it commonly fail?
What information may be used?
Which decisions must remain with a person?
What should happen when something goes wrong?
Staff also need permission to act on that knowledge. There is little value in teaching someone to question an AI output if deadlines, targets or managerial expectations make disagreement difficult. A trained employee who is expected to accept the system’s recommendation is not providing meaningful human oversight. Institutional readiness includes the authority to pause, correct or reject an output without being treated as an obstacle to adoption. Article 4 of the EU AI Act has applied since 2 February 2025. It requires providers and deployers to support the development of AI literacy among staff and others operating AI systems on their behalf. Amendments that entered into force in July 2026 removed the requirement to guarantee a specific or “sufficient” level, but the organisational obligation remains. The European Commission says national market-surveillance authorities began supervising and enforcing the provision from 2 August 2026.
The Commission’s current guidance says literacy measures should reflect the person’s existing knowledge, the organisation’s role, the risks of the particular system and the context in which it is used. It also makes clear that reading the product instructions may be inadequate. European Commission AI literacy guidance. The UK Government’s AI Playbook similarly places the skills needed to implement and use AI among its ten principles for public-sector organisations. Its guidance connects literacy with understanding limitations, using AI securely and retaining meaningful human control. UK Government AI Playbook
Do not measure readiness by how many people completed an AI course. Ask whether the people closest to the work can recognise an unsafe, unsuitable or unreliable use, and whether your organisation has given them the authority to respond.
