
The first five articles of the European Union’s AI Act entered into application on 2 February:
Article 1: “Subject matter”
Article 2: “Scope”
Article 3: “Definitions”
Article 4: “AI literacy”
Article 5: “Prohibited AI practices”
Under Article 4 of the AI Act, from 2 February 2025 providers and deployers of AI systems must ensure that their staff have a sufficient level of AI literacy. In practice that means employees need to know how AI works, how it affects decision-making, and what risks are involved.
The full article, if you want it
AI Act, Article 4, AI literacy: Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.
In Finland, though, there is a waiting period under way while more detailed guidance from the authorities on applying the articles is expected. At the same time, organisations’ obligations are looming on the horizon and action should be taken.
The guidance on AI literacy (Article 4) published by the Dutch data protection authority (Autoriteit Persoonsgegevens, “AP” here) in late January 2025 works well as a first road map. It is hard to see the Finnish authority’s interpretation differing from that of its Dutch colleagues.
I therefore found it worth translating AP’s four-page original document into Finnish, since it was only available in Dutch. You can download the Finnish version from the Finnish version of this article.
Below is a short summary of the main points in AP’s guidance.
Why does AI literacy matter so much?
AI is no longer just a technological tool but a strategic dimension reaching into company processes, employees’ daily work, and customers’ experiences. From an AI literacy perspective, the most important thing is to make sure the whole organisation — not just the IT department or the lawyers — understands AI’s risks, opportunities, and legal obligations.
That does not mean everyone needs the same knowledge, or that everyone should attend the same training. There is no one-size-fits-all solution. What matters, according to AP, is that staff can interpret the results AI systems produce and understand how decisions made with AI affect the people those decisions concern.
A four-step action plan
AP offers a straightforward, practical way to approach AI literacy:
Map and identify: start by finding out where and how AI is used in your organisation. Map every system and application that uses algorithms or automated decision-making. That makes the risks and opportunities visible.
Set goals: set clear goals for how the organisation’s AI expertise and capability areas should develop. Prioritise measures by risk level. That ensures investment is directed correctly and that ethical and legal requirements are met.
Implement strategies and measures: make the plan concrete. Organise training, coach leadership and staff, and create clear guidance for everyday situations. Make sure everyone understands what AI literacy is about — don’t leave it as the specialists’ responsibility alone.
Evaluate and improve continuously: AI develops fast, and so do standards and regulation. Using the technology therefore requires continuous monitoring and updating. Carry out regular reviews in which you bring skills needs and guidance up to date.
The AI Act – an opportunity for Finnish organisations
Organisations should understand that investing in AI literacy is not only a legal safety net but a genuine competitive advantage. According to the final report of Finland’s Kasvuriihi growth project, published at the end of February, “skills and talent are the key bottleneck in adopting AI.”
When an organisation invests systematically in AI literacy and ensures its technical and ethical foundations are strong, it can genuinely stand out in the market by offering durable, innovative AI solutions. That also supports the Kasvuriihi recommendation above, which emphasises cooperation between the private and public sectors in advancing AI expertise. Strong AI maturity thus creates competitive advantage and increases trust between stakeholders, when data use, risk management, and ethical principles go hand in hand — benefiting both organisations and society as a whole.
Enjoyed this piece? Subscribe to get notified about new Tekoälyfoorumi articles straight to your inbox. We’d also hugely appreciate it if you left us a review on Google. Thank you. 💙





