Article content
In briefShow moreShow lessFrom 2 February 2025, the AI Act's bans on certain unacceptable practices and its AI literacy duty started applying in the EU.
- From 2 February 2025, the AI Act's bans on certain unacceptable practices and its AI literacy duty started applying in the EU.
- AI literacy is a governance task, not merely a general course.
- These duties began applying in EU member states, not Norway. Norwegian effect awaited EEA incorporation and a Norwegian KI law.
What happened
From 2 February 2025, the AI Act's bans on certain unacceptable practices and its AI literacy duty started applying in the EU. The prohibitions included specified manipulation, social scoring and certain biometric uses.
AI literacy is a governance task, not merely a general course. Training should fit role, system and risk: buyers need supplier controls, users need boundaries and quality checks, and management needs escalation.
Legal status in Norway
These duties began applying in EU member states, not Norway. Norwegian effect awaited EEA incorporation and a Norwegian KI law.
What the sources clarify
AI literacy did not mean giving everyone the same course. Measures had to reflect a person's role, knowledge, experience and context of use, as well as risks to affected people. Staff also needed to recognise prohibited practices before procurement or pilot use. Organisations could start with role-based examples: what a buyer must ask, what a developer must document, and when a caseworker must stop or escalate. Evidence of compliance lies in the connection between actual use, appropriate competence measures and follow-up, rather than attendance at a generic presentation.
The competence plan should trace back to the system inventory. A caseworker needs practice with errors and overrides, a developer needs data and logging requirements, and a manager needs stop and escalation thresholds. When use or model changes, training should be updated and understanding tested through scenarios, showing real capacity for responsible operation.
Practical implications
Management should ask the system owner to show which roles were trained, how understanding was tested and which events trigger refreshers. If a user does not understand the limits of human oversight or prohibited practices, access should remain restricted until competence is demonstrated.
Sources
European Commission: “AI Act regulatory framework and application timeline,” 2 February 2025.
EUR-Lex: “Regulation (EU) 2024/1689 — Official Journal text,” 12 July 2024.
For discussion
Which control should we verify first?







