IA in the EU in 2025

Artificial Intelligence Has Entered a New Era of Compliance
Artificial intelligence crossed a new threshold at the beginning of February—one of particular significance for corporate compliance officers: the first five articles of the European AI Act have officially come into force. This marks the formal beginning of the AI compliance era.
If your company uses artificial intelligence and operates in Europe, or if it develops and markets AI systems used within the EU, it may now fall under the scope of the regulation. You must therefore begin integrating compliance policies and procedures into your company’s AI adoption strategy—sooner rather than later.
Understanding Articles 4 and 5 of the AI Act
The first three articles of the AI Act can be set aside for now; they serve primarily as a preamble outlining the law’s objectives, scope, and key definitions. It is Articles 4 and 5 that demand the full attention of compliance officers, who must now begin to assess their implications for company policies, risk assessments, and employee training programs.
What Does Article 4 of the EU AI Act Say?
Let’s begin with Article 4. It states that all providers and deployers of artificial intelligence systems must:
“Take measures to ensure, to the extent possible, an adequate level of AI literacy among their staff and other persons involved in the operation or use of AI systems on their behalf, taking into account their technical knowledge, experience, education, and training, as well as the context in which the AI systems are intended to be used and the persons or groups of persons on whom the systems are intended to be used.”
Defining ‘AI Literacy’ in the European AI Act
The term "AI literacy" refers to the skills, knowledge, and awareness that enable providers, users, and impacted individuals—within the context of their rights and responsibilities under the regulation—to deploy AI systems with informed understanding. It also entails recognizing both the opportunities and risks of AI, as well as the potential harms it may cause.
In other words, your organization must train its employees to understand the risks AI can pose—a seemingly simple requirement that opens the door to a host of practical challenges.
AI Compliance Begins with AI Governance
At its core, the challenge is this: you cannot develop meaningful AI literacy within your organization if you don’t first understand how your company is using AI. This is becoming increasingly problematic, as it’s now incredibly easy for employees to incorporate AI tools into their workflows and daily routines.
Take, for example, DeepSeek—a Chinese generative AI app that seemingly came out of nowhere and quickly became one of the most popular applications on the internet. What privacy risks does DeepSeek pose? What cybersecurity vulnerabilities might it introduce to your organization? Nobody really knows (even though nearly every data protection authority in Europe is actively trying to find out).
Thus, before you can even begin crafting the policies, procedures, and training needed to meet the expected level of AI fluency, your leadership team must first establish some form of governance mechanism to oversee and guide employee use of AI.
A large organization, for instance, might create an "AI Use Council," composed of leaders from first-line operational functions alongside second-line risk management departments (compliance, privacy, HR, legal, cybersecurity). Together, they would develop internal rules for AI adoption. Perhaps some AI systems may be used, others not; perhaps certain tasks are AI-permissible, while others remain off-limits; maybe all customer-facing AI tools begin with a disclaimer like “You are now interacting with AI”—and so on.
The Role of Ethics, Leadership, and Corporate Culture
Where do ethics, tone at the top, and corporate culture fit into all of this? Ideally, they should permeate the entire discussion. Leadership must demonstrate a clear commitment to the ethical use of AI—even if the organization is still grappling with the specific ethical questions that arise from particular use cases. This is where your AI governance council must step in.
Once executive leadership sends a clear message that (a) using AI is encouraged, but (b) we will adopt it carefully, ethically, and in compliance with the law—then a strong culture of ethics will naturally give rise to a culture of responsible AI use. From there, developing the appropriate level of AI literacy becomes much more achievable.
What Does Article 5 of the EU AI Act Say?
Article 5 introduces prohibited AI practices—a foundational element of the EU AI Act, establishing a hierarchy of acceptable AI uses, beginning with the most serious use cases that are banned altogether.
Many of these prohibited practices will not come as a surprise to leaders familiar with Western regulatory standards. For example, the law forbids AI that:
Employs “subliminal techniques beyond a person’s consciousness or deliberately manipulative or deceptive techniques” to materially distort a person’s behavior;
Monitors individuals to predict the likelihood of them committing a crime, “based solely on profiling or assessing their personality traits or characteristics”;
Infers a person’s emotional state in workplace or educational settings—unless it’s for medical or safety reasons.
There’s no need to delve into every prohibited use case here. What matters for compliance officers is that your organization has clear policies on which AI uses are unacceptable—backed by enforcement mechanisms to ensure no one implements them, knowingly or otherwise.
For instance, it’s not far-fetched to imagine a third-party vendor or business partner using AI in a prohibited manner on your company’s behalf. You’ll therefore need firm policies, strong contract management capabilities, and robust third-party oversight. And to return to the point on AI literacy—your employees must be trained to recognize that this represents a third-party AI risk, and that the company will need their cooperation to avoid it.
A New Era, Grounded in Familiar Principles
In time, the EU AI Act will introduce additional layers of acceptable AI use, each requiring less oversight as the associated risks decrease. Corporate ethics and compliance teams will face new challenges, needing to design processes for evaluating the risks of these varied use cases and implement corresponding controls.
In many ways, your AI compliance program will rest on the familiar pillars of a strong ethics and compliance framework. In other ways, it represents an entirely new frontier. Ready or not, that future has already arrived...