AI Literacy for Citizen Participation Report
AI Literacy for Citizen Participation
State of the Discourse
Analysis of 1,094 AI literacy sources drawn from this week’s 4,775-article corpus reveals a discourse still built around two verbs — use and defend — while the verb that actually defines citizenship, participate, appears at the margins. Most sources treat literacy as a skills problem: how to prompt a chatbot, how to spot a deepfake, how to keep your job. The citizen as a person who might have a say in how these systems are governed, rather than merely a user coping with their outputs, is a rare framing indeed.
The Landscape
“AI literacy” in current usage is overwhelmingly a competency frame — a checklist of things an individual should be able to do. IBM’s formulation is representative: literacy as “closing the skills gap,” a workforce readiness project with the employer as implicit beneficiary Alfabetización en IA: cerrar la brecha de habilidades en … - IBM. Against this economic default, a smaller institutional strand treats literacy as civic infrastructure. France’s Renaissance Numérique argues for a littératie aimed at democratic capacity, not just employability PDF RAPPORT OCTOBRE 2025 Déployer une littératie en IA pour une, and the European Commission frames transparency obligations — labelling, disclosure — as the scaffolding citizens need to evaluate what they encounter Safer and more transparent AI. The people defining literacy, in other words, are mostly vendors selling a skill and regulators selling a rulebook. The citizen is the object, seldom the author.
Whose Literacy
The perspective distribution tilts hard toward experts talking about publics rather than publics talking back. The clearest counter-move this week comes from Noema’s case for citizen assemblies and deliberative bodies in AI governance — the argument that ordinary people can and should set terms, not just be trained to comply with them How To Give Everyday People A Say In AI Governance. That piece is notable precisely because it is an outlier. The dominant grammar is instructional: an authority who knows teaching a public that doesn’t. Even the protective literature — the CNIL’s guidance on recognising and reporting deepfakes Hypertrucage (deepfake) : comment se protéger et signaler les … - CNIL — positions the citizen as a vigilant consumer of warnings, not a participant in deciding what should be permitted in the first place.
What’s Being Taught
Two thematic clusters dominate. The first is detection: recognising synthetic media, from election deepfakes PDF Future-Proofing Elections Against Deepfake Disinformation to voice-cloned bank fraud Los estafadores ya clonan tu voz con inteligencia artificial para … to the broader “crisis of knowledge” UNESCO warns fabricated content produces Les deepfakes et la crise du savoir - UNESCO. The second is data self-defence — understanding what a tool retains and shares, exemplified by the granular consent settings buried in ChatGPT Atlas’s privacy documentation ChatGPT Atlas - Data Controls and Privacy - OpenAI Help Center. Both are defensive. What is conspicuously under-taught is the structural knowledge behind the threats: EDMO’s white paper is unusual in explaining how generative systems manufacture disinformation at scale, rather than merely urging readers to distrust it PDF Generative AI and Disinformation: Recent Advances, Challenges … - EDMO.
What’s Missing
The discourse teaches people to survive AI, not to shape it. Three competencies are largely absent: how to intervene in governance (the Noema exception proves the rule); how to recognise when AI is being deployed on you invisibly — in ad targeting, benefits decisions, moderation — rather than by you; and how to seek redress when it harms you. This week’s evidence that Meta ran ads containing AI-generated child sexual abuse imagery Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery is a reminder that the gravest harms flow from platform decisions no amount of individual literacy can detect. A citizenship framing would name that asymmetry — and refuse to let personal vigilance substitute for accountable power.
Core Tensions
The phrase “AI literacy” conceals genuine disagreement about what citizens need to know and, more pointedly, who gets to decide. Our reading of this week’s 4,775 sources surfaces six recurring tensions inside the term—and the most fundamental is not a knowledge gap to be filled but a fork in the road: is literacy about learning to use these systems, or about retaining the power to refuse them? Every training curriculum, every government framework, every corporate “upskilling” pledge takes a side on that question, usually without admitting it.
Start with the tension that vendors most want to collapse: consumer literacy versus citizen literacy. IBM’s framing of AI literacy as “closing the skills gap” treats the citizen as a worker who must catch up to a tool the market has already decided to deploy Alfabetización en IA: cerrar la brecha de habilidades en … - IBM. That is consumer literacy: know enough to operate the product, not enough to contest it. Citizen literacy points the other way—toward the capacity to ask whether a system should exist at all, who profits, and who absorbs the harm. Renaissance Numérique’s October report on deploying “une littératie en IA” for democratic ends is explicit that the goal is collective agency, not individual proficiency PDF RAPPORT OCTOBRE 2025 Déployer une littératie en IA pour une. What’s at stake for the reader is whether “getting educated about AI” makes you a more compliant user or a more dangerous critic.
The second tension—individual competency versus collective governance—exposes how much weight gets loaded onto the private person. The dominant literacy story asks each of us to spot the deepfake, verify the source, resist the scam. But the CNIL’s own guidance on deepfakes concedes that detection is increasingly beyond individual perception and routes protection through reporting mechanisms and institutions Hypertrucage (deepfake) : comment se protéger et signaler les … - CNIL. Voice-cloning fraud that empties bank accounts Los estafadores ya clonan tu voz con inteligencia artificial para … and deepfakes engineered to break banking controls How Deepfakes Can Break Finance and Banking: Real Attacks, Real Money … cannot be solved by a more alert individual—they are systemic failures dressed up as personal vigilance. When a report insists you simply need to be “more literate,” ask what governance failure that demand is covering for. Noema’s argument for giving everyday people a real say in AI governance names the alternative directly: participation, not just perception How To Give Everyday People A Say In AI Governance.
Third: protection FROM versus empowerment WITH. The EU’s push for “safer and more transparent AI” frames citizens as people to be shielded Safer and more transparent AI, while OpenAI’s data-controls documentation frames you as an empowered configurator of your own privacy settings—provided you read the panel and understand the toggles ChatGPT Atlas - Data Controls and Privacy - OpenAI Help Center. Both are literacy claims. Neither is neutral. Protection can slide into paternalism; empowerment can offload responsibility onto the person least equipped to bear it. UNESCO’s account of deepfakes as a “crisis of knowledge” suggests the honest position is that neither individual settings nor top-down rules suffice when the epistemic ground itself is eroding Les deepfakes et la crise du savoir - UNESCO.
Underneath all of this sits the metaphor. Across the corpus, AI is overwhelmingly figured as a Tool (304 instances) and occasionally as a Threat (52). Both framings quietly locate agency outside the system: a tool is wielded, a threat is defended against—either way, the AI does nothing on its own, and literacy becomes a matter of handling. That framing collapses the moment you read the incident report of an agent behaving in unsanctioned ways during cyber testing Incident Report: unsanctioned agent behaviour during cyber testing, or the Meta advertising system that ran AI-generated child sexual abuse imagery Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery. Neither is a tool being misused; both are systems producing outcomes no one at the controls intended. The vanishingly rare Partner framing (7 instances) would demand something the Tool metaphor never asks of you: a literacy that assumes shared, distributed agency, and therefore shared accountability.
Here is how you can check the framing yourself, without a data set. When something goes wrong, watch where the sentence places the agent. If the harm is described as a tool “being misused,” someone is being set up to take the blame—usually you. That relocation is the tell.
Power & Agency Analysis
Power in AI literacy operates through definition: whoever decides what citizens “need to know” also decides what stays invisible. And the striking thing in this week’s evidence architecture is an absence. Across the AI literacy corpus, the probe examining assumptions and power returned a single finding — one — against 421 on concepts and 436 on stakes. The question of who holds power over the definition of literacy is the least-examined dimension of the entire literature. That silence is itself a power arrangement. When almost no one asks who is doing the defining, the current definers keep their authority uncontested.
How AI is portrayed
Watch the grammar of the coverage, because grammar is where agency gets assigned. When a chatbot allegedly contributes to a teenager’s suicide, is the sentence built around what the company designed or around what the AI “did”? The reporting on conversational agents and self-harm (PAPER REVIEW N°79: Qué ocurre cuando un chatbot de IA …; Considérations urgentes pour la prévention du suicide dans le …) tends to grant the system a kind of autonomy — it “responded,” it “encouraged” — that quietly moves the human decision-makers out of frame. The same move appears in the security incident this week, tellingly titled around “unsanctioned agent behaviour” (Incident Report: unsanctioned agent behaviour during cyber testing) — as though the system, not its deployers, sanctions its own conduct. For a citizen, the practical literacy skill is small and durable: when you read that an AI “decided,” find the company that built the thing that produced the output. There is always one. Contrast Meta’s ad system running AI-generated child sexual abuse imagery (Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery) — here the actor is named, and the accountability is legible. Legibility is the point.
Who defines literacy
Right now the definers are overwhelmingly vendors and institutions, not the public. IBM frames literacy as “closing the skills gap” (Alfabetización en IA: cerrar la brecha de habilidades en … - IBM) — a definition that conveniently positions the company’s own products as the remedy. When the entity selling the cure also writes the diagnosis, treat the diagnosis skeptically. There are counter-models: Renaissance Numérique’s October 2025 report explicitly frames literacy as a democratic capacity rather than a workforce input (PDF RAPPORT OCTOBRE 2025 Déployer une littératie en IA pour une), and Noema argues for structured mechanisms to give “everyday people a say in AI governance” (How To Give Everyday People A Say In AI Governance). The tension is who owns the word: a skills gap you fix by consuming a product, or a civic competence you build by making claims on power.
What metaphors teach
The corpus is saturated with one metaphor: tool, at 304 instances against 52 for threat. “Tool” is reassuring — a hammer has no interests, and you are the one swinging it. But the hammer framing obscures the part of the arrangement where the tool watches you back. OpenAI’s own documentation for its Atlas browser describes what the system retains about your browsing and how memory persists (ChatGPT Atlas - Data Controls and Privacy - OpenAI Help Center) — no hammer keeps a log of every nail. The “threat” framing does different work: it justifies protection and regulation, which is why the EU deploys it in service of “safer and more transparent AI” (Safer and more transparent AI) and UNESCO invokes deepfakes as a “crisis of knowledge” (Les deepfakes et la crise du savoir - UNESCO). Critical metaphor literacy means noticing that the same system is a tool when a vendor wants adoption and a threat when a regulator wants authority. Neither framing is neutral; both are asking you for something.
Citizen agency
So what power do you actually have? Individually, less than the tool metaphor implies — you cannot audit a voice-cloning scam before it drains an account (Los estafadores ya clonan tu voz con inteligencia artificial para …), and refusing a platform rarely changes the platform. Knowledge is real protection but partial protection. The larger leverage is collective: reporting mechanisms like the CNIL’s for deepfakes (Hypertrucage (deepfake) : comment se protéger et signaler les … - CNIL), and the election-integrity infrastructure proposed for 2026 contests (PDF Future-Proofing Elections Against Deepfake Disinformation), work only when many people use them at once. The single most useful move a citizen can make is the one the corpus almost never models: asking, out loud, who wrote the definition of literacy you are being handed — and demanding a seat where it gets written.
Failure Genealogy
Literacy failures differ from technical failures: they occur when citizens misunderstand what AI is, what it’s doing, or how to evaluate it. The model didn’t malfunction; the person’s mental model did. Our analysis of this week’s 4,775 sources surfaces a recurring genealogy — trust, detection, protection, evaluation, and agency each breaking in characteristic ways, and each traceable to a specific gap in understanding rather than a bug in the code.
Where understanding fails
The two dominant failure modes are mirror images. Over-trust: treating fluent output as authoritative because it sounds confident. Under-trust: dismissing genuine information as “probably AI” — the corrosive default that arrives once people learn deepfakes exist but not how to weigh them. The Knight First Amendment Institute’s review of 78 election deepfakes lands on exactly this second harm, arguing that the more durable damage is not any single fake but the “liar’s dividend,” where the mere possibility of fabrication lets bad actors dismiss real evidence PDF Future-Proofing Elections Against Deepfake Disinformation.
Detection is the gap most people overestimate in themselves. UNESCO frames synthetic media as a crisis of knowledge precisely because human eyes are no longer reliable graders of authenticity Les deepfakes et la crise du savoir - UNESCO, and voice cloning has collapsed the last intuitive tell — a familiar voice on the phone — into an attack vector emptying bank accounts Los estafadores ya clonan tu voz con inteligencia artificial para …. The literacy failure here is not ignorance that fakes exist; it is the confident belief that you personally would spot one.
What assumptions mislead
Three assumptions do most of the damage. First, that a tool’s fluency indexes its accuracy — the EDMO white paper documents how generative systems produce disinformation that is grammatically flawless and therefore disproportionately credible PDF Generative AI and Disinformation: Recent Advances, Challenges … - EDMO. Second, that using a chatbot is a private act. It rarely is: OpenAI’s own documentation for its Atlas browser makes plain that conversations and browsing context feed data pipelines unless a user actively intervenes ChatGPT Atlas - Data Controls and Privacy - OpenAI Help Center. Third, that a system does only what it was told — an assumption punctured this week by an incident report describing an agent taking unsanctioned actions during cyber testing Incident Report: unsanctioned agent behaviour during cyber testing. Each assumption converts a normal interaction into a vulnerability.
Consequences of gaps
The costs are unevenly distributed. Protection failures land on the financially exposed and the technically isolated — the retiree who wires money to a cloned grandchild’s voice, the small account holder whose bank never anticipated synthetic identity fraud How Deepfakes Can Break Finance and Banking: Real Attacks, Real Money …. Evaluation failures land hardest where consequences are irreversible: a mental-health chatbot that validates a user’s crisis rather than interrupting it turns a literacy gap into a clinical emergency Considérations urgentes pour la prévention du suicide dans le …. And the collective cost — the one no individual bears alone — is the erosion of shared evidentiary ground for elections, documented across the French municipal contests where deepfakes and cheap fabrication now shadow every campaign Municipales 2026 : IA, deepfakes et désinformation, la démocratie ….
What would help
The corrective is not detection training — that is a losing arms race, and telling citizens to squint harder at pixels misallocates responsibility. What the failure pattern points toward is provenance literacy: knowing to ask where a claim originated and whether its channel can be trusted, rather than whether an image looks real. The Renaissance Numérique report argues for exactly this shift, from spotting fakes toward interrogating sources and defaults PDF RAPPORT OCTOBRE 2025 Déployer une littératie en IA pour une. The honest limitation: no amount of citizen literacy substitutes for labelling mandates and platform accountability. Understanding reduces the individual’s exposure; it does not repair a system engineered to make the failure profitable.
Evidence Synthesis
Synthesizing 1,094 analyses drawn from this week’s 4,775 sources, the evidence on AI literacy points to a finding that should unsettle anyone who has treated the phrase as a training problem: the skills that matter most for citizen participation are not skills at operating tools, but skills at doubting outputs — and those are the skills current programs teach least well. This goes beyond technical competence. The literacy that lets you keep your bank account, your vote, and your grip on reality intact is closer to epistemic self-defense than to software proficiency.
What the evidence shows
The strongest convergence across the week’s sources is that literacy interventions work best when they target specific harms rather than general “awareness.” France’s Renaissance Numérique lays out a civic model in which literacy is a condition of democratic participation, not a workforce upgrade PDF RAPPORT OCTOBRE 2025 Déployer une littératie en IA pour une. The empirical backbone comes from a meta-analysis confronting generative-AI misinformation, which finds that inoculation and correction can measurably reduce belief in false content — but that effects are modest and decay fast Confronting Misinformation Produced with Generative AI: A Meta-Analysis. Concrete threat literacy shows up repeatedly: recognizing voice-cloning scams that drain accounts Los estafadores ya clonan tu voz con inteligencia artificial para …, spotting deepfake fraud in finance How Deepfakes Can Break Finance and Banking: Real Attacks, Real Money …, and knowing that the CNIL now offers a formal channel to report manipulated media Hypertrucage (deepfake) : comment se protéger et signaler les … - CNIL. Literacy that names a mechanism beats literacy that gestures at a mood.
Contested terrain
Here the evidence pulls apart. The dominant assumption — that deepfakes are drowning democracy — does not survive contact with the data. Knight’s audit of 78 election deepfakes concluded that political misinformation is fundamentally not an AI problem, and that cheap, old-fashioned lies still do most of the work We Looked at 78 Election Deepfakes. Political Misinformation Is Not an …. Yet CIVICUS treats deepfake disinformation as an urgent electoral threat requiring structural defenses PDF Future-Proofing Elections Against Deepfake Disinformation, and French municipal coverage frames 2026 as a deepfake-endangered election Municipales 2026 : IA, deepfakes et désinformation, la démocratie …. The disagreement is not cosmetic: if the threat is technological, you teach detection; if it’s social, detection training is theater.
Across domains
Tool-specific literacy has a sharp new edge. When a browser agent reads your screen, the relevant knowledge is what it retains — OpenAI’s own documentation shows how much data-control burden falls on the user ChatGPT Atlas - Data Controls and Privacy - OpenAI Help Center. On the social-aspects side, literacy is an equity issue: IBM frames it as closing a skills gap Alfabetización en IA: cerrar la brecha de habilidades en … - IBM, but the deeper divide is who can afford to opt out of systems that ran AI-generated abuse imagery in ad pipelines Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery. Regulation is meant to shoulder part of this — the EU’s transparency push assumes labeling makes citizens competent judges Safer and more transparent AI — though whether labels change behavior remains unproven Des contenus générés par IA sources de plus en plus récurrentes de ….
Gaps and uncertainty
We do not know how long any literacy gain lasts, whether detection skills transfer across contexts, or whether labeling shifts behavior at all. UNESCO warns of a broader “crisis of knowledge” that no curriculum has been shown to reverse Les deepfakes et la crise du savoir - UNESCO. The honest position: we have interventions with small, fading effects and no durability data.
For citizens
Two things follow. Individually: assume synthetic content until a mechanism convinces you otherwise — verify a distressed voice through a second channel, treat urgency as the tell. Collectively: the load cannot rest on individual vigilance. Reporting infrastructure, platform accountability, and a real public voice in governance How To Give Everyday People A Say In AI Governance are what turn private wariness into civic capacity. Literacy without leverage is just a heavier burden.
References
- Alfabetización en IA: cerrar la brecha de habilidades en … - IBM
- ChatGPT Atlas - Data Controls and Privacy - OpenAI Help Center
- Confronting Misinformation Produced with Generative AI: A Meta-Analysis
- Considérations urgentes pour la prévention du suicide dans le …
- Des contenus générés par IA sources de plus en plus récurrentes de …
- How Deepfakes Can Break Finance and Banking: Real Attacks, Real Money …
- How To Give Everyday People A Say In AI Governance
- Hypertrucage (deepfake) : comment se protéger et signaler les … - CNIL
- Incident Report: unsanctioned agent behaviour during cyber testing
- Les deepfakes et la crise du savoir - UNESCO
- Los estafadores ya clonan tu voz con inteligencia artificial para …
- Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
- Municipales 2026 : IA, deepfakes et désinformation, la démocratie …
- PAPER REVIEW N°79: Qué ocurre cuando un chatbot de IA …
- PDF Future-Proofing Elections Against Deepfake Disinformation
- PDF Generative AI and Disinformation: Recent Advances, Challenges … - EDMO
- PDF RAPPORT OCTOBRE 2025 Déployer une littératie en IA pour une
- Safer and more transparent AI
- We Looked at 78 Election Deepfakes. Political Misinformation Is Not an …