
EU AI Act: Practical Compliance for Businesses
This course turns the dense legal text of the EU AI Act into a practical roadmap for businesses that build, buy, or deploy AI. You will learn how to classify your AI use cases, understand concrete obligations and deadlines, and design a proportionate compliance program that fits your organization.
Course Content
11 modules · 2h 45m total
From Legal Text to Business Reality: What the EU AI Act Actually Is
Instead of wading through hundreds of pages of legalese, step into a clear big-picture view of the EU AI Act: what it covers, why it exists, and how it will reshape the way businesses build and use AI in and beyond Europe.
Timelines and Thresholds: When Your Obligations Start to Bite
Deadlines in the EU AI Act are staggered and easy to misunderstand—this module turns the timeline into a practical calendar so you know exactly what is expected of your business in 2025, 2026, 2027 and beyond.
Risk Categories in Practice: From Banned to Minimal-Risk AI
Not all AI is treated equally: discover how the EU AI Act slices the AI landscape into four risk tiers and what that really means for chatbots, scoring systems, computer vision, and more in your portfolio.
Are We High-Risk? Classifying Your AI Systems Step by Step
Before you can comply, you need to know which of your systems are high-risk; walk through a practical classification workflow that turns abstract annexes into a concrete inventory of AI systems and their risk levels.
Obligations for Providers: Building Compliant High-Risk AI
If your organization develops or places AI systems on the EU market, this module turns the dense list of provider obligations into a practical checklist for product, engineering, and compliance teams.
Obligations for Deployers: Using AI Systems Responsibly in Your Business
Most organizations do not build AI from scratch—they deploy it; learn what responsibilities fall on deployers, even when AI is purchased from vendors or embedded in SaaS tools.
General-Purpose and Foundation Models: New Duties for the AI Stack
Foundation models and general-purpose AI sit underneath many applications; uncover the special rules the EU AI Act creates for these models and how they ripple through the AI supply chain.
Governance and Enforcement: AI Office, AI Board, and National Authorities
Behind the rules sits a new governance ecosystem; see how the European AI Office, national authorities, and market surveillance bodies will interact with your organization in practice.
Designing Technical and Organizational Controls for Compliance
Turn legal requirements into concrete design choices: from data governance and documentation templates to human oversight protocols and cybersecurity controls that satisfy AI Act expectations.
Vendors, Contracts, and Cross-Regulation: Making Compliance Work in the Real World
Most AI systems arrive through vendors, cloud platforms, and APIs; learn how to align contracts, procurement, and governance with the AI Act while also navigating GDPR, the Data Act, and other EU rules.
Your AI Act Roadmap: From Gap Analysis to Implementation Plan
Bring everything together by drafting a tailored AI Act compliance roadmap for your organization, prioritizing actions by risk, deadlines, and business impact.
Read the Textbook
Read every chapter for free, right here in your browser.
In 2024, the EU adopted the AI Act as Regulation (EU) 2024/1689. It is the world’s first comprehensive horizontal law on artificial intelligence. As of mid-2026 (today), it is in a phased roll-out: some rules already apply, others are about to, and the rest will follow on a fixed timeline.
At a high level, the AI Act tries to do three things: Protect people and fundamental rights from harmful AI. Create a single, predictable rulebook for AI across the EU market. Support innovation and trust, so businesses can scale AI solutions safely.
Instead of banning AI or regulating every detail, the Act uses a risk-based approach: Some AI uses are prohibited (unacceptable risk). Some are high-risk and face strict obligations. Some are limited-risk and need transparency. Most AI is minimal risk with no specific AI Act duties.
Study Flashcards
Key concepts from this course as flashcard pairs.
From Legal Text to Business Reality: What the EU AI Act Actually Is
AI Act (Regulation (EU) 2024/1689)
An EU regulation establishing a risk-based framework for the development, placement on the market, and use of AI systems and general-purpose AI models in and affecting the EU.
AI system
A machine-based system with varying levels of autonomy that, for explicit or implicit objectives, generates outputs (predictions, recommendations, decisions) influencing physical or virtual environments.
General-purpose AI model (GPAI)
A model that can be used for a wide range of tasks, such as large language or multimodal models, and that may be integrated into many downstream AI systems.
Provider
An organization that develops an AI system or GPAI model and places it on the market or puts it into service under its own name or trademark.
Deployer
An organization that uses an AI system under its authority, for example a bank using an AI credit scoring tool or an employer using an AI hiring assistant.
Importer
An EU-based operator that places on the EU market an AI system from a provider established outside the EU.
+4 more flashcards
Timelines and Thresholds: When Your Obligations Start to Bite
Entry into force
The date a law becomes legally valid. For the EU AI Act, this was August 1, 2024, when it started existing as binding EU law, even though many obligations applied later.
Entry into application
The date when specific obligations of a law start to apply in practice. For the AI Act, many general rules apply around August 2, 2026, with other parts applying earlier or later.
Prohibited (unacceptable-risk) AI practices
Certain AI uses banned outright, such as manipulative systems, some social scoring by public authorities, and most real-time remote biometric ID in public spaces. These bans started applying around February 2025.
High-risk AI system
An AI system used in sensitive contexts like critical infrastructure, education, employment, essential services, law enforcement, migration, or justice. It faces strict obligations that apply later and with transitional periods.
General-purpose AI (GPAI) model
A broad, flexible AI model (such as a large language model) that can perform many tasks and be integrated into many systems. The AI Act sets baseline and enhanced duties for GPAI providers, with timelines linked to future standards.
AI literacy
The knowledge and skills people need to understand and use AI systems responsibly. Under the AI Act, organizations are expected to improve AI literacy of staff, especially as general rules apply from August 2026 onward.
+1 more flashcards
Risk Categories in Practice: From Banned to Minimal-Risk AI
Unacceptable-risk AI (prohibited)
AI practices banned under Article 5, such as certain manipulative systems, public authority social scoring, specific biometric uses (emotion recognition at work/school, sensitive attribute inference), predictive policing of individuals, and untargeted facial image scraping.
High-risk AI
AI systems that are safety components of regulated products or match Annex III use cases (e.g., biometrics for access control, grading exams, hiring decisions, credit scoring, social benefits decisions, some law enforcement and migration tools, judicial support systems).
Limited-risk AI
AI that is not prohibited or high-risk but triggers transparency duties, such as chatbots, some emotion recognition and biometric categorization systems, and tools that generate or manipulate realistic content like deepfakes.
Minimal or no-risk AI
AI systems that do not fall into prohibited, high-risk, or limited-risk transparency-trigger categories. They face no AI Act-specific obligations beyond general laws (e.g., data protection, consumer protection).
Annex III
An annex of the EU AI Act listing **standalone high-risk AI use cases** by sector and purpose. Used to decide when an AI system is high-risk even if it is not a safety component of a regulated product.
Article 5
The article in the EU AI Act that defines **prohibited AI practices**, such as certain manipulative systems, exploitative uses, social scoring by public authorities, some biometric applications, predictive policing of individuals, and mass facial scraping.
+1 more flashcards
Are We High-Risk? Classifying Your AI Systems Step by Step
AI system (EU AI Act – simplified)
Software using learning or complex inference techniques that, for defined objectives, generates outputs like predictions, recommendations, or decisions that influence environments.
Annex II high-risk AI
AI systems embedded in products regulated by existing EU product safety laws (e.g., medical devices, machinery) where the AI performs a safety-related function.
Annex III high-risk AI
Stand-alone AI systems used in specific high-impact areas (e.g., employment, credit scoring, education, critical infrastructure, law enforcement) listed in Annex III.
Embedded AI system
An AI component that is integrated into a physical or digital product (such as a medical device or machine) and operates as part of that product’s safety or functionality.
Stand-alone AI system
An AI system delivered as software or a service (e.g., a web API or internal tool) that is not tied to a specific regulated product but may still be high-risk via its use case.
AI inventory
An internal register listing all AI systems, including their purpose, owner, delivery type, users, affected persons, and whether they fall under Annex II or Annex III.
Obligations for Providers: Building Compliant High-Risk AI
Provider (under the AI Act)
A natural or legal person that develops an AI system (or has it developed) and places it on the EU market or puts it into service under their own name or trademark.
High-risk AI system
An AI system listed in the AI Act’s high-risk categories (for example, certain systems in employment, credit scoring, education, critical infrastructure, law enforcement, or healthcare) that must meet strict requirements.
Risk management system
A continuous process to identify, analyze, evaluate, and control risks to health, safety, and fundamental rights throughout the AI system’s lifecycle, with documented plans and evidence.
Technical documentation
The structured set of documents that describe the AI system, its purpose, design, data, risk controls, performance, and post-market monitoring plan, used to demonstrate compliance in conformity assessment.
Conformity assessment
The procedure used to show that a high-risk AI system meets AI Act requirements, sometimes involving a notified body, and leading to an EU declaration of conformity and CE marking.
Harmonized standard
A European standard developed by recognized bodies and cited in the EU Official Journal; following it gives a presumption of conformity with the legal requirements it covers.
+1 more flashcards
Obligations for Deployers: Using AI Systems Responsibly in Your Business
Deployer (under the EU AI Act)
An organization that uses an AI system in the course of its own activities (e.g., a company using an AI recruitment tool), regardless of who built the system.
Provider (under the EU AI Act)
An organization that develops an AI system or foundation model and places it on the EU market under its own name or trademark, or substantially modifies an existing system.
High-risk AI system
An AI system used in sensitive areas listed in the AI Act (such as employment, credit, healthcare, education, public services) where errors can significantly affect people's rights or safety.
Human oversight (for deployers)
Processes ensuring qualified humans can understand, supervise, and, when necessary, override or disregard AI outputs in real-world use.
Data quality (for deployers)
The obligation to ensure input data you supply to a high-risk AI system is relevant, accurate, and appropriate for your context, reducing bias and errors.
Logging and record-keeping
Maintaining logs of AI system operation (inputs, outputs, versions, decisions) so that decisions can be traced, audited, and investigated if problems arise.
+2 more flashcards
General-Purpose and Foundation Models: New Duties for the AI Stack
General-purpose AI model (GPAI model)
An AI model trained on broad data at scale, capable of performing a wide range of tasks, and reusable across many downstream systems and applications.
GPAI model provider
An entity that develops and places a GPAI model on the EU market, or substantially modifies such a model and releases it under its own name or trademark.
Systemic-risk GPAI model
A GPAI model whose capabilities or deployment scale create significant cross-sector risks to health, rights, the environment, democracy, or the rule of law, based on thresholds and assessments set by the EU.
Technical documentation (GPAI context)
Documentation describing a GPAI model’s architecture, training process, capabilities, limitations, evaluation methods, and reasonably foreseeable misuse, shared with authorities and downstream users.
Training data summary
A public, meaningful description of the main datasets, sources, and categories of data used to train a GPAI model, supporting copyright transparency without disclosing full datasets.
Codes of practice (GPAI)
EU-endorsed documents that translate GPAI obligations, especially for systemic-risk models, into concrete technical and organizational measures; following them can help demonstrate compliance.
Governance and Enforcement: AI Office, AI Board, and National Authorities
European AI Office
A specialized structure within the European Commission that leads on general-purpose AI supervision, systemic risks, and cross-border coordination, and supports guidance, investigations, and enforcement under the AI Act.
European AI Board
An EU-level coordination body composed of national authorities and the Commission. It issues opinions and recommendations to ensure consistent application of the AI Act across Member States.
National Competent Authority (NCA)
A national regulator designated by each Member State to supervise AI Act compliance, receive incident reports, conduct investigations, and often run regulatory sandboxes.
Market Surveillance Authority (MSA)
A national authority responsible for checking that products, including AI systems as products or safety components, comply with EU rules. It can inspect, test, and order corrective measures or withdrawals.
Regulatory Sandbox (AI Act context)
A controlled environment run by a national authority where organizations can develop and test AI systems under supervision, with tailored regulatory conditions but preserved safety and fundamental rights protections.
General-Purpose AI (GPAI) Provider
An organization that develops and places on the market a general-purpose AI model that can be used for many downstream tasks. Under the AI Act, such providers face specific obligations and oversight by the AI Office.
Designing Technical and Organizational Controls for Compliance
AI Management System (AIMS)
An organizational framework, described in ISO/IEC 42001, for systematically managing AI risks and controls across their lifecycle, integrated with existing management systems.
Human-in-the-loop (HITL)
An oversight pattern where the AI provides recommendations but a human must review and approve or reject them before action is taken.
Data lineage
Documentation of where data comes from, how it is transformed, and which AI systems use it, enabling traceability and accountability.
Red-teaming (for AI)
Structured testing in which internal or external teams try to make an AI system behave harmfully or unsafely, to discover vulnerabilities and improve defenses.
AI incident
An event where an AI system causes or risks causing significant harm, such as safety issues, serious discrimination, or security and privacy breaches.
Vendors, Contracts, and Cross-Regulation: Making Compliance Work in the Real World
Provider (AI Act)
An entity that develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark.
Deployer (AI Act)
An entity that uses an AI system under its authority, except when using it for personal non-professional activity.
High-risk AI system
An AI system listed or falling under categories in the AI Act that pose significant risks to health, safety, or fundamental rights, such as recruitment, credit scoring, or biometric identification.
General-purpose AI (GPAI) model
An AI model that can be used for a wide range of tasks and is not designed for a specific narrow purpose; subject to specific AI Act rules when placed on the EU market.
Data processing agreement (DPA)
A GDPR-required contract between controller and processor that sets out how personal data is processed, secured, and transferred.
Regulatory Map
A concise overview for a given AI system showing applicable laws (AI Act, GDPR, Data Act, DSA, sectoral rules), roles, and main obligations.
Your AI Act Roadmap: From Gap Analysis to Implementation Plan
AI system inventory
A structured list of all AI systems in an organization, capturing attributes like owners, function, lifecycle status, risk category, dependencies, and business criticality.
Risk category (AI Act)
Classification of AI systems as prohibited, high-risk, limited-risk (with transparency duties), or minimal risk, based on their use and impact.
Gap analysis
A systematic comparison between current practices and AI Act requirements for each system, identifying missing or weak controls.
Priority tier
A label (for example, Tier 1, 2, 3) showing how urgently a remediation action should be done, considering regulatory risk, business impact, and effort.
Phased implementation plan
A time-bound roadmap divided into stages (e.g. immediate, foundation, high-risk readiness, optimization) that sequences compliance projects.
AI Governance Committee
A cross-functional group that oversees AI use cases, approves high-risk deployments, monitors compliance KPIs, and updates the AI roadmap.
+2 more flashcards