Intermediate
EU AI Act Practitioner for Privacy Teams
Translate the EU AI Act into an operational inventory, role map, classification method, evidence set and implementation plan for privacy and governance teams.
About this course
A practitioner course for privacy, governance, security and procurement teams who now own AI obligations. It builds the artefacts the law expects: an AI inventory, a role map across the value chain, a defensible classification method, transparency and oversight evidence, and a phased implementation plan. Written for a global audience, because the AI Act reaches organisations wherever they are established when their AI systems or the outputs of those systems are used in the European Union.
What you will be able to do
- Identify whether an organisation is acting as provider, deployer, importer, distributor or another regulated actor
- Classify AI uses and recognise prohibited, transparency and high-risk obligations
- Connect AI Act controls with privacy, security, procurement and product governance
- Prepare appropriate evidence for transparency, human oversight, data governance and monitoring
- Build an implementation plan aligned to the current phased application dates
Course content
- 1
Scope, actors and the regulatory map
Establish when the AI Act applies and which value-chain role your organisation holds for each system.
- Scope, actors and the regulatory map35 min
4-question quiz
- 2
Risk classification and prohibited practices
Run a defensible classification workflow instead of labelling every AI tool high-risk.
- Risk classification and prohibited practices35 min
4-question quiz
- 3
AI literacy and organisational governance
Meet the Article 4 literacy duty and stand up an inventory, ownership model and acceptable-use evidence.
- AI literacy and organisational governance30 min
4-question quiz
- 4
General-purpose AI and model supply chains
Understand GPAI provider duties, downstream information flows and what to demand in procurement.
- General-purpose AI and model supply chains35 min
4-question quiz
- 5
Article 50 transparency duties
Apply interaction, biometric categorisation, synthetic-content marking and deepfake disclosure duties correctly.
- Article 50 transparency duties30 min
4-question quiz
- 6
High-risk system lifecycle
Work through risk management, data governance, documentation, logging, accuracy, robustness, security and oversight.
- High-risk system lifecycle40 min
4-question quiz
- 7
Deployer duties, assessments and monitoring
Operate instructions for use, input-data controls, logs, oversight, notice and incident escalation as a deployer.
- Deployer duties, assessments and monitoring30 min
4-question quiz
- 8
Enforcement, current dates and implementation workshop
Map the phased application dates as they stand on 28 August 2026 and build an evidence-based 90-day plan.
- Enforcement, current dates and implementation workshop35 min
4-question quiz
- 9
Final AssessmentFinal assessment
Confirm your understanding across the full course.
10-question final assessment