Digital Transformation & Artificial Intelligence

EU AI Act Risk Classification and Obligations for Providers and Deployers

Learn to classify AI systems under the EU AI Act's risk tiers and map the specific conformity, documentation and monitoring obligations that follow for providers and deployers.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

The EU AI Act assigns different legal obligations depending on which risk tier an AI system falls into, and getting that classification wrong at the start of a compliance programme leads either to expensive over-engineering of low-risk tools or to genuine exposure on systems that should have been treated as high-risk. This course gives compliance, legal and product teams a working method for classifying AI systems against the Act's prohibited, high-risk, limited-risk and minimal-risk categories, and for identifying which obligations attach to each role an organisation plays, whether provider, deployer, importer or distributor. Participants work through the criteria for high-risk classification under Annex III, including AI used in employment, credit scoring, education and law enforcement contexts, and learn what a conformity assessment, technical documentation file and post-market monitoring plan must actually contain for a system in that tier. The course also covers the specific transparency duties for limited-risk systems such as chatbots and synthetic media, and the narrower but firm prohibitions on practices such as social scoring and certain biometric categorisation. Participants leave with a completed classification for at least one real AI system and a mapped list of the obligations it triggers.

Expected Learning Outcomes

01

Classify an AI system against the EU AI Act's prohibited, high-risk, limited-risk and minimal-risk tiers.

02

Apply the Annex III criteria to determine whether a system used in employment or credit decisions is high-risk.

03

Identify which obligations attach to the organisation depending on its role as provider, deployer or distributor.

04

Scope the content of a technical documentation file required for a high-risk AI system.

05

Plan a conformity assessment route appropriate to the classified system and its intended purpose.

06

Draft the transparency disclosures required for limited-risk systems such as chatbots and synthetic content.

07

Design a post-market monitoring plan that captures incidents and performance drift after deployment.

Who Should Attend

01

Compliance officers building an EU AI Act compliance programme

02

Legal counsel advising on AI product classification and obligations

03

Product managers responsible for AI features sold into the EU market

04

Risk managers assessing AI systems used in regulated decisions

05

Procurement teams reviewing third-party AI systems as deployers

06

AI governance leads coordinating cross-functional compliance work

Course Modules

Select any module to see its sessions and points.

01

Understanding the Risk-Based Framework

2 sessions · 8 points

Session 1The Four Risk Tiers and Their Logic

  • Explain the reasoning behind the Act's tiered approach compared with a single uniform rule for all AI.
  • Distinguish prohibited practices from high-risk systems that remain lawful under strict conditions.
  • Identify limited-risk obligations that apply regardless of a system's underlying risk classification.
  • Recognise minimal-risk systems where the Act imposes no binding obligations beyond voluntary codes.

Session 2Applying the Annex III High-Risk Criteria

  • Work through Annex III's listed use cases, including employment, education, credit and essential services.
  • Assess whether a system's intended purpose, not its underlying technology, triggers high-risk classification.
  • Apply the narrow exceptions that keep certain qualifying systems out of the high-risk category.
  • Document the classification rationale to withstand challenge from a regulator or a client's own review.
02

Roles and Their Obligations

2 sessions · 8 points

Session 1Determining the Organisation's Role

  • Distinguish provider, deployer, importer and distributor roles as defined by the Act for a given system.
  • Identify situations where substantial modification shifts a deployer into the provider role instead.
  • Map internal teams, such as engineering and procurement, to the obligations their role in the chain creates.
  • Clarify shared obligations where a system is built on a third-party general-purpose AI model.

Session 2Provider Obligations for High-Risk Systems

  • Establish a risk management system covering the AI system's lifecycle from design to withdrawal.
  • Implement data governance measures addressing training, validation and testing data quality.
  • Maintain technical documentation sufficient for an authority to assess the system's compliance.
  • Register the system in the required EU database before it is placed on the market.
03

Conformity, Documentation and Deployer Duties

2 sessions · 8 points

Session 1Conformity Assessment and CE Marking

  • Determine whether the system qualifies for self-assessment or requires third-party conformity assessment.
  • Prepare the declaration of conformity and affix CE marking once the assessment is successfully completed.
  • Plan reassessment triggers for substantial modifications made after the initial conformity assessment.
  • Coordinate conformity assessment timelines with product release schedules to avoid last-minute delays.

Session 2Deployer Obligations and Human Oversight

  • Assign trained human oversight for high-risk systems capable of intervening in or halting an output.
  • Monitor the system's operation and report serious incidents or malfunctions to the provider and authorities.
  • Conduct a fundamental rights impact assessment where deployment context requires one under the Act.
  • Keep logs generated by the system for the retention period the Act requires of deployers.
04

Transparency, Monitoring and Programme Management

2 sessions · 8 points

Session 1Limited-Risk Transparency Obligations

  • Disclose to users when they are interacting with an AI system such as a chatbot rather than a person.
  • Label AI-generated or manipulated audio, image or video content as required for synthetic media.
  • Inform individuals subject to emotion recognition or biometric categorisation systems as required.
  • Review marketing and product interfaces to confirm transparency disclosures are genuinely visible to users.

Session 2Post-Market Monitoring and Programme Governance

  • Establish a post-market monitoring plan that tracks performance drift and emerging risks after deployment.
  • Define an incident reporting process that meets the Act's timelines for serious incident notification.
  • Assign an accountable owner for AI Act compliance who coordinates legal, product and engineering input.
  • Schedule periodic re-classification reviews as systems, use cases or the applicable guidance evolve.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course