The EU AI Act
The world’s first comprehensive AI law, article by article
- The EU AI Act at a Glance: Purpose, Scope, and the Risk Pyramid — Why the world’s first comprehensive AI law exists, how its four-tier risk pyramid and parallel GPAI track work, who it reaches (including outside Europe), and the staged timeline on which its obligations bite. (5 lessons, 55 min)
- Prohibited AI Practices: The Unacceptable Tier — The eight practices Article 5 bans outright — manipulation, exploitation, social scoring, predictive policing, face-scraping, emotion recognition, biometric categorisation, and real-time biometric identification — their exceptions, the RBI authorization machinery, and where the line to high-risk actually runs. (4 lessons, 55 min)
- High-Risk Classification: Art 6, Annexes I & III, and the Filter — The two independent routes into the high-risk tier, all eight Annex III areas with their carve-outs, and the Art 6(3) filter — including the profiling tripwire that no derogation escapes. (5 lessons, 55 min)
- Inside the High-Risk Rulebook: Arts 8–15 Article by Article — The seven substantive requirements every high-risk system must meet — risk management, data governance, documentation, logging, transparency, human oversight, and robustness — with the evidence each demands and the ISO 42001 / NIST RMF crosswalk. (6 lessons, 60 min)
- The Value Chain: Providers, Deployers, Importers, Distributors — Who owes what along the AI value chain — the Art 16 provider checklist, importer and distributor gatekeeping, the Art 25 role-switch traps, deployer duties under Art 26, and the fundamental rights impact assessment. (5 lessons, 55 min)
- Transparency and General-Purpose AI: Art 50 and the GPAI Chapter — The four disclosure duties of Art 50, machine-readable marking of synthetic content, and the GPAI model regime — Art 53 baseline duties, the 10²⁵ FLOPs systemic-risk trigger, Art 55 safety duties, and the Code of Practice. (5 lessons, 60 min)
- Conformity Assessment, Standards, CE Marking, and Post-Market Duties — How a high-risk AI system actually gets to market: harmonized standards and presumptions of conformity, the Article 43 assessment routes, notified bodies and certificates, Annex IV documentation, the CE mark and EU database — and the post-market monitoring and serious-incident clocks that never stop running. (5 lessons, 55 min)
- Governance, Enforcement, Penalties, and Sandboxes — Who actually runs the AI Act — the AI Office, the Board, and national market surveillance authorities — how enforcement escalates from evaluation to Union-wide safeguard, what individuals can claim under Articles 85–87, the three-tier penalty regime, the sandbox and real-world-testing machinery, and how the Act meshes with GDPR, DSA, product liability, and the Digital Omnibus. (6 lessons, 60 min)