EU AI Act Compliance in Practice: Risk Mapping and a Remediation Roadmap
The EU AI Act applies to every organisation that uses, develops or procures AI systems, not only to the companies that build them. The prohibited practices and the AI-literacy measures have applied since February 2025; the transparency duty and the enforcement architecture since August 2026; the high-risk requirements apply from December 2027. For most organisations the gap is not awareness but the file: a register of their AI systems, the obligations for each, a gap analysis and a roadmap.
This full-day workshop is built around doing rather than listening. Working in table groups on one continuous synthetic case, Pithecus Robotics, in an interactive exercise environment on participant laptops, you inventory eight AI systems, classify each, apply the route out of high risk, work out whose obligations they are (provider, deployer, or the organisation that becomes a provider without building anything), separate what applies now from what applies later, rehearse the regulator's request list, mark the gaps against six components of a compliance programme and build a roadmap with owners. A private transfer then applies the method to your own organisation or, if you are deciding whether to acquire an AI system, to a build-or-buy memo.
You leave with a file, not an opinion: a register, an obligation set, a gap grid and an outline remediation roadmap. The EU AI Act Explained (ACT-A) is strongly recommended beforehand. No legal training assumed.
Content
- Risk classification in practice: mapping an estate of AI systems against the Act, and the route out of high risk
- Whose obligations: provider, deployer, and the organisation that becomes a provider without building anything
- Two regimes on one system: the AI Act and the GDPR side by side, and what applies when
- What you must be able to show: the chain from the law to the evidence, and the regulator's visit
- Gap analysis against six components of a compliance programme, and the remediation roadmap with owners and horizons
Learning Outcomes
By the end of this training, the participant will be able to:
- Map at least three AI systems used in their organisation against the Act's risk classification framework
- Identify the applicable compliance obligations for each classified system
- Distinguish provider and deployer obligations and apply them to their organisational context
- Draft a gap analysis and outline remediation roadmap for their highest-priority AI compliance issues
Training Method
Structured compliance workshop. Participants work in table groups through seven guided exercises in an interactive exercise environment on their laptops, applying the Act to one continuous synthetic case (Pithecus Robotics) and then, privately, to their own organisational context or to a build-or-buy decision. Each participant leaves with a completed register, gap analysis and outline roadmap. No coding required; all examples use synthetic data.
Certification
Certificate of ParticipationPrerequisites
The EU AI Act Explained (ACT-A) is strongly recommended beforehand. No legal training assumed.
Planning and location
09:00 - 17:00