EU AI Act Deployer and Governance Course
The Article 4 baseline covers everyone who uses AI. This course covers the person who has to answer for it. It contains all 20 baseline lessons plus 12 more on writing and enforcing an AI policy, the documentation a regulator or customer will ask for, AI security and shadow AI, the risk register, and the governance cadence that keeps all of it current.
| Lessons | 32 video lessons |
|---|---|
| Duration | Approximately 6.8 hours |
| Level | Practitioner — for the people accountable for AI use |
| Access | 12 months from enrolment |
| Format | On-demand video, learn at your own pace |
| Course language | Video lessons in English. |
| Price | €349 per person |
Why does the deployer role carry more exposure than the literacy duty?
Article 4 is not listed among the obligations in Article 99(4), so it carries no fine of its own. Deployer obligations under Article 26 are on that list, in the tier reaching up to 15 million euro or 3% of worldwide annual turnover, whichever is higher. The same training decision therefore sits under two very different citations depending on what your organisation actually does with AI.
That gap is where governance work belongs. An organisation using AI at low risk needs literacy and house rules. An organisation deploying a high-risk system needs a policy people actually follow, records it can produce on request, a named owner for each system, and a cadence that reviews them. That is what this course teaches.
The Digital Omnibus on AI deferred the high-risk obligations — 2 December 2027 for standalone Annex III systems, 2 August 2028 for AI inside regulated products. It did not defer Article 4, and it did not defer the work of getting ready. The deferral bought preparation time; it removed nothing.
If you only need the literacy baseline for general staff, the Article 4 course is the smaller and cheaper option.
What the course covers
- Everything in the Article 4 baseline — all 20 of those lessons are included here, so nobody buys the same content twice
- Why an AI policy is worth writing, what belongs in it, and how to roll it out so that people follow it
- The documentation and transparency records a regulator, insurer or enterprise customer will ask to see
- AI security in practice: the threat picture, protecting company data, access control and identity
- Shadow AI — finding the tools nobody told you about, and deciding what to do once you have
- Building an AI risk register that stays current instead of being written once and forgotten
- Governance cadence: who meets, how often, what they decide and what gets written down
- Auditing your AI use and improving it, including which measures are actually worth tracking
Full curriculum — all 32 lessons
Every lesson is short and self-contained. Work through them in order, or go straight to the sections you need.
| 1 | What an LLM actually is |
| 2 | Tokens and context in plain English |
| 3 | Why AI guesses: probability, not lookup |
| 4 | Strengths: what AI is genuinely great at |
| 5 | Limits and failure modes to expect |
| 6 | What hallucinations are and why they happen |
| 7 | Spotting hallucinations in the wild |
| 8 | Verification habits that scale |
| 9 | When not to trust it |
| 10 | What you should never paste |
| 11 | Consumer vs business data handling |
| 12 | Bias, fairness, and disclosure |
| 13 | Basic legal and copyright awareness |
| 14 | The regulatory landscape |
| 15 | The EU AI Act explained |
| 16 | Risk categories and obligations |
| 17 | Knowing your company's AI rules |
| 18 | Using approved tools the right way |
| 19 | Protecting data at work |
| 20 | When to ask before you act |
| 21 | Why you need an AI policy |
| 22 | Writing the policy document |
| 23 | Rolling out and enforcing policy |
| 24 | Documentation and transparency |
| 25 | Staying compliant over time |
| 26 | AI security threats overview |
| 27 | Protecting company data |
| 28 | Access control and identity |
| 29 | Shadow AI and its risks |
| 30 | Building an AI risk register |
| 31 | Governance committees and cadence |
| 32 | Auditing and continuous improvement |
Who is this course for?
- The person accountable for how AI is adopted — owner, managing director, operations lead
- IT, HR, legal, compliance and data protection roles
- Anyone who has to write the AI policy and then make it stick across a team that never asked for one
- Organisations preparing now for the high-risk obligations that apply from December 2027
What this course does not do
- No official EU certificate exists for the AI Act at any tier, and this course does not issue one.
- It teaches deployer and governance duties in general terms. The competence of a named human overseer of a specific high-risk system, under Article 26(2) and Article 14(4), is inseparable from that system and needs system-specific training on top of this.
- It does not classify your AI systems for you or tell you whether a given system is high-risk. That is a legal assessment on your own facts.
- It is not legal advice and is no substitute for advice on your own systems and contracts.
Frequently asked questions
How is this different from the Article 4 course?
It contains all 20 Article 4 lessons plus 12 more on policy, documentation, security, risk and governance. Buy the baseline for everyone who uses AI. Buy this one for the smaller group who are accountable for how it is used and who have to produce the records.
Does this satisfy the Article 26 human oversight requirement?
Not on its own. It covers the organisational duties: policy, documentation, risk register, governance cadence and audit. The competence of a named overseer under Article 26(2) depends on the specific high-risk system and needs training built around that system.
Why does Article 26 matter more than Article 4 for penalties?
Article 4 is absent from the Article 99(4) list and carries no fine of its own. Deployer obligations under Article 26 are on that list, in the tier reaching 15 million euro or 3% of worldwide annual turnover, whichever is higher.
The high-risk rules were delayed. Can this wait?
The deferral moved standalone Annex III systems to 2 December 2027 and AI in regulated products to 2 August 2028. It bought preparation time, not an exemption. Policy, system inventory, risk register and governance cadence take longer to build than the time remaining.
How long do I have access, and does it renew automatically?
Twelve months from enrolment. It is a one-off purchase, not a subscription, so nothing renews on its own. We send a reminder before access ends so you can decide whether to extend for another year.
Should we buy both courses?
Usually yes, in different quantities. The baseline for everyone who touches AI, this one for the handful of people who own the policy, the records and the decisions. This course already includes the baseline, so nobody needs to be enrolled twice.
Enrol now and get instant access to all 32 lessons.
Buying for a team? Volume rates are available for larger groups — get in touch and tell us how many seats you need.
Sources: Regulation (EU) 2024/1689 and the European Commission AI Literacy Q&A.
Last updated: 17 August 2026
Español (España)
Polski (PL)
Italiano (IT)
Deutsch (Deutschland)
Français (France)
Nederlands (nl-NL)
English (United Kingdom)