Universal Skills · Advanced · S5
AI Governance & the EU AI Act
Risk tiers, deployer obligations, acceptable-use policy, human oversight, audit readiness, EU AI Act, NIS2, ISO 42001
- Duration
- 2 days · 9:00–17:00 each day (13h contact, incl. breaks + lunch)
- Participant level
- Intermediate: regular AI users
- Format
- Working governance workshop
- Participants
- 15 included · 30 maximum (flexible group size)
- Prerequisite
- S1 recommended
- Price
- EUR 8,500 (EUR 450 per extra participant)
- Discovery Session
- On request
Amounts in EUR, excl. VAT.
Regulatory statusRequired for managers & governance owners · EU AI Act deployer duties + NIS2 management-training duty
ai-generatedWhat participants will be able to do
- Build a compliant AI governance framework for your organisation
- Classify your AI systems under EU AI Act risk tiers
- Design the mandatory training map for your workforce
- Prepare for an EU AI Act conformity assessment
Tools & resources
What changes after this module
The people who govern AI can classify the organisation’s AI systems under the EU AI Act and the wider standards landscape (NIS2, ISO/IEC 42001, the Council of Europe AI Convention, OECD), meet deployer obligations, put an acceptable-use policy and human oversight in place, and stand ready for audit, turning compliance into the right to deploy AI at scale.
Who should attend
Everyone. Intermediate: regular AI users.
Programme
This agenda is indicative. Content, sequencing, and examples are adapted to your team's context, tools, and objectives.
Before you start
- S1 recommended
- Suited to managers, compliance/legal, IT/security leads, and AI-governance owners
- Bring a rough inventory of where AI is used in your area
| Day 1 | 9:00–10:30 | The regulatory landscape in depth: The EU AI Act: scope, the risk tiers (prohibited, high-risk, limited, minimal), the timeline (Art. 4 literacy in force Feb 2025, enforced from Aug 2026; prohibited practices Feb 2025; GPAI Aug 2025; the Digital Omnibus: adopted mid-2026: deferred Annex III high-risk to 2 Dec 2027 and Annex I to 2 Aug 2028, BUT Art. 50 transparency still applies 2 Aug 2026 with watermarking to 2 Dec 2026, and added an Art. 5 ban on nudifier/CSAM systems from 2 Dec 2026), penalties (€35M/7%€15M/3%€7.5M/1.5%); and where NIS2 (Art. 21 cyber), ISO/IEC 42001 (the certifiable AI management system, 38 controls), the Council of Europe Framework Convention on AI (the first binding AI treaty: EU ratified 15 May 2026) and the OECD principles fit. Hands-onClassify a set of AI use-cases into the risk tiers, starting the AI system inventory you’ll carry across both days into policy, oversight, and the audit checklist. |
| 10:30–10:45 · ☕ Break | ||
| Day 1 | 10:45–12:30 | Provider vs deployer & your obligations: Which role you are in; deployer duties (Art. 26); Annex III high-risk areas (incl. employment/HR); transparency (Art. 50); fundamental-rights impact. Hands-onMap your organisation’s AI systems to roles and obligations. |
| 12:30–13:30 · 🍽 Lunch break | ||
| Day 1 | 13:30–15:30 | Data governance & the GDPR/Monaco interface: GDPR, Monaco Loi 1.565, AIPD/DPIA; data governance for AI; sovereignty. Hands-onDraft a DPIA/AIPD outline for one higher-risk system. |
| 15:30–15:45 · ☕ Break | ||
| Day 1 | 15:45–17:00 | Day 1 review: Consolidating your risk picture. Hands-onBuild your AI system risk register so far. |
| Day 2 | 9:00–10:30 | Building the acceptable-use policy: What a good AI policy contains; approved tools; do’s and don’ts; roles and responsibilities. Hands-onDraft your organisation’s AI acceptable-use policy (core sections). |
| 10:30–10:45 · ☕ Break | ||
| Day 2 | 10:45–12:30 | Human oversight by design: Art. 14 (provider design duty) + Art. 26 (deployer’s duty to assign a competent, trained, authorised overseer); meaningful oversight (genuine friction, not a rubber-stamp) into high-risk workflows; sign-off and escalation. Hands-onDesign human-oversight controls for one high-risk workflow. |
| 12:30–13:30 · 🍽 Lunch break | ||
| Day 2 | 13:30–15:30 | Documentation, audit & incident readiness: Record-keeping, logging, conformity; serious-incident reporting; audit-readiness. Hands-onBuild an audit-readiness checklist and a serious-incident response outline. |
| 15:30–15:45 · ☕ Break | ||
| Day 2 | 15:45–17:00 | Roadmap & wrap: Turning it into action. Hands-onTurn it all into a 90-day AI governance action plan. |
Deliverables
- AI system inventory + risk classification
- DPIA/AIPD outline
- Draft acceptable-use policy
- Human-oversight controls for a high-risk workflow
- Audit-readiness checklist
- 90-day governance action plan
Interested in running this module for your team? Get in touch and we'll tailor the format, dates, and delivery to your context.
Request this trainingYour trainer
Senior expert
Has implemented EU AI Act compliance programmes end to end; audit-readiness experience
Discovery Session
We also offer a Discovery Session: a 3-hour introduction to the core concepts. Given the breadth of this programme, we recommend the full training for the complete curriculum and extended practice.
3 hours · From €3,500 · Groups of 5 to 15 - On request
Request a Discovery SessionPart of a bigger path
- StarterEUR 17,500 · 4 training days
- ProfessionalEUR 45,000 · 10 training days
- EnterpriseEUR 115,000 · up to 30 training days
Frequent questions
Can modules be taken individually?
Yes. Every module stands alone at a fixed price, and every module counts toward a programme if you continue.
Where does training happen?
At your premises or remote, on your dates, for private cohorts. Open sessions run on a fixed monthly calendar.
Which AI tools do you train on?
Yours. Every module ships in four ecosystem editions and runs its exercises on your real stack.
Who delivers?
Inforca's senior consultants and trainers. Flagged modules and the executive track are delivered at senior-expert level.
Discuss this module in a First Call: fit, dates, and the path around it.
No commitment · our team responds within one business day