The Compliance Playbook
Everything in this course condenses to one workflow: find your AI, classify it, assign roles, and meet the duties for each tier before its deadline. This final lesson turns the law into a one-page action plan - plus the penalties that make it worth doing.
What Non-Compliance Costs
The Act’s fines are tiered by the seriousness of the breach, and like the GDPR they bite on global turnover:
| Breach | Maximum fine |
|---|---|
| Using a prohibited practice (Lesson 3) | Up to €35M or 7% of total worldwide annual turnover, whichever is higher |
| Breaching most other obligations (high-risk, GPAI, transparency) | Up to €15M or 3% of turnover |
| Supplying incorrect or misleading information to authorities | Up to €7.5M or 1% of turnover |
For SMEs and startups, the caps are applied proportionately (the lower of the fixed amount or the percentage). The headline numbers are aimed at large providers, but enforcement, corrective orders, and forced withdrawal from the EU market apply to everyone.
The Ten-Step Action Plan
- Build an AI inventory. List every AI system you build, embed, or use. You cannot classify what you have not catalogued.
- Assign a role to each system. Provider, deployer, importer, distributor - per system, not per company (Lesson 1).
- Run the Article 5 screen first. Anything near a prohibited practice is the top priority - it is already enforceable and carries the 7% fine (Lesson 3).
- Classify each system into a tier. High, limited, or minimal, using the decision path from Lesson 2.
- Flag the high-risk systems early. They need risk management, data governance, documentation, human oversight, and a conformity assessment - the longest lead time (Lesson 4).
- Map your GPAI exposure. Do you train, fine-tune, or just call foundation models? Fine-tuning can make you a provider (Lesson 5).
- Add transparency labels. Disclose AI chat, mark generated content, label deepfakes - cheap, so just do it (Lesson 6).
- Stand up the management systems. Risk-management and quality-management processes, plus the documentation templates behind them (Lesson 7).
- Deliver AI-literacy training. Already required since Feb 2025; record what you do.
- Set up post-market monitoring. Incident reporting, logging retention, and a corrective-action path before launch, not after.
Tailored Quick-Starts
If you mostly build AI products (provider)
Your weight is in Lessons 3, 4, and 5. Prioritise the Article 5 screen, then the high-risk documentation stack for any Annex III system, and determine whether any model you train or fine-tune pulls you into GPAI-provider duties.
If you mostly use third-party AI (deployer)
Your weight is in Lessons 4 (deployer duties) and 6. Use systems per the provider’s instructions, assign human oversight, inform staff before workplace deployment, and add transparency disclosures. Watch the deployer-to-provider trap if you re-brand or re-purpose a system.
If you resell or distribute AI (importer/distributor)
Verify that the systems you place on the market carry the CE marking, declaration of conformity, and provider information before you pass them on, and keep records.
Where This Course Ends and Counsel Begins
This course gives you the map: the tiers, the duties, the timeline, and the action plan. It does not replace legal advice on your specific systems. Use it to scope the work, ask the right questions, and brief your counsel efficiently - then confirm the close calls (is this Annex III? have we become a provider?) against the official text and qualified legal advice.
Ready to Go Deeper?
Live instructor-led courses from our partners. Affiliate disclosure.
AI & ML Courses - 30% Off
Live instructor-led AI, machine learning, data science, and cloud courses for working professionals. Use code Limited30 at checkout.
EdurekaDataCamp - AI & Data Science
Hands-on Python, machine learning, and AI courses with interactive exercises and real projects.
DataCampedX - Top AI Courses
University-level AI courses from MIT, Harvard, Stanford. Earn certificates that employers recognize.
edX