Seven-module certification for deployers of AI systems under the EU AI Act: Art. 26 obligation by obligation, human oversight, logs, the Art. 25 trap, transparency duties, and the evidence a supervisor will ask for.

Almost every organisation in scope of the AI Act is a deployer and nothing else. It buys AI, licenses it, embeds it, and puts it to work. It does not train models, does not place systems on the market, and will never affix a CE marking to anything.

Almost every piece of published guidance is written for providers.

That gap is what this track closes. It works through the obligations that actually attach to the organisation using the system, in the order you meet them, with the carve-outs that decide most real cases — and it is honest about the ones you do not owe, because a compliance programme that does work it does not owe is a programme that will run out of budget before it does the work it does.

The seven modules

Module 1 — Are you a deployer, and of what? Art. 3(4), the inventory, and classification read from the buyer's seat rather than the builder's. Where the Art. 6(3) filter helps you and where it cannot.

Module 2 — Article 26, paragraph by paragraph The twelve paragraphs turned into an operating procedure, with the evidence each one produces.

Module 3 — Human oversight that survives a review Art. 14 as a design duty on the provider, Art. 26(2) as an assignment duty on you, and automation bias as the thing that quietly voids both.

Module 4 — Logs, monitoring, suspension, incidents Art. 12 logging, the six-month retention floor in Art. 26(6), when to stop using a system, and what cooperation under Art. 73 actually asks of you.

Module 5 — The Article 25 trap Three triggers, each of which turns a deployer into a provider. How to recognise them before procurement rather than after an audit.

Module 6 — Transparency you owe directly Art. 50(3) and 50(4) are deployer duties, in force now. Plus Art. 26(11) information to affected persons and the Art. 86 right to explanation.

Module 7 — The evidence file What a supervisor asks for, in what order: the classification record, the FRIA determination, the Art. 4 literacy register, and the vendor file that Art. 13 should have given you.

What the examination asks

Twenty questions drawn from a bank, stratified so every module is covered, graded on our server. The pass mark is 70%. The questions are scenario-based and the intuitive answer is frequently wrong — because in this Regulation it frequently is.

A certificate carries a public id anyone can verify, and an Open Badge you can attach to a LinkedIn profile.

Before you start

This track assumes the free Fundamentals course — scope, the four tiers, the roles, the timetable. If you cannot yet say whether a given system is Annex III without looking it up, start there.

This is not the same examination

The Fundamentals examination checks that you have read the Regulation. This one checks that you could apply it to a real case — same subject, different question.

Fundamentals (free) Deployer (this track)
Questions served 1520
Question bank 60101
Modules covered 57
What is tested Whether you are in scope, and by what Whether you could run the obligation, not whether you can name it
Access Open, no card required Track holders only

Two sample questions on the same article. They are written for this page and appear in no bank.

Fundamentals — free

Which article sets out the obligations of a deployer of a high-risk AI system?

  1. Article 16
  2. Article 26
  3. Article 43
  4. Article 72
Show the answer and the reasoning

Answer 2. Art. 16 is the provider's list, Art. 43 is conformity assessment and Art. 72 is post-market monitoring. A single fact, and you either know it or you do not — which is what a foundation examination is for.

Deployer — this track

Your AI vendor hosts the system and holds the logs. Your sector regulator requires seven years of decision records. Your contract is silent on log export. Where does that leave your Art. 26(6) position?

  1. Compliant — six months is the statutory floor and the vendor is holding them
  2. Compliant for the AI Act, non-compliant for the sector rule, and the two can be reconciled later
  3. Exposed on both: the duty is limited to logs under your control, and Art. 26(6) defers to the longer sectoral period
  4. Not your problem — a hosting arrangement transfers the retention duty to the vendor
Show the answer and the reasoning

Answer 3. Two qualifiers do the work. 'To the extent those logs are under their control' turns custody into a contractual question you have not settled; and 'unless provided otherwise in applicable Union or national law' means the seven-year sectoral rule governs, not the six-month floor. Nothing here is a fact to recall — it is three provisions and a contract read together.

Every paper is drawn per candidate and stratified across all modules; the order of the options differs between candidates. Grading happens on the server — the answer key never reaches the browser.

Frequently Asked Questions

Art. 3(4) defines a deployer as a natural or legal person using an AI system under its own authority, except where the use is a purely personal, non-professional activity. If your organisation buys or licenses AI and puts it to work, you are a deployer. The overwhelming majority of organisations in scope of the AI Act are deployers and nothing else — which is why almost all published guidance, written for providers, misses their actual obligations.

Twelve paragraphs, and they read as an operating procedure rather than a policy: use the system per the instructions, assign oversight to competent and trained people, keep control of input data where you have it, monitor operation, suspend and notify when a risk appears, keep the automatically generated logs for at least six months, inform workers' representatives before putting a workplace system into service, cooperate with authorities, and inform people subject to decisions taken with the system.

Yes, and it is the most expensive mistake in this area. Art. 25 lists three triggers: putting your own name or trademark on a high-risk system, making a substantial modification to it, or changing its intended purpose so that it becomes high-risk. Any one of them makes you the provider, with the whole of Chapter III — risk management, technical documentation, conformity assessment, CE marking, registration — landing on you.

Most do not. Art. 27 applies to bodies governed by public law, private entities providing public services, and deployers of the systems listed in Annex III points 5(b) and 5(c) — creditworthiness scoring, and risk assessment and pricing in life and health insurance. A private employer deploying an Annex III recruitment system owes no FRIA. This is the single most over-claimed obligation in the market.

The Art. 5 prohibitions and the Art. 4 AI literacy duty have applied since 2 February 2025. The Art. 50 transparency duties have applied since 2 August 2026. The Chapter III obligations attaching to standalone Annex III high-risk systems — which is where Art. 26 bites hardest — apply from 2 December 2027 after the Digital Omnibus deferral, and 2 August 2028 for AI embedded in Annex I regulated products.

No, and none exists. In the AI Act, conformity assessment and notified bodies apply to AI systems, not to people, so no body can be notified to certify a person. This is a private certificate with a public id anyone can verify, issued by Regulation AI. We say so on the certificate itself.

Take compliance further with the AI Act Academy

A free course, a server-graded exam, a verifiable certificate — and the working templates.