Free 5-module EU AI Act training course: scope, risk classification (Annex I/III/GPAI), core obligations, deadlines, and enforcement. Certificate of completion for EU AI Act Art. 4 AI literacy requirement. Start immediately, no registration.
The exam is free, needs no account, and the certificate carries an id anyone can verify.
Free · 15 questions · 70% to pass · retake as often as you need · verifiable id
Five modules from zero to compliance-ready
This is the Art. 4 AI literacy course. Every organisation that develops or deploys AI systems in the EU must ensure relevant staff understand their AI Act obligations. The Fundamentals course is designed to satisfy this requirement and takes under 3 hours.
→ Already familiar with the basics? Go to the Pro certification → to implement your compliance programme.
The AI Act Fundamentals course covers the EU AI Act from its legal basis to practical compliance obligations. Each module builds on the previous. All content is free — no paywall, no registration.
Module 1: What is the EU AI Act? →
Estimated time: 20 minutes
- The AI Act's legal basis (Art. 114 TFEU — internal market harmonisation)
- Geographic scope: who it applies to (providers, deployers, importers, distributors — even if established outside the EU)
- Definition of an "AI system" under Art. 3(1) — and what is explicitly excluded
- The relationship between the AI Act and GDPR, DORA, NIS2, and sector-specific regulation
- Key institutions: national competent authorities, EU AI Office, notified bodies
→ Background: AI Act overview →
Module 2: Risk Classification →
Estimated time: 25 minutes
- The four-tier risk pyramid: prohibited, high-risk, transparency, minimal
- Prohibited practices (Art. 5): the eight banned AI uses, in effect since 2 February 2025
- Annex I high-risk (Art. 6(1)): AI embedded as safety components in regulated products
- Annex III high-risk (Art. 6(2)): the 8 standalone high-risk AI domains
- The Art. 6(3) exclusion mechanism: how to self-assess out of high-risk
- GPAI models (Chapter V): definition, tiers, systemic risk threshold
- Transparency obligations (Art. 50): chatbots, synthetic content, emotion recognition
→ Background: Annex III guide → · Annex I guide → · GPAI guide → · Prohibited practices →
Module 3: Core Obligations for High-Risk AI →
Estimated time: 30 minutes
- Art. 9 — Risk management system: continuous, iterative, documented
- Art. 10 — Data governance: training, validation, and testing data quality requirements
- Art. 11 + Annex IV — Technical documentation: what must be in the technical file
- Art. 13 — Transparency and provision of information to deployers
- Art. 14 — Human oversight: design measures, override capability
- Art. 15 — Accuracy, robustness, and cybersecurity: performance levels and residual risk
- Art. 17 — Quality management system (QMS): from design to post-market monitoring
- Art. 43 — Conformity assessment: self-assessment vs. third-party routes
- Art. 71 — EU AI database registration: what to register, when, how
→ Background: Compliance Checklist →
Module 4: GPAI Models — Who Is the Provider After You Fine-Tune? →
Estimated time: 20 minutes
- What counts as a general-purpose AI model (Art. 3(63)) — and why a model is not a system
- Provider obligations under Art. 53: documentation, downstream information, copyright policy, training-content summary
- The systemic-risk presumption at 10^25 FLOPs and the extra Art. 55 duties
- The one-third compute rule: fine-tuning only makes you the provider of the modified model above ~1/3 of the original's training compute
- Why your enterprise LoRA is orders of magnitude below that line
- Where the model regime and your system's regime meet — and where they do not
→ Background: GPAI obligations →
Module 5: Deadlines and Enforcement — What Is Due, and What It Costs →
Estimated time: 20 minutes
- The full timetable after the Digital Omnibus — what moved and what did not
- Art. 50 transparency applies 2 August 2026 and was NOT deferred — the nearest real deadline
- Annex III deferred to 2 December 2027; Annex I to 2 August 2028
- Who enforces: national market surveillance authorities, and why your financial supervisor is likely to be yours
- The three Art. 99 bands: €35M/7%, €15M/3%, €7.5M/1% — and the SME rule that inverts them
- The order a programme should actually work in
→ Background: Deadlines & Timeline → · Digital Omnibus 2026 → · Sanction Estimator →
Get your AI literacy certificate
After reading all 5 modules, you have covered the core EU AI Act requirements as required by Art. 4 (AI literacy obligation for providers and deployers).
The certificate is issued after a short exam covering the five modules, and carries a unique ID that anyone can verify. It documents structured EU AI Act training you can file against your Art. 4 AI literacy measures. Fifteen questions are drawn from a bank and graded on the server — the answer key never reaches your browser. Score 70% or more and the certificate is issued immediately, with an Open Badge you can add to LinkedIn.
→ Sit the exam now → · Verify a certificate →
For the next level — risk assessment templates, technical documentation templates, and QMS extension guides — see AI Risk Management Pro →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
The 5 modules take approximately 2-3 hours total to complete. Each module has an estimated reading time of 20-30 minutes and ends with a short knowledge check. You can complete modules in any order or over multiple sessions.
Yes, and it is free. After the five modules you sit a 15-question exam graded on the server; at 70% or more a certificate is issued with a unique ID that anyone can check on the public verification page, plus an Open Badge. It records a dated AI literacy measure you can file under Art. 4.
Art. 4 binds the organisation rather than the individual, and since the Digital Omnibus (Regulation (EU) 2026/1744) rewrote it in July 2026 it asks providers and deployers to take measures supporting AI literacy — not to guarantee a level for any given person. This course is one such measure: it covers scope, risk classification, role-based obligations and deadlines, and the certificate gives you a dated, nominative record for your AI governance file.
The free Fundamentals course (5 modules, ~3 hours) covers the EU AI Act conceptually — what it requires and why. The Pro certification (8 modules, ~10 hours + 3 templates) goes into implementation: how to build a risk management system (Art. 9), write the technical file (Annex IV), design human oversight (Art. 14), and complete the conformity assessment (Art. 43). If you are implementing a compliance programme, you need the Pro tier.