← Consultant Academy
EU AI ACT PRACTITIONER MAP

Know where to look — not just what to memorise

A consultant does not need to recite the Regulation from memory. They do need a reliable route from client facts to the relevant legal topic, evidence request and escalation decision.

Eight-step analysis method

  1. 1. Define the AI use case and intended purpose in plain English.
  2. 2. Identify entities, geography and role(s) for the specific system/model activity.
  3. 3. Screen prohibited practices before assuming the use is merely high-risk or lower-risk.
  4. 4. Run the Article 6 / Annex I or Annex III high-risk pathway where relevant.
  5. 5. Run separate transparency and GPAI analyses instead of treating them as subcategories of high-risk.
  6. 6. Map requirements to the correct actor: provider, deployer and other supply-chain roles.
  7. 7. Identify required evidence, conformity/registration steps, monitoring and change triggers.
  8. 8. Date-stamp the conclusion and retain the authoritative source used.
Article 3
Definitions

Use the legal definitions rather than informal product language when role or system status matters.

Article 4
AI literacy

Providers and deployers take measures supporting AI literacy appropriate to people, experience and context.

Article 5
Prohibited practices

Screen exact conditions and exceptions; high-consequence ambiguity should be escalated.

Article 6 + Annexes I/III
High-risk classification

Follow the statutory pathway from intended purpose and listed use rather than classifying by model brand.

Articles 8–15
Requirements for high-risk AI

Risk management, data governance, technical documentation, logging, information, human oversight, accuracy, robustness and cybersecurity.

Article 16 onward
Provider obligations

Translate system requirements into provider responsibilities, conformity work and evidence.

Article 26
Deployer obligations

Operational use, oversight, monitoring, logs and other duties can remain with the deployer even when the system was purchased from a compliant provider.

Article 27
Fundamental-rights impact assessment

Determine whether the deployer/use triggers the FRIA duty and coordinate rather than confuse it with a GDPR DPIA.

Article 43
Conformity assessment

Select the applicable route; do not assume every high-risk system needs third-party approval.

Articles 47–49
Declaration, CE marking and registration

Understand the evidence and registration steps that follow the relevant conformity pathway.

Article 50
Transparency

Run a separate analysis for direct AI interaction and specified synthetic/manipulated content scenarios.

Articles 51–55
GPAI and systemic risk

Separate model-level obligations from downstream AI-system roles and identify additional systemic-risk duties where applicable.

Post-market & incidents
Lifecycle compliance

Monitor the deployed system, investigate material performance/risk signals and maintain incident/escalation processes.

Consultant evidence chain

For each material conclusion keep: client fact → evidence → relevant legal pathway → working conclusion → uncertainty/exception → action or escalation. Do not replace this chain with a single red/amber/green score.

Open current consolidated Act ↗Open current-law desk guide

Reviewed 15 September 2026. Educational internal training map only. Confirm the current consolidated legislation and official guidance before using a conclusion with a live client.