Module
Module 5 of 6Lesson 1 of 2~22 min

Qualify your product under the AI Act: roles, risk levels, timeline

Lesson 1 of the module "AI Act and GDPR" in the course "Secure an AI product: prompt injection, guardrails and the AI Act".

Lesson objective

By the end of this lesson, you will be able to qualify each AI feature of your product under the AI Act - AI system or not, your company's role, risk level, obligations and application dates after the Digital Omnibus - and to record this analysis, dated, to review with a lawyer.

Where it fits

AI Act and GDPR

What does the AI Act require of my product, from when, and how does it fit with the GDPR?

Lessons in this module

  1. Qualify your product under the AI Act: roles, risk levels, timeline (this lesson)
  2. Article 50 transparency and interplay with the GDPR

What you will learn in the course

This lesson is part of the course Secure an AI product: prompt injection, guardrails and the AI Act

  • Map the attack surface of an AI product and its risks with the OWASP Top 10 for LLM Applications 2025, in a prioritized risk register.
  • Analyze a product's direct and indirect prompt injection paths, system prompt leakage and data exfiltration (lethal trifecta).
  • Specify layered guardrails (input, output, rights, human approval, isolation, limits) with testable criteria and their cost.
  • Plan red teaming, abuse monitoring and incident response for an AI feature.
  • Qualify a product under the AI Act (role, risk level, prohibited practices, transparency, timeline) and connect this analysis with the GDPR.