AI-GOV · Path 3: Govern and protect
EU AI Act and AI Governance
Two days after which you hold an AI register, a literacy plan and a policy draft instead of a slide deck full of paragraphs.
- Duration
- 2 days
- Group
- up to 12 people
- Format
- In-house · Remote · Open enrollment
- Language
- German or English
- Price
- €15,800 flat, plus VAT
Who this track is for
For owners in legal, data protection, information security, compliance and IT governance who need to turn the EU AI Act from text into a working state. Ideal when AI is already in use and someone has to set up oversight cleanly.
Who it is not for
Not for teams that first need a shared basic understanding. They start with the AI Literacy Praxislabor (AI-LIT-LAB). Anyone who wants to classify specific applications books the AI Risk Classification Lab (AI-RISK).
Starting situation
In many organisations the law has been read and filed away, but there is no register of the AI in use, no documented role model and no rule for who approves a new application. Oversight began in August 2026, and the board is no longer asking whether but who is responsible for what.
This exists after the track
- A populated AI inventory of your real applications with role, purpose and data class per entry
- A role model that maps provider, deployer, importer and distributor onto your organisation, with named owners
- A literacy plan under Art. 4 that assigns competence by role and context instead of training everyone across the board
- A policy draft for AI use, aligned with your existing data protection and information security rules
- A control calendar with dates, triggers and responsibilities for ongoing oversight
Prerequisites
Basic knowledge of your own organisation and access to existing policies. Legal training is not required, decision authority in your area helps.
Preparation before the track
You fill in a profile sheet for up to ten AI applications you already run or plan, and you bring your existing data protection and IT security policies. These real documents are worked on during day two.
What's included
- Two on-site or remote days with Dino Bordonaro and up to twelve participants
- Template pack: AI inventory table, role model matrix, literacy plan grid, policy skeleton and control calendar
- Current status of the Digital Omnibus package with a clear read on what is solid today and what is still moving
- Audit-proof training documentation and certificates of attendance as a building block for your Art. 4 evidence
- A 30-minute follow-up call after four weeks on the state of your five artefacts
Agenda
Day 1
What the EU AI Act actually requires
The risk-based approach without panic: Art. 4 has applied since February 2025, oversight since August 2026. Core question for the room: where does the duty of best effort end and where does theatre begin? No prescribed certificate, no direct fine for Art. 4.
Digital Omnibus status
What the simplification package moves and what it does not. Decision per participant: which preparation is already solid today, which do we deliberately hold off on without breaching the duty of best effort?
Role model on your organisation
Provider, deployer, importer, distributor. Exercise: each participant assigns their three most important applications to a role and names who in the house carries the obligation. High risk follows the use case and role, not the industry as a blanket rule.
Populating the AI inventory
We start your register. Per application: purpose, data class, role, owner. Day result: a first populated inventory table with at least five real entries per participant.
Day 2
Literacy plan under Art. 4
Competence by role and context instead of mandatory training for all. Exercise: from your roles we derive who needs which level and enter it into the literacy grid.
Policy workshop on your documents
We write the policy draft using your real policies as the basis. Decision per house: what do we regulate anew, what points back to existing data protection and security rules?
Approval process and control calendar
Who approves a new AI application, in which steps, with which documentation? We build the approval path and enter recurring controls with dates and triggers into the calendar.
Bringing it together and naming gaps
We line up inventory, role model, literacy plan, policy and control calendar. Day result: an honest gap list with owners and deadlines for the next four weeks.
Exercises and lab share
The entire second day is a workshop on the participants' real documents and applications. No sample cases are produced, only your five artefacts.
Platforms
Delivered on your premises or remotely. Work happens on your own policies and your own application register, no customer data is placed into third-party systems.
Transfer evidence
The state of the five artefacts at the end of day two and the gap list are reviewed. Attendance and content are documented in an audit-proof way.
Artifacts you take home
- Populated AI inventory of your real applications
- Role model matrix with named owners
- Literacy plan under Art. 4 as a grid per role
- Policy draft for AI use
- Control calendar with dates, triggers and responsibilities
Optional extensions
- AI Risk Classification Lab (AI-RISK) to classify your concrete use cases with confidence
- AI Literacy Praxislabor (AI-LIT-LAB) to roll out the literacy plan at scale
- Secure GenAI and Agent Threat Modeling (AI-SEC) for the security side of your high-value applications
Boundaries
The track delivers structure, templates and your first population. It does not replace individual legal advice or a lawyer's review of your finished documents.
Frequently asked questions
Do we get a certificate at the end that makes us AI Act compliant?
No, no such certificate exists and we do not claim it. The EU AI Act does not prescribe a specific certificate. You receive solid working states and documented training as a building block for your Art. 4 evidence.
Should we rather wait because of the Digital Omnibus?
No. The risk-based approach and the duty of best effort remain in place. We read the current status and decide point by point what you fix today and what you watch, without suspending your obligations.
We are not a high-risk company, do we still need this?
High risk follows the concrete use case and your role, not your industry as a blanket rule. That is exactly what we clarify on your real applications, so you neither over-regulate nor overlook anything.