AI Compliance Foundations
The compliance-relevant AI literacy you need before EU AI Act risk tiers, ISO/IEC 42001, and vendor due diligence make sense in practice.
AI governance has moved from a leadership talking point to a regulatory-driven compliance function with real deadlines. Build the foundation and the execution depth to own that work credibly.
The professional landscape is shifting. Here is what is at stake for compliance & ai governance professionals who do not yet have a structured AI skills foundation.
Compliance officers, legal and risk staff, and data protection professionals are increasingly handed AI oversight responsibilities with no prior technical or regulatory foundation in the area. A structured foundation — how AI systems actually behave, and the model-risk vocabulary of bias, drift, hallucination, and explainability — is the difference between asking a sharp follow-up question and nodding along to a vendor's reassurance.
The EU AI Act, GDPR Article 22, the NIST AI Risk Management Framework, and ISO/IEC 42001 all show up in the same AI governance conversation, often with little explanation of how they relate. Knowing which is binding law, which is a voluntary standard, and which applies to a specific system is foundational — and frequently assumed rather than taught.
AI capability arrives embedded in existing vendor software long before any compliance function is positioned to track it centrally. An unclassified inventory is the single most common starting gap in this field — and the ability to build a first, honest triage under time pressure is a concrete, demonstrable skill worth certifying.
Free, self-paced courses ending in a verifiable certificate you can share on LinkedIn.
The compliance-relevant AI literacy you need before EU AI Act risk tiers, ISO/IEC 42001, and vendor due diligence make sense in practice.
The operational layer of AI governance — EU AI Act conformity, ISO/IEC 42001, risk classification, and audit-ready documentation.
A real excerpt of what each course covers, pulled straight from the lesson list.
+3 more lessons in the full course
+3 more lessons in the full course
Common questions from compliance & ai governance professionals considering these courses.
Start with AI Compliance Foundations if you are new to AI-related compliance work — it builds the technical model, model-risk vocabulary, and regulatory orientation that the advanced course assumes. If you already have that foundation and need the operational depth of formal risk classification, conformity assessment, and audit evidence practice, go directly to AI Governance and Compliance.
Yes, at an orientation level — enough to correctly place a described AI system in the right general region of the regulatory landscape and understand how the frameworks relate. The advanced AI Governance and Compliance course covers the same frameworks in full operational depth: formal risk-tier classification, conformity assessment mechanics, and audit-ready documentation.
Yes — that is exactly who these courses are built for. Neither course requires you to build or code an AI system. AI Compliance Foundations teaches the specific, compliance-relevant mental model of how AI systems generate outputs and why they fail differently than traditional software, without requiring an engineering background.
AI Compliance Foundations has a 24-question exam with a 50-minute time limit. AI Governance and Compliance has a 32-question exam with a 58-minute time limit. Both require 75% to pass, with up to three attempts, and test applied judgment in realistic compliance scenarios rather than memorized rule citations.
Copy, adapt, and use these prompts directly in ChatGPT, Claude, or any major AI assistant.
Prompt 1
AI System Risk-Tier Classifier
You are an AI governance analyst. Based on the following AI system description: [SYSTEM DESCRIPTION], identify which EU AI Act risk category it most likely falls into (prohibited, high-risk, limited-risk, or minimal-risk) and list the specific factors driving that classification. Flag anything genuinely ambiguous rather than forcing a single answer — this is a first-pass triage, not a legal determination.Prompt 2
Vendor AI Due-Diligence Questionnaire
Draft a vendor due-diligence questionnaire for an AI tool that will process [DATA TYPE] in a [USE CASE] context. Cover: what data the tool is trained or fine-tuned on, what data we would send it in production, human-review and override mechanisms, logging and audit-trail capabilities, and how the vendor handles a request to explain a specific output.Prompt 3
Plain-Language Regulation Summary
Summarize the following regulatory text for a non-legal audience of business stakeholders: [PASTE REGULATION OR ARTICLE TEXT]. Preserve every obligation, deadline, and exception — do not simplify away anything that changes what a reader is required to do. Flag any term that has a specific legal meaning different from its plain-English meaning.Prompt 4
AI System Inventory Entry
Based on this system description: [DESCRIPTION], draft a structured entry for an AI system inventory: system name, business owner, what it is used for, what data it processes, whether it is vendor-provided or built in-house, and what human oversight exists today. Mark any field you cannot confidently fill in as "needs follow-up" rather than guessing.Prompt 5
Framework Gap Analysis
Compare the following description of our current AI governance practice: [DESCRIPTION OF CURRENT PRACTICE] against the Govern function of the NIST AI Risk Management Framework. List every gap as a specific, actionable item, not a general observation — and note which gaps look most urgent given [CONTEXT, e.g. an upcoming audit or a new high-risk system going live].The tools most used by compliance & ai governance professionals who are already getting results with AI.
ChatGPT or Claude (enterprise plan)
Best for drafting policy documents, turning dense regulatory text into plain-language summaries, and structuring vendor questionnaires — use an enterprise plan with a data processing agreement in place, never a personal consumer account, for anything touching real vendor or system data.
Credo AI
An AI governance platform purpose-built for this function — model and system registries, risk assessments mapped to frameworks like the EU AI Act and NIST AI RMF, and audit-ready evidence tracking, rather than a general-purpose GRC tool retrofitted for AI.
Perplexity AI
Useful specifically because it cites its sources — for regulatory research, an unsourced answer from a general chat assistant is a liability, not a shortcut, so a tool that shows you the underlying document is worth the extra step of verification it still requires.
A sample of the topics covered across the recommended courses for compliance & ai governance professionals.
Every course on Deliberate Academy is free. No subscription, no credit card, no paywall. Read the lessons, pass the exam, and earn a certificate you can put on LinkedIn — today.