Phase 7: Responsible AI, Governance & Risk · 50 min · EU AI Act · NIST AI RMF · Python
AI Regulation for PMs
You don't need to read Annex III. You need to know which five questions get you 90% of the way to the right tier.
Hiring signal: AI PM job postings increasingly name EU AI Act and NIST AI RMF fluency explicitly, not as legal trivia but as the ability to turn 'high-risk system' into a concrete requirements list before legal gets involved. PMs who can run a first-pass regulatory triage save weeks of outside-counsel cycles and are trusted to scope features that touch regulated domains.
What you will learn
- Classify an AI feature against the EU AI Act's four risk tiers using its use case, not its technology
- Explain what each NIST AI RMF function (Govern, Map, Measure, Manage) requires in terms a PM can act on
- Identify which product decisions get triggered by a 'high-risk' or 'limited-risk' classification
- Turn a regulatory classification into a specific, actionable requirements list for a PRD
The Problem
A PM at a mid-size insurtech company is scoping a feature: an LLM that drafts a recommended claim-approval decision, which a human adjuster can accept, edit, or override. Legal asks the obvious question — "is this high-risk under the EU AI Act?" — and the PM has two bad options: guess (risky, since fines for the most serious violations run up to the greater of €35 million or 7% of global annual turnover), or hand it to outside counsel and wait three weeks for an answer that a five-minute structured lookup should have produced in the design review.
Neither is necessary. The EU AI Act and the NIST AI Risk Management Framework are both, for a PM's purposes, mechanical enough to triage yourself for the first pass — not to replace legal sign-off on anything that actually matters, but to walk into that legal conversation already knowing the likely tier, the likely obligations, and exactly which specific fact (does a human really override this, or just rubber-stamp it?) will decide the answer. That's the skill research on AI PM job postings names explicitly: not compliance-officer depth, but the ability to turn "high-risk system" into a requirements list before legal gets involved.
The EU AI Act: Four Tiers, Decided by Use Case Not Technology
The EU AI Act does not regulate "AI" as a technology — it regulates specific use cases, and the tier is decided by what the system does to a person, not what's under the hood. A simple logistic regression screening job applicants is high-risk. A frontier LLM writing marketing copy is minimal-risk. The sophistication of the model is irrelevant to the tier.
| Tier | What triggers it | What it means for a PM |
|---|
| Unacceptable | Social scoring by public authorities, real-time biometric ID in public for law enforcement (narrow exceptions), manipulative/subliminal techniques causing harm, exploiting vulnerable groups | Cannot ship in the EU, full stop — this should be caught in the opportunity-assessment stage, not after a PRD is written |
| High | Annex III domains: biometric ID, critical infrastructure, education, employment/worker management, access to essential services (credit, insurance, benefits), law enforcement, migration, justice | Risk management system, data governance documentation, human oversight design, conformity assessment, logging, post-market monitoring — this becomes a real chunk of the roadmap, not a checkbox |
| Limited | Chatbots/conversational AI, synthetic/deepfake content, emotion recognition or biometric categorization | Disclosure obligations only: tell users they're talking to AI, label synthetic content |
| Minimal | Everything else | No mandatory obligations beyond existing law |
The claims-drafting example above is high-risk: insurance is an Annex III essential-service domain, and "the adjuster can technically override it" doesn't move the tier down if overrides are rare in practice — auditors specifically look for rubber-stamp oversight as a red flag that the human-in-the-loop requirement isn't real.
The five questions that get you 90% of the way there
(1) Does this fall into an Article 5 prohibited-practice category? (2) Does this operate in an Annex III domain — biometrics, employment, credit/insurance/benefits, education, law enforcement, critical infrastructure, migration, justice? (3) Does the system interact with users in a way that could be mistaken for a human, or generate synthetic media? (4) Is a human genuinely making the final call, or nominally reviewing an output they almost always accept? (5) Is the underlying model itself a general-purpose foundation model above the systemic-risk compute threshold — a separate obligation track from the application tier. Answer these five before you call legal, and the call becomes "confirm my triage" instead of "please figure this out."
Unlock the full lesson
You've read the first 2 sections. The rest of this lesson covers NIST AI RMF: Govern, Map, Measure, Manage, Turning "High-Risk" Into a PRD, Build It, What to Practice — plus a hands-on lab, quiz, and project artifact.
Create a free account to unlock Phase 0 and Phase 1 of every course — no credit card.
Browse all courses · View pricing · DeVenture Academy