EU AI Act
What should you ask in an EU AI Act interview, and how should candidates answer?
Every AI governance hire in Europe claims to know the EU AI Act. These questions check whether they can apply it: roles, risk tiers, the 2026 dates and the duties that follow, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.
What should an employer ask an EU AI Act candidate?
Each question maps to a part of the law, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.
How would you decide whether we are the provider or the deployer of an AI system?
Listen for: The Article 3 definitions, then Article 25: putting our name on a high-risk system, making a substantial modification or changing its intended purpose makes us the provider.
Roles: Articles 3 and 25
Walk me through the Act's risk tiers.
Listen for: Banned practices (Article 5), high-risk systems (Article 6 with Annexes I and III), transparency duties (Article 50), general-purpose AI models (Chapter V), and everything else.
Risk tiers
Which dates matter to us after the July 2026 amendment?
Listen for: 2 February 2025 for literacy and the bans, 2 August 2025 for general-purpose models, 2 August 2026 as the general date, 2 December 2027 for Annex III high-risk systems, 2 August 2028 for Annex I.
Article 113 as amended
What would you do in your first month to get us ready for 2 December 2027?
Listen for: An inventory, a risk tier and an owner for each system, then a gap list against Article 26 (deployers) or Article 16 (providers).
High-risk duties
How does the AI Act sit alongside GDPR?
Listen for: Both apply. Deployers use the provider's information for the DPIA under Article 26(9), and the fundamental rights impact assessment can build on the DPIA.
Articles 26 and 27
What does Article 4 ask of us today?
Listen for: Measures to support the AI literacy of staff and others using AI on our behalf, fitted to their role and the context of use, with a record of what was done.
Article 4
Marketing wants to publish AI-generated images of people. What applies?
Listen for: Article 50(4): deployers must disclose deepfakes, from 2 August 2026, with a lighter touch for evidently artistic or satirical work.
Article 50
A high-risk system we deploy causes a serious incident. What happens next?
Listen for: Inform the provider straight away under Article 26(5), keep the logs, and support the provider's report to the market surveillance authority under Article 73.
Articles 26(5) and 73
EU AI Act interview scorecard
EU AI Act interview scorecard
Candidate: ______ Interviewer: ______ Date: ______
| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you decide whether we are the provider or the deployer of an AI system? | The Article 3 definitions, then Article 25: putting our name on a high-risk system, making a substantial modification or changing its intended purpose makes us the provider. | |
| 2 | Walk me through the Act's risk tiers. | Banned practices (Article 5), high-risk systems (Article 6 with Annexes I and III), transparency duties (Article 50), general-purpose AI models (Chapter V), and everything else. | |
| 3 | Which dates matter to us after the July 2026 amendment? | 2 February 2025 for literacy and the bans, 2 August 2025 for general-purpose models, 2 August 2026 as the general date, 2 December 2027 for Annex III high-risk systems, 2 August 2028 for Annex I. | |
| 4 | What would you do in your first month to get us ready for 2 December 2027? | An inventory, a risk tier and an owner for each system, then a gap list against Article 26 (deployers) or Article 16 (providers). | |
| 5 | How does the AI Act sit alongside GDPR? | Both apply. Deployers use the provider's information for the DPIA under Article 26(9), and the fundamental rights impact assessment can build on the DPIA. | |
| 6 | What does Article 4 ask of us today? | Measures to support the AI literacy of staff and others using AI on our behalf, fitted to their role and the context of use, with a record of what was done. | |
| 7 | Marketing wants to publish AI-generated images of people. What applies? | Article 50(4): deployers must disclose deepfakes, from 2 August 2026, with a lighter touch for evidently artistic or satirical work. | |
| 8 | A high-risk system we deploy causes a serious incident. What happens next? | Inform the provider straight away under Article 26(5), keep the logs, and support the provider's report to the market surveillance authority under Article 73. |
Source: https://credentialpress.com/guides/eu-ai-act-interview-questions
Which questions should an EU AI Act candidate prepare for?
Which part of the Act do you know best?
How to answer: Pick one part and show it applied: a system, the tier you gave it, and the duty that followed.
What changed in July 2026?
How to answer: Regulation (EU) 2026/1744 moved Annex III high-risk duties to 2 December 2027 and Annex I to 2 August 2028, rewrote Article 4, and added relief for small mid-caps. Say what that changes in a plan.
How would you explain the Act to a sales team in two minutes?
How to answer: What is banned, what makes a system high-risk, and what customers must be told. Skip the Article numbers.
Have you turned the Act into controls?
How to answer: Name the control set you used, for example one built on ISO/IEC 42001, and say what it did not cover.
What should a candidate ask the employer?
- Do you keep an AI inventory with a risk tier for each system?
- Which AI systems do you provide, and which do you deploy?
- Who signs off a high-risk deployment, and who reports incidents?
Where next?
Also free: the EU AI Act mind map and the EU AI Act 10-question quiz, plus every other credential on our study tools page. For depth, the AI Governance Framework and the AI Governance Worked Scenarios trace each duty to its Article, written to the 2024 text.
Frequently asked questions
What should an employer ask an EU AI Act candidate?
Questions that test each exam domain in practice, for example: How would you decide whether we are the provider or the deployer of an AI system? Walk me through the Act's risk tiers. Which dates matter to us after the July 2026 amendment?
What should an EU AI Act candidate ask the employer?
Do you keep an AI inventory with a risk tier for each system? Which AI systems do you provide, and which do you deploy? Who signs off a high-risk deployment, and who reports incidents?
How should a candidate prepare for an EU AI Act interview?
Pick one part and show it applied: a system, the tier you gave it, and the duty that followed.
Which books go deeper on EU AI Act?

Building one that survives the EU AI Act. 22 chapters, 384 pages.

AI Governance Worked Scenarios
24 worked situations under the EU AI Act, decided against the Articles. 81 pages.
Sources
- Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026, read 2 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), read 2 October 2026
Credential Press is independent of the EU institutions.