Training
Operational control and regulatory compliance after deployment
This course addresses operational compliance for AI systems adapted through Parameter-Efficient Fine-Tuning (PEFT) under Regulation (EU) 2024/1689 (the EU AI Act). For this programme, PEFT includes techniques such as LoRA, QLoRA and adapters that change a base model's behaviour without retraining all parameters.
Whether a PEFT-adapted system is high-risk depends on intended purpose, not on the adaptation method. Where that purpose places the system in a high-risk class, the Act continues after the system is put into service. The adapted system is the system in use. The adapter is part of it.
The course translates the articles named for this programme into purpose-specific controls for a live PEFT deployment: the base model, the adapter, the data used to adapt it, and how that stack is watched after go-live.
PEFT changes behaviour with a small set of additional parameters. Failures named for this course - bias transferred from adaptation data, catastrophic forgetting of earlier behaviour, and adapter poisoning - sit in that change. A poisoned adapter is not visible if oversight only reviews the base model card. Forgetting is not visible if testing only repeats the adaptation set.
Data governance has to reach the adaptation set. Oversight has to see outputs after the adapter is applied. Logs have to record which adapter and which base version ran. Monitoring has to cover bias transfer, loss of prior behaviour, and integrity of the adapter in production.
The course is built around the articles already named for this programme.
Classification remains purpose-specific. The course does not treat every deployment of this architecture as high-risk, and it does not treat high-risk status as optional once intended purpose meets the Act's tests.
By the end of the course, participants will be able to:
Six modules. Each module stays inside the articles listed above.
How the Act classifies the adapted system by intended purpose. When a PEFT use is high-risk and when it is not. Why the adapter does not sit outside the system for the purpose of those tests.
What a person must be able to see in outputs after adaptation. When oversight must disable an adapter or revert to a prior version. Escalation for bias transfer and for sudden loss of earlier behaviour.
Article 12 as it applies to base version, adapter version and output. Article 10 as it applies to adaptation data. Article 15 as it applies to robustness against adapter poisoning and to accuracy after the change.
Adapter behaviour over time. Forgetting relative to the pre-adaptation baseline. Integrity of the adapter file in production. The deployer's related duty under Article 26 to use the system as instructed and to watch its operation.
Article 9 after deployment: a poisoned or swapped adapter, an adaptation that changes behaviour outside the intended purpose. Isolating the adapter. Recording the incident so the risk-management file can be updated.
How Articles 17 and 8 require the base model, the adapter and the adaptation data to sit inside one quality-management system. What an assessor would need in order to test the live adapted system against the claimed purpose. The record means the information the Act already requires. The course does not add a separate product pack.
The course is written for people responsible for PEFT-adapted systems that are in production, or that are being prepared for a high-risk intended purpose under the articles above. It assumes familiarity with the EU AI Act. It is not a survey of fine-tuning methods.