AI Assurance Institute Logo AI Assurance Institute

Training

Vector Database Systems under the EU AI Act

Operational control and regulatory compliance after deployment

Overview

This course addresses operational compliance for vector database (VDB) systems under Regulation (EU) 2024/1689 (the EU AI Act). For this programme, VDB systems are used for semantic search, similarity matching, recommendation and retrieval-augmented generation.

Whether a VDB system is high-risk depends on intended purpose, not on the use of embeddings. Where that purpose places the system in a high-risk class, the Act continues after the system is put into service.

The course translates the articles named for this programme into purpose-specific controls for a live vector store: how items are embedded, indexed, retrieved and ranked, and how that chain is watched after go-live.

Why vector databases need their own operational treatment

A vector database retrieves by similarity in embedding space. Failures named for this course - embedding poisoning, retrieval-bias amplification, and ranking that affects rights - sit in the vectors and in the ranker. A poisoned embedding is not the same event as a wrong generated sentence. Drift in embeddings after the last test changes what the system returns without a visible code change.

When the VDB feeds a RAG pipeline, it is still part of the system in use. Oversight has to reach retrieved neighbours and ranked lists. Logs have to reconstruct the query vector, the hits and the rank. Monitoring has to cover embedding drift, retrieval bias and ranking that no longer matches the intended purpose.

Articles in scope

The course is built around the articles already named for this programme.

Classification remains purpose-specific. The course does not treat every deployment of this architecture as high-risk, and it does not treat high-risk status as optional once intended purpose meets the Act's tests.

What you will learn

By the end of the course, participants will be able to:

Course structure

Six modules. Each module stays inside the articles listed above.

1. Regulatory context and the Article 8 lenses

How the Act classifies systems by intended purpose. When a VDB use - search, matching, recommendation or retrieval into generation - is high-risk and when it is not.

2. Human oversight under Article 14

What a person must be able to see in retrieved neighbours and ranked lists. When oversight must drop a result, freeze an index, or stop a query. Escalation for poisoned embeddings and for ranking that affects rights.

3. Logging, traceability and observability

Article 12 as it applies to queries, hits and ranks. Article 10 as it applies to the data that are embedded. Article 15 as it applies to robustness of the index and accuracy of retrieval in operation.

4. Post-market monitoring under Article 72

Embedding drift after the last test. Retrieval bias over time. Ranking that has moved away from the intended purpose. The deployer's related duty under Article 26 to use the system as instructed and to watch its operation.

5. Operational risk controls and incident response

Article 9 after deployment: a poisoned vector, an index built from an unintended store, a ranker that promotes a harmful neighbour. Isolating the affected embeddings. Recording the incident so the risk-management file can be updated.

6. Integration and audit readiness

How Articles 17 and 8 require the embedding model, the index and the ranker to sit inside a quality-management system. What an assessor would need in order to test the live VDB against the claimed purpose. The record means the information the Act already requires. The course does not add a separate product pack.

Who the course is for

The course is written for people responsible for vector database systems that are in production, or that are being prepared for a high-risk intended purpose under the articles above. It assumes familiarity with the EU AI Act. It is not a survey of embedding methods.

Register for upcoming training