Start here if you're doing the hands-on work.

Eight stops, straight to the working material. This assumes you already know what an AIMS or a model card is — for the orientation version, see the heads-of walk instead.

  1. The risk register, in full 47 individually assessed risks, scored by severity, mapped to controls and framework clauses — filterable by category or framework.
  2. The control register, in full 22 mitigating controls, mapped back to the risks they address by effectiveness: primary, supporting, or compensating.
  3. Templates and checklists Downloadable, working documents — not summaries of what a document should contain.
  4. Definitive terminology Cross-referenced with the frameworks and risks that use each term, so you're not guessing at scope.
  5. The delivery lifecycle Architecture, evaluation, monitoring, and incident response — the control points that turn intent into a running system.
  6. The threat model Five categories mapped to the OWASP Top 10 for LLM Applications, plus a working control flow for AI systems.
  7. Primary sources The regulation, standards, and technical references worth citing directly — curated, not aggregated.
  8. The Article 4 literacy obligation, explained A seven-stop learning path built around the EU AI Act's staff AI-literacy requirement — already in force.

The library grows as engagements surface more.

A starting scaffold, not an exhaustive register — see the resources library for what's worth reading beyond this site.