Maria Rudneva
Dr. Maria Rudneva is an Innovation Manager at Delft University of Technology, where her work focuses on artificial intelligence, innovation, and digital transformation. Her professional lens is grounded in the practical application of AI governance and compliance, helping organizations translate fast-moving regulatory requirements into concrete, real-world system decisions rather than abstract policy statements. She specializes in applying the EU AI Act, including AI system classification, intended purpose, and provider and deployer responsibilities, and has presented on EU AI Act high-risk system classification as well as on AI tool selection and risk awareness in education settings. She also serves as a compliance assessor at ExplorAI, a conformity assessment body in formation for high-risk AI systems under the Act, with PMP and CAICO certifications providing a relevant professional anchor.
Scope, requirements and high-risk AI: managing project decisions under the EU AI Act A pilot AI tool can quietly turn into a high-risk one: a supplier tweaks a feature, users lean on it for a critical decision, and the project's compliance obligations shift without anyone noticing. Maria Rudneva shows project teams how to catch that shift early, in her session, "Scope, requirements and high-risk AI: managing project decisions under the EU AI Act". This practical, clear-eyed session explores how routine project decisions can quietly change an AI system's risk status under the EU AI Act at every level (project, product, and organizational), offering fresh perspectives and actionable insights to keep AI delivery compliant without turning project managers into legal experts. Maria walks through how AI projects that start as pilots, assistants, or "low-risk" add-ons can shift in risk level as they're integrated into larger solutions, handed to new user groups, or applied beyond their original intended purpose, and what that shift means for who is responsible under the Act. Through practical, case-based examples, she connects EU AI Act requirements directly to familiar project management practices: scope management, requirements changes, vendor discussions, risk registers, acceptance criteria, and go-live gates. Structured around Q&A and audience interaction, the session focuses on recognizing the early signals like a scope extension, a vendor feature change, a new use case, before they become late-stage compliance surprises.
Learning goals summary:
- Understand that it's not just about whether an AI system started out low-risk; it's about whether project decisions have quietly moved it into high-risk territory.
- Learn to identify when project decisions (a scope change, a new user group, an evolving use case) push an AI system into high-risk territory under the EU AI Act.
- Distinguish between provider and deployer roles, and understand how those responsibilities can shift in practice.
- Catch risk shifts early, long before they become late-stage compliance surprises.