AnyLearn
All lessons

Law & Compliance lessons & courses

14 lessons · 4 learning paths · free, quiz-checked, no signup required

Regulatory mechanics explained like engineering: AML and KYC obligations, data-protection regimes, and the institutional processes behind enforcement. What the rules require, whom they bind, and how compliance programs are actually structured.

Learning paths

Law & Compliance
advanced

Product Liability for Software: The 2024 Directive

For forty years it was arguable that software was not a product, and therefore not covered by strict liability. Directive (EU) 2024/2853 ends that argument, applies to products placed on the market from 9 December 2026, and reaches cloud services a device depends on. It also lets courts order disclosure of your evidence and presume defectiveness when complexity makes proof excessively difficult. This path follows the Directive: what is now a product, what counts as a defect, who pays for what, and how a claim is proved.

4 lessons · certificate
Law & Compliance
advanced

The EU Cyber Resilience Act: Building Products Under Product Law

From 11 September 2026, manufacturers must report actively exploited vulnerabilities in their products within 24 hours. From 11 December 2027, software and connected hardware carry a CE mark for cybersecurity. Regulation (EU) 2024/2847 places connected products under the same machinery that governs toys and lifts, and most engineering teams have never worked under product law. This path follows the Regulation itself: what it covers and whom it binds, what Annex I demands of the product and of the manufacturer, how the reporting clocks run, and what evidence survives an inspection.

4 lessons · certificate
Law & Compliance
intermediate

AI for Lawyers: Tools, Workflows, and Ethics

A practical guide to using AI in legal practice without the career-ending mistakes. Learn the landscape of legal AI tools and the risks unique to law (hallucinated citations, confidentiality), the core workflows where AI saves the most time (research, drafting, contract and document review), and how professional duties, competence, confidentiality, candor, and reasonable fees, govern responsible use. Objective, evergreen, and built around keeping the lawyer in charge.

3 lessons · certificate
Law & Compliance
advanced

AI compliance in Europe and Switzerland

The regulatory regimes an AI or fintech operator meets across the EU and Switzerland, in three lessons. Start with the data-protection foundation (GDPR and the revised Swiss FADP), move to the AI Act's risk tiers and the NIS2 security baseline, then finish with financial-sector rules: DORA operational resilience and Swiss banking secrecy. You will learn what each regime requires, whom it binds, and how a compliance program is structured.

3 lessons · certificate

All Law & Compliance lessons

Law & Compliance
advanced

Proof: Disclosure, Presumptions, and the Complexity Rule

Strict liability is worthless if the claimant cannot prove a defect they never saw. Articles 9 and 10 answer that with a disclosure order, three presumptions of defectiveness, a presumption of causation, and a rule turning complexity into the claimant's ally. This lesson works through the cascade, the three-year and ten-year clocks, and what a defendant should be able to produce.

10 steps·~15 min
Law & Compliance
advanced

Who Pays, and For What Damage

The Directive builds a chain of liable operators so an injured person in the EU always has someone to sue. This lesson covers the manufacturer and component manufacturer, the importer and fulfilment service provider route, the distributor's one-month rule, online platforms, how a modification makes you a manufacturer, the heads of damage including data loss, and the exemptions.

10 steps·~15 min
Law & Compliance
advanced

Defectiveness: The Safety a Person Is Entitled to Expect

A product is defective when it lacks the safety a person is entitled to expect. Article 7 turns that into circumstances a court weighs, several written for software: the ability to learn after release, interconnection, cybersecurity requirements, and recalls. This lesson works through the list, the rule that a later improvement is not an admission, and why compliance is not a defence.

10 steps·~15 min
Law & Compliance
advanced

Software as a Product: What the New Liability Directive Changed

Directive (EU) 2024/2853 replaces the 1985 regime and settles a forty-year argument by naming software a product. This lesson covers the new definition and why delivery method is irrelevant, why information is not a product, how components and related services extend the net, where open source sits, and why liability cannot be disclaimed by contract.

10 steps·~15 min
Law & Compliance
advanced

Proving It: Conformity Routes, Documentation, and Enforcement

Meeting the essential requirements is not the same as being able to show it. This lesson covers the Annex VIII modules and which one each tier allows, the harmonised-standards lever that keeps class I self-assessable, the public-documentation route open to open-source manufacturers, what Annex VII must contain, when a modification restarts the assessment, and the three penalty tiers.

11 steps·~17 min
Law & Compliance
advanced

Reporting Under Article 14: The 24, 72 and 14-Day Clocks

Article 14 is the first Cyber Resilience Act duty to bite, and it reaches products already on the market. This lesson covers the two narrow triggers, who receives a report and through which platform, what each of the three stages must contain, the separate duty to tell users, where the clock starts and why that is the hard part, and how the cascade compares with NIS2, GDPR and DORA.

10 steps·~15 min
Law & Compliance
advanced

Annex I: The Product Properties and the Processes Behind Them

Annex I is two lists doing different jobs: thirteen properties the product must have, and eight things the manufacturer must keep doing. This lesson works through both, including the secure-by-default and automatic-update rules, what the software bill of materials clause actually demands, the five-year support period floor and the ten-year shelf life on each update, and what must reach the user.

11 steps·~17 min
Law & Compliance
advanced

The Cyber Resilience Act: What It Covers and Who It Binds

Regulation (EU) 2024/2847 puts software and connected hardware under product safety law, with a CE mark for cybersecurity. This lesson sets the scope: what counts as a product with digital elements, why a cloud backend can be part of one, what sector law carves out, where open source and stewards sit, the four risk tiers from Annex III and IV, and how a reseller becomes a manufacturer.

11 steps·~17 min
Law & Compliance
intermediate

Using AI Ethically in Law: Duties and Safeguards

For lawyers, AI is not just a productivity question but an ethics question. Learn how professional duties, competence, confidentiality, candor to the court, and reasonable fees, apply to AI use, why bar authorities now issue formal guidance on it, how to vet a tool and supervise its output, and how to build a simple responsible-AI policy that keeps you on the right side of your obligations.

7 steps·~11 min
Law & Compliance
intermediate

AI for Legal Research, Drafting, and Contract Review

A practical guide to the legal workflows where AI saves the most time. Learn how to run AI-assisted legal research and verify it, draft contracts and letters from strong prompts and firm precedents, review contracts to flag risks at scale, and triage large document sets, with the human-in-the-loop discipline that keeps every output reliable.

7 steps·~11 min
Law & Compliance
intermediate

How AI Is Changing Legal Work: Tools and Risks

AI is reshaping how lawyers research, draft, and review, but it carries a career-ending risk unique to law: confidently invented case law. Learn the main categories of legal AI tools and what each actually does, the difference between general and law-specific systems, and why hallucination and confidentiality make verification non-negotiable for every lawyer.

7 steps·~11 min
Law & Compliance
advanced

DORA and Swiss Banking Secrecy: Two Regimes, Two Jobs

The EU Digital Operational Resilience Act governs how financial entities withstand ICT disruptions, while Article 47 of the Swiss Banking Act is a criminal confidentiality duty over client data. This advanced lesson dissects both mechanisms, their exceptions, and why an institution can fall under both at once.

11 steps·~17 min
Law & Compliance
advanced

The EU AI Act and NIS2: Risk Tiers and Cyber Baselines

Map how the EU AI Act sorts systems into four risk tiers with matching duties, and how NIS2 sets a horizontal cybersecurity baseline with strict reporting clocks. Learn who each rule binds and how compliance is structured.

12 steps·~18 min
Law & Compliance
intermediate

Data Protection Under the EU GDPR and the Revised Swiss FADP

Learn how the EU GDPR and the revised Swiss Federal Act on Data Protection actually work: who they bind, when they apply across borders, the lawful bases and rights they create, and how enforcement and sanctions differ between the two regimes.

11 steps·~17 min