Skip to main content

AI Security & Governance Fundamentals

Wishlist Share

About Course

An accessible entry point for anyone who needs to be competent about AI risk without becoming a specialist — product managers, analysts, compliance staff, engineers new to the area, and leaders who have to approve things.

The course explains how modern AI systems actually work at the level needed to reason about their risks, then walks through the failure modes that matter, the frameworks now shaping obligations, and the controls that reduce exposure. No mathematics and no coding are required. Where a control is weaker than its marketing suggests, the course says so.

What you will learn

  • Describe how large language models and AI applications work in practical terms
  • Recognise where AI is already in use in an ordinary organisation
  • Explain the main AI failure modes in plain language
  • Understand what the EU AI Act and NIST AI RMF ask of organisations
  • Identify what data an AI feature touches and why that matters
  • Recognise prompt injection and why it is difficult to eliminate
  • Ask useful questions before an AI system is approved
  • Know when to escalate to a specialist

Course Outline

Module-1 HOW THESE SYSTEMS WORK

  • Models, training, inference and context in practical terms
  • What a model does and does not remember
  • Retrieval, tool use and agents — what changes with each
  • Exercise: describe one AI feature you use in this vocabulary

Module-2 WHERE AI ALREADY IS

  • AI arriving inside software you already own
  • Staff use of public tools, sanctioned or not
  • Procured features versus built features
  • Exercise: find three AI features in your current stack

Module-3 WHAT GOES WRONG

  • Confident wrong answers, and why fluency is not accuracy
  • Leaking information through outputs
  • Prompt injection, explained without jargon
  • Systems that can act, not only answer
  • Bias, and where it enters
  • Exercise: match five real incidents to failure modes

Module-4 THE RULES TAKING SHAPE

  • EU AI Act risk tiers and who they apply to
  • NIST AI RMF as a way of organising the work
  • How privacy law already applies to AI, today
  • Transparency, disclosure and record-keeping duties
  • Exercise: tier three use cases

Module-5 DATA, THE PART THAT MATTERS MOST

  • What data an AI feature reads, sends and stores
  • Vendor terms: training use, retention, sub-processors
  • Personal and confidential data in prompts
  • Exercise: complete a short data-flow questionnaire for one feature

Module-6 CONTROLS AND THEIR LIMITS

  • Access control, scoping and least privilege for AI features
  • Guardrails: what they catch and what they miss
  • Human review that adds value rather than delay
  • Logging and monitoring basics
  • Exercise: pick controls for a low-risk and a high-risk feature

Module-7 ASKING THE RIGHT QUESTIONS

  • A review checklist for a proposed AI feature
  • Signals that something needs specialist review
  • Documenting a decision so it can be revisited
  • Exercise: review a proposal using the checklist
Show More

Student Ratings & Reviews

No Review Yet
No Review Yet