AI Security & Governance Fundamentals
About Course
An accessible entry point for anyone who needs to be competent about AI risk without becoming a specialist — product managers, analysts, compliance staff, engineers new to the area, and leaders who have to approve things.
The course explains how modern AI systems actually work at the level needed to reason about their risks, then walks through the failure modes that matter, the frameworks now shaping obligations, and the controls that reduce exposure. No mathematics and no coding are required. Where a control is weaker than its marketing suggests, the course says so.
What you will learn
- Describe how large language models and AI applications work in practical terms
- Recognise where AI is already in use in an ordinary organisation
- Explain the main AI failure modes in plain language
- Understand what the EU AI Act and NIST AI RMF ask of organisations
- Identify what data an AI feature touches and why that matters
- Recognise prompt injection and why it is difficult to eliminate
- Ask useful questions before an AI system is approved
- Know when to escalate to a specialist
Course Outline
Module-1 HOW THESE SYSTEMS WORK
- Models, training, inference and context in practical terms
- What a model does and does not remember
- Retrieval, tool use and agents — what changes with each
- Exercise: describe one AI feature you use in this vocabulary
Module-2 WHERE AI ALREADY IS
- AI arriving inside software you already own
- Staff use of public tools, sanctioned or not
- Procured features versus built features
- Exercise: find three AI features in your current stack
Module-3 WHAT GOES WRONG
- Confident wrong answers, and why fluency is not accuracy
- Leaking information through outputs
- Prompt injection, explained without jargon
- Systems that can act, not only answer
- Bias, and where it enters
- Exercise: match five real incidents to failure modes
Module-4 THE RULES TAKING SHAPE
- EU AI Act risk tiers and who they apply to
- NIST AI RMF as a way of organising the work
- How privacy law already applies to AI, today
- Transparency, disclosure and record-keeping duties
- Exercise: tier three use cases
Module-5 DATA, THE PART THAT MATTERS MOST
- What data an AI feature reads, sends and stores
- Vendor terms: training use, retention, sub-processors
- Personal and confidential data in prompts
- Exercise: complete a short data-flow questionnaire for one feature
Module-6 CONTROLS AND THEIR LIMITS
- Access control, scoping and least privilege for AI features
- Guardrails: what they catch and what they miss
- Human review that adds value rather than delay
- Logging and monitoring basics
- Exercise: pick controls for a low-risk and a high-risk feature
Module-7 ASKING THE RIGHT QUESTIONS
- A review checklist for a proposed AI feature
- Signals that something needs specialist review
- Documenting a decision so it can be revisited
- Exercise: review a proposal using the checklist
Student Ratings & Reviews
No Review Yet