The learning path

Stage 1: First principles

What AI actually is, how it is built, and why it needs governing.

  • What Is AI? From Rules to Reasoning Machines — The working definitions of AI that laws actually use, how machines learn, why generative AI changed everything, and what these systems still cannot do.
  • The AI Lifecycle: From Data to Deployment to Retirement — The seven stages every AI system passes through, what can go wrong at each one, the supply chain behind every model, and where governance controls actually attach.
  • Why AI Needs Governance: A Taxonomy of Harms and Risks — The documented ways AI systems hurt people — bias, privacy invasion, safety failures, security exploits, information pollution, manipulation, and systemic risks — organised into the taxonomy that risk-assessment work is built on, with the real cases behind each category.
  • How AI Governance Works: Laws, Standards, and Everything Between — The instruments of AI governance and how to tell them apart: hard law versus soft law, horizontal versus sectoral regulation, risk-based versus rights-based philosophies, the regulatory toolbox, how to read statutes and standards, and an orientation tour of the three pillars — the EU AI Act, NIST AI RMF, and ISO/IEC 42001.

Stage 2: Principles, people, and history

The ethics vocabulary, the cast of actors, and how we got here.

  • Core Ethics Principles and Trustworthy AI — The canonical principles — fairness, transparency, explainability, accountability, privacy, safety and robustness, human oversight — where they came from (OECD, UNESCO, EU HLEG), how NIST turns them into trustworthiness characteristics, why fairness definitions mathematically conflict, and what it takes to move from principles to practice.
  • Who’s Who in AI Governance: Actors, Roles, and Responsibilities — The cast of AI governance — providers, deployers, regulators, standards bodies, auditors, safety institutes, civil society — who owes what to whom, and where you fit in.
  • From Asimov to the AI Act: A History of AI Governance — Eight decades in five eras: from fictional robot laws through privacy statutes, algorithmic scandals, and principle declarations to binding law — and the recurring patterns that let you predict what happens next.

Stage 3: The three pillars

NIST AI RMF, the ISO standards stack, and the EU AI Act — plus the soft law connecting them.

  • NIST AI RMF Deep Dive: Govern, Map, Measure, Manage — The voluntary framework that became America’s de facto AI governance standard: where it came from, how risk and the seven trustworthiness characteristics actually work, every category of the four functions, profiles and the Playbook, the ISO 42001 and EU AI Act crosswalk, and why a non-binding document keeps showing up in statutes and courtrooms.
  • Generative AI Risks and Bias: NIST-AI-600-1 and SP 1270 — NIST’s two most consequential companion documents: the Generative AI Profile’s twelve risk categories with the real incidents behind them, how its suggested actions plug into the RMF functions, and SP 1270’s socio-technical account of bias — systemic, statistical, and human-cognitive — with the fairness math and the state laws it prefigured.
  • The AI Standards Landscape and Core Terminology (ISO/IEC 22989) — Who writes AI standards and why they matter, how to read IS/TS/TR labels and shall/should language, the Harmonized Structure behind every management system standard, and the ISO/IEC 22989 vocabulary the whole ecosystem is built on.
  • ISO/IEC 42001 Clause by Clause: Building the AI Management System — The world’s first certifiable AI management system standard, taken apart clause by clause: context and role determination, leadership and the AI policy, risk and impact assessment planning, support and operation, performance evaluation, and improvement — mapped onto the PDCA cycle.
  • Annex A Controls and Annexes B, C, D: The Control Framework — The 38 controls in nine groupings that give ISO/IEC 42001 its teeth: what each control grouping demands, how Annex B guidance turns requirements into practice, how Annex C objectives and risk sources seed your risk assessment, and how to build a defensible Statement of Applicability.
  • AI Risk Management and Impact Assessment: ISO/IEC 23894 and 42005 — How ISO 31000’s risk architecture becomes AI-specific through ISO/IEC 23894, how ISO/IEC 42005:2025 turns impact assessment into a repeatable method, and how the two disciplines — organisational-risk lens and affected-party lens — interlock inside the AIMS and alongside DPIAs and FRIAs.
  • Trustworthiness, Bias, and AI Quality: The TR Series and 25059 — The informative layer of the SC 42 ecosystem: ISO/IEC TR 24028’s trustworthiness attributes and threat catalogue, TR 24027’s bias taxonomy, TR 24368’s ethics themes, and the ISO/IEC 25059 quality model — and how non-certifiable guidance becomes concrete AIMS objectives, controls, and metrics.
  • The EU AI Act at a Glance: Purpose, Scope, and the Risk Pyramid — Why the world’s first comprehensive AI law exists, how its four-tier risk pyramid and parallel GPAI track work, who it reaches (including outside Europe), and the staged timeline on which its obligations bite.
  • Prohibited AI Practices: The Unacceptable Tier — The eight practices Article 5 bans outright — manipulation, exploitation, social scoring, predictive policing, face-scraping, emotion recognition, biometric categorisation, and real-time biometric identification — their exceptions, the RBI authorization machinery, and where the line to high-risk actually runs.
  • High-Risk Classification: Art 6, Annexes I & III, and the Filter — The two independent routes into the high-risk tier, all eight Annex III areas with their carve-outs, and the Art 6(3) filter — including the profiling tripwire that no derogation escapes.
  • Inside the High-Risk Rulebook: Arts 8–15 Article by Article — The seven substantive requirements every high-risk system must meet — risk management, data governance, documentation, logging, transparency, human oversight, and robustness — with the evidence each demands and the ISO 42001 / NIST RMF crosswalk.
  • The Value Chain: Providers, Deployers, Importers, Distributors — Who owes what along the AI value chain — the Art 16 provider checklist, importer and distributor gatekeeping, the Art 25 role-switch traps, deployer duties under Art 26, and the fundamental rights impact assessment.
  • Transparency and General-Purpose AI: Art 50 and the GPAI Chapter — The four disclosure duties of Art 50, machine-readable marking of synthetic content, and the GPAI model regime — Art 53 baseline duties, the 10²⁵ FLOPs systemic-risk trigger, Art 55 safety duties, and the Code of Practice.
  • Global Soft Law: OECD, UNESCO, and the G7 Hiroshima Process — The machinery behind the world’s non-binding AI rulebook: how the OECD built the evidence hub, how UNESCO turned ethics into assessment tools that governments actually run, how the G7 answered ChatGPT in months — and how soft law quietly writes tomorrow’s statutes.

Stage 4: Binding law, jurisdiction by jurisdiction

US federal and state law, China, Asia-Pacific, and the privacy/IP foundations underneath.

  • Privacy and Data Protection Law for AI: GDPR from Scratch — The data protection law every AI governance framework silently assumes you know: GDPR lawful bases, controller and processor roles, data-subject rights, Article 22 automated decision-making, DPIAs, international transfers — plus the EDPB’s AI rulings and the American answer in CCPA/CPRA and California’s ADMT regulations.
  • The Federal Posture: Executive Orders, OMB, and the Preemption Fight — How US federal AI policy actually works when Congress won’t legislate: the whiplash from EO 14110 to EO 14179, America’s AI Action Plan and its companion orders, the OMB memos that run agency AI, the escalating war over state-law preemption, and how to plan compliance inside a policy regime that can reverse itself in a single afternoon.
  • Sectoral Enforcement: FTC, EEOC, CFPB, FDA, and Financial Regulators — How AI actually gets policed in America without an AI statute: the FTC’s deception and unfairness playbook and the delete-your-model remedy, Title VII and ECOA applied to algorithms, FDA’s lifecycle regime for adaptive medical devices, SR 11-7 as the original model-risk framework, and the map of which enforcer reaches which harm.
  • State AI Laws in Depth: Colorado, California, Texas, Illinois, NYC, and Beyond — The real AI law of the United States is state law. Colorado’s repeal-and-replace saga, California’s four-statute stack, Texas TRAIGA’s intent-based prohibitions, Illinois and NYC on hiring algorithms, Utah’s disclosure regime, New York’s RAISE Act — and the ten patterns that let you read any new state bill in five minutes.
  • China: The World’s Most Developed Binding AI Rulebook — How China built the world’s densest stack of binding AI rules — algorithm filing, deepfake consent, generative-AI licensing-in-all-but-name, and mandatory content labeling — and what its vertical, iterative playbook means next to the EU’s horizontal one.
  • Asia-Pacific: Japan, South Korea, Singapore, India, and Australia — Five democracies, five different answers: Korea’s AI Basic Act — the world’s second horizontal AI statute — beside Japan’s no-penalty promotion law, Singapore’s testing toolkit, India’s labeling rules, and Australia’s bet on existing law.
  • The UK, Canada, Brazil — and the Missing Map: Africa, the Middle East, Latin America — Three democracies that promised AI laws and stalled — the UK’s regulator-led experiment, Canada’s dead bill, Brazil’s bicameral grind — then the map most curricula skip: the African Union’s continental strategy, Gulf-state ambition, Latin America beyond Brazil, and the data workers who make frontier AI possible.
  • The United Nations and the Treaty Track: Global Digital Compact and the CoE Convention — How AI governance reached the UN General Assembly — dueling consensus resolutions, the Global Digital Compact, an IPCC-style Scientific Panel co-chaired by Yoshua Bengio and Maria Ressa — and how the Council of Europe wrote the first binding AI treaty, plus the ratification mechanics that decide when a treaty actually bites.
  • AI and Intellectual Property: Training Data, Outputs, and the Litigation Wave — The copyright wars over training data — NYT v. OpenAI, Thomson Reuters v. Ross, Getty v. Stability — plus fair use factor by factor, the EU/Japan/UK text-and-data-mining exceptions, who owns AI outputs after Thaler, voice and likeness rights after the ELVIS Act, and the collision between trade secrets and transparency mandates.
  • Biometric Surveillance, Law Enforcement AI, and Protecting Children — Facial recognition in policing and its wrongful-arrest record, predictive policing and border AI, the BIPA litigation machine, and the fast-hardening law of children online: age assurance, design codes, companion chatbots, and CSAM/NCII regimes.
  • Sector by Sector: Health, Employment, Finance, Education, and Vehicles — How five regulated sectors actually govern AI: FDA clearances and the MDR interplay in healthcare, algorithmic management and the Platform Work Directive at work, SR 11-7 and insurance rules in finance, proctoring and UNESCO guidance in education, and the UNECE/NHTSA split on automated vehicles.

Stage 5: Governance in practice

Programs, assessments, testing, monitoring, incidents — tying every control to the law it satisfies.

  • Designing the AI Governance Operating Model — How to turn AI principles into working machinery: program sequencing and maturity, centralized vs hub-and-spoke structures, committee and CAIO design, three lines of defense, RACI discipline, policy architecture, metrics, and the culture that makes any of it real.
  • The AI Center of Excellence: Organizing for AI Adoption — The organizational delivery vehicle for AI adoption: what the cloud CoE story teaches, the dual enable-and-govern mandate, three operating models and when to migrate between them, the team, the intake-to-production machinery, the artifact library, and a first-year roadmap that ends with the center making itself less necessary.
  • AI Inventory, Use-Case Intake, and Risk Triage — Step zero of every governance program: finding the AI you already have — including the shadow and embedded kind — building a registry that stays true, designing proportionate intake, and triaging every use case to a risk tier mapped to the laws that bite.
  • AI Risk and Impact Assessment Methodologies — How practitioners actually run AI assessments: the taxonomy of instruments (AIA, DPIA, FRIA, validation), Canada’s scored AIA, GDPR and AI Act triggers, severity scoring and its critiques, residual-risk sign-off, and how to run one assessment machine instead of five.
  • Data Governance and Documentation Artifacts for AI — Provenance and lineage, lawful and licensed training data, synthetic data and the unlearning problem, and the documentation stack — datasheets, model cards, system cards, and the regulator-facing tech file — with a map of who writes what, when, and which law demands it.
  • Testing and Evaluation: Fairness Math, Red-Teaming, and Explainability — The technical core of AI assurance: where bias enters, the fairness metrics and their impossibility results in full detail, disparate-impact math and bias audits, benchmarks and red-teaming, and the explainability toolkit — SHAP, LIME, counterfactuals — matched to the audiences governance must serve.
  • Human Oversight, Post-Deployment Monitoring, and Incident Response — What happens after launch: designing human oversight that actually works, catching drift before it becomes harm, governing model changes and logs, running AI incident response against real regulatory clocks, and learning from the world’s incident databases.
  • Third-Party AI, Generative AI, Agentic AI, and Frontier Governance — Governing the AI you did not build: vendor due diligence and the contract clauses that actually matter, generative AI controls from acceptable use to prompt injection, agentic AI permissioning and action logging, and how to read frontier safety frameworks as an enterprise buyer.
  • Guardrails in the Cloud: Implementing Controls on AWS, Azure, and GCP — How legal obligations become running configuration: the enterprise LLM gateway pattern, Amazon Bedrock Guardrails, Azure AI Content Safety and the Foundry stack, the Vertex AI safety stack — and how to map every control back to the audit.
  • The GenAI Security Scoping Matrix: Know What You’re Securing — AWS’s Generative AI Security Scoping Matrix turns one hard question — what exactly are we securing? — into five workload scopes and five security disciplines. Learn to place any genAI use case on the buy-to-build spectrum and read off what governance, legal, risk, controls, and resilience demand at that position.
  • The Generative AI Lens: AWS Well-Architected for GenAI — How to run a Well-Architected review on a generative AI workload: the six pillars through AWS’s GenAI lens, the GENOPS-to-GENSUS best-practice grammar, and how the review’s findings map onto ISO/IEC 42001, NIST AI RMF, and your guardrail stack.
  • The Responsible AI Lens: Well-Architected for Trustworthy AI — How to interrogate a single AI use case with AWS’s Responsible AI Lens: ten dimensions of responsible AI, eight lifecycle focus areas from use case to decommissioning, the RAIUC-to-RAIMON best-practice grammar, and how release criteria, system cards, and monitoring evidence map onto ISO/IEC 42001, NIST AI RMF, and the EU AI Act.
  • Compute Governance, Export Controls, and the Science of AI Safety — Why chips became the chokepoint of AI policy: the US–China export-control arc from October 2022 to the Diffusion Rule and its rescission, compute thresholds as legal triggers, cloud KYC, and data-center politics — then the safety science a governance expert must be able to interrogate: alignment, dangerous-capability evals and their limits, interpretability, and safety cases.
  • AI, Elections, Labor, Competition, and the Planet — The societal frontiers where AI governance is being invented case by case: synthetic media and election law, algorithmic collusion and foundation-model antitrust, algorithmic management and labor policy, the environmental governance of compute, business-and-human-rights due diligence, and the military AI debate.

Stage 6: Expert synthesis

Certification audits, board governance, and cross-jurisdiction capstones.

  • Conformity Assessment, Standards, CE Marking, and Post-Market Duties — How a high-risk AI system actually gets to market: harmonized standards and presumptions of conformity, the Article 43 assessment routes, notified bodies and certificates, Annex IV documentation, the CE mark and EU database — and the post-market monitoring and serious-incident clocks that never stop running.
  • Governance, Enforcement, Penalties, and Sandboxes — Who actually runs the AI Act — the AI Office, the Board, and national market surveillance authorities — how enforcement escalates from evaluation to Union-wide safeguard, what individuals can claim under Articles 85–87, the three-tier penalty regime, the sandbox and real-world-testing machinery, and how the Act meshes with GDPR, DSA, product liability, and the Digital Omnibus.
  • Board-Level AI Governance: ISO/IEC 38507 and Organizational Accountability — What governing bodies — not engineers — must do about AI: the ISO/IEC 38500 Evaluate–Direct–Monitor model, how ISO/IEC 38507 adapts it for AI, risk appetite and policy cascades, three lines of defense, board reporting, and the accountability that no board can delegate to a vendor or an algorithm.
  • Certification, Audit, and Integrated Management Systems: ISO/IEC 42006 — How a 42001 certificate actually gets made: the accreditation chain from IAF to your auditor, what ISO/IEC 42006:2025 demands of certification bodies, the Stage 1/Stage 2 journey and the three-year cycle, how findings are classified and closed, and how to run one integrated management system across 42001, 27001, 27701, and 9001.
  • The EU AI Act Interface: Harmonized Standards and the 42001 Playbook — Where voluntary standards meet binding law: how the New Legislative Framework turns harmonised standards into a presumption of conformity, what CEN-CLC/JTC 21 is actually delivering (and how late), what the 2026 AI Omnibus did to the high-risk clock, how 42001 maps — and fails to map — onto Articles 9–15 and 17, and a 12-step playbook for building an AIMS that is ready for both regimes.
  • Lead Implementer Track: Building an AIMS from Mandate to Certificate — The practitioner playbook for taking an organisation from “we should govern AI” to an accredited ISO/IEC 42001 certificate: winning the mandate, scoping and gap analysis, planning artifacts that survive audit, operating the system without drowning in paper, internal audit and management review as steering instruments, and running the certification project itself.
  • Lead Auditor Track: Auditing an AIMS with ISO 19011 Discipline — The other side of the audit table: what a Lead Auditor credential actually attests, the ISO 19011 principles that make findings defensible, how to plan and staff an AI audit, interview and sample like a professional, write nonconformities that survive challenge, and evaluate corrective action without crossing the consultancy line.
  • Capstone: Building and Defending a US AI Compliance Program — One company, one multistate deployment, worked end to end: build the program on the NIST RMF spine, crosswalk one control set to ten regimes, run an LL144-grade bias audit, survive an incident with three regulator clocks running, and defend it all — privilege, cure periods, RMF defenses, and preemption scenario planning included.
  • Legal Intersections, Liability, and the Failure Files — Where AI governance meets the courtroom: GDPR Article 22 and the SCHUFA doctrine, the liability regimes that decide who pays when AI fails, and the forensic post-mortems — COMPAS, Amazon, the toeslagenaffaire, Clearview, Air Canada, NEDA Tessa — each traced to the control that would have caught it.
  • Summits, Safety Institutes, and Comparing Regimes Like a Pro — The analytic capstone of the global domain: the summit series from Bletchley to Delhi and what its renames reveal, the safety-institute network and its politics, the four axes that let you compare any two regimes in ninety seconds, and the multinational compliance playbook that turns comparison into strategy.

Stage 7: The AIGP overlay

Exam-weighted recaps and full mock exams for the IAPP AIGP credential.