- AIadvanced
The LLM Threat Model: Why the Model Cannot Defend Itself
Guardrails exist because a language model cannot reliably distinguish instructions from data. This lesson builds the threat model: the OWASP Top 10 for LLM Applications, direct and indirect prompt injection, jailbreaks, data leakage, and why tool-using agents turn a content problem into a security one.
9 steps·~14 min - Businessintermediate
The Competencies: What You Need to Know, and How Deep
AI governance sits at the intersection of four competency areas, and almost nobody arrives holding all of them. This lesson sets out what each requires and how deep it must go: regulatory literacy, enough technical understanding to ask the right questions, assurance discipline, and the organisational skill the function runs on. It closes on certifications and what they are worth.
9 steps·~14 min - Businessintermediate
The AI Governance Function: What the Work Is and Who Does It
AI governance is a body of work before it is a job title, and most of it is done by people whose title says something else. This lesson sets out what the work consists of, how it splits across legal, risk, data protection and engineering, why a dedicated role appears at some scales and not others, and what the data protection officer precedent does and does not tell you.
9 steps·~14 min - Businessintermediate
Doing the Work: Artefacts, Evidence, and Getting In
Nobody hires for AI governance on the strength of a certificate. This lesson covers what to actually produce: the four artefacts that demonstrate competence, how to build them from work already available inside your current job, routes in from each adjacent profession, what the first ninety days look like, and an honest account of the parts of this work that are unpleasant.
9 steps·~14 min - Businessintermediate
Contracts, Ongoing Management, and Exit
The contract is where a deployer's leverage lives, because almost every duty you hold depends on information the provider controls. This lesson covers the clauses that matter for AI, allocating AI Act obligations between the parties, change notification and substantial modification, monitoring a live system for drift, incident cooperation, and designing an exit before you need one.
10 steps·~15 min - Businessintermediate
Diligence and Evaluation: Testing the Claim
Vendor claims are marketing until you test them. This lesson covers the diligence pack worth requesting, why the instructions for use are the single most valuable document in a high-risk purchase, questions about model provenance and the AI-specific attack surface, designing a pilot that can actually fail, shadow-mode evaluation, and the red flags that should end a procurement early.
9 steps·~14 min - Businessintermediate
What You Are Actually Buying: Scoping an AI Purchase
AI procurement fails at the scoping stage, before any vendor is contacted. This lesson covers what makes an AI purchase different from ordinary software, the regulatory position you inherit from the seller, the questions that determine whether you become a provider yourself, how to specify a problem rather than a product, and the build-buy-or-do-nothing decision that should precede any shortlist.
10 steps·~15 min - Businessadvanced
Conformity Assessment, CE Marking, and Life After Launch
A high-risk system reaches the market through a defined gate and stays there under continuing obligations. This lesson covers which conformity assessment procedure applies and when a notified body is involved, the declaration of conformity and CE marking, registration, substantial modification and reassessment, post-market monitoring, and serious incident reporting with its tiered deadlines.
10 steps·~15 min - Businessadvanced
What a High-Risk System Must Actually Do
Once a system is high-risk, Articles 8 to 15 set out what it must satisfy. This lesson works through them as engineering requirements rather than legal text: risk management as a continuous process, data governance including the 2026 change on special category data for bias detection, human oversight as a design property, accuracy and robustness, and transparency toward the deployer.
10 steps·~15 min - Businessadvanced
Classifying a High-Risk AI System: Annex I, Annex III, and the Derogation
High-risk classification determines whether an organisation faces a substantial compliance programme or almost none. This lesson works through both routes: the Annex I product-safety route as narrowed in 2026, the eight Annex III use-case areas with the boundaries that get argued, and the Article 6(3) derogation, its conditions, and the assessment you must document to rely on it.
10 steps·~15 min - Businessintermediate
Technical Documentation and the Evidence Trail
Governance that leaves no trace is indistinguishable from no governance. This lesson covers the documentation the AI Act requires: Annex IV technical documentation and its simplified SME forms, the quality management system, instructions for use, log retention, the fundamental rights impact assessment, registration, and how to make documentation a byproduct.
10 steps·~15 min - Businessintermediate
Policy, Decision Rights, and the AI Risk Register
With an inventory in place, governance becomes a question of who decides what. This lesson covers the AI policy and what actually belongs in it, acceptable-use rules people can follow, decision rights mapped with RACI, the approval gate a new system passes through, an AI risk register with risks specific to these systems, and escalation that works when something goes wrong at eleven at night.
10 steps·~15 min - Businessintermediate
The Foundation: AI Inventory, Classification, and Ownership
An AI governance framework that starts with a policy is built on nothing. This lesson covers the artefact everything else depends on: finding the AI systems you actually run, including the ones inside software nobody bought as AI, recording the fields that make the inventory usable, classifying each system, assigning real ownership, and binding the whole thing to triggers so it stays true.
10 steps·~15 min - Businessbeginner
The Proportionate Path: Compliance Without a Legal Department
There is no small-business exemption in the AI Act, but there is proportionality, and the 2026 Omnibus widened it. This lesson covers the simplifications for SMEs and the new small mid-cap category, the minimum defensible position for a deployer, how to sequence work against the amended deadlines, where GDPR work can be reused, and when you genuinely need a lawyer.
9 steps·~14 min - Businessintermediate
Risk Tiers and the Amended Compliance Timeline
The AI Act sorts systems into four tiers by what they are used for, not by how sophisticated they are. This lesson covers prohibited practices, the two routes into the high-risk tier, the derogation that lets a listed system out, the transparency duties, and the timeline as amended by the 2026 Digital Omnibus: which dates moved, which did not, and how grandfathering works.
10 steps·~15 min - Businessbeginner
The EU AI Act: What It Covers and Which Role You Hold
Before any obligation applies, two questions decide everything: is this an AI system under the Act, and what role does your organisation hold in relation to it? This lesson covers the definition of an AI system, the provider, deployer, importer and distributor roles, the acts that turn a deployer into a provider, the Act's reach beyond the EU, and what falls outside it entirely.
10 steps·~15 min - Businessintermediate
Delivering AI Literacy: Keeping It Current and Showing Your Work
A designed program still has to be delivered, kept current as tools change, and documented well enough to show what you did. This lesson covers delivery formats and why attaching training to tool rollout beats annual campaigns, measurement that is useful rather than required, the records that constitute evidence, refresh triggers, and an honest account of what an AI literacy program cannot fix.
9 steps·~14 min - Businessintermediate
Designing an AI Literacy Program: Inventory, Tiers, and Curriculum
A single company-wide e-learning module satisfies nobody and teaches almost no one. This lesson turns the AI Act's own factors into a design method: inventory the AI systems actually in use, segment the population by what they do with them, and build a layered curriculum from a universal baseline through role-specific modules to high-risk operator training, with the content that belongs in each.
10 steps·~15 min - Businessintermediate
AI Literacy and What the EU AI Act Actually Requires
AI literacy has a legal definition in the EU AI Act, and the obligation attached to it changed in 2026. This lesson covers Article 3(56), the original Article 4 duty to ensure a sufficient level of literacy, how the Digital Omnibus reframed it as an obligation of effort rather than result, who is bound, which AI systems are in scope, and the adjacent duties that remain hard requirements.
10 steps·~15 min - Businessintermediate
The Write Path: Capturing Knowledge and Earning Trust
Retrieval solved the read side, so the constraint moved to what gets written down. This lesson covers the capture write path: architecture decision records, docs-as-code, change-triggered updates, and making capture cheap enough to survive. Then how to evaluate a company brain with golden questions, groundedness, and a permission regression suite, plus the failure modes that end these projects.
10 steps·~15 min - Businessintermediate
Company Brain Architecture: Connectors, Permissions, and Freshness
The hard parts of an internal knowledge system are not the ones a public RAG tutorial covers. This lesson builds the architecture: connectors and the ingestion path, the permission problem and why early binding beats late binding, oversharing inherited from your existing access control, entity resolution across silos, and the staleness and conflicting-truth problems that break internal corpora.
11 steps·~17 min - Businessintermediate
Institutional Memory: Why Companies Forget What They Know
Before building a company brain, understand the problem it inherits. This lesson covers explicit versus tacit knowledge, Nonaka's SECI spiral, why the 1990s knowledge-management wave left rotting repositories behind, and what retrieval and LLMs genuinely changed. The answer is precise: they collapsed the cost of reading, and did nothing at all about the cost of writing.
10 steps·~15 min - AIadvanced
LIME and SHAP: Attributing a Single Prediction
Two methods dominate local explanation, and both perturb the input. LIME fits a small interpretable model near one prediction. SHAP borrows the Shapley value from game theory and is the unique attribution satisfying local accuracy, missingness and consistency. This lesson builds both mechanisms, compares KernelSHAP with TreeSHAP, and is precise about what a SHAP value does not mean.
11 steps·~17 min - AIintermediate
Explainable AI: The Landscape of Model Explanations
A model that predicts well can still be impossible to justify. This lesson maps explainable AI: interpretable-by-design versus post-hoc, global versus local, model-specific versus model-agnostic. It covers the global workhorses (permutation importance, partial dependence, ICE), faithfulness versus plausibility, and the argument that post-hoc explanation is the wrong tool for high-stakes decisions.
11 steps·~17 min

