1. Why AI needs governing
The risk categories that matter
You don't need an exhaustive risk register to govern AI sensibly. Most of what can go wrong falls into six categories, and knowing them lets you ask the right questions about any proposed use.
Confidentiality leakage
Client data, personal data, or commercially sensitive information entered into tools whose data handling terms don't protect it. This is the most immediate risk for most small firms and the one most likely to damage a client relationship.
Inaccuracy and hallucination in decisions
AI output that is confidently wrong. The organisational version of this risk is worse than the individual one: an unverified figure or invented citation that enters a report, a quote, or a decision-making process can propagate a long way before anyone catches it.
Bias and discrimination
Models can reproduce biased patterns from their training data. Where AI touches decisions about people, recruitment, performance, credit, customer treatment, the organisation carries the discrimination risk, and UK equality law doesn't stop applying because software was involved.
IP and copyright
Two directions. Your material going in: uploading content you don't have the right to share. AI content coming out: generated text or images may raise questions about ownership and originality, and purely AI-generated work has an uncertain copyright position. Check what your vendor commits to on this.
Over-reliance and deskilling
If juniors never draft from scratch and reviewers stop reading critically because "the AI is usually right", the organisation slowly loses the expertise it needs to check the AI at all. This one is quiet, cumulative, and easy to miss.
Vendor lock-in
Building workflows around one provider's tool, pricing, and data formats without an exit plan. The AI market moves fast; the ability to switch is worth protecting.
› Course contents
Why AI needs governing
The regulatory landscape
Building your AI policy and approving tools
Running AI day to day
Putting it into practice