AI Governance as a User
What AI is, where it fails, what you owe, and when to escalate. Written for anyone whose work now involves AI, whether or not that was ever in the job description. Supports the AI literacy duty that the EU AI Act places on providers and deployers, proportionate to role.
What is AI
0/1Where the boundary sits between AI and ordinary software, and why the legal definition matters more than the marketing one.
How machine learning works
0/1Training and inference, and why accuracy on a test set is not accuracy in your hands.
Generative AI and large language models
Next-token prediction, and why fluency and correctness are unrelated properties.
AI agents and automation
What changes when a model can plan, remember, call tools and act.
Where AI fails
Failure modes as a taxonomy rather than a list of anecdotes.
Bias and discrimination
How bias enters, why fairness metrics are incompatible, and what the law prohibits.
Hallucination and unreliability
Why confident fabrication is intrinsic, and the verification habits that survive deadlines.
Data protection and the privacy perimeter
What leaves your organisation when you paste into a chatbot.
Security risks
Prompt injection, data leakage, and what an attacker does to an AI feature.
Synthetic content and the rules around it
Disclosure, visible labelling and machine-readable marking as three separate duties.
When AI is used on your data
The rights an individual has when a significant decision is automated.
AI at work, and the AI you do not see
AI already embedded in the tools you use, and how features arrive by vendor update.
Explainability and transparency
What an explanation is worth, and the difference between an explanation and a justification.
High-quality prompting
Specification rather than incantation, and why long prompts are not better prompts.
The AI supervisor
Human oversight as a statutory concept, and why approving at volume is not oversight.
The escalation matrix
What to escalate, to whom, how fast, and when the reporting clock starts.
AI governance: what it means for each of us
Governance as individual duties rather than a committee's problem.
Working with an AI policy, or without one
How to read a policy for what it actually requires, and what to do when there is none.
Governance platforms and shadow AI
What these platforms do and do not do, and how unapproved use gets discovered.
AI in business and governance workflows
Where AI sits in the work, and the risk of governing an opaque system with another one.