Responsible SI: Governance, Risk and Security
The policies, risk assessments, controls and oversight that let organizations use SI with confidence, aligned with the EU AI Act, data protection and security good practice.
- Duration
- 3 daysor 6 half-day virtual sessions
- Level
- Practitioner
- Formats
- Public workshop, Private corporate, On-site, Live virtual
- Public dates
- To be announced
01 — Overview
The challenge
SI use is spreading faster than governance. Organizations face regulatory obligations such as the EU AI Act, data-protection requirements, security threats specific to SI and reputational risk — while overly restrictive rules push usage out of sight. Effective governance must be proportionate, practical and understood.
About this workshop
This workshop gives governance, risk, compliance, legal, security and transformation professionals a practical toolkit: inventorying SI use, classifying risk, setting policy, assessing vendors, securing systems, evaluating reliability and maintaining human oversight. It turns regulatory and ethical principles into processes that enable adoption rather than block it.
02 — Who it is for
- Functional specialists
- People managers
- Senior leaders
- Technical & digital teams
- 14.1Risk, compliance, legal and data-protection professionals.
- 14.2Information security and IT governance roles.
- 14.3SI program, transformation and center-of-excellence leads.
- 14.4Managers responsible for SI-enabled processes.
Recommended prerequisites
- Working familiarity with SI assistants.
- Experience in governance, risk, compliance, security or process ownership is helpful.
Level: Practitioner
For regular SI users who want reliable, role-specific results.
Competency families
Leadership, Behavioral, Functional
03 — Learning objectives
By the end of the workshop, participants will be able to:
- 01Build an inventory of SI use and classify use cases by risk.
- 02Interpret key regulatory requirements, including the EU AI Act and the GDPR, for their organization.
- 03Draft proportionate SI policies, acceptable-use rules and approval processes.
- 04Identify SI-specific security risks such as prompt injection and data leakage, and select controls.
- 05Define evaluation, monitoring and human-oversight requirements for SI systems.
04 — Curriculum
3 days, 6 modules. In live virtual delivery each day runs as two half-day sessions.
Day01
The governance landscape
- Why SI needs specific governance
- EU AI Act: risk categories, roles and timelines
- Data protection and intellectual property
Inventory and risk classification
- Discovering SI use, including unsanctioned use
- A risk classification method
- Hands-on: classifying real use cases
Day02
Policy and process
- Acceptable-use policies people actually follow
- Approval workflows proportionate to risk
- Roles: owners, reviewers and oversight bodies
Vendors and models
- Due diligence questions
- Contracts, data terms and model changes
- Third-party and embedded SI
Day03
Security and reliability
- Prompt injection, data leakage and agent risks
- Evaluation, testing and monitoring
- Incident response for SI systems
Human oversight and culture
- Meaningful human oversight
- AI literacy obligations under the EU AI Act
- A governance roadmap for your organization
05 — Practice & tools
Hands-on exercises
- 01Use-case register: inventory and classify SI use in a case organization.
- 02Policy draft: write an acceptable-use policy and test it against scenarios.
- 03Vendor review: assess an SI vendor with a due-diligence questionnaire.
- 04Attack demonstration: observe and mitigate prompt injection on a sample agent.
- 05Roadmap: define governance priorities for the next 12 months.
Practical skills developed
- 01SI use-case inventory and risk classification.
- 02Policy and standard drafting.
- 03Vendor and model due diligence.
- 04Threat modeling for SI systems.
- 05Evaluation and oversight design.
Tools, technologies and workflows
- Frameworks
- EU AI Act risk categories, the NIST AI Risk Management Framework and ISO/IEC 42001
- Templates
- use-case register, risk assessment, policy and vendor questionnaires
- Security demonstrations
- prompt-injection and data-leakage scenarios on sample systems
Product names are examples, not endorsements. Private workshops use your organization’s approved tools; our teaching is vendor-neutral.
Technology maturity: Established
Governance frameworks are established and still evolving. Regulatory guidance changes continuously, and the curriculum is reviewed accordingly.
Maturity map06 — Outcomes
The organization gains visibility of its SI use and risk profile.
Expected outcomes
- Policies are proportionate, understood and followed.
- SI-specific security risks are addressed with appropriate controls.
- Governance supports adoption instead of blocking it.
Participants leave with
- 01An SI use-case register and risk classification template.
- 02A draft acceptable-use policy and approval workflow.
- 03A vendor due-diligence questionnaire.
- 04A 12-month governance roadmap.
07 — Dates & delivery
Public sessions
No public dates are published yet.
Register your interest below and we will contact you as soon as a session is scheduled. Dates, venue and fees are confirmed before you commit to anything.
Available formats
- Public instructor-led workshopsIndividual professionals building their own skills.Available
- Private corporate workshopsTeams and departments learning together.Available
- On-site corporate trainingLarger groups and several cohorts in sequence.Available
- Live virtual instructor-led trainingDistributed and international teams.Available
For your organization
This workshop can be delivered privately for your teams — on-site, at a venue or live virtual — with cases and exercises adapted to your context.
Request a proposalWhere it fits
08 — Register interest
Register interest
Tell us that you would like to join this workshop. Registering interest is not a booking: we contact you when dates are confirmed, and you decide then.