AI-G01 — AI Governance and Institutional Policy

Wishlist Share

About Course

Course Code: AI-G01  |  School: School of Artificial Intelligence  |  Cluster: Level 4 — Governance & Policy

Level: Advanced  |  Duration: 6 weeks · 24–30 learning hours  |  Language: English  |  Certificate: Executive Certificate (non-degree)  |  Format: Self-paced with AI support under human supervision

Overview

Institutions acquire AI capability faster than they acquire the authority to govern it. Procurement happens in one department, deployment in another, and accountability nowhere. This course is about closing that gap by writing policy that is enforceable rather than aspirational.

The course is built around drafting. Learners produce an actual governance instrument for their own institution: scope, definitions, permitted and prohibited uses, an approval pathway proportionate to risk, disclosure requirements, procurement clauses, an incident procedure, and a review cycle with named owners. Frameworks are studied because they supply structure and defensible language, not because compliance with a framework is itself a goal.

The position taken throughout is that a policy nobody can apply is worse than no policy, because it transfers risk to whoever acted in good faith without guidance. Every clause learners write is tested against a concrete scenario before it is accepted.

Learning outcomes

On completion, a successful learner will be able to:

  1. Map the decision rights, existing policy instruments and accountability lines that AI use in your institution already touches.
  2. Classify intended uses by risk using a defensible scheme, and set approval thresholds proportionate to that classification.
  3. Draft enforceable policy clauses on permitted use, prohibited use, disclosure, data handling and human accountability.
  4. Specify procurement and vendor requirements, including documentation, audit rights, data residency and exit conditions.
  5. Design an incident reporting and escalation procedure with defined timescales and named roles.
  6. Align an institutional instrument with recognised frameworks without overclaiming compliance or certification.
  7. Plan implementation: training, monitoring, review cycle, and the evidence that would show the policy is working.

Who this course is for

Rectors, deans, directors, secretaries-general, heads of legal and compliance, registrars, IT and data protection officers, and advisers drafting AI policy for universities, ministries, research institutes and NGOs.

Prerequisites

Working familiarity with AI concepts at the level of AI-F01 and AI-F03. Experience of institutional policy or regulatory work is expected; learners without it should take AI-F01 first. Access to your institution’s existing policy documents is required for the assessed work.

Syllabus

Module 1 — What is already governed

Focus. AI use rarely falls into a vacuum. Data protection law, research ethics, procurement rules, academic integrity codes and employment policy already apply. The first task of governance is to find out what binds you before writing anything new.

Lessons. 1.1 Locating existing authority and decision rights. 1.2 Data protection as the binding constraint. 1.3 Research ethics and academic integrity overlap. 1.4 Gap analysis rather than greenfield drafting.

Core reading. Regulation (EU) 2024/1689 (Artificial Intelligence Act), articles 1–6 for scope and definitions. Undang-Undang Republik Indonesia Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi, for learners in Indonesian institutions.

Deliverable. Authority and gap map for your institution (two pages).

Module 2 — Risk classification and proportionate approval

Focus. Building a classification scheme that a busy administrator can actually apply. Tiering by consequence, reversibility and affected population, and attaching approval thresholds to tiers rather than to technologies.

Lessons. 2.1 Consequence, reversibility, affected population. 2.2 Tiering schemes and their failure modes. 2.3 Approval pathways proportionate to tier. 2.4 Testing a scheme against edge cases.

Core reading. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (2023), GOVERN and MAP functions. Regulation (EU) 2024/1689, articles 6–7 and annex III.

Deliverable. Risk classification scheme with approval thresholds, tested against five scenarios from your own institution.

Module 3 — Drafting the instrument

Focus. Clause-level drafting. Scope and definitions, permitted use, prohibited use, mandatory disclosure, data handling, and the requirement that a named human remains accountable for every consequential output.

Lessons. 3.1 Scope and definitions that survive technological change. 3.2 Permitted and prohibited use. 3.3 Disclosure obligations and their enforcement. 3.4 Human accountability clauses.

Core reading. UNESCO, Recommendation on the Ethics of Artificial Intelligence (Paris: UNESCO, 2021). Luciano Floridi & Josh Cowls, “A Unified Framework of Five Principles for AI in Society”, Harvard Data Science Review 1, no. 1 (2019).

Deliverable. Draft policy sections one to four.

Module 4 — Procurement, vendors and dependency

Focus. Most institutional AI risk arrives through a contract. Documentation requirements, audit rights, data residency and secondary use, model change notification, service continuity, and exit.

Lessons. 4.1 What to require in documentation. 4.2 Data residency and secondary use. 4.3 Model change and version notification. 4.4 Exit, portability and continuity.

Core reading. ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system (clause structure and control themes; the full standard is a paid publication). NIST AI RMF 1.0, GOVERN 6 on third-party risk.

Deliverable. Procurement annex: required clauses and evaluation criteria for AI vendors.

Module 5 — Incidents, monitoring and evidence

Focus. What counts as an AI incident, who must be told and within what period, how incidents are recorded, and what monitoring evidence would demonstrate that the policy is operating rather than merely existing.

Lessons. 5.1 Defining a reportable incident. 5.2 Escalation timescales and named roles. 5.3 Recording, review and correction. 5.4 Monitoring indicators and audit trails.

Core reading. Inioluwa Deborah Raji et al., “Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing”, Proceedings of FAT* (ACM, 2020). NIST AI RMF 1.0, MANAGE function.

Deliverable. Incident procedure and monitoring plan.

Module 6 — Implementation and honest claims

Focus. Training, communication, the review cycle, and the discipline of describing your position accurately. Alignment with a framework is not certification, and saying so protects the institution.

Lessons. 6.1 Training and communication that changes behaviour. 6.2 Review cycle and version control. 6.3 What you may and may not claim publicly. 6.4 Presenting the instrument for approval.

Core reading. OECD, Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449 (2019, amended 2024).

Deliverable. Final submission: complete governance instrument with implementation plan and an accurate statement of alignment.

Assessment

Component Weight
Authority and gap map 12%
Risk classification scheme with scenario tests 20%
Draft policy sections 25%
Procurement annex 15%
Incident procedure and monitoring plan 13%
Final instrument and implementation plan 15%
Total 100%

Pass mark 70 per cent. All assessed components must be attempted. Every mark in this course is issued by a human assessor; no assessment outcome is generated automatically.

Rubric criteria

Each assessed artefact is marked against four criteria at four levels (distinction, pass with merit, pass, fail).

  1. Enforceability: could an administrator apply this clause to a real request without further interpretation?
  2. Proportionality: is the approval burden matched to the consequence, rather than uniform or arbitrary?
  3. Legal and institutional fit: does the instrument sit correctly alongside existing obligations rather than duplicating or contradicting them?
  4. Honesty of claim: does the document describe its own status accurately, avoiding implied certification?

Reading list

Standards and instruments. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (2023). ISO/IEC 42001:2023. OECD, Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449 (2019, amended 2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act). UNESCO, Recommendation on the Ethics of Artificial Intelligence (2021). Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (Indonesia).

Peer-reviewed. Inioluwa Deborah Raji et al., “Closing the AI Accountability Gap”, Proceedings of FAT* (ACM, 2020). Luciano Floridi & Josh Cowls, “A Unified Framework of Five Principles for AI in Society”, Harvard Data Science Review 1, no. 1 (2019). Jessica Fjeld et al., Principled Artificial Intelligence, Berkman Klein Center Research Publication 2020-1 (2020).

Practitioner. Paul Voigt & Axel von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide (Cham: Springer, 2017), for the data protection drafting patterns reused in AI policy.

All items are published works identifiable by author, title and publisher. Learners obtain them through an institutional library or the publisher. The Academy does not distribute copyrighted texts.

Academic integrity and use of AI

Generative tools may be used in producing assessed work under three conditions. Use must be disclosed in a short statement appended to each submission, naming the tool and the task it performed. Any factual or technical claim originating from a generative tool must be verified against a citable source before it enters assessed work, and the verification must be evidenced. The analytical judgement in each artefact must be the learner’s own and must be defensible in a short follow-up. The instrument you submit will be read as a document you would put before your own governing body. Generic policy text imported wholesale from a generative tool or another institution without adaptation and attribution will not be credited.

Instructor: pending owner confirmation. Pricing: pending owner approval. Reference list verified against publisher records; any later addition is marked for verification before publication.

Show More

Course Content

Module 0 — Start Here

  • Welcome and How This Course Works

Module 1 — Core Concepts

Module 2 — Frameworks and Standards

Module 3 — Evidence and Sources

Module 4 — Analysis

Module 5 — Cases and Application

Module 6 — Assessment Preparation

Module 7 — Final Project

Student Ratings & Reviews

No Review Yet
No Review Yet

Want to receive push notifications for all major on-site activities?