Why Week 1 starts here, not with the law

Before learners in the AI Governance, Risk & Compliance Practitioner programme get anywhere near NIST AI RMF, ISO/IEC 42001 or the EU AI Act, they spend a week on something more basic: understanding what AI actually is, and how it differs from ordinary software. Not to turn anyone into an AI engineer. To give them enough grounding to ask the right questions once real systems and real regulation enter the picture.

The questions Week 1 is really about

Every framework, standard and law covered later in the programme comes back to a small set of practical questions. Week 1 exists to make asking them second nature:

  • What is this AI doing?
  • What data is it using?
  • Who is using it, and who is affected by it?
  • What can go wrong?
  • Who is responsible?
  • What evidence do we need before trusting it?

Plain language, not jargon

The teaching leans on everyday comparisons rather than technical definitions. One example we use: training an AI model is like training someone new in a fruit shop. Show them enough apples, bananas and mangoes, and they start recognising the pattern, round means apple, long and yellow means banana, without anyone writing down a formal rule. That is the basic idea behind most machine learning. The risky part is not the pattern-spotting itself. It is that the pattern can be wrong, biased, incomplete or based on examples that do not represent everyone it will later be used on.

A working case study runs through the whole week

Week 1 introduces HireAI, an AI recruitment screening system used as a running example across the programme. Learners are not asked to memorise facts about it. They are asked to describe what it does, work out who could be affected by it if it gets something wrong, and decide what a human reviewer should still control, before any framework language enters the conversation.

What Week 1 covers

Across the week, learners work through: what AI is and how it differs from traditional software; the relationship between AI, Machine Learning, Deep Learning and Generative AI; supervised and unsupervised learning; small models vs large models, proprietary vs open-source, and text vs multimodal systems; foundation models and Large Language Models; hallucination; Retrieval-Augmented Generation (RAG); AI agents; training vs inference; the AI lifecycle from idea to retirement; and the AI actors, developer, provider, deployer, user, affected person and supplier, whose responsibilities the rest of the programme builds on.

The first piece of real evidence

Week 1 closes with learners producing their first AI System Description, a structured account of what a system is, who it affects, what data it uses and what a human still controls. It is a small document, but it sets the pattern for the rest of the course: you cannot govern an AI system you cannot clearly describe.

This is one week of twenty-four. The full breakdown of every module is on the AI Governance, Risk & Compliance Practitioner programme page.