OpenAI Shelves GPT-6.1 Astra After Safety Tests: What Went Wrong?
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
Learn how to conduct an EU AI Act compliance audit with practical steps for scoping AI systems, assessing roles and classifications, testing controls, gathering evidence, identifying gaps, managing remediation, and maintaining ongoing audit readiness under the latest regulatory requirements.
Managers do not need to learn how to build AI models. They do need to know how to decide whether AI should be used, what risks require attention, who is accountable, what evidence should support approval, where human oversight matters, and how an AI system should be monitored after deployment.
Effective AI governance training for managers therefore needs to go beyond basic AI awareness. It should connect AI literacy with risk management, accountability, policies, controls, regulatory awareness, vendor oversight, and practical business decision-making.
The goal is not to turn managers into engineers, lawyers, auditors, or compliance specialists. It is to give them enough knowledge to ask informed questions, recognise when specialist review is needed, and make or oversee responsible AI-related decisions.
A useful manager-focused learning path looks like this:
|
Learning area |
What a manager should understand |
What a manager does not need to master |
|
AI fundamentals |
Purpose, capabilities, limitations, intended use |
Model architecture or advanced coding |
|
AI risk |
Potential impacts, controls, residual risk, escalation |
Complex quantitative risk modelling |
|
Accountability |
Ownership, approval authority, responsibility |
Every specialist governance process |
|
Regulation |
Relevant obligations and escalation triggers |
Acting as legal counsel |
|
Human oversight |
When human review and intervention matter |
Designing technical interfaces |
|
Monitoring |
Evidence, incidents, performance and change |
Building monitoring infrastructure |
|
Vendor governance |
What evidence to request before approval |
Conducting every technical test personally |
For a broader explanation of the organisational discipline, see AI governance.
AI governance is the organisational system used to direct and oversee how AI is selected, developed, purchased, deployed, used, monitored, changed, and retired. It brings together decision rights, accountability, policies, risk processes, controls, documentation, oversight, and escalation.
Several related concepts overlap with governance but are not interchangeable.
AI risk management focuses on identifying, assessing, treating, monitoring, and communicating risks. AI ethics considers values and outcomes such as fairness, human autonomy, transparency, and potential harm. AI compliance focuses on legal, regulatory, contractual, and internal requirements. AI security addresses threats, vulnerabilities, access, resilience, and misuse.
Governance connects these areas to organisational decisions.
For a manager, that means questions such as: What is this system being used for? Who owns the decision? Who could be affected? What evidence supports approval? Which controls are necessary? When should the issue be escalated?
Governance is therefore not exclusively a technical responsibility. Business managers may participate throughout the AI lifecycle, particularly when proposing use cases, approving budgets, purchasing AI tools, overseeing employees who use AI, accepting operational risk, or deciding whether a system should continue to operate.
Managers increasingly encounter AI through procurement, internal tools, generative AI, analytics, customer systems, HR technology, automated recommendations, and AI-enabled products.
The governance significance depends on how the technology is used.
An AI assistant used to improve the wording of an internal document does not create the same questions as an AI system used to analyse job applications, influence credit decisions, prioritise customers, or process sensitive information.
Managers therefore need enough governance knowledge to recognise when a use case creates operational, legal, privacy, security, ethical, financial, or reputational considerations.
They also need to know the limits of their own role. A manager should not independently decide complex questions of legal interpretation, cybersecurity assurance, data protection, model validation, or regulatory classification when specialist expertise is required.
Good governance clarifies who participates, who is responsible for specific activities, who has authority to approve a decision, and who remains accountable for the organisational outcome.

Manager-focused training should build enough knowledge for informed oversight without requiring deep model-development expertise.
Managers should understand basic distinctions between common forms of AI, including predictive systems, recommendation tools, classification systems, generative AI, and AI-supported decision systems.
The most important starting point is the intended use.
Governance cannot be assessed effectively if the organisation cannot clearly explain what the AI is supposed to do, who will use it, what decisions it influences, and who may be affected.
Managers should also understand relevant organisational roles under applicable regulation. For example, the current EU AI Act legal text on EUR-Lex distinguishes a provider that develops or has an AI system developed and places it on the market or puts it into service under its own name from a deployer that uses an AI system under its authority in a professional context.
A business buying an AI service may therefore face different governance questions from the organisation that developed it.
Manager training should introduce relevant AI governance principles such as accountability, transparency, fairness and non-discrimination, privacy, human oversight, safety, security, traceability, and responsible use.
These should not be presented as one universal checklist.
Different standards, frameworks, regulations, and organisations group responsible AI concepts differently. For example, the OECD AI Principles include human rights and democratic values, transparency and explainability, robustness, security and safety, and accountability. The OECD states that the principles were originally adopted in 2019 and updated in May 2024 to reflect technological and policy developments.
For managers, principles become useful when converted into decision questions.
Accountability becomes: Who owns the decision?
Transparency becomes: What should users or affected stakeholders understand?
Fairness becomes: Could this use create unjustified differences in treatment?
Human oversight becomes: Where should a person be able to review, challenge, override, or stop the system?
Managers should learn to think about AI risk in context.
That includes identifying what could go wrong, who could be affected, the potential severity of an impact, relevant controls, uncertainty, remaining or residual risk, and circumstances that require escalation.
They should also understand that an AI risk assessment is not a one-time approval exercise.
A system can change. A vendor can release a new version. Employees can begin using it for purposes that were not originally approved. New data may be introduced. Performance may deteriorate. Regulatory expectations may change.
Governance therefore requires monitoring and reassessment when the system or its context changes.
Understanding AI governance roles helps managers distinguish participation from accountability.
Depending on the organisation and use case, governance may involve business owners, executive leadership, legal and compliance, privacy, cybersecurity, enterprise risk, data governance, technical teams, procurement, internal audit, and governance committees.
Four concepts are particularly important.
Participation means contributing to a governance process. Responsibility means performing an assigned activity. Authority means having the power to approve, reject, suspend, or escalate a decision. Accountability means being answerable for the decision or outcome.
A privacy team reviewing data protection issues does not automatically become accountable for the business purpose of the AI system. A technical team maintaining a model does not automatically own the decision to use it in a particular business process.
Managers should understand the purpose of AI policies, acceptable-use rules, AI inventories, approval processes, risk assessments, vendor reviews, documentation, monitoring arrangements, incident procedures, escalation routes, and decision records.
They do not need to produce every specialist document themselves.
They should be able to ask whether appropriate evidence exists.
For example: Is the intended use documented? Has the necessary review occurred? Are owners identified? What controls were approved? What would trigger escalation? How will important changes be detected?
Documentation allows an organisation to reconstruct not only what decision was made, but why it was considered reasonable at the time.
Managers are often more likely to buy AI than build it.
Vendor governance should therefore be part of management training.
A manager assessing an external AI service should understand what the system does, what data it receives, whether the proposed organisational use matches its documented purpose, what evidence the supplier provides about testing and limitations, how material changes are communicated, what privacy and security information is available, and what happens if the organisation needs to restrict or suspend use.
Vendor assurances should support governance decisions, not replace the organisation's own assessment of its use case.
Managers need to understand the status of the instruments they encounter.
Law ≠ standard ≠ framework ≠ principle ≠ organisational policy.
The EU AI Act is regulation. The NIST AI Risk Management Framework is a voluntary risk-management framework. ISO/IEC 42001 is an international management-system standard. The OECD AI Principles are non-binding principles and recommendations.
Confusing these categories can lead to poor governance decisions, such as treating voluntary guidance as legislation or assuming that adopting a framework automatically demonstrates legal compliance.
Build the foundation: AI Governance Fundamentals provides structured introductory learning for people who want to develop knowledge of AI governance, risk, accountability, and organisational oversight.
The most useful AI governance skills for managers are capabilities that improve actual decisions.
|
Skill |
A manager should understand |
A manager should be able to do |
|
AI literacy |
Purpose, capabilities and limitations |
Challenge an unclear or unsuitable AI use case |
|
Risk thinking |
Potential harms, uncertainty and controls |
Ask what could fail and who could be affected |
|
Governance awareness |
Policies, ownership and approval processes |
Identify the required governance route |
|
Accountability |
Responsibility, authority and escalation |
Determine who owns and approves a decision |
|
Regulatory awareness |
Relevant regulatory concepts |
Recognise when specialist review is needed |
|
Stakeholder management |
Different business and specialist perspectives |
Bring the right functions into the decision |
|
Oversight |
Evidence, monitoring, incidents and change |
Ask whether controls remain effective |
|
Decision-making |
Benefits, risk, evidence and uncertainty |
Proceed, modify, pause, reject, or escalate |
Managers who are new to the subject may first benefit from AI governance training for beginners before moving into role-specific decision-making.
Managers, technical teams, compliance professionals, and senior executives need different levels of depth.
Technical teams may require detailed knowledge of architecture, data quality, model evaluation, testing, security, monitoring, and technical controls.
Legal and compliance professionals may require deeper regulatory interpretation, classification analysis, documentation, evidence, and assurance knowledge. Professionals in these functions may therefore need more specialised AI governance training for compliance professionals.
Managers need enough technical and regulatory literacy to understand the decision context, challenge assumptions, assess evidence, identify owners, and know when specialist involvement is necessary.
Senior executives may focus more heavily on governance structures, risk appetite, investment decisions, organisational accountability, reporting, and whether governance is working effectively across the enterprise.
Training should therefore reflect role, responsibility, existing knowledge, AI systems used, organisational context, and applicable obligations rather than assuming that every manager requires the same curriculum.
The NIST AI Risk Management Framework is intended to help organisations manage risks to individuals, organisations, and society associated with AI. NIST describes the AI RMF as voluntary and designed to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
Its core functions are Govern, Map, Measure, and Manage.
Managers do not need to memorise every category or subcategory. They should understand the logic: establish governance, understand the context and risks, evaluate relevant risks, and manage them through prioritised action.
As of September 2026, NIST states that AI RMF 1.0 is being revised.
According to ISO's official ISO/IEC 42001 page, ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System within an organisation.
Its relevance to managers is organisational.
A management-system approach connects policies, objectives, responsibilities, processes, risks, evaluation, and continual improvement rather than focusing only on an individual model.
ISO/IEC 42001 is an international standard. It is not legislation, and implementing it should not be represented as automatically satisfying every legal obligation that may apply to an organisation.
The EU AI Act follows a risk-based regulatory approach, and obligations vary according to factors including the AI system, intended purpose, risk category, and the organisation's role.
AI literacy is particularly relevant to management training.
The European Commission's current Article 4 AI literacy guidance explains that providers and deployers must take measures to support the development of AI literacy among relevant staff and other people dealing with AI systems on their behalf, taking account of factors such as knowledge, experience, education, training, and context. Following the 2026 amendments, Article 4 no longer mandates a particular “sufficient” level for every individual.
The Commission also states that Article 4 does not impose one mandatory training format, does not require a specific certificate, and does not require a particular AI governance structure.
Managers should also recognise high-risk concepts without attempting to perform legal classification alone. The European Commission's current enforcement timeline states that rules for Annex III high-risk systems apply from 2 December 2027, while rules for high-risk AI embedded in regulated products apply from 2 August 2028.
Current dates and legal requirements should always be checked against official sources before a business relies on them.
Managers can use a simple governance sequence:
Define the AI use case. State what the system will do and what decision or process it influences.
Identify affected stakeholders. Consider users, customers, employees, applicants, or others who may experience its effects.
Determine the organisation's role. Understand whether the organisation builds, provides, buys, deploys, or otherwise uses the system.
Identify risks and relevant obligations. Consider operational, legal, privacy, security, ethical, and other relevant issues.
Assign owners and decision authority. Clarify who performs reviews, who approves, and who can escalate or suspend use.
Identify controls and specialist reviews. Determine what evidence is required before a decision can be made.
Make the governance decision. Proceed, modify, delay, reject, or escalate based on evidence and remaining risk.
Establish monitoring and escalation. Decide what will be reviewed and what events require action.
Reassess when the context changes. Material changes in the system, vendor, data, purpose, performance, or regulatory environment may require new review.
After suitable training, a manager should be able to ask questions such as: What is the AI actually being used for? Who could be affected? What could go wrong? Who owns the system? What evidence supports approval? Which specialists need to review it? Where is human oversight meaningful? What would cause us to pause the system? How will we detect changes in risk?
Consider a fictional company evaluating an AI tool that ranks applicants before recruiters decide whom to interview.
|
Governance question |
Management reasoning |
|
Intended use |
Rank applications to support interview selection |
|
Affected stakeholders |
Applicants, recruiters and hiring managers |
|
Potential concerns |
Unfair outcomes, unsuitable data, inaccurate ranking, privacy, over-reliance |
|
Relevant roles |
HR, business owner, privacy, legal/compliance, security, procurement, technical assurance |
|
Human oversight |
Recruiters retain meaningful ability to review and challenge recommendations |
|
Evidence |
Vendor information, testing evidence, risk assessment, approval record |
|
Escalation |
Complaints, unexplained ranking patterns, failures or material system changes |
|
Monitoring |
Outcomes, incidents, performance, use changes and control effectiveness |
The EU AI Act's Annex III legal text includes certain AI systems intended for recruitment or selection, including analysing and filtering job applications and evaluating candidates, among the listed employment high-risk use cases. The Commission states that the relevant Annex III rules apply from 2 December 2027 under the current timeline.
That does not mean every recruitment technology should be classified by a manager without specialist analysis.
The management lesson is simpler: an AI-supported recruitment system can raise sufficiently important questions that the organisation should establish its intended use, assess the relevant risks and obligations, identify appropriate reviewers, determine meaningful human oversight, maintain evidence, and define monitoring before relying on it.
Good management training should connect learning directly to decisions.
It should cover enough AI fundamentals to understand use cases and limitations, governance principles, AI risk management, roles and accountability, policies and controls, documentation, regulatory awareness, major frameworks and standards, vendor governance, monitoring, human oversight, and practical scenarios.
The practical test is whether a manager finishes the training better able to evaluate an AI proposal.
Can they clarify the intended use? Identify affected stakeholders? Recognise credible risks? Ask for appropriate evidence? Understand who needs to participate? Distinguish legal requirements from voluntary frameworks? Recognise when specialist review is required? Decide what monitoring and escalation should follow approval?
Training should also be current. Regulation and official guidance can change, so material that discusses laws such as the EU AI Act should show when it was reviewed and use primary sources where possible.
No single curriculum is universally appropriate. A manager overseeing low-impact internal productivity tools may need a different level of depth from someone overseeing AI in recruitment, healthcare, financial services, critical infrastructure, or another consequential context.
Managerial AI governance capability develops through a practical progression:
AI literacy → governance principles → risk → accountability → controls → practical oversight
The objective is not to make managers the deepest expert in every discipline.
It is to help them recognise governance issues, challenge unclear assumptions, ask better questions, involve the appropriate specialists, interpret evidence, make decisions within their authority, and know when an issue should be escalated.
For managers and business leaders building that foundation, AI Governance Fundamentals provides a structured starting point for learning about governance principles, AI risk, accountability, and organisational oversight.
This article provides educational information and should not be treated as legal advice. Organisations should assess requirements according to their jurisdiction, role, AI system, intended use, sector, and specific circumstances.
AI governance training for managers teaches business leaders how to understand AI use cases, recognise risks, identify accountability, evaluate controls and evidence, apply appropriate oversight, and know when specialist review or escalation is required.
Managers need AI literacy, but they generally do not need deep programming or model-development expertise for management-level governance. They should understand what an AI system does, its limitations, its intended use, and which technical questions require specialist input.
Useful capabilities include AI literacy, risk thinking, governance awareness, accountability, regulatory awareness, stakeholder coordination, vendor oversight, evidence evaluation, monitoring, and decision-making.
Relevant concepts commonly include accountability, transparency, fairness and non-discrimination, privacy and data protection, safety, security, human oversight, traceability, and responsible use. Different frameworks and organisations may structure these concepts differently.
Depending on the organisation, AI governance may involve business or system owners, executives, technical teams, legal and compliance, privacy, security, data governance, risk, procurement, internal audit, and governance committees. The exact structure should reflect organisational context rather than a universal template.
Managers can benefit from understanding the NIST AI RMF conceptually, particularly its Govern, Map, Measure, and Manage functions. NIST describes the framework as voluntary, so it should not be presented as legislation or as a universal legal requirement.
Managers involved in organisational AI oversight can benefit from understanding its management-system approach. ISO describes ISO/IEC 42001 as an international standard for establishing, implementing, maintaining, and continually improving an AI management system.
Article 4 requires providers and deployers to take measures that support the development of AI literacy among relevant staff and other people dealing with AI systems on their behalf. The European Commission explains that no single mandatory training format or specific certificate is prescribed and that the approach should reflect the relevant people, AI systems, risks, and context.
Management training focuses more heavily on business decisions, ownership, risk, evidence, oversight, vendor governance, and escalation. Compliance-focused training generally requires deeper attention to applicable obligations, regulatory interpretation, controls, documentation, monitoring, and assurance.
Start by defining the use case, identifying affected stakeholders, determining the organisation's role, assessing relevant risks and obligations, assigning ownership, obtaining necessary specialist reviews, establishing controls, making a documented decision, and defining monitoring and escalation arrangements. Governance should be reconsidered when the system or its context materially changes.
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
AI Law
Learn AI compliance requirements, key risks, the EU AI Act, NIST AI RMF, ISO 42001, and practical steps to build...
AI Law
Understand AI regulation in the United States in 2026, including federal rules, state AI laws, privacy, discrimination and practical compliance...