Quest 6 of 15
Safe Use, Policy & Governance
Responsible AI in the workplace: approved-tool lists, data classes (what may go into copilots), human review on customer-facing outputs, bias and privacy guardrails, and lightweight governance so innovation does not create unmanaged risk. Turn shadow AI (staff using personal accounts) into governed practice. For example, a policy can require internal copilots for HR questions while blocking pasting employee records into public tools.
Start here
Governance turns experiments into accountable operations. You do not need to be a lawyer — you need clear rules, owners, and escalation paths.
Big idea
As AI scales, organisations need policies for permitted tools, data classes, incidents, and regular review — not ad hoc decisions per department.

Learn one idea at a time
Read, explore, then mark each idea when you can explain it.
Idea 1 of 7
Governance answers, in advance and in writing, the questions that otherwise get decided ad hoc by whoever is in the room: who may use which AI tools, on which classes of data, for which purposes — and who has the authority to approve a new use case. The practical embodiment is small: a one-page policy, a use-case register with named owners, and a lightweight approval route for anything new that touches customers, money, or staff decisions. Without this, every department improvises its own rules, the organisation's real AI posture becomes whatever its least careful team is doing, and nobody discovers that until an incident makes it visible.
Live interactive diagrams
Tap nodes, stages, or cards to explore — these diagrams match this module’s ideas.
Governance review cycle
Permitted tools and data classes.
Choose a deep dive
Open the topics you want to explore. The detail stays folded until you need it.
Deep dive 1Governance makes responsible use repeatable
Governance is the practical system of roles, rules, evidence, and review that turns values into decisions. It should tell staff which tools are approved, which data they may enter, and who can approve a higher-risk use case. A short, usable process beats a policy that nobody can follow.
Deep dive 2Risk should match the consequence
A drafting assistant for internal meeting notes needs different controls from a tool affecting hiring, credit, health, or public benefits. Higher-risk uses need stronger testing, documentation, human review, and escalation. Review controls regularly because both the tool and local regulation can change.
Deep dive 3Worked example: one incident, handled well
A knowledge assistant confidently tells several staff an outdated leave policy, and one team schedules around it before the error surfaces. The response follows the pre-agreed playbook: the owner temporarily disables the affected answer topic, posts a correction to everyone who asked the question recently (the logs make them findable), fixes the root cause by re-indexing the current policy document and archiving the stale one, and records the incident with dates and actions. Total elapsed time: two days. Nothing about this required heroics — only that an owner, logs, a kill switch, and a communication route existed before the incident happened.
Deep dive 4A register you can maintain in a spreadsheet
Governance fails when the paperwork is heavier than the organisation can carry. A workable AI register is one row per use case: name, business owner, what data it touches, risk level (does it affect customers, money, or staff decisions?), what human review exists, approval date, and next review date. Fifteen minutes per use case, reviewed quarterly. The register's real power is the conversation it forces — the moment nobody can name an owner or a review step for a live tool, you have found your risk. Start simple; formal tooling can come when the list outgrows the sheet.
Deep dive 5Workplace AI policy
Approved tools, data classes, human review on external comms, incident escalation.

One-minute challenge
Connect this lesson to real life
Name one situation where this idea could help, and one thing a person should still check.
Explore a real-world example
Use the arrows to connect the idea to a visible situation.
Photo example
Example: stop shadow AI
Offer internal copilot + training instead of banning without alternatives.

Key terms
Tap a term to flip and read the definition.
Optional further learningFree textbooks and trusted online resources
These sources informed the course structure. Use them to revisit a concept or study it in more depth.
Ready check
Tick each idea only when you could explain it without looking back.
Ready for practice? Finish ethics quizzes and policy drafting — apply governance to realistic cases.
Extra context (audience, logistics, curriculum notes)
Built for: Ensures managers can sponsor useful tools without exposing the company to legal, security, or reputational harm.
Formats: Structured debate format (live or async with recorded arguments) · Policy template walkthrough · Legal/compliance guest Q&A where available
Week 6 — workplace AI policy, risk, and governance (report §1).
Next up
Ready for the next part?
When you've finished the reading, inline exercises, and knowledge check for this part, check the box to continue.