New: Roadmaps ordered paths through our cheat sheets and flashcards, so you always know what to study next.
Explore themSee what's new on GitHubFrom responsible-AI principles to classifying an AI system across US, EU, and global regulation.
A 9-step learning path. Follow it in order, or jump to what you need.
This path is for privacy, compliance, legal, product, and policy professionals who need working knowledge of how AI systems get governed, not how to build them. Plan on about 6 weeks at a few hours a week, moving from responsible-AI principles and bias and fairness through explainability and data privacy law into the NIST AI RMF, the EU AI Act, US sector rules, and international frameworks. It stays on the policy and compliance side: it skips the LLM attack techniques, jailbreak testing, and red-team tooling that AI Security & Red Teaming covers, and it does not reteach how to build or train a model. By the end you can classify an AI system's regulatory risk tier, run a fairness check against real metrics, explain a model's decision to someone who did not build it, and flag the privacy and sector-specific obligations a given deployment triggers.
Expected: general professional familiarity with how software products get built and used at your organization. Helpful but not required: a background in privacy, compliance, or legal work, or prior exposure to how machine learning models get trained.
Starts here because you can hold any AI decision at your organization up against these six principles today, no risk framework or dataset required yet, and every later step in this path measures itself against them.
Step 3's bias audit and step 4's explanations both assume you already know what's inside the box: a rule-based tool, a trained classifier, and a generative model fail in different ways, and governing them starts with telling them apart.
You can walk through the core principles, fairness, transparency, accountability, human oversight, and tell someone in plain terms what kind of AI system you're actually looking at. Next up: putting real numbers on how fair, or unfair, that system is.
Finish this section to unlock.
+100 XP
This is where governance gets uncomfortable: once you see that satisfying one fairness metric usually means failing another, is this AI fair stops being a yes or no question and starts being a trade-off you have to defend, using the model types from step 2.
Bias audits from step 3 need a way to show their work: SHAP and LIME turn the model said no into a specific list of factors a rejected applicant, or a regulator, can actually see.
An explanation you can hand a regulator is also a GDPR obligation: the right to explanation from step 4 sits inside a much bigger set of consent, minimization, and automated-decision rules you need before touching real personal data.
Pull the principles, fairness checks, explanations, and privacy rules from steps 1 through 5 into one operating structure: the NIST AI RMF's four functions and the EU AI Act's risk tiers are what most organizations actually build their governance program around.
You can run a fairness check, explain a model's decision to someone who didn't build it, flag a GDPR-relevant privacy risk, and place a system on the EU AI Act's risk tiers using the NIST AI RMF; a few minutes of due flashcards keeps chapter 1's principles fresh while you build on them here. Next up: seeing how those rules change once you leave the EU.
Finish this section to unlock.
+100 XP
The EU AI Act's risk tiers from step 6 do not apply in Ohio: a hiring algorithm, a medical device, and a credit model each answer to a completely different US regulator, and knowing which one is half the job.
Take this if you're heading toward the technical side of AI safety or red-teaming work: RLHF and Constitutional AI are how the model behavior you've been governing from the outside actually gets shaped from the inside, and it pairs well with AI Security & Red Teaming.
Take one AI system through every earlier step at once: an EU AI Act classification, a US sector rule from step 7, and a completely different regime in the UK, China, or Canada can all apply to the same deployment, and reconciling them is what an AI governance professional is actually paid to do.
You can trace one AI system through ethics, fairness, privacy, and risk classification, then place it correctly across US sector rules and international law at once, the exact skill this badge certifies: reading any AI deployment against the regulatory map wherever it operates.
Finish this section to unlock.
+100 XP
Finish every required step, at least 70% of them genuinely done (not skipped), to earn this badge and 500 XP.