Skip to main content
    Insightful AI

    SMEs & Public Sector

    AI for leaders and senior decision-makers

    The accountability briefing for CEOs, MDs, directors, and board members who carry legal responsibility for how their organisation uses AI.

    This is not a briefing on how to use AI tools. It covers what you are legally answerable for when your organisation uses AI, how to set and sign off a risk appetite, and the questions to ask before you approve an investment. Participants leave with the understanding to govern AI use and the documentation to evidence it.

    Duration
    Half day, 3.5 hours
    Delivery
    In person or online
    Group size
    Up to 15 participants
    Price
    £995 ex VAT per session

    The accountability gap most boards have not yet closed

    The board keeps asking about AI. When the questions get specific, about legal exposure, or about what happens if something goes wrong, most senior teams find they do not have a clear answer. 54% of UK organisations have minimal AI governance or none, and only 7% have an embedded governance approach (Trustmarque AI Governance Index, 2025). The accountability sits at board level, but most senior leaders have never received a briefing that explains what that accountability requires of them in UK law.

    Who this course is for

    This course is designed for the people who carry legal accountability, not the people who use AI tools day to day. That includes CEOs, MDs, directors, senior managers, senior responsible owners, and board members. For public sector organisations, this means department leads, senior responsible owners in local authorities, NHS trusts, and central government bodies.

    Right for you ifNot right for you if
    You lead or sit on a board with legal accountability for your organisation's AI useYou want a foundation course covering how AI tools work (see AI Fluency for Organisations)
    You are a senior responsible owner in a public sector bodyYou are an information governance lead or DPO who needs operational data protection training (see Responsible AI and Data Protection)
    Your leadership team approves AI investments without a structure for risk or due diligenceYou need to build the organisation's AI governance, policy, and accountability mapping from scratch (see AI Governance for Organisations)
    You have been asked to evidence board-level oversight by a regulator, funder, or auditorYou are looking for practical staff training on approved tool use and output verification (see Safe Use of Generative AI Tools)

    This course is different from AI Fluency for Organisations. That course gives all staff the conceptual foundation to work with AI responsibly. This course addresses what law requires of you specifically: what boards must sign off, what oversight structures to put in place, and what to ask before approving an investment. The two run well together as a paired programme.

    What participants will be able to do after this course

    • Explain what your organisation is answerable for when it uses AI, under the UK General Data Protection Regulation (UK GDPR) and, where relevant, the EU AI Act (Regulation (EU) 2024/1689)
    • Set and record a risk appetite for AI use that managers and staff can act on
    • Run an AI investment or supplier decision through the right questions before approving it
    • Judge a vendor's claims independently against what the tool will do with your data and in your workflows, rather than relying on the vendor's own assessment
    • Put in place the senior oversight structures the Information Commissioner's Office (ICO) expects to see documented
    • For public sector participants: check an AI decision against the 10 core principles of the UK Government AI Playbook
    • Brief your own board, senior team, or trustees on where the organisation stands and what happens next

    What the course covers

    This is an accountability briefing, not a skills course for users. Every topic addresses what leaders are required to know and act on.

    What you are legally responsible for

    Senior management obligations under UK GDPR and, where relevant, the EU AI Act. The ICO expects signed senior approval of AI risks as part of the accountability principle. This is the foundation of the session.

    Setting and recording risk appetite

    Risk appetite for AI is a documented decision, not a general intention. This section covers how to define which AI use categories are acceptable, what level of oversight applies to each, and who is responsible. Participants leave with a structure they can put to use immediately.

    Evaluating AI investments and vendor claims

    The questions to ask before approving a supplier contract, and how to judge what a tool will do with your specific data and in your workflows rather than in a sales demonstration.

    ICO oversight structures

    What the ICO expects to find when it reviews senior management's engagement with AI risk, and how to produce the records that demonstrate it.

    UK Government AI Playbook

    For participants in local authorities, NHS trusts, and central government, this section maps decisions to the 10 core principles of the UK Government AI Playbook (Government Digital Service, February 2025).

    All content is built around your organisation's tools, policies, and regulatory position. The discovery call before the session is what makes every delivery bespoke. Participants also leave with a repeatable method for approaching AI approval and oversight decisions that they use after the session.

    How the course is delivered

    Discovery call

    Before any session, we speak with you about your organisation's AI position, the questions your board or senior team faces, and the regulatory exposure that applies to your sector. This shapes the entire session. No two deliveries are identical.

    Bespoke delivery

    The course runs in-house at your premises or online by video call, for groups of up to 15 participants. Larger leadership teams are accommodated across multiple sessions. All materials are written for your organisation, your tools, and your sector's obligations.

    Compliance documentation

    Participants receive documented training completion evidence meeting ICO audit expectations.

    What is included

    £995 ex VAT includes:

    • A pre-course discovery call
    • Bespoke course materials tailored to your organisation
    • A repeatable method for approaching AI approval and oversight decisions, for use after the course
    • Documented training completion evidence meeting ICO expectations
    • All session materials shared with your organisation after the session
    • A follow-up call after the course, offered to every client
    • A certificate of completion on request, at no extra charge

    How this course aligns with UK and EU regulation

    UK GDPR

    Under UK GDPR, the accountability principle requires organisations to demonstrate that risks of AI use involving personal data have been assessed, documented, and formally approved at senior level. The ICO expects a maintained AI risk register, written policies, senior sign-off on risks, and a Data Protection Impact Assessment (DPIA) for any high-risk AI processing. ICO fines reach £17.5 million or 4% of worldwide annual turnover.

    This course prepares leaders to put that oversight in place and produce the evidence auditors look for. The ICO has not mandated AI training as a standalone legal requirement, and has not enforced against inadequate AI training specifically. It expects to find evidence of senior accountability within the UK GDPR accountability principle.

    Data (Use and Access) Act 2025

    The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Where an organisation uses AI to make decisions affecting individuals, those individuals must be informed of that use, able to make representations, and able to request human intervention. Meaningful human intervention means a person reviews and can challenge the decision, not approve it by default. Leaders are accountable for ensuring those conditions exist within their organisation.

    EU AI Act

    Article 4 of the EU AI Act (Regulation (EU) 2024/1689) creates a direct obligation to ensure staff AI literacy. It has been in force since 2 February 2025. For organisations with EU exposure (those that place an AI system on the EU market, serve EU clients, or produce AI outputs used in the EU), Article 4 is binding law. This course addresses that obligation at leadership level. For UK-only organisations with no EU exposure, Article 4 carries no direct legal force. It sets the benchmark UK regulatory thinking is moving toward.

    Article 26, which governs the obligations of AI system deployers, now applies from 2 December 2027 for standalone high-risk AI systems and 2 August 2028 for AI embedded in regulated products. The Digital Omnibus on AI (Regulation (EU) 2026/1744), which set those dates, entered into force on 27 July 2026. Transparency obligations under Article 50 were not deferred and have applied since 2 August 2026. For organisations with EU exposure, penalties for non-compliance with deployer obligations reach €15 million or 3% of worldwide annual turnover.

    We recommend taking independent legal advice on your organisation's specific EU exposure before treating any of the above as a compliance position.

    UK Government AI Playbook and the public sector governance gap

    For public sector participants, this course maps decisions to the 10 core principles of the UK Government AI Playbook (Government Digital Service, February 2025). The National Audit Office (March 2024) found that only 21% of government bodies had an AI strategy, and only 30% had AI-specific risk or assurance processes, despite 70% piloting or planning AI use. Among local councils, the Local Government Association (June 2025) found 95% using or exploring AI, but 28% still had no AI usage policy for corporate devices.

    Alan Turing Institute AI Skills for Business Competency Framework

    The Alan Turing Institute's AI Skills for Business Competency Framework is a voluntary benchmark that defines 'AI Leaders' as those with senior responsibility for AI governance, requiring expert-level understanding of privacy, risk oversight, and strategic assessment. This course addresses the leadership accountability domain of that framework. It is a voluntary standard, not a legal requirement.

    Built on regulatory expertise, not general awareness

    Insightful AI is registered on the UK Register of Learning Providers, UK Provider Reference Number (UKPRN) 10098807.

    Every session addresses named legal obligations, not general awareness. We cite what auditors look for: the UK GDPR accountability principle as it applies to AI, the correct penalty tier for EU AI Act deployer obligations, and the Data (Use and Access) Act 2025 human-intervention standard. Most providers cannot state these accurately. Getting them right is itself the evidence of capability.

    The course is designed and delivered by practitioners, with co-founders Ben Sefton and Kane Lukassen leading the team.

    Where this course fits in the programme

    Board members and senior leaders carry accountability from the moment their organisation uses AI. This course does not sit at a fixed point in the six-course sequence. It can be taken independently or alongside other courses.

    Most organisations run this course at the same time as AI Fluency for Organisations, giving all staff the conceptual foundation and leadership the accountability briefing together.

    • AI Governance for Organisations is a full-day session for the managers and IG leads who build and run the governance structure: AI policy, risk classification, accountability mapping, and supplier due diligence.
    • Responsible AI and Data Protection is for information governance leads and DPOs who need the data protection detail: UK GDPR, DPIAs, and lawful basis for AI processing.
    • AI Impact and ROI Auditing is an independent, board-ready assessment of what your AI investments are delivering.

    View all SME and public sector courses

    Frequently asked questions

    Who is this briefing for?
    This course is for CEOs, MDs, directors, senior managers, senior responsible owners, and board members who carry legal accountability for how their organisation uses AI. It is not designed for operational staff or those building governance structures. If your role involves approving AI investments or signing off oversight arrangements, this course is designed for you.
    What are we legally responsible for when we use AI?
    Under UK GDPR, senior management are expected to have assessed and formally signed off the risks of AI use involving personal data, maintaining documented evidence of that oversight. The Data (Use and Access) Act 2025 also requires that where AI makes decisions affecting individuals, meaningful human review must be available. These obligations apply regardless of your organisation's size.
    How is this different from the AI governance for organisations course?
    AI Governance for Organisations is for the managers and information governance leads who build and run the governance structure: risk classification, AI policy, supplier due diligence. This course briefs the people who set the risk appetite and sign it off. Governance leads attend that course. Board members and senior leaders attend this one.
    Does the EU AI Act apply to our organisation?
    If your organisation serves EU clients, places AI on the EU market, or produces AI outputs used in the EU, Article 4 has been binding law since February 2025 and Article 26 deployer obligations are due to apply. For UK-only organisations, it sets the benchmark UK regulation is moving toward. UK GDPR accountability obligations apply to you now regardless of EU exposure.
    What will our leadership team be able to do afterwards?
    After this course, leaders will be able to set and document a risk appetite for AI use, run an AI investment through the right questions before approving it, put in place the oversight structures the ICO expects, and brief their own board or trustees on where the organisation stands. They will know what to sign, what to document, and what to challenge.
    Can this course be delivered to our board specifically, in our sector?
    Yes. The discovery call before each session is specifically for this: to understand your sector, your tools, your regulatory exposure, and the questions your board faces. No two sessions are identical. The course is delivered in-house at your premises or online, for your leadership group, built around your organisation's position.
    Do our staff need AI training too, or just our leaders?
    Both. This course covers leadership accountability, not staff tool use. Staff AI competence and safe practice sit with AI Fluency for Organisations and Safe Use of Generative AI Tools. Most organisations run the leadership briefing and staff courses at the same time, or in sequence.
    What does the course cost and what is included?
    £995 ex VAT covers a half-day session of up to 15 participants. The price includes the pre-course discovery call, bespoke materials, a method for ongoing AI oversight decisions, training completion evidence, all session materials, a follow-up call, and a certificate of completion on request. There are no additional charges.

    Book a free discovery call

    The discovery call takes around 30 minutes. We will discuss your organisation's AI position, the questions your board or senior team faces, and how to structure the session around them.

    Book a free discovery call

    Ready to explore what AI can do for your organisation?

    Whether you're just getting started or looking to scale, we'll help you find the right path, responsibly.