Skip to main content
    Insightful AI

    SMEs & Public Sector

    AI governance for organisations

    A full-day course that gives your senior managers, information governance leads and compliance officers the ability to classify AI risks, build an AI policy, run supplier due diligence and produce the documentation your regulator expects to see.

    Duration
    Full day, 7 hours
    Delivery
    In-house or online
    Group size
    Up to 15 participants
    Price
    £1,695 ex VAT per session

    AI is already happening. Governance is what is missing.

    71% of UK employees have used AI tools their organisation has not approved, and 51% do so every week (Microsoft/Censuswide, October 2025). 61% of UK organisations allow staff to use generative AI, but only 31% of employers worked on a generative AI policy in the past year (CIPD Labour Market Outlook, Autumn 2025).

    That gap is where risk accumulates. Your leadership is accountable for AI decisions they may not know are being made. Your information governance and compliance teams are being asked about regulatory obligations they have not been equipped to answer for AI specifically. Only 7% of UK organisations have an embedded AI governance position, and 54% have minimal governance or none at all (Trustmarque AI Governance Index, 2025).

    Governance does not stop organisations using AI. It is what makes using AI defensible.

    Who is this course for?

    This course is written for the people who carry the governance work: senior managers accountable for AI decisions, information governance leads and Data Protection Officers (DPOs), compliance officers, those managing AI procurement, and managed service providers implementing AI tools for clients.

    If participants need foundational AI knowledge before this day, AI Fluency for Organisations is the recommended starting point.

    Right for you ifNot right for you if
    You manage AI systems that process personal data or make decisions about individualsYou want a board-level AI briefing (see AI for leaders and senior decision-makers)
    Your organisation uses AI tools that have not been formally approved or risk-assessedYour team needs foundational AI knowledge before tackling governance (start with AI Fluency for Organisations)
    Board, trustees or a regulator are asking questions about AI accountability you cannot answer with documentationYou need the governance work done for you rather than the capability built in-house (see AI Ethics & Governance)
    You are a public sector body implementing the UK Government AI Playbook's 10 principlesYour organisation has no AI use at all, approved or otherwise

    What your team will be able to do after this course

    After this course, participants can:

    • Classify the organisation's AI uses by risk level under the EU AI Act (Regulation (EU) 2024/1689) and the UK General Data Protection Regulation (UK GDPR), applied to the tools they use
    • Map accountability for each AI system: who owns each decision and where human oversight sits in the chain
    • Develop an AI policy that fits the organisation's tools, sector and regulatory obligations, not a generic template adapted from a download
    • Run due diligence on AI vendors and the tools brought in through managed service providers or third-party IT partners
    • Produce the documentation the Information Commissioner's Office (ICO) expects at audit: a Data Protection Impact Assessment (DPIA) for high-risk uses, an AI risk register, and documented senior sign-off
    • Answer board, trustee or regulator questions about AI accountability with specific, documented evidence

    Participants also leave with a repeatable method for putting governance around new AI tools as adoption continues. The course does not need repeating every time a new tool arrives.

    What the course covers

    Every delivery is built around the client's own tools, approved platforms, existing policies and regulatory position. No two sessions are identical.

    AI risk classification

    Using the EU AI Act and UK GDPR as the classification structure, participants work through their own AI systems to identify which are high-risk and what that designation requires in practice.

    Accountability mapping

    For AI that makes or informs decisions about individuals, accountability must be documented and defensible. Participants map their own systems to identify where human oversight sits and where it is absent.

    AI policy development

    This session produces a working draft specific to the organisation's tools, risk profile and sector obligations. Participants leave with a policy they can explain and defend, not one adapted from a template.

    Supplier due diligence

    Most organisations use AI tools built and maintained by third parties. This section covers what to ask vendors, what to look for in contracts and how to handle AI brought in through managed service providers.

    Documentation and audit readiness

    Participants leave with an AI risk register structure, DPIA templates for their specific deployments, and the record of senior sign-off the ICO's audit requirements demand.

    How the course is delivered

    Discovery call

    Before any session, we run a scoping call to understand your AI tools, current policies, sector and regulatory position. Every delivery is different because every organisation's situation is different.

    Bespoke delivery

    The full day runs at your premises or online via video call, for up to 15 participants. Larger teams are accommodated across multiple sessions. Every scenario, example and documentation template is built around your organisation.

    Follow-up call

    Offered to every client after the session at no extra charge. Questions that surface after the room closes get answered.

    What is included

    • A pre-course discovery call to scope the day to your tools, policies and regulatory position
    • Bespoke course materials built for your organisation
    • A method guide participants use after the course to govern new AI tools as adoption continues
    • Documented training completion evidence meeting ICO audit expectations
    • All session materials shared after delivery
    • A follow-up call at no additional charge
    • A certificate of completion on request, at no extra charge

    How this course aligns with UK and EU regulation

    Every delivery names specific regulatory obligations and produces evidence your organisation has addressed them.

    EU AI Act (Regulation (EU) 2024/1689)

    AI literacy requirements under Article 4 applied from 2 February 2025. Prohibited AI practices under Article 5 applied from the same date. Financial penalties for breaches have applied since 2 August 2025. Transparency obligations under Article 50 have applied since 2 August 2026. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026. It deferred Article 26 deployer obligations to 2 December 2027 for standalone high-risk AI systems and 2 August 2028 for AI embedded in regulated products. Article 4 AI literacy obligations were not changed. Organisations should use the deferral as preparation time and plan against the 2 December 2027 date.

    Breaches of Article 26 obligations carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. The Act's maximum penalty tier, which applies to prohibited practices under Article 5, reaches €35 million or 7% of worldwide annual turnover.

    UK GDPR and the ICO

    The UK General Data Protection Regulation (UK GDPR) applies to any AI that processes personal data. The ICO expects a Data Protection Impact Assessment (DPIA) for high-risk uses, written policies, senior sign-off on AI risks, and a maintained AI risk register. ICO fines can reach £17.5 million or 4% of worldwide annual turnover, whichever is higher. This course produces evidence that meets those expectations under the UK GDPR accountability principle.

    Data (Use and Access) Act 2025

    The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Where an organisation uses AI to make decisions affecting individuals, those individuals must be informed, able to make representations, and able to request human review. The person reviewing must be able to challenge the decision, not simply approve it. The course addresses this through accountability mapping and AI policy development.

    UK Government AI Playbook (public sector)

    The UK Government AI Playbook (Government Digital Service, February 2025) sets 10 principles for accountable public sector AI use. For public sector participants, the course maps governance work to these principles. The National Audit Office found in March 2024 that 70% of government bodies were piloting or planning AI, but only 30% had risk or assurance processes that explicitly covered AI. The Local Government Association found that 41% of responding councils had a specific AI policy as of June 2025.

    Evidence and trust

    Insightful AI is registered with the UK Register of Learning Providers. UK Provider Reference Number (UKPRN): 10098807.

    Every delivery names specific obligations: Article 4 and Article 26 of the EU AI Act, the ICO's accountability and audit framework requirements, the Data (Use and Access) Act 2025 requirement for meaningful human intervention, and the UK Government AI Playbook's 10 principles. The documentation participants produce is built on those named standards.

    Our training is designed and delivered by practitioners whose careers were built in high-accountability environments. Co-founders Ben Sefton and Kane Lukassen lead the Insightful AI team.

    Where this course fits in the programme

    This is the governance-intensive course in the Insightful AI SME and public sector training programme.

    If you want the governance work done for you rather than your team building it, the AI Ethics & Governance service produces the policy, risk register and documentation through an external engagement.

    Frequently asked questions

    Who should attend: our senior managers or our information governance and compliance people?
    Both, where possible. Senior managers provide the authority to make governance decisions stick across the organisation. IG leads, DPOs and compliance officers carry out the risk classification and documentation work. Where only one group can attend, IG and compliance leads will take the most direct use from the day. Senior managers are the primary audience for AI for leaders and senior decision-makers.
    Does the EU AI Act apply to our organisation?
    Whether the EU AI Act (Regulation (EU) 2024/1689) applies depends on EU exposure. Organisations that place AI systems on the EU market, or produce AI outputs used in the EU (including by EU-based clients), are in scope and face direct legal obligations. For UK-only organisations with no EU exposure, the Act has no direct legal force in the UK at present. It is, however, the standard UK regulatory thinking is moving toward. This course establishes your position.
    What will our team be able to do after the course that they cannot now?
    After this course, your team can classify AI uses by risk level, document accountability for each system, build a workable AI policy, run due diligence on AI vendors, and produce the documentation the ICO expects at audit. They also leave with a repeatable method for governing new AI tools as adoption continues, so the work done on the day stays useful as your use of AI develops.
    How is this different from general data protection training?
    Standard data protection training covers UK GDPR obligations and DPIA processes. It does not cover EU AI Act risk classification, accountability mapping for AI-specific decisions, or supplier due diligence for AI vendors. This course equips your IG and compliance team for AI governance specifically, built around your own tools and regulatory exposure rather than generic scenarios.
    What documentation do we walk away with?
    Participants leave with a draft AI policy tailored to your tools and sector, an AI risk register structure, DPIA templates for your specific AI deployments, and documented training completion evidence meeting ICO audit requirements.
    Is it delivered in person or online, and how many people can attend?
    Both options are available: at your premises or online via video call. Groups of up to 15 participants per session. Larger organisations are accommodated across multiple sessions at the same per-session rate.
    What does it cost?
    £1,695 ex VAT for a full day (7 hours), in-house, for up to 15 participants. At capacity, that is approximately £113 per person.
    How current is the regulatory content, given the rules keep changing?
    Every delivery reflects the current regulatory position. The EU AI Act timeline on this page names the Digital Omnibus deferral now in force (Regulation (EU) 2026/1744, 27 July 2026), the 2 December 2027 date for Article 26 obligations, and the transparency obligations that have applied since 2 August 2026. The pre-course discovery call confirms your current regulatory exposure. A follow-up call is offered to every client after the session.

    Book a free discovery call

    The most common governance gap we see is not unwillingness. It is a lack of structure. AI use is already happening in most organisations. This course gives your team the ability to document it, defend it and put governance around it before a regulator, board or auditor asks.

    Book a free discovery call

    Ready to explore what AI can do for your organisation?

    Whether you're just getting started or looking to scale, we'll help you find the right path, responsibly.