TRAIL
Leading AI adoption
Inventory, ownership, risk appetite, procurement, and the EU AI Act obligations that follow a deployer, not just a builder.
Governing AI well starts with knowing what's actually in use, then building the ownership, policy, and evidence structures that make responsible adoption durable rather than a one-time review. This trail is the leadership counterpart to the Build ring's engineering discipline.
By the end you'll be able to run a real AI inventory, name what a genuine governance-ownership structure requires, set an explicit risk appetite, ask the right procurement questions, meet the deployer obligations the EU AI Act actually imposes, and know what a board needs to see to exercise real oversight.
Begin trail →- 1StewardBuilding an AI inventory
You can't govern what you don't know exists. Start with genuine discovery — embedded features and shadow adoption are the usual blind spots.
- 2StewardGovernance ownership
A policy nobody is accountable for enforcing changes nothing. Name a real owner with real authority.
- 3StewardSetting AI risk appetite
Without an explicit, written risk appetite, every team sets its own by default — usually higher than leadership would have chosen.
- 4StewardAI procurement
The questions to ask a vendor before signing, including the deployer obligations you inherit that have nothing to do with who built the system.
- 5StewardEU AI Act: practical measures
From knowing a system is high-risk to the operational checklist that follows: oversight, monitoring, records, and impact assessments.
- 6StewardWorkforce consultation
The people whose work an AI system changes usually see its failure modes before the rollout metrics do. Build a real channel for that.
- 7StewardFundamental rights impact
Some AI decisions touch rights a standard risk assessment doesn't capture — who could be unfairly excluded, even when the system works as designed.
- 8StewardBuilding evidence packs
When a regulator, auditor, or journalist asks how you know it's safe, the answer is either ready or it isn't.
- 9StewardIncident governance
Beyond the technical fix: whether this incident needs disclosure, escalation, or a change to the standing policy that should have caught it.
- 10StewardReporting AI risk to a board
Close the loop: a board that only hears capability wins isn't positioned to actually govern. What a substantive report includes.