TRAIL

Leading AI adoption

Inventory, ownership, risk appetite, procurement, and the EU AI Act obligations that follow a deployer, not just a builder.

Governing AI well starts with knowing what's actually in use, then building the ownership, policy, and evidence structures that make responsible adoption durable rather than a one-time review. This trail is the leadership counterpart to the Build ring's engineering discipline.

By the end you'll be able to run a real AI inventory, name what a genuine governance-ownership structure requires, set an explicit risk appetite, ask the right procurement questions, meet the deployer obligations the EU AI Act actually imposes, and know what a board needs to see to exercise real oversight.

10 landmarks · 58 min · 0/10 explored

Begin trail
  1. 1StewardBuilding an AI inventory

    You can't govern what you don't know exists. Start with genuine discovery — embedded features and shadow adoption are the usual blind spots.

  2. 2StewardGovernance ownership

    A policy nobody is accountable for enforcing changes nothing. Name a real owner with real authority.

  3. 3StewardSetting AI risk appetite

    Without an explicit, written risk appetite, every team sets its own by default — usually higher than leadership would have chosen.

  4. 4StewardAI procurement

    The questions to ask a vendor before signing, including the deployer obligations you inherit that have nothing to do with who built the system.

  5. 5StewardEU AI Act: practical measures

    From knowing a system is high-risk to the operational checklist that follows: oversight, monitoring, records, and impact assessments.

  6. 6StewardWorkforce consultation

    The people whose work an AI system changes usually see its failure modes before the rollout metrics do. Build a real channel for that.

  7. 7StewardFundamental rights impact

    Some AI decisions touch rights a standard risk assessment doesn't capture — who could be unfairly excluded, even when the system works as designed.

  8. 8StewardBuilding evidence packs

    When a regulator, auditor, or journalist asks how you know it's safe, the answer is either ready or it isn't.

  9. 9StewardIncident governance

    Beyond the technical fix: whether this incident needs disclosure, escalation, or a change to the standing policy that should have caught it.

  10. 10StewardReporting AI risk to a board

    Close the loop: a board that only hears capability wins isn't positioned to actually govern. What a substantive report includes.