top of page

IAPP AIGP, study guide domain i

  • Writer: Ley Muller
    Ley Muller
  • Aug 21
  • 24 min read

Domain i: Understanding the Foundations of Artificial Intelligence


Domain i.a Understand what AI is, and why it needs governance

Understand the basic elements of AI and ML

  •  Understand common elements of AI/ML definitions under new and emerging law

  • Technology (engineered or machine-based system; or logic, knowledge, or learning algorithm).

    • AI 

      • “An engineered or machine-based system that can, for a given set of objectives, generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments. AI systems are designed to operate with varying levels of autonomy.” - NIST

    •  An AI model 

      • best defined as a program that has been trained on a set of data to find patterns within that data.

      • This definition captures the essence of machine learning, where the model learns from the data to make predictions or decisions.

    •  “Machine learning (ML)

      • Systems that can automatically improve from experience by finding patterns in data, rather than following explicit rules

      • Systems can automatically improve from experience through predictive patterns

    •  Knowledge-based systems are a form of artificial intelligence (AI) designed to capture the knowledge of human experts to support decision-making. An expert system is an example of a knowledge-based system because it relies on human expertise.  

  •  Automation (elements of varying levels).

    •  Automation is any technology that reduces human labor, especially for predictable or routine tasks.

    •  AI simulates human intelligence with machines that can learn, reason, and act independently.

    •  Essentially, automation is about setting up machines to follow commands. AI is about setting up machines to mimic humans and think for themselves. 

  •  Example AI systems

    •  linear and statistical models,

    •  decision trees,

    •  deep learning

    •  various applications like computer vision, speech recognition, and NLP.

  •  Examples of each of these types

    •  Inference

    •  Statistical

    •  Probabilistic

    •  Deterministic

  •  Role of humans (define objectives or provide data).

    • The work of humans can be enhanced by AI, AI is meant to help make human’s work more efficient and better quality.

    • Humans may define the objective for an AI, or may provide the data to train the AI to perform a certain objective (analyze data, create something, etc)

    • “Humans decide which datasets are discoverable, linked and analyzed.” 

    • Humans determine whether data, algorithms, algorithmic methods, code and people — as brought together and operating within technical,  operational and legal controls, safeguards and guide rails specified by the same or different humans — are reliable and safe to produce appropriate outputs that lead to appropriate outcomes on humans or the environment. Humans, directly or indirectly, consciously or otherwise, determine what is appropriate.

  •  Output (content, predictions, recommendations, or decisions).

    • Predictive AI - offers predictions, can be used to inform recommendations or decisions 

    • Generative AI - generates new content, such as text, images, and video


Parameters

Generative AI

Predictive AI

Objective

Generates new, original content or data

Predicts and analyzes existing patterns or outcomes

Function

Creates new information or content

Makes predictions based on existing data

Training data

Requires diverse and comprehensive data

Requires historical data for learning and prediction

Examples

Text generation, image synthesis

Forecasting, classification, regression

Learning process

Learns patterns and relationships in data

Learns from historical data to make predictions

Use cases

Creative tasks, content creation

Business analytics, financial forecasting

Challenges

May lack specificity in output

Limited to existing patterns, may miss novel scenarios

Training complexity

Generally more complex and

resource-intensive

Requires less complex training compared to generative models

Creativity

Generative AI is creative and produces things that have never existed before

Predictive AI lacks the element of content creation

Different algorithms

Generative AI uses complex algorithms and deep learning to generate new content based on the data it is trained on

Predictive AI generally relies on statistical algorithms and machine learning to analyze data and make predictions

 

Why AI governance? 

  • = because of Core Al characteristics such as automation, adaptability, speed, and autonomy → require active governance due to their impact on decision-making, legal liability, and risk.

    • starts with defining  the corporate strategy for AI... and aligning systems with business purpose and operational context.

  • Understand what it means that an AI system is a socio-technical system.

  • A socio-technical system is a type of system in which both social and technical elements are intertwined with each other. AI Systems are considered social-technical because they are not just technical tools but also have a social impact on the people who use them and are affected by them. 

  • Understand the potential harms to an individual (civil rights, economic opportunity, safety).

    •  “An inaccurate system will implicate people for crimes they did not commit. And it will shift the burden onto defendants to show they are not who the system says they are.”  

    •  “Face recognition uniquely impacts civil liberties. The accumulation of identifiable photographs threatens important free speech and freedom of association rights under the First Amendment, especially because such data can be captured without individuals’ knowledge.”

    •  ”The collection and retention of face recognition data poses special security risks. All collected data is at risk of breach or misuse by external and internal actors, and there are many examples of misuse of law enforcement data in other contexts. Face recognition poses additional risks because, unlike a social security number or driver’s license number, we can’t change our faces. Law enforcement must do more to explain why it needs to collect so much sensitive biometric and biographic data, why it needs to maintain it for so long, and how it will safeguard it from breaches.”

    •  ”Our biometrics are unique to each of us, can’t be changed, and often are easily accessible. Face recognition, though, takes the risks inherent in other biometrics to a new level because it is much more difficult to prevent the collection of an image of your face. We expose our faces to public view every time we go outside, and many of us share images of our faces online with almost no restrictions on who may access them. Face recognition therefore allows for covert, remote, and mass capture and identification of images. The photos that may end up in a database could include not just a person’s face but also how she is dressed and possibly whom she is with.”  

    •  ”Government surveillance like this can have a real chilling effect on Americans’ willingness to engage in public debate and to associate with others whose values, religion, or political views may be considered different from their own. For example, researchers have long studied the “spiral of silence”— the significant chilling effect on an individual’s willingness to publicly disclose political views when they believe their views differ from the majority.1” 

  • Understand the potential harms to a group (discrimination towards sub-groups).

    •  ”Face recognition disproportionately impacts people of color.Face recognition misidentifies African Americans and ethnic minorities, young people, and women at higher rates than whites, older people, and men, respectively. Due to years of well-documented, racially biased police practices, all criminal databases—including mugshot databases—include a disproportionate number of African Americans, Latinos, and immigrants. These two facts mean people of color will likely shoulder significantly more of the burden of face recognition systems’ inaccuracies than whites.”

    •  ”Due to years of well-documented racially-biased police practices, all criminal databases—including mugshot databases—include a disproportionate number of African Americans, Latinos, and immigrants. These two facts mean people of color will likely shoulder exponentially more of the burden of face recognition inaccuracies than whites.”

    •  ”If job seekers’ faces are matched mistakenly to mug shots in the criminal database, they could be denied employment through no fault of their own. Even if job seekers are properly matched to a criminal mug shot, minority job seekers will be disproportionately impacted due to the notorious unreliability of FBI records as a whole”

  • Understand the potential harms to society (democratic process, public trust in governmental institutions, educational access, jobs redistribution).

    •  Emily Bender claims the real risks and harms are more “about concentration of power in the hands of people, about reproducing systems of oppression, about damage to the information ecosystem, and about damage to the natural ecosystem (through profligate use of energy resources).”

  • Understand the potential harms to a company or institution (reputational, cultural, economic, acceleration risks). 

    • Sensitive Data Exposure:

      • Handling large datasets can lead to unintended exposure of confidential information, including customer and business data, posing risks of identity theft, financial fraud, and loss of public trust. Protection of privacy and data security have been prioritized and will be subject to closer scrutiny as a result of the recent executive order.

    • Cybersecurity Vulnerabilities:

      • Integration of AI with entities’ institutional platforms can create entry points for hackers, risking not just data theft but also potential disruption of operations, particularly supply chains.

    •  Data Control Concerns:

      • Relying on external AI solutions can lead to issues with data control and governance, and can potentially expose companies to additional risks if vendors do not meet ESG or cybersecurity standards.

    •  Opaque Decision Processes:

      • The complexity of AI algorithms, especially in deep learning, often results in a lack of transparency and explainability, making it difficult for stakeholders to understand how decisions are made. This “black box” nature of AI can hinder accountability and trust in AI-driven ESG initiatives.

    •  Accountability Challenges:

      • In cases where AI-driven decisions lead to adverse ESG outcomes, it can be difficult to attribute responsibility, complicating legal and ethical accountability.

    •  Compliance Complexity:

      • AI systems utilized in an effort to enhance ESG performance may not account or keep up with the rapidly expanding number of ESG-related laws, regulations and standards developing across different regions, increasing the risk of inadvertent non-compliance.

    •  Legal Uncertainties:

      • Rapidly evolving AI technologies can outpace existing legal frameworks, creating uncertainties about liability for collection, maintenance and use of data, intellectual property rights, and other legal issues.

  • Understand the potential harms to an ecosystem (natural resources, environment, supply chain). 

    •  High Energy Consumption:

      • The computation-intensive nature of training and running AI, particularly large models, can lead to high energy consumption and significant carbon footprints, potentially contradicting environmental sustainability efforts.

    •  Life Cycle Impact of AI Hardware:

      • The production, operation, and disposal of the hardware necessary for AI (e.g., servers, data centers) contribute to environmental concerns such as electronic waste and resource depletion.

  •  Understand the characteristics of trustworthy AI systems

    • Understand what it means for an AI system to be ″human-centric.″

      •  Creating AI systems that amplify and augment rather than displace human abilities. HCAI seeks to preserve human control in a way that ensures artificial intelligence meets our needs while also operating transparently, delivering equitable outcomes, and respecting privacy.

      •  Human-centered AI learns from human input and collaboration, and continuously  improves based on human feedback.

      •  Human-centered design = prioritizing user needs, requirements, and feedback, and keeping users involved in dev

  • Understand the characteristics of an accountable AI system (safe, secure and resilient, valid and reliable, fair).

    •  The obligation and responsibility of the creators, operators and regulators of an AI system to ensure the system operates in a manner that is ethical, fair, transparent and compliant with applicable rules and regulations (see fairness and transparency).

    •  Accountability ensures the actions, decisions and outcomes of an AI system can be traced back to the entity responsible for it.

    •  Resilient = maintains its level of performance within defined acceptable limits despite real-world or adversarial conditions is described as resilient. Resilience in AI refers to the system's ability to withstand and recover from unexpected challenges, such as cyber-attacks, hardware failures, or unusual input data. This characteristic ensures that the AI system can continue to function effectively and reliably in various conditions, maintaining performance and integrity.

    •  Combines robustness + reliability, with the capacity to adapt and recover

    •  Robustness = system's strength against errors,

    •  reliability ensures consistent performance over time.

    •  Requires roles and responsibilities of AI stakeholders

  • Understand what it means for an AI system to be transparent. Broader concept than explainability

    •  The extent to which information regarding an AI system is made available to stakeholders, including disclosing whether AI is used

    •  It implies openness, comprehensibility and accountability in the way AI algorithms function and make decisions.

  • Understand what it means for an AI system to be explainable. (XAI)

    •   The ability to describe or provide sufficient information about how an AI system generates a specific output or arrives at a decision in a specific context to a predetermined addressee.

    •  XAI is important in maintaining transparency and trust in AI.

    •  explainability specifically targets the regulatory concern about understanding outputs.

    •   "Explainability refers to the understanding of how a black-box model works. The black-box problem exists because some models are too complex for human interpretation. Explainability methods aim to provide meaningful insight into the logic and decision-making of AI systems."


Know common AI principles

  • OECD AI Principles  

    •  = first intergovernmental standard on AI, 2019

    •  Promotes AI that is innovative and trustworthy and that respects human rights and democratic values.

    •  Value-based principles

      •  inclusive growth, sustainable dev, well-being

      •  Human rights and democratic values, incl fairness and privacy

      •  Transparency & explainability

      •  Robustness, security, safety

      •  Accountability

      •  Recommendations for policy

      •  Invest in AI R&D

      •  Foster an inclusive AI-enabling ecosystem

      •  Shape an enabling interoprable governance and policy environment

      •  Build jhuman capacity and prepare for labo rmarket transformation

      •  International cooperation for trustworthy AI

    •  Governments should promote the development of multi-stakeholder, consensus-driven global technical standards for interoperable and trustworthy AI.

  • White House Office of Science and Technology Policy Blueprint for an AI Bill of Rights . 5 principles:

    •  Safe and Effective SystemsYou should be protected from unsafe or ineffective systems.

    •  Algorithmic Discrimination ProtectionsYou should not face discrimination by algorithms and systems should be used and designed in an equitable way

    •  Data PrivacyYou should be protected from abusive data practices via built-in protections and you should have agency over how data about you is used.

    •  Notice and ExplanationYou should know that an automated system is being used and understand how and why it contributes to outcomes that impact you.

    •  Human Alternatives, Considerations, and FallbackYou should be able to opt out, where appropriate, and have access to a person who can quickly consider and remedy problems you encounter.

    •  From Principles to Practice—a handbook for anyone seeking to incorporate these protections into policy and practice

  • High-level Expert Group AI 

    • European Commission appointed a group of experts to provide advice on its artificial intelligence strategy.

      •  Deliverable 1: Ethics Guidelines for Trustworthy AI The document puts forward a human-centric approach on AI and list 7 key requirements that AI systems should meet in order to be trustworthy.

      •  Deliverable 2: Policy and Investment Recommendations for Trustworthy AI 33 recommendations to guide trustworthy AI towards sustainability, growth, competitiveness, and inclusion. At the same time, the recommendations will empower, benefit and protect European citizens.

      •  Deliverable 3: The final Assessment List for Trustworthy AI (ALTAI) A practical tool that translates the Ethics Guidelines into an accessible and dynamic self-assessment checklist. The checklist can be used by developers and deployers of AI who want to implement the key requirements. This new list is available as a prototype web based tool and in PDF format.

      •  Deliverable 4: Sectoral Considerations on the Policy and Investment Recommendations The document explores the possible implementation of the recommendations, previously published by the group, in three specific areas of application: Public Sector, Healthcare and Manufacturing & the Internet of Things.

  • UNESCO Principles  

    •  Good of humanity

    •  Peaceful use

    •  Inclusion

    •  Gender equality

    •  Protection of environment and ecosystems

    •  Tries to articulate values and princiøles and practical realization, via concrete policy recommendations

    •  “ protect, promote and respect human rights and fundamental freedoms, human dignity and equality, including gender equality; to safeguard the interests of present and future generations; to preserve the environment, biodiversity and ecosystems; and to respect cultural diversity in all stages of the AI system life cycle”

  • Asilomar AI Principles

    • 23 principles divided into 3 categories developed at a conference sponsored by the Future of Life Institute (nonprofit)  

      •  Category: research

      •  Category. Ethics and values

      •  Category: longer-term issues

  •  OCED’s Framework for Ethical AI Governance

    •  Self-regulation model

    •  prevent societal harms by balancing innovation with ethical considerations

  •  The Institute of Electrical and Electronics Engineers Initiative (IEEE) on Ethics of Autonomous and Intelligent Systems

    •  “To ensure every stakeholder involved in the design and development of autonomous and intelligent systems is educated, trained, and empowered to prioritize ethical considerations so that these technologies are advanced for the benefit of humanity.”

    •  ethics-by-design

    •  It complements the NIST framework by focusing on ethical risk management,

    •  Eight general principles:

      •  human rights and well-being, transparency, accountability, effectiveness, competence and “awareness of misuse” in addition to “data agency,” giving individuals control over their data

  • CNIL AI Action Plan.  (French)

    • Understanding the functioning of AI systems and their impacts on people:

    •  addressing key data protection issues relevant to the design and operation of AI applications.

    • These issues include the protection of publicly available data on the web against scraping, the protection of data transmitted by users of AI systems, and consequences for the rights of individuals to their data with respect to data collected for training AI applications and the outputs produced by AI systems, among other issues.

    •  Guiding the development of AI that respects personal data: To support organizations innovating in the field of AI and to prepare for the potential passage of the EU AI Act, the CNIL will publish guidance and best practices on several AI topics, including a guide on rules applicable to the sharing and re-use of data as well as recommendations for the design of generative AI systems.

    •   Auditing and controlling AI systems: The CNIL plans to develop a tool to audit AI systems and will continue to investigate complaints lodged with its office related to AI, including generative AI.

 

Domain i.b establish and communicate organizational expectations for AI governance


  •  1 Most important = define roles and responsibiltiies

  •  2 Understand the need for cross-disciplinary collaboration in AI governance program

    •  (ensure UX, anthropology, sociology, linguistics experts are involved and valued).

  •  3 create and deliver training & awareness program to all stakeholders on aI terminology, strategy, governance

  •  4 differentiate approaches to AI governance based on:

    •  Company size….

    •  Maturity….

    •  Industry…

    •  Products & services…

    •  Objectives…

    •  Risk tolerance…

  •  5 identify differences among AI dev, deployers, users from a governance perspective (e.g. re: responsibilities, opportunities, needs)

  

 OECD framework for the classification of AI systems.

  •  https://oecd.ai/en/classification , OECD Framework for the Classification of AI systems (EN)

  •  The Framework is used to:

    •  Promote a common understanding of AI: Identify features of AI systems that matter most, to help governments and others tailor policies to specific AI applications and help identify or develop metrics to assess more subjective criteria (such as well-being impact).

    •  Inform registries or inventories:

      •  help describe systems and their basic characteristics in inventories or registries of algorithms or automated decision systems.

    •   Support sector-specific frameworks:

      •  Provide the basis for more detailed application or domain-specific catalogs of criteria, in sectors such as healthcare or in finance.

    •  Support risk assessment:

      •  Provide the basis for related work to develop a risk assessment framework to help with de-risking and mitigation and to develop a common framework for reporting about AI incidents that facilitates global consistency and interoperability in incident reporting.

    •  Support risk management: Help inform related work on mitigation, compliance and enforcement along the AI system lifecycle, including as it pertains to corporate governance.

  •  classifies AI systems and applications along the following dimensions:

    •  People & Planet- This considers the potential of applied AI systems to promote human-centric, trustworthy AI that benefits people and planet. In each context, it identifies individuals and groups that interact with or are affected by an applied AI system. Core characteristics include users and impacted stakeholders, as well as the application’s optionality and how it impacts human rights, the environment, well-being, society and the world of work.

    •   Economic Context- This describes the economic and sectoral environment in which an applied AI system is implemented. It usually pertains to an applied AI application rather than to a generic AI system, and describes the type of organization and functional area for which an AI system is developed. Characteristics include the sector in which the system is deployed (e.g. healthcare, finance, manufacturing), its business function and model; its critical (or non-critical) nature; its deployment, impact and scale, and its technological maturity.

    •   Data & Input- This describes the data and/or expert input with which an AI model builds a representation of the environment. Characteristics include the provenance of data and inputs, machine and/or human collection method, data structure and format, and data properties. Data & Input characteristics can pertain to data used to train an AI system (“in the lab”) and data used in production (“in the field”).

    •  AI Model- This is a computational representation of all or part of the external environment of an AI system – encompassing, for example, processes, objects, ideas, people and/or interactions that take place in that environment. Core characteristics include technical type, how the model is built (using expert knowledge, machine learning or both) and how the model is used (for what objectives and using what performance measures).

    •  Task & Output- This refers to the tasks the system performs, e.g. personalisation, recognition,forecasting or goal-driven optimisation; its outputs; and the resulting action(s) that influence the overall context. Characteristics of this dimension include system task(s); action autonomy; systems that combine tasks and actions like autonomous vehicles; core application areas like computer vision; and evaluation methods.


tasks of an AI system

  • Predictive AI is finding innumerable use cases across a wide range of industries. If managers knew the future, they would always take appropriate steps to capitalize on how things were going to turn out. Anything that improves the likelihood of knowing the future has high value in business. Predictive AI use cases include financial forecasting, fraud detection, healthcare, and marketing.

  •  Recognition = Identifying and categorising data (e.g. image, video, audio and text) into specific classifications as well as image segmentation and object detection.

    •  Type: supervised classification

  •  Event detection = : Connecting data points to detect patterns, as well as outliers or anomalies.

    •  Type: multiple: ML, unsupervised, reinforcement learning

  •  forecasting=  Using past and existing behaviours to predict future outcomes. 

    • Often used for decision support.

    •  Supervised, descriptive analytics, predictive analytics, projective analytics.

  •  Personalization = Developing a profile of an individual and learning and adapting its output to that individual over time. Ex: recommender system based on search and browning

    •  Type: supervised or reinforcemen tlearning

  •  Interactions support =  Interpreting and creating content to power conversational and other interactions between machines and humans (possibly involving multiple media such as voice, text and images). Examples: chatbots, voice assistants

    •  Types. Semi-supervised, reinforcement

  •  Goal-driven optimization =  Finding the optimal solution to a problem for a cost function or predefined goal. Ex. game playing

  •  Reasoning with knowledge structures infers new outcomes that are possible, if they are not present in existing data, through modelin gand simulation. Ex: expert systems, diagnoses

    •  Type: causal reasoning (not correlation) with AI types beyond ML 

  •  Understand the differences among types of AI systems

  

Weak AI

Strong AI / AGI / deep AI

Limited to perform specific tasks

 

helps convert enormous amounts of data into useful information by identifying patterns and generating predictions.

 

Can’t break rules

Perform intelligent human level activities

Programmed for fixed function

Have the ability to learn, think and perform new activities like humans

It doesn’t have any consciousness or awareness of its own.

It poses creativity, common sense and logic like humans.

They have a goal to complete a task with creative and accurate solutions.

They have a goal to solve problems at a faster pace.

Examples of weak AI include Alexa, Siri and Google Assistant. NLP, Google Maps

(suggesting alternative routes), ChatGPT, Email Spam Filter

There are no real examples of strong AI because it is a hypothetical theory. Some fictional examples are Wall-E and Big Hero 6.

Useful for: Cyber Security, Robots with high intellect, Integration of strong AI in IoT (Internet of Things), Language translation machines

Image recognition systems

 

Understand the basics of machine learning and its training methods (supervised, unsupervised, semi-supervised, reinforcement).

  •  Supervised- work with pre-labeled data. Classification and regression are the most common types of supervised learning algorithms.

    •  “Classification algorithms decide the category of an entity, object or event as represented in the data. The simplest classification algorithms answer binary questions such as yes/no, sales/not-sales or cat/not-cat. More complicated algorithms lump things into multiple categories like cat, dog or mouse.

      •  ex: decision trees, logistic regression, random forest, support vector machines.” 

      •  Classification = discriminative!

    •  Regression algorithms identify relationships within multiple variables represented in a data set. This approach is useful when analyzing how a specific variable such as product sales correlates with changing variables like price, temperature, day of week or shelf location.

      •  Ex: linear regression, multivariate regression, decision tree and least absolute shrinkage and selection operator (lasso) regression.” 

  •  Unsupervised- Automates the process of finding patterns in a dataset.

    •  “Clustering algorithms help group similar sets of data together based on various criteria. Practitioners can segment data into different groups to identify patterns within each group.”

      •  Don’t need human-labelled data

    •  “Dimension reduction algorithms explore ways to compact multiple variables efficiently for a specific problem.”

  •  Semi-supervised- uses a mix of labelled and unlabelled data (which the supervised portions then label)

  •  Reinforcement- used to improve models after they’ve been deployed.The most common reinforcement learning algorithms use various neural networks. 

  • Understand deep learning, generative AI, multi-modal models, transformer models, and the major providers.

    •  Deep learning

      •  “Deep learning is a type of machine learning and artificial intelligence (AI) that imitates the way humans gain certain types of knowledge. Deep learning models can be taught to perform classification tasks and recognize patterns in photos, text, audio and other various data. It is also used to automate tasks that would normally need human intelligence, such as describing images or transcribing audio files.”  

      •  Common techniques include gradient descent, momentum, and backpropagation

      •  Enables a computer to learn by example.

      •  Can be used for digital assistants, fraud detection, and facial recognition

      •  Is able to create accurate predictive models from large amounts of unlabeled, unstructured data

    • Generative AI

      •   Generates content, like images and text. Newer version of AI compared to predictive AI, which recognizes patterns across time. This is a type of deep learning that generates content to resemble existing data.

    • Multi-modal models

      •  A subset of deep learning that deals with the fusion and analysis of data from multiple modalities, such as text, images, video, audio, and sensor data. Combines the strengths of different modalities to create a more complete representation of the data, leading to better performance on various machine learning tasks. 

      •  Multimodal learning presents two primary benefits :

        • Multiple sensors observing the same data can make more robust predictions, because detecting changes in it may only be possible when both modalities are present.

        • The fusion of multiple sensors can facilitate the capture of complementary information or trends that may not be captured by individual modalities

        •  In general, multimodal architectures consist of three parts :

          • Unimodal encoders encode individual modalities. Usually, one for each input modality.

          • A fusion network that combines the features extracted from each input modality, during the encoding phase.

          • A classifier that accepts the fused data and makes predictions.

    • Transformer models

      •  A type of deep learning model, used for Natural Language Processing (NLP). These models can translate text and speech in near-real-time. Transformer models work by processing input data, which can be sequences of tokens or other structured data, through a series of layers that contain self-attention mechanisms and feedforward neural networks. Transformer models are trained using supervised learning, where they learn to minimize a loss function that quantifies the difference between the model's predictions and the ground truth for the given task. 

  • Understand natural language processing: text as input and output.

    •  “the input is a block of text (either written text or text converted from speech), and the output is some desired characteristic of the text, such as its purpose (search query, command, review, etc.) and meaning or tone (positive, negative, angry, biased).”  

  • Understand the difference between robotics and robotic processing automation (RPA).

    •  “The term 'robotics' specifically relates to machines that can see, sense, actuate and, with varying degrees of autonomy, make decisions.” 

    •  “RPA is a software robot that mimics human actions, whereas artificial intelligence is the simulation of human intelligence using computer software.”

  • Understand the AI technology stack

    • “The AI stack is a structural framework comprising interdependent layers, each serving a critical function to ensure the system’s efficiency and effectiveness. Unlike a monolithic architecture, where each component is tightly coupled and entangled, the AI stack’s layered approach allows for modularity, scalability, and easy troubleshooting. This architecture comprises critical components such as data ingestion, data storage, data processing, machine learning algorithms, APIs, and user interfaces.

    •  These layers act as the foundational pillars that support the intricate web of algorithms, data pipelines, and application interfaces in a typical AI system.

    • “The Generative AI tech stack comprises infrastructure, ML models (e.g., GANs, transformers), programming languages, and deployment tools.

      •   It's structured in 3 layers—Applications, Model, and Infrastructure—guiding tech choices for efficient development, cost reduction, and tailored outputs.” 

  • Platforms and applications.

    •  “A well-architected AI tech stack fundamentally comprises multifaceted application frameworks that offer an optimized programming paradigm, readily adaptable to emerging technological evolutions. Such frameworks, including LangChain, Fixie, Microsoft’s Semantic Kernel, and Vertex AI by Google Cloud, equip engineers to build applications equipped for autonomous content creation, semantic comprehension for natural language search queries, and task execution through intelligent agents.”

  • Model types.

    •  Foundation Models (FMs), essentially serving as the cognitive layer that enables complex decision-making and logical reasoning. Large scale, pre-trained models.

    •  Closed-Source Foundation Models- obscures or protects the AI models, provenance of training data, and/or the underlying code. Tends to be faster and can be used via various cloud services.

    •  Open-Source Foundation Models- openly sharing AI models, the provenance of training data and the underlying code. While not as fast, it enables greater scrutiny of underlying code, models and data and often results in improved explainability and security.

  • Compute infrastructure: software and hardware (servers and chips).

    •   Software

      •  “ AI infrastructure will need a software stack that includes machine learning libraries and frameworks (like TensorFlow, PyTorch, or Scikit-learn), a programming language (like Python), and possibly a distributed computing platform (like Apache Spark or Hadoop). You'll also need tools for data preparation and cleaning, as well as for monitoring and managing your AI workloads.” 

    •  Hardware

      •  “Machine learning and AI tasks are often computationally intensive and may require specialized hardware such as GPUs or TPUs. These resources can be in-house, but increasingly, organizations leverage cloud-based resources which can be scaled up or down as needed, providing flexibility and cost-effectiveness.” 

      •  “Accelerator chips optimized for model training and inference workloads”

      •  GPUs (Graphical Processing Units) are well-suited to running AI applications due to their ability to run many tasks concurrently, which significantly enhances processing speed.

  • Understand the history of AI and the evolution of data science

    • 1956 Dartmouth summer research project on AI 

      •  Birth of AI as a field of research

      •  “the conference was “to proceed on the basis of the conjecture that every aspect of learning or any other feature of intelligence can in principle be so precisely described that a machine can be made to simulate it.”

    • Summers, winters and key milestones.

      •  “The peaks, or AI summers, see innovation and investment. The troughs, or AI winters, experience reduced interest and funding.” 

      •  1956–1974: THE GOLDEN YEARS

        •  During the Golden Years of AI, the programs – including computers solving algebra word problems and learning to speak English – seem "astonishing" to most people.

      •  1974–1980: 20TH CENTURY AI WINTER

        •  The first AI winter occurs as the capabilities of AI programs remain limited, mostly due to the lack of computing power at the time. They can still only handle trivial versions of the problems they were supposed to solve.

      •  1987–1993: A RENEWED INTEREST

        •  The business community's fascination and expectations of AI, particularly expert systems, rise. But they are quickly confronted by the reality of their limitations.

  • Understand how the current environment is fueled by exponential growth in computing infrastructure and tech megatrends (cloud, mobile, social, IOT, PETs, blockchain, computer vision, AR/VR, metaverse).

    •  Increasing computing and storage capacities 

    •   Enormous growth in the amount of data available for learning and analysis.

    •  The development of learning machines based on artificial and neural networks.

    •  

Domain i.c Policies and procedures to apply throughout the AI life cycle

 

  • Create and implement policies to ensure ovesight & accountability across all AI life cycle stages, specifically

    •  Use case assessment

    •  Risk management

    •  Ethics by design

    •  Data acquisition and use

    •  Model development

    •  Training & testing

    •  Deploying & monitoring

    •  Documentation & reporting

    •  Incident management

  •  Evaluate and update existing data privacy and security policies for AI

  •  Create and implement policies to manage third-party risk

    •  Make sure you have already thought about your AI strategy and needs - should you buy from a vendor instead of developing in-house?

    •  Identify suppliers that fit your requirements

      •  Reputation and history with AI?

      •  Scan the market, make a shortlist, and sort suppliers by their level of criticality (low to critical)

    •  Due diligence and risk decision

      •  Prioritize risks by use case

      •  Conduct due diligence activities in proportion to the levell fo impact the AI system will have

      •  Higher impact/risk → more info you need from the vendor

    •  Make your risk decision based on due diligence and info received from the vendor

      •  Structure agreements based on the allocation of risks and rewards between the parties.

      •  What controls do you want to add to the contract?

      •  Are risk and compliance requirements clearly defined?

      •  Do we have audit and monitoring rights?

    •  Monitoring, auditing and awareness

      •  Monitor performance - as expected or drift?

      •  Can you add to the system?

      •  Who is responsible for the contract?

      •  Are regular reassessments conducted?

    •  Offboarding

      •  How will you revoke supplier access to systems and data?

      •  What is the process for secure data return or destruction?

      •  Do you need ot replace the vendor? Or will you go for a new solution?

    •  Supply chain

    •  Human resources


Extra?

  •  Understand the similarities and differences among existing and emerging ethical guidance on AI: Understand how the ethical guidance is rooted in Fair Information Practices (FIPPs), European Court of Human Rights, and Organization for Economic Cooperation and Development principles.

  •  Fair Information Practicies (FIPPS)- a collection of widely accepted principles that agencies use when evaluating information systems, processes, programs, and activities that affect individual privacy. The FIPPs are not requirements; rather, they are principles that should be applied by each agency according to the agency’s particular mission and privacy program requirements. 

    •  Access and Amendment- Agencies should provide individuals with appropriate access to PII and appropriate opportunity to correct or amend PII.

    •  Accountability- Agencies should be accountable for complying with these principles and applicable privacy requirements, and should appropriately monitor, audit, and document compliance. Agencies should also clearly define the roles and responsibilities with respect to PII for all employees and contractors, and should provide appropriate training to all employees and contractors who have access to PII.

    •  Authority- Agencies should only create, collect, use, process, store, maintain, disseminate, or disclose PII if they have authority to do so, and should identify this authority in the appropriate notice.

    •  Minimization- Agencies should only create, collect, use, process, store, maintain, disseminate, or disclose PII that is directly relevant and necessary to accomplish a legally authorized purpose, and should only maintain PII for as long as is necessary to accomplish the purpose.

    •  Quality and Integrity- Agencies should create, collect, use, process, store, maintain, disseminate, or disclose PII with such accuracy, relevance, timeliness, and completeness as is reasonably necessary to ensure fairness to the individual.

    •  Individual Participation- Agencies should involve the individual in the process of using PII and, to the extent practicable, seek individual consent for the creation, collection, use, processing, storage, maintenance, dissemination, or disclosure of PII. Agencies should aso establish procedures to receive and address individuals’ privacy-related complaints and inquiries.

    •  Purpose Specification and Use Limitation- Agencies should provide notice of the specific purpose for which PII is collected and should only use, process, store, maintain, disseminate, or disclose PII for a purpose that is explained in the notice and is compatible with the purpose for which the PII was collected, or that is otherwise legally authorized.

    •  Security- Agencies should establish administrative, technical, and physical safeguards to protect PII commensurate with the risk and magnitude of the harm that would result from its unauthorized access, use, modification, loss, destruction, dissemination, or disclosure.

    •  Transparency- Agencies should be transparent about information policies and practices with respect to PII, and should provide clear and accessible notice regarding creation, collection, use, processing, storage, maintenance, dissemination, and disclosure of PII.

  •  European Court of Human Rights  Rules on individual or State applications alleging violations of the civil and political rights set out in the European Convention on Human Rights.

  •   OECD principles ==   Ensuring the basis of an effective corporate governance framework The corporate governance framework should promote transparent and efficient markets, be consistent with the rule of law and clearly articulate the division of responsibilities among different supervisory, regulatory and enforcement authorities.

    •  The rights and equitable treatment of shareholders and key ownership functions

    • ‘The corporate governance framework should protect and facilitate the exercise of shareholders’ rights and ensure the equitable treatment of all shareholders, including minority and foreign shareholders. All shareholders should have the opportunity to obtain effective redress for violation of their rights.’

    • Basic shareholder rights should include the right to:

      •  Secure methods of ownership registration;

      •  Convey or transfer shares;

      •  Obtain relevant and material information on the corporation on a timely and regular basis;

      •  Participate and vote in general shareholder meetings;

      •  Elect and remove members of the board; and

      •  Share in the profits of the corporation.

    •  Institutional investors, stock markets, and other intermediaries‘The corporate governance framework should provide sound incentives throughout the investment chain and provide for stock markets to function in a way that contributes to good corporate governance.’

      •  All shareholders of the same series of a class should be treated equally

      •  Insider trading and abusive self-dealing should be prohibited

      •  Members of the board and key executives should be required to disclose to the board whether they, directly, indirectly or on behalf of third parties, have a material interest in any transaction or matter directly affecting the corporation.

    •  The role of stakeholders in corporate governance

      • The corporate governance framework should recognize the rights of stakeholders established by law or through mutual agreements and encourage active co-operation between corporations and stakeholders in creating wealth, jobs, and the sustainability of financially sound enterprises.

    •  Disclosure and transparency = The corporate governance framework should ensure that timely and accurate disclosure is made on all material matters regarding the corporation, including the financial situation, performance, ownership, and governance of the company.

    •  The responsibilities of the board = The corporate governance framework should ensure the strategic guidance of the company, the effective monitoring of management by the board, and the board’s accountability to the company and the shareholders.

  


Comments


bottom of page