Start from the work you do.

Six routes through the site, one per audience. Each names the questions that audience brings, walks the chapters, patterns, tools, templates, datasets and figures in the order it needs them, and lists the obligations that matter most to it.

Whatever your route, what AI governance means is the common ground: the definition and the frameworks every route builds on.

The questions each audience brings.

Three per route, answered in brief on each hub and in full in the Body of Knowledge.

The three questions each audience brings, by route
Route Questions
For engineers
  • What do I actually have to build?
  • Which tests count as evidence?
  • What must the running system record?
For CISOs and risk leads
  • Where does AI risk sit in the framework we already have?
  • Which threats are new, and what contains them?
  • When it fails, who do we tell, and by when?
For legal counsel and DPOs
  • Which role do we hold, and for which system?
  • How do the FRIA and the DPIA fit together?
  • What must we tell the people affected?
For executives and boards
  • Which decisions are ours to take?
  • What should we see in the board pack?
  • What does the law already expect of us?
For the public sector
  • Do we need a fundamental rights impact assessment?
  • What has to be public, and to whom?
  • What about the systems we already run?
For SMEs and start-ups
  • What is the least we must do?
  • Does the EU AI Act ease anything for small companies?
  • We only use third-party AI. What is ours to do?

Or start with the argument.

The Thesis sets out why governance has to run in the system, not sit beside it.