මධ්‍යම දිනයක් · පැය 6ක්

AI Governance and Responsible Use

One day for the people who sign off AI use and have to answer for it afterwards

මෙම පාඨමාලාව ගැන

AI governance fails in two recognisable ways. The first is a policy document that circulates once and is never opened again. The second is a blanket ban, which moves the same activity onto personal accounts where nobody can see it. This day is designed to produce neither. It is six hours of assembly work, and you leave with documents that an auditor, a client or a regulator can actually be shown.

The morning begins with the register, because nothing can be governed until it has been listed. You build an inventory of the AI systems your organisation genuinely uses, each with an owner, a purpose, the data it touches and its approval status, and you work out how to surface the tools bought quietly on a personal card without pushing them further out of sight. Every entry is then classified by risk, by data sensitivity and by what a wrong output would cost, so that each tier gets a proportionate control rather than one rule stretched across everything.

You then map those controls onto work that has already been done for you. The NIST AI Risk Management Framework and ISO/IEC 42001 give you a structure to borrow from without committing to a full management system in one quarter, and the EU AI Act risk tiers tell you which uses are prohibited, which count as high risk and which carry transparency obligations. The Act applies in phases and its timetable has been amended since it entered into force, so the session works from the position current on the day you attend. Data protection runs alongside: Sri Lanka's Personal Data Protection Act No. 9 of 2022, and GDPR or UK GDPR where your customers and clients bring them into scope, with the practical questions of lawful basis, purpose, retention, cross-border transfer, and what a data subject request means when part of the answer is sitting in a chat log. This is orientation for the people who run the process. It is not legal advice and it does not replace your own advisers.

The afternoon is about controls that hold. Human oversight only counts if the reviewer has the time, the information and the authority to overturn an output, so you design a review step that meets that test rather than one that produces a signature. You write a disclosure standard covering what is labelled as AI-assisted, what clients are told, and where provenance is attached using Content Credentials and the underlying C2PA standard. You run a simple fairness check on a real decision your organisation makes and record what you found, comfortable or otherwise. And you assemble the documentation an audit will ask for before it asks.

The day closes on vendors and incidents: the due diligence questions that decide whether a tool is usable at all, the contract terms worth arguing over, and a procedure for the day an AI system produces something harmful, covering who is told, how it is contained, what is recorded and who reviews it afterwards. You finish with a twelve-week plan naming the first three things to do and who owns each. Runs live online, in the classroom in Colombo, or privately for a leadership, compliance or risk team, priced in LKR for Sri Lanka and USD internationally.

ඔබට කළ හැකි වන දේ

  • Build a register of the AI systems and assistants your organisation uses, with an owner, a purpose, the data involved and an approval status for each.
  • Surface unapproved AI use in a way that brings it into the register rather than driving it further underground.
  • Classify each use by risk, data sensitivity and the cost of a wrong output, and set a proportionate control level for each tier.
  • Map your controls to the NIST AI Risk Management Framework and ISO/IEC 42001 without adopting an entire management system at once.
  • Identify where the EU AI Act risk tiers apply to what you do, and what evidence each tier expects you to hold.
  • Work out lawful basis, purpose, retention and cross-border transfer for personal data entering an AI system under Sri Lanka's Personal Data Protection Act and, where relevant, GDPR.
  • Design a human oversight step the reviewer can genuinely perform, with the time, the information and the authority to overturn the output.
  • Write a disclosure standard covering AI-assisted work, client notification and provenance with Content Credentials.
  • Run a fairness check on a real decision your organisation makes, and record the method and the result.
  • Assemble a vendor due diligence pack and an incident procedure covering reporting, containment, record and review.

මෙය කා සඳහාද

  • Compliance, risk and data protection officers writing an organisation's first AI standard
  • IT and information security managers approving AI tools and handling access
  • Heads of HR, finance and operations where AI touches decisions about people or money
  • Agency and consultancy owners answering client due diligence questions about AI use
  • Directors and company secretaries accountable for AI at board level

කලින් ඔබට අවශ්‍ය දේ

  • You should have some responsibility for approving, buying, auditing or setting the rules for AI use in your organisation.
  • No technical or legal background is required, and nothing in the day is legal advice.
  • Bring a list of the AI tools your organisation currently uses, and any client questionnaire you have been asked to complete.

ඉදිරි දින

ඉදිරි දින, මිල සහ ඉතිරි ආසන සමඟ
කවදාද කෙසේද කොහේද ආසන මිල වෙන් කරන්න
22 Sep 2026 09:00–16:00 +0530 සජීවී ඔන්ලයින් ඔන්ලයින් ආසන තිබේ $495.00
6 Oct 2026 09:00–16:00 +0530 මුහුණට මුහුණ ආසන තිබේ $594.00
13 Oct 2026 09:00–16:00 +0530 සජීවී ඔන්ලයින් ඔන්ලයින් ආසන තිබේ $495.00
3 Nov 2026 09:00–16:00 +0530 සජීවී ඔන්ලයින් ඔන්ලයින් ආසන තිබේ $495.00
17 Nov 2026 09:00–16:00 +0530 මුහුණට මුහුණ ආසන තිබේ $594.00
24 Nov 2026 09:00–16:00 +0530 සජීවී ඔන්ලයින් ඔන්ලයින් ආසන තිබේ $495.00
ඕනෑම වේලාවක පටන් ගන්න ස්වයං වේගයෙන් ඔන්ලයින් නිතරම තිබේ $99.00

අප ආවරණය කරන දේ

ඉගැන්වෙන අන්තර්ගතය පැය 6ක් පමණ

Module 1 — Knowing what you have

The register, the owners and the tools nobody declared.

  • What AI governance is for, and the two ways it usually fails 20 min
  • Building the register: system, owner, purpose, data, approval status 30 min
  • Finding unapproved AI use without driving it further underground 25 min
Module 2 — Risk, frameworks and the law

Classifying each use, then borrowing structure from frameworks instead of inventing your own.

  • Classifying use by risk, data sensitivity and the cost of being wrong 30 min
  • Mapping controls to the NIST AI Risk Management Framework and ISO/IEC 42001 25 min
  • EU AI Act risk tiers: prohibited uses, high risk, transparency duties and general-purpose models 25 min
  • Sri Lanka's Personal Data Protection Act, GDPR and personal data inside AI systems 25 min
Module 3 — Controls that hold

Oversight, disclosure, fairness testing and the documentation an audit asks for.

  • Human oversight that is real: time, information, authority and a record of the decision 30 min
  • Disclosure and labelling, and provenance with Content Credentials and the C2PA standard 25 min
  • Fairness: testing a real decision your organisation makes and writing down what you found 30 min
  • Documentation: system records, data descriptions and what you keep for an audit 20 min
Module 4 — Vendors, incidents and the first twelve weeks

Due diligence, what to do when something goes wrong, and a plan with named owners.

  • Third-party due diligence: training on your data, retention, processing location, logging and exit 25 min
  • Incidents: reporting a bad output, containment, the record and the review 25 min
  • A twelve-week plan: the first three actions, who owns them and what goes to the board 25 min

උගන්වන්නේ කවුද

MyLearnPlus AI Faculty

Working practitioners teaching the AI and generative AI track

The AI track is taught by people who use these tools in paid work every week: prompt and workflow design, assistants deployed inside real teams, automation built and maintained, generative imagery taken to a finished deliverable, and the governance conversations that follow. We are deliberate about credentials here. There is no independent, universally recognised certification for generative AI practice in the way there is for Adobe software, so we do not display one. What we require instead is evidence: work that shipped, tools used in production rather than demonstrated once, and the ability to say clearly where a model is unreliable. An instructor who cannot show you a failure case is not ready to teach this material.

Because the tools change between cohorts, the AI faculty carry an obligation the Adobe faculty do not: every course is re-checked against the current versions of the products it teaches before each scheduled run, and anything that has moved is corrected in the slides, the exercise files and the workbook. Classes are staffed one instructor per cohort, named in your joining instructions, with a second instructor assisting on large private groups and on hands-on build sessions where people need help at their own screen. A new instructor teaches the syllabus under observation before running it alone, and a substitute teaches the same syllabus from the same materials.

ගුරු මණ්ඩලය ගැන තව කියවන්න

ඇතුළත් වන දේ

  • Class recording, available for 12 months
  • Editable templates: AI register, risk classification, disclosure standard, vendor due diligence pack and incident procedure
  • Course workbook with the frameworks and the mapping tables used in each exercise
  • Control checklist mapped to the NIST AI Risk Management Framework and ISO/IEC 42001
  • MyLearnPlus certificate of completion
  • Instructor email support after the class for questions on your draft documents
  • One free repeat of the same live class, terms shown on the booking page

ඉගෙනුම්කරුවන් කියන දේ

තවම සමාලෝචන නැත. මෙම පාඨමාලාව අලුතින් ප්‍රකාශයට පත් කළ එකකි, අප විසින්ම ලියූ දෙයක් ඔබට පෙන්වනවාට වඩා කිසිවක් නොපෙන්වීම අපි කැමැත්තෙමු. ඉගෙනුම්කරුවන් සමාලෝචන තබන විට ඒවා මෙහි පෙනෙනු ඇත.

මිනිසුන් අසන ප්‍රශ්න

Is any of this legal advice?
No. The course is orientation and process design for the people who run AI governance day to day. It tells you what to establish, what to record and which questions to put to your legal or compliance contact. Obligations under Sri Lanka's Personal Data Protection Act, GDPR and the EU AI Act are covered so that you know what is in scope and what evidence is expected. Sign-off stays with your own advisers.
How is this different from AI for Managers?
AI for Managers is a decision day: which use cases are worth doing, what a pilot costs and how to brief upwards. This is the day after that decision has been taken. It covers the register, risk classification, oversight design, disclosure, fairness testing, vendor due diligence and incident handling, in the detail an audit or a client questionnaire asks for. The two overlap only on vendor questions, which are taken considerably further here.
We only use ChatGPT and Microsoft Copilot. Is a governance day not excessive?
That is the most common starting position, and it is exactly what the register is for. The questions do not change with scale: which staff use what, on which data, with whose approval, who checks the output before it is relied on, and what happens when it is wrong. A small organisation can answer all of that in a day and end up better governed than a large one with a policy nobody reads.
We do not sell into the EU. Why does the EU AI Act matter to us?
Because it usually reaches you through a customer before it reaches you directly. Sri Lankan agencies, outsourcing providers and software firms are increasingly asked AI questions in client due diligence, and those questionnaires are written against the Act and against ISO/IEC 42001. The session covers where the Act applies, where it does not, and how to answer a questionnaire honestly when the true answer is that a control is not in place yet.
Do I need my own laptop?
Yes. The whole day is document work: a register, a risk classification, a disclosure standard, a due diligence pack and an incident procedure, all in editable templates you take away. Bring your list of tools in use and any client questionnaire you have been asked to complete, since those make the best material for the afternoon exercises.
What if I miss the day, and do you issue a certificate?
The session is recorded and available to you for twelve months, and every live booking includes one free repeat of the same class, with the terms shown on the booking page for each date. You receive a MyLearnPlus certificate of completion recording the course title, hours and date, which is a record of training rather than an industry credential or a compliance certification.
Can you run this privately, and can my employer be invoiced?
Yes to both, and a private run is the most common way this course is booked. It uses your own tool inventory, your own data categories and your own client questionnaires, so the register and the control set you finish with are real rather than illustrative. We invoice organisations against a purchase order, in LKR for Sri Lankan companies and in USD internationally.

මධ්‍යම දිනයක්

AI for Managers

One day for managers: score AI use cases against your own workload, draft an acceptable use policy, question vendors properly and plan a pilot you can measure.

උසස් දින 2ක්

Building with LLM APIs

Two days of Python against the OpenAI and Anthropic APIs: streaming, tool use, structured output, retrieval, evaluation and a bill you can predict.

කණ්ඩායමකට මෙය අවශ්‍යද?

ඔබේ දිනවල, ඔබේ කාර්යාලයේ හෝ ඔන්ලයින්ව, ඔබේ කණ්ඩායම සැබවින්ම කරන වැඩට ගළපා අපි මෙම පාඨමාලාව පෞද්ගලිකව පවත්වන්නෙමු. ඔබට අවශ්‍ය දේ අපට කියන්න, අපි මිල ගණනක් එවන්නෙමු.

මිල ගණනක් ලබා ගන්න