AI risk is a system property. It depends on data, sources, permissions, workflow decisions, deployment, reviewers, logs, vendors, and the ability to contain failure. This section turns those concerns into concrete control artifacts.
What You Will Be Able to Do
- Classify data and choose safer processing routes.
- Evaluate private and open-source deployment choices without treating hosting as a complete privacy solution.
- Design risk-tiered human review, access, logging, and retention.
- Operate evaluation, monitoring, rollback, and incident response.
Guided Sequence
Data and deployment decisions
- When Not to Send Data to a Public LLM — A data-routing decision matrix covering sensitivity, authorization, contracts, retention, and safer alternatives.
- Anonymize Customer Data with AI — A de-identification protocol with data inventory, transformation rules, residual-risk testing, and approval.
- Open-Source LLMs You Can Host — A hostable-model shortlist assessed for task fit, license, hardware, security, evaluation, and support.
- Deploy Your Own Private LLM — A private-inference architecture decision covering threat model, operations, cost, controls, and ownership.
Review and system controls
- How to Design Human Review for AI Systems — A risk-tiered review matrix defining triggers, evidence, approvers, correction logging, and escalation.
- AI Access Control, Logging, and Retention Policies — An AI access, logging, and retention standard mapped to roles, data classes, and evidence needs.
Third-party and production governance
- AI Vendor Risk Assessment and Procurement Checklist — A documented vendor assessment covering data, security, model controls, contracts, operations, and exit.
- AI Evaluation, Monitoring, and Incident Response for Production Systems — A production evaluation plan with monitored indicators, rollback triggers, incident roles, and evidence requirements.
Lesson Library
| Lesson | Level | Time | Learner output |
|---|---|---|---|
| When Not to Send Data to a Public LLM | Beginner | 15 min | A data-routing decision matrix covering sensitivity, authorization, contracts, retention, and safer alternatives. |
| Anonymize Customer Data with AI | Intermediate | 15 min | A de-identification protocol with data inventory, transformation rules, residual-risk testing, and approval. |
| Open-Source LLMs You Can Host | Advanced | 20 min | A hostable-model shortlist assessed for task fit, license, hardware, security, evaluation, and support. |
| Deploy Your Own Private LLM | Advanced | 20 min | A private-inference architecture decision covering threat model, operations, cost, controls, and ownership. |
| How to Design Human Review for AI Systems | Intermediate | 15 min | A risk-tiered review matrix defining triggers, evidence, approvers, correction logging, and escalation. |
| AI Access Control, Logging, and Retention Policies | Advanced | 20 min | An AI access, logging, and retention standard mapped to roles, data classes, and evidence needs. |
| AI Vendor Risk Assessment and Procurement Checklist | Advanced | 20 min | A documented vendor assessment covering data, security, model controls, contracts, operations, and exit. |
| AI Evaluation, Monitoring, and Incident Response for Production Systems | Advanced | 20 min | A production evaluation plan with monitored indicators, rollback triggers, incident roles, and evidence requirements. |
Completion Standard
A lesson is complete when the stated learner output has been produced, reviewed against representative evidence, and assigned an owner or next decision. Reading the page without producing the artifact is orientation, not completion.
Practice Case
Use the Harborline Services running case when you do not have safely redacted examples from your own organization.
Where to Go Next
- Return to the Academy home
- Browse the Academy Practice Cases