New Cohort Starts:

Donate
← Back to the skill map
Reliability & Operations/AI & reliability

AI Safety & Governance

10 micro-topics in Reliability & Operations, each with the evidence that proves you have it and the written reason behind every link. Before you start, it rests on 9 other domains. Downstream, it holds up 3 domains.

10 topics  ·  depth 2–15 of 16  ·  6 internal links  ·  12 in  ·  3 out

Before you start

Load-bearing links first. Each one says what in this domain rests on what outside it, and why.

Observability

3 links

load-bearing

Prevent PII leakage rests on Keep sensitive data out of logs

Redaction in logs is the first version of this control.

load-bearing

Make AI decisions explainable rests on Trace LLM applications

Explanation draws on the recorded path.

load-bearing

Maintain audit trails rests on Correlate logs across services

An audit trail is correlated logging with retention.

Retrieval (RAG)

2 links

load-bearing

Defend against prompt injection rests on Inject retrieved context

Retrieved content is untrusted input in the prompt.

load-bearing

Prevent PII leakage rests on Inject retrieved context

Retrieval can pull personal data into a prompt.

Delivery & CI/CD

1 link

load-bearing

Run an AI incident response rests on Roll back safely

Containment usually means reverting.

Documentation

1 link

load-bearing

Run an AI incident response rests on Write a runbook

Incident response runs from a runbook.

LLM Evals

1 link

load-bearing

Measure and mitigate bias rests on Build an evaluation dataset

Fairness metrics run over an evaluation set.

Data Ingestion

1 link

load-bearing

Recognize data poisoning risk rests on Build a repeatable ingestion pipeline

Poisoning targets the ingestion path.

Model Foundations

1 link

load-bearing

Identify sources of bias rests on Compare learning paradigms

Bias enters through training data.

Model Integration

1 link

load-bearing

Implement content safety filters rests on Configure safety settings

Provider settings are the first filter; yours is the second.

Prompt Engineering

1 link

load-bearing

Defend against prompt injection rests on Structure prompts for reliable parsing

Injection attacks the boundary between instruction and data.

What you will be able to do

In prerequisite order. Each idea names the artifact that closes it, the market demand that put it on the map, and what it stands on.

Depth 2  ·  conceptual  ·  unassisted  ·  M25 §25.1

Identify sources of bias

Traces unfair output to data and design

Evidence
Names a plausible bias source in a real system
Market anchor
AI ethics
Rests on
load-bearing

Compare learning paradigms · Model Foundations

Bias enters through training data.

Depth 6  ·  meta  ·  guided  ·  M25 §25.1

Measure and mitigate bias

Applies fairness metrics and monitors over time

Evidence
Reports a fairness metric before and after a change
Market anchor
AI ethics
Rests on
load-bearing

Identify sources of bias

You measure the thing you can name.

load-bearing

Build an evaluation dataset · LLM Evals

Fairness metrics run over an evaluation set.

Depth 6  ·  meta  ·  guided  ·  M25 §25.3

Make AI decisions explainable

Surfaces why a system produced an output

Evidence
A user-facing explanation survives scrutiny
Market anchor
AI governance
Rests on
load-bearing

Trace LLM applications · Observability

Explanation draws on the recorded path.

Depth 8  ·  representational  ·  scaffolded  ·  M25 §25.3

Maintain audit trails

Records what the system did and on what basis

Evidence
Reconstructs a past decision from the audit log
Market anchor
AI governance · compliance
Rests on
load-bearing

Correlate logs across services · Observability

An audit trail is correlated logging with retention.

Depth 9  ·  conceptual  ·  guided  ·  M25 §25.4

Apply AI governance frameworks

Works within GDPR, ISO 42001 and model cards

Evidence
Produces a model card for a shipped feature
Market anchor
AI governance · compliance
Rests on
load-bearing

Maintain audit trails

Compliance requires evidence.

load-bearing

Make AI decisions explainable

Model cards and disclosures are explanation artifacts.

Depth 10  ·  conceptual  ·  guided  ·  M25 §25.2

Recognize data poisoning risk

Knows how corrupted inputs propagate

Evidence
Names the ingestion point an attacker would target
Market anchor
AI security
Rests on
load-bearing

Build a repeatable ingestion pipeline · Data Ingestion

Poisoning targets the ingestion path.

supporting

Defend against prompt injection

Both treat inputs as an attack surface.

Depth 11  ·  meta  ·  guided  ·  M25 §25.4

Run an AI incident response

Detects, contains and reports a failure

Evidence
Executes an incident runbook in a drill
Market anchor
Incident response
Rests on
load-bearing

Apply AI governance frameworks

Reporting obligations shape the response.

load-bearing

Roll back safely · Delivery & CI/CD

Containment usually means reverting.

load-bearing

Write a runbook · Documentation

Incident response runs from a runbook.

Depth 14  ·  conceptual  ·  scaffolded  ·  M25 §25.2

Defend against prompt injection

Treats retrieved and user content as untrusted

Evidence
An injected instruction in a document is not executed
Market anchor
AI security
Rests on
load-bearing

Structure prompts for reliable parsing · Prompt Engineering

Injection attacks the boundary between instruction and data.

load-bearing

Inject retrieved context · Retrieval (RAG)

Retrieved content is untrusted input in the prompt.

Depth 14  ·  conceptual  ·  unassisted  ·  M25 §25.2

Prevent PII leakage

Keeps personal data out of prompts, logs and outputs

Evidence
A red-team prompt fails to extract stored data
Market anchor
Privacy · AI security
Rests on
load-bearing

Keep sensitive data out of logs · Observability

Redaction in logs is the first version of this control.

load-bearing

Inject retrieved context · Retrieval (RAG)

Retrieval can pull personal data into a prompt.

Depth 15  ·  procedural  ·  scaffolded  ·  M25 §25.5

Implement content safety filters

Blocks disallowed content on input and output

Evidence
Filter blocks a harmful request and logs it
Market anchor
AI safety
Rests on
load-bearing

Configure safety settings · Model Integration

Provider settings are the first filter; yours is the second.

load-bearing

Defend against prompt injection

Filters implement the defense.

What rests on this domain

Everything downstream that names an idea here as a prerequisite, grouped by where it lives.

Harness Engineering

1 link

load-bearing

Write a policy layer rests on Defend against prompt injection

Untrusted input is the reason the policy exists.

Agents

1 link

supporting

Insert human approval rests on Maintain audit trails

Approvals are only meaningful if they are recorded.

Delivery & CI/CD

1 link

supporting

Run a production readiness review rests on Implement content safety filters

Safety measures are part of the launch review.

Retool. Retrain. Relaunch.

375 ideas. 17 weeks. No tuition, ever.

Vets Who Code is a veteran-run 501(c)(3). The accelerator is free, remote, and we don’t take a share of your first paycheck.

Free · Remote · 17 weeks · EIN 86-2122804