Do you actually know
what AI governance is?
Most people who answer “yes” name a tool. Ten questions on the distinctions underneath — the ones that decide whether anything you have bought actually protects you.
This matters more than it sounds. If a team cannot separate governance from observability, or due care from due diligence, then no amount of tooling produces a defensible position: there is no documented decision, no named owner, and nothing to hand an auditor, an underwriter or opposing counsel. Literacy is not the soft part of this subject. It is the precondition for every control that follows — which is why EU AI Act Article 4 has required it of providers and deployers since February 2, 2025.
Every answer traces to the SanctumShield Academy field guide, the single source behind its role-based tracks and certification exam. Nothing leaves your browser.
An organization has a strong AI policy that everyone follows, but it was never written down, dated or approved. In governance terms, what do they have?
Choose an answer to see the evidence
EU AI Act Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy among the people operating AI on their behalf. It has been in force since February 2, 2025 — the Digital Omnibus split the Act’s timeline but did not defer this. ISO/IEC 42001 makes competence a documented, auditable management-system requirement rather than an assumed background condition.
Both ask for the same two things: build the competence, and be able to show that you built it. A quiz is not that record. The Academy is built to produce it — role-based tracks, a deterministic examination, and Training and Acknowledgment Records that evidence the programme exists.