Concept library
883 concepts across 20 domains and 101 tracks. Each track is a coherent sequence — read it top to bottom or dip in wherever the gap is.
All domains
01Foundations
02Transformer Internals
03Training & Fine-Tuning
04Reinforcement Learning
05Inference, Systems & Hardware
06Applied LLM Engineering
07Reasoning, Evaluation & Safety
08Multimodal & Applications
09Classical ML & Statistical Learning
10Causal Inference & Experimentation
11Time Series & Forecasting
12Graphs, Recommenders & Structured Data
13Generative Modelling Beyond Transformers
14Efficiency, Compression & Edge AI
15Search & Information Retrieval
16Data & Feature Engineering
17MLOps & Platform Engineering
18Security, Privacy & Adversarial ML
19Governance, Risk & Responsible AI
20Human-AI Interaction, Product & Economics
19
Governance, Risk & Responsible AI
Frameworks, regulation and audit evidence, treated as engineering rather than paperwork.
5tracks
25concepts
284cards
3.0hreading
AI Governance Frameworks NIST AI RMF, ISO/IEC 42001, internal review boards, and turning principles into gates that actually block. 5 concepts · 54 cards
- 01 ISO/IEC 42001 and Certifiable Management Systems What a management system standard certifies, why certification is about process consistency rather than model quality, and where it fits alongside a risk framework.
- 02 Risk Tiering and Impact Assessment How to classify AI systems by consequence rather than by technology, what an impact assessment should establish before a system is built, and why the affected-population question is the one that changes designs.
- 03 The NIST AI Risk Management Framework What the four functions of the AI RMF actually ask an organisation to do, why Govern is the one that determines whether the rest happens, and what a voluntary framework can and cannot deliver.
- 04 Incident Response for AI Systems Why an AI incident often has no error to page on, what detection has to rely on instead, and the response steps that differ from a conventional outage.
- 05 Turning Principles into Gates That Block Why AI principles documents change nothing on their own, the properties a gate needs to have force, and the design that keeps a review board from becoming either a bottleneck or a formality.
AI Regulation & Compliance The EU AI Act risk tiers, sectoral rules, transparency obligations and evidence a regulator will accept. 5 concepts · 52 cards
- 01 The AI Act Compliance Timeline as It Now Stands The phased application dates, the deferral of high-risk obligations agreed in 2026, and what remained on the original schedule when the rest moved.
- 02 The EU AI Act Risk Tiers How the Act classifies systems into prohibited, high-risk, transparency-obligated and minimal, why the classification turns on use rather than technology, and where the boundaries are genuinely unclear.
- 03 Evidence a Regulator Will Accept The difference between a policy and evidence of its operation, what an assessor actually asks for, and how to instrument a system so compliance artefacts are produced automatically rather than assembled retrospectively.
- 04 Provider and Deployer Obligations Why the same system carries different duties depending on your role, the actions that turn a deployer into a provider, and how the split shapes contracts between the two.
- 05 Sectoral Rules and Overlapping Regimes Why the AI Act is rarely the only regime applying, how data protection, sector rules and product safety interact with it, and the practical approach to satisfying several at once.
Fairness & Bias Group and individual criteria, impossibility results, measurement under missing attributes, and mitigation costs. 5 concepts · 60 cards
- 01 Where Bias Enters the Pipeline The six distinct points at which disparity is introduced, why calling them all "biased data" prevents fixing them, and which stage each mitigation actually addresses.
- 02 Bias in Generative Models Why classification fairness metrics do not transfer to open-ended generation, the harm categories that appear instead, and the evaluation approaches that produce actionable findings.
- 03 Group Fairness Criteria and Why They Conflict Demographic parity, equalised odds and calibration stated precisely, the impossibility result showing you cannot have all three, and what choosing between them commits you to.
- 04 Measuring Fairness Without the Attribute The methods for estimating disparity when group membership is unavailable, why proxy inference introduces error in a direction that matters, and how to report a result built on an estimate.
- 05 Mitigation at Pre-, In- and Post-Processing The three points at which a fairness intervention can act, what each costs in accuracy and in flexibility, and the legal constraint that decides which are available.
Transparency & Documentation Model and system cards, datasheets, disclosure of evaluations, and documentation that survives an audit. 5 concepts · 60 cards
- 01 Datasheets for Datasets The questions a dataset's documentation has to answer for someone deciding whether to use it, why the composition and collection sections carry the weight, and what happens when a dataset outlives the answers.
- 02 Disclosure Without Overclaiming What honest capability communication looks like, why published evaluation numbers mislead by default, and the specific claims that most often outrun their evidence.
- 03 Documentation That Survives an Audit The properties that separate documentation an assessor accepts from documentation they discount, why generated beats written, and how to structure a technical file so it stays true as the system changes.
- 04 Explaining a Decision to the Person Affected Why feature attributions are not explanations for a subject, what a counterfactual explanation provides instead, and the gap between technical interpretability and the account a person is owed.
- 05 System Cards and Documenting the Whole Pipeline Why documenting a model is insufficient when behaviour is produced by a pipeline, what a system card adds, and how to keep documentation current when the system changes weekly.
AI Assurance & Audit Third-party evaluation, red-team evidence, incident reporting, and control testing for AI systems. 5 concepts · 58 cards
- 01 Assurance for Continuously Changing Systems Why point-in-time assurance is a poor fit for systems that retrain weekly, what continuous assurance requires instead, and how to define the change that resets the conclusion.
- 02 Control Testing for AI Systems How to test whether a stated control actually operates, the difference between design and operating effectiveness, and the AI-specific controls whose testing is unfamiliar to conventional auditors.
- 03 Independent Evaluation and Structured Access Why external scrutiny requires access that providers have reasons to withhold, the mechanisms proposed to reconcile the two, and what safe harbour would need to cover.
- 04 Red-Team Evidence and Its Limits What a red-team exercise contributes to an assurance case, why coverage cannot be quantified, and how to report results so they inform a decision rather than reassuring the reader.
- 05 What an AI Audit Can and Cannot Establish The three things an audit might mean, why access level determines what conclusions are available, and the gap between certifying a process and certifying an outcome.