AI New Zealand

About 10.5 hours · Human-marked final assessment

AI Leaders Course

A self-paced certificate course for the person made responsible for AI. Learn to set the rules, bring your people with you, choose the work and the tools worth paying for, and keep it all defensible. You finish with a ninety day plan you wrote yourself and can defend in front of a board.

Course Overview

  1. Section 1

    The Mandate

    What you will be able to do: 1. Explain, in one sentence each, the difference between the body that decides and the body that diffuses, and say why conflating them is the most common structural error in AI governance. 2. Diagnose which of the four maturity stages your organisation is actually in, using observable behaviour rather than the documents you happen to own, and name which of the four AI OS layers you have and which you do not. 3. Write a one-paragraph mandate that contains real decision rights, a budget, an escalation list, a reporting cadence and an end date, and get it signed. 4. Interrogate any statistic put in front of you with three questions, and explain to a sceptical board chair why you are not going to repeat one of them.

    • The job is not what you think it is

      You have not been made the AI expert. You have been made the person who makes good AI use happen safely, and that is a different job requiring different tools.

    • Where your organisation actually sits

      The stage that feels most like progress is the one carrying the most risk, and it is where most New Zealand firms your size are sitting right now.

    • A mandate with teeth

      A mandate that does not contain the words "is authorised to approve" is a compliment, not a mandate.

    • Says who?

      A leader who is caught inflating one number stops being believed on all of them, and the correction usually arrives in public.

    1 quiz · 1 practical exercise

  2. Section 2

    The Honest Baseline

    What you will be able to do: 1. Explain to a board why prohibition produces less safety than provision, using evidence you can defend, and say clearly what that evidence does not prove. 2. Run a three-part baseline with a small IT team: tool discovery, a five-question anonymous pulse and an honest governance inventory, and date it. 3. Explain why a better policy will not stop people concealing AI use, and name the intervention that will. 4. Ask any vendor the two questions that matter about your data, and assess whether an AI incident is a potential notifiable privacy breach rather than an IT ticket.

    • Shadow AI is a provisioning failure

      Your data is not leaking. It is being handed over, deliberately, by competent people solving a real problem you have not solved for them.

    • Your before picture

      You get exactly one chance to take an honest measurement of your organisation before you start changing it, and you are about to spend it.

    • Why people hide it

      Concealment is not a compliance failure. It is a rational response to a measured reputational penalty, and a better policy will not touch it.

    • Three things to say out loud

      Almost every reassuring sentence a vendor gives you about your data is true and incomplete, and the gap between true and complete is where your exposure sits.

    • When it is a breach, not an IT ticket

      "An employee pasted client data into a public AI tool" is a potential notifiable privacy breach, and the person who decides that is not your IT manager.

    1 quiz · 1 practical exercise

  3. Section 3

    The People

    What you will be able to do: 1. Make the people-first argument to a board as a commercial argument, using a New Zealand number, without using the word culture once. 2. Explain in plain English what a generative AI tool is actually doing when it answers, why it is confidently wrong rather than uncertain, and why that is the system working as designed. 3. Run the Four Gates on any piece of information in about five seconds, and route the ones that stop you rather than guessing. 4. Place any task on the Delegation Grid using reversibility and verifiability, and say which of the three human checkpoints your workflow actually has. 5. Draw the line between sanctioned space to play and the bar for proposing, and choose a first three use cases that teach your organisation the right thing about what AI is for.

    • The case you have to make

      Your first real persuasion job is not about tools. It is convincing a board that the impact and the opportunity land on people first, and that this is a revenue argument rather than a culture argument.

    • A shared mental model of how these tools work

      Ninety-four people do not need to understand how these tools work. They need to understand the same thing about how these tools work, and it fits in about six sentences.

    • The Four Gates: what data do I share?

      Every person in your organisation needs one question they can ask in five seconds before they paste anything, and it has to end in a route rather than a rule.

    • The Delegation Grid: what can I hand over?

      Everybody asks whether they could undo it. Almost nobody asks whether they could check it, and the second question is the one that ends careers.

    • The Three Checkpoints: where does the human stay?

      "Human in the loop" almost always means one person glancing at a finished thing, which is the weakest possible intervention placed at the worst possible moment.

    • From understanding to real work

      People need somewhere to play and a bar to clear before they propose, and the first three things you approve teach your organisation what AI is for more powerfully than anything you write down.

    1 quiz · 1 practical exercise

  4. Section 4

    The Register

    What you will be able to do: 1. Walk a real workflow and find where value is leaking, without asking anyone "where could we use AI?" 2. Run a ten-field intake that kills about a third of submissions on purpose, and keep a register with eight status values, including the two that make it credible. 3. Score competing use cases with adapted RICE and a risk multiplier, show your arithmetic, and explain out loud what the score does not know. 4. Publish a Now / Next / Later / Not doing roadmap that a board chair can defend, with reasons attached to every decline. 5. Ask of any submission what it would need to know and whether it could get to it today, and tell a knowledge problem apart from an AI one.

    • Use cases are the wrong unit

      People submit tools. The thing that produces value is a workflow, and you find it by counting the handoffs, not by asking for ideas.

    • The intake form and the register

      The intake form is a filter, not a suggestion box, and the register is a management artefact whose most valuable rows are the failures.

    • Scoring without pretending

      A score is a conversation structure and a defence against the loudest voice in the room. It is not a truth machine, and anyone quoting it to three decimal places is doing theatre.

    • Five things the score will not catch

      Every shortlisted use case gets five questions the arithmetic cannot ask, and the second one kills more value than the other four combined.

    • Now, Next, Later, Not doing

      Four horizons, each with a test, and the fourth column is the one that makes the other three believable.

    • The Org Brain

      AI value is gated by whether your organisation's information is findable, and a use case that depends on information nobody can find is a knowledge project wearing an AI label.

    1 quiz · 1 practical exercise

  5. Section 5

    The Guardrails

    What you will be able to do: 1. Explain to a board, without overstating it, which existing New Zealand laws bite on AI use, which obligations are live now, and where the genuine gaps are. 2. Assign a risk tier to an incoming request in under five minutes, and defend the assignment, including when the honest answer is that it sits between two tiers. 3. Assess a tool against six sections and seven critical items, and know which failures require a minuted Sponsor exception rather than a conditional approval. 4. Run an incident from report to systemic change, and understand why a reported incident count of zero is a warning rather than a result. 5. Give one firm-wide answer to a client, a tender panel or an insurer who asks how you use AI, and know which of your own contracts you must read before you give it. 6. Say who in your organisation may build an agent, who may assign one to somebody else, and who owns it in six months.

    • The legal floor in New Zealand

      "There is no AI law in New Zealand" is true and useless. The obligations arrive through the law you are already subject to, and several of them are live right now.

    • Tier the intake or strangle yourself

      The tier model is not a risk taxonomy. It is a queueing system, and the service level attached to each tier is the part that decides whether people use your front door.

    • Approving tools

      You are not choosing the best tool. You are deciding which tools your organisation can defend using, and the ones that will hurt you are mostly the ones you did not choose at all.

    • Guidelines first, policy second

      You need two documents with different jobs, written in that order, and neither of them is the control.

    • When it goes wrong

      How you handle the first incident determines whether you ever hear about the second one.

    • The client conversation

      Your clients are already asking how you use AI, and most firms answer badly because nobody has decided what the firm's answer is.

    • Who may build an agent

      A staff member building an agent is not shadow AI. It is shadow software, and the difference matters, because it persists, runs when nobody is watching, and outlives the person who made it.

    1 quiz · 1 practical exercise

  6. Section 6

    The Money

    What you will be able to do: 1. Build a defensible twelve-month AI cost position for your organisation that separates actual, estimated and unknown, and that includes the cost nobody budgets for. 2. Read a token-based invoice, explain in plain English where the money went, and name the three controls that would give the most of it back. 3. Set four cost controls before a pilot starts, each with an owner and a date, in the order that actually works. 4. Write the VALUE MEASURED and GOVERNANCE HEALTH sections of a quarterly board report so that a sceptical chair can defend them without you in the room.

    • No baseline, no approval

      Hours saved without a destination for the hours is not a benefit, and a board that catches you inflating one number stops believing all of them.

    • Where the money actually goes

      Licences are the cost everyone budgets, shelfware is the cost everyone discovers, and unbudgeted committee and champion time is the cost that actually kills programmes.

    • Tokens, in plain English

      You are no longer buying software, you are buying consumption, and the sentence "we bought seats so our AI cost is fixed" stopped being true in 2026.

    • Four controls that cost nothing

      Visibility before restriction. Every organisation that got this wrong got it wrong by capping first and looking second.

    • The one page the board actually reads

      One page, seven headings, quarterly, and the heading everybody leaves blank is the one that decides whether the next quarter is wasted.

    1 quiz · 1 practical exercise

  7. Section 7

    Keeping It Alive

    What you will be able to do: 1. Select an AI Champions Network by nomination rather than advertisement, sized honestly, covering the map rather than the org chart, and containing at least one person who is not convinced. 2. Explain why there is a measured reputational penalty for disclosing AI use, why it makes public recognition a control rather than a perk, and aim the intervention at the evaluators rather than the users. 3. Build a dashboard of six to eight numbers that separates leading indicators from lagging ones, name an owner and a source for each, and say honestly what it can and cannot attribute. 4. Read a stall correctly, tell the difference between governance that is too tight and governance that is too light, and write a recovery plan with owners and dates rather than a list of intentions.

    • Building the Network

      You are looking for two or three people, you find them by asking who people already go to, and one of them should not be convinced.

    • Recognition is the control, not the perk

      People hide AI use because there is a measured reputational penalty for disclosing it, and that penalty almost entirely disappears in workplaces that visibly celebrate AI use. Public recognition is therefore a control that changes behaviour, not a morale exercise.

    • Measuring what actually changed

      Licence counts are not adoption, adoption is not value, and the number that tells you whether anything really changed is one almost nobody collects.

    • It will stall

      It will stall between month four and month seven, that is normal rather than failure, and the only thing that determines what happens next is whether you can read which of eleven known failures you are actually looking at.

    • Before the final assessment

      The seven things you have built, three things to keep in mind, and what the final assessment asks of you.

    1 quiz · 1 practical exercise