Building buy-in: leadership, training, AI literacy and culture
A governance program only works if people follow it. That takes three things: leadership backing, staff who know what they may do with AI, and a culture that rewards doing it well. AI literacy is also a legal requirement under Article 4 of the EU AI Act.
Why this matters for the exam
A governance program only works if people follow it. That takes three things: leadership backing, staff who know what they may do with AI, and a culture that rewards doing it well. AI literacy is also a legal requirement under Article 4 of the EU AI Act. Meeting that requirement takes training staff actually apply.
What you need to know
The last topics covered structures and how to tailor them. This one is about the people inside them. Buy-in is built on four fronts, in the order a program typically tackles them: leadership support, stakeholder engagement, training, and culture.
Each front builds on the one before it: leadership support makes engagement possible, engagement shapes the training, and a culture sustains the training. Training and culture work continue throughout rather than finishing as stages.
Getting leadership on board
Leadership support determines whether governance produces real behavioral and cultural change or stays on paper. It is built in three ways:
- Identify leaders already using AI who would support better governance — useful allies, since teams often face pressure from leadership, shareholders and customers to build AI fast.
- Explain how responsible AI is a differentiator — transparency about real governance can make a product more appealing to buyers.
- Show leadership how it can govern AI. That means explaining what data-science and model-operations teams need: investment in engineers, hardware and software, and realistic timelines. It also means being fluent in the applicable law, so governance is presented as risk mitigation.
Transparency with leadership about the organization's actual governance maturity matters too. Sometimes the honest conclusion is that the organization should hold off on more advanced AI capabilities until governance catches up.
Engaging the wider stakeholder group
The next step is the broader stakeholder group. The work runs roughly in sequence:
- Determine who the stakeholders actually are: solicit suggestions from leadership and existing governance teams, include users where possible, and aim for diversity across age, gender, race, region and culture.
- Involve them early, using existing structures and lessons already learned.
- Define the business case: goal, cost and benefit, and whether AI use aligns with the organizational mission.
- Assess whether AI is even the right solution for the stated purpose.
- Continuously evaluate progress and mitigate issues.
- Identify internal and external risks.
Some of this work is often handled by a smaller internal AI review committee or ethics committee rather than the full stakeholder group.
Training and AI literacy
Engaged stakeholders still need practical knowledge, and training content should be tailored the same way governance structures are. Each organization builds its own curriculum.
Training should focus on the organization's own use of AI and its governance practices rather than on AI in general. Three areas make up the content: AI terminology, AI strategy, and AI governance.
Good training covers the technology and the people: how the AI works, and its effect on people including their privacy and personal agency.
Employees should be trained on permissible uses before being granted AI access. For generative AI, staff need one instruction: do not input sensitive, personal or classified information without required approval.
AI literacy is the skills, knowledge and understanding that let people engage with AI in an informed, responsible and effective way: grasping fundamental concepts, capabilities and limitations, and recognizing potential benefits and risks. A lack of literacy leads directly to mistrust, misuse, and an inability to identify or mitigate risk.
Article 4 of the EU AI Act requires providers and deployers to ensure a "sufficient level of AI literacy" among staff and others operating AI systems on their behalf. The EU AI Office maintains a repository of AI literacy practice examples.
ISO/IEC 22989:2022 establishes standardized AI terminology, defining over 100 key AI concepts. It supplies the shared vocabulary that literacy work builds on, in a field whose regulation otherwise lacks harmonized language.
Building a culture of responsible AI
Training happens on set dates, and culture keeps practice consistent between them. Building it takes sustained work in several areas:
- Highlight customer value and trust as an incentive for safe, effective AI products.
- Recognize cultural variation, and regularly check that policies are not inadvertently disadvantaging any group.
- Define responsible AI as a discipline in its own right.
- Engage HR to define work roles and success measures, so practitioners are actually rewarded for doing this well.
- Set a common AI vocabulary across the organization to reduce miscommunication.
- Keep providing knowledge resources and training.
Culture becomes concrete in documented AI runbooks and playbooks. These are clear guidelines on what should and should not be done with AI. Internal legal and organizational structures are updated alongside them, so everyone knows their role.
That completes the people and structures of governance: who holds which role, how the program is organized, how it is tailored, and how the people inside it are brought along. Next up: a new competency — what governance actually requires at each moment of a system's life, starting with the life cycle itself.
Remember
- Article 4 of the EU AI Act makes staff AI literacy a legal requirement for providers and deployers, and ISO/IEC 22989 supplies the standardized vocabulary underneath it, defining over 100 key AI concepts.
- Training should focus on the organization's own AI use and governance practices, not general AI education, and should happen before staff get AI access.
- Leadership buy-in decides whether governance changes behavior or stays on paper; frame it as risk mitigation and a product differentiator.
- Culture is what keeps practice consistent between training sessions. Runbooks and playbooks turn it into concrete, checkable guidance.
Practise this topic
Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.
Previous: Tailoring AI governance to your organization
Next: The AI development life cycle: from planning to decommissioning
Back to the AIGP study guide.
AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.