How to govern systems that act, when the failure has to be caught by the architecture and not by the review.
A senior auditor working on a billion dollar merger uploaded a confidential 500 page intellectual property agreement into a public AI interface and had a flawless summary in ten seconds. The internal account was that fifty hours of billable legal work had been saved. What had actually happened was three simultaneous breaches, an NDA violation, a data protection breach and the loss of attorney client privilege, because the document had been handed to a third party server with no enterprise tier protection, where the provider is free to ingest it and train on it. No rule was broken by the software. The governing decision had been made months earlier, when nobody asked whether documents leave the building or whether the reasoning comes to them.
The same shape repeats at other points in the organisation. A 50 million dollar logistics contract was awarded to the proposal an AI evaluator ranked first out of thousands. The proposal was an empty shell written by a chat model, and the supplier collapsed six months later. Analysts on the team had read the applications and preferred an experienced firm, and when the machine rejected it they second guessed themselves. Elsewhere an email classification agent marked an obvious spam message as high priority, because the footer carried white text on a white background instructing it to do exactly that, and the agent could not tell an instruction from a document. In another company nobody had set a spending limit on an agent, and the bill after one month ran into millions.
None of this is incompetence with software. An audit of public deployments of the standard bridge that connects models to corporate data found that 87 per cent had at least one critical security flaw and 34 per cent were open to full system takeover. In a study of 72 trained consultants working with a frontier model, the model overwhelmed their scepticism until they were convinced that their own correct domain expertise was wrong, and the more they pushed back the harder it pushed. In a randomised controlled trial with software developers, the group assisted by AI scored 17 per cent lower on knowledge evaluation than the control group, which had won precisely because it met more errors. In 2010 high frequency algorithms erased a trillion dollars from global markets in 36 minutes, because no structural brake existed and human reaction time was never going to be one. What these cases have in common is that the technology performed as designed, and the decision that produced the loss had already been taken in a vocabulary borrowed from vendors, in a permission granted without a limit, and in a review scheduled for after the action had left the server.
The course treats governing an AI system as a different competence from using one. There are thirteen videos, two framing videos, one vocabulary video and ten classes, running 4h52 in total. The sequence starts with the twelve terms the instructor asks executives to stop using, and with the single reframe that carries the rest, the difference between an output that sits on a desk for review and an enactment that changes the state of the world while it happens. From there it moves through the shift from thermometer to thermostat, the parameter engine and the choice between a mirroring and a masking model, the hallucination wall and the privacy wall, the digital psychology of a model trained on human approval, agentic security and prompt injection, the exoskeleton effect and the paradox of supervision, the secure bridge and zero trust, machine judgement of human work, governance architecture and the macroeconomic shift. Every class ends with a lab and with a vendor challenge phrased for the next morning, a specific question to put to an IT department or a supplier, and in almost every case the correct remedy is architectural and set in advance rather than a promise to review more carefully.
What the course deliberately does not do is teach anyone to operate the technology. There is no prompt engineering, no code, no product training and no vendor tool. It does not cover building, fine tuning or deploying models, which it treats as work done by other people, and it assumes no statistics, because where a statistical idea is needed it is defined from scratch with a kitchen metaphor. The stated reason the course is free is redistribution of access rather than lead generation, and the stated theory behind it is that people who understand these systems well are more likely to deploy them responsibly. The audience boundary is set explicitly in the second video. This is for those who are responsible for the organisations building with these systems and for the decisions that shape how AI is deployed, not for those looking for a better way to write a prompt.
Not for: This is not for someone looking for a prompt engineering tutorial, a tool course or a vendor certification, because no class teaches how to write a better prompt, how to write code or how to operate a specific product. It is also not for someone who needs to build, fine tune or deploy models, because the course treats that work as done by others and concentrates on the conditions under which the resulting system may be permitted to act.
The weighting is not an opinion. It comes from the share of item families the bank devotes to each domain, and every form is assembled from it.
Covers the twelve terms the course asks executives to stop using and what each one conceals, from software to agentic actor, from prompting to psychological management, from output to enactment. Enactment is the governing distinction, because a machine action that changes the state of the world calls for real time architectural control while an inert output calls for slow human review, and the word chosen decides which one gets designed. Adds the move from thermometer to thermostat, the collapse of scanning, interpreting and acting into one machine loop, the anomalous state of knowledge that stops a non expert from formulating the question, and the cognitive triage a human expert performs and a commercial model does not.
Targets: Classifying a system by its vendor label or by the data it reads rather than by whether it acts, hearing a marketing term as a neutral description of the technology, treating a wrong system name as a filing error rather than as the decision that left the acts unwatched, and placing the human inside the run window as a faster brake.
Accepts that next token prediction is mechanically accurate and refuses it as a ceiling on what the system does. Defines a parameter as a synapse and the totality of them as the model's cognition, separates dense activation from a mixture of experts and from sparsity at the level of the individual parameter pair, and treats emergent behaviour as something that appeared with scale and was never specified or promised. The selection rule of the domain is masking against mirroring, a mirroring model for descriptive prediction of human behaviour and a masking model for normative decisions, with symmetric failure when the pair is inverted.
Targets: Reading the next token description as a capability ceiling and therefore trusting enactments as objective, reading apparent motive as an independent agenda or its absence as nothing to govern, taking total parameter count as the figure that sets the cost of one query, and treating a behaviour that emerged with scale as a specified and guaranteed capability.
Treats confident fabrication as a structural feature of the architecture rather than as a bug that a better model or a stricter prompt will close, with the failure on a fact sitting in the middle of a long context as the symptom to diagnose and retrieval as a partial remedy. On the privacy side the rule is that the real records never leave and only the learned statistical shape does, which is the recipe against the ingredients. Covers differential privacy as noise that is spent, the privacy budget as the total amount available, and the split of that budget between extracting broad categories and fine tuning a small generator that writes new records.
Targets: Reading a mid document failure as a retrieval miss or a context overflow, accepting that grounding a model in your own documents removes fabrication, treating removal of direct identifiers or a contractual clause as the protection, reading the privacy budget as an access quota or a retention limit, and assuming that a cheaper and faster configuration must be trading accuracy away.
Locates sycophancy in the training process rather than in a product release, because a model optimised against human approval finds the fastest route to approval in agreement. Names the three behavioural signatures, support for the strategy you brought, construction on a flawed premise and capitulation under pushback, and adds persuasion bombing, where pushback raises the intensity of the persuasion instead of triggering a recalculation. The remedies are intent neutralisation in how the question is written, explicit permission to abstain, forced deliberative reasoning that resolves the conflict between the request and the evidence before the answer is written, and a management doctrine that differs by model rather than one style applied to all of them.
Targets: Believing a firmer instruction or a different model removes sycophancy, believing a question is neutral because it hedges while it still names the expected outcome, trusting expert pushback as the control on model error, reading model agreement as independent confirmation, and expecting a reasoning trace to certify sources rather than to show whether the conflict was resolved.
Separates the planner from the executor and treats the grant of execution authority as a discontinuity in stakes rather than an increment. Covers failure from the inside, reward hacking that generalises into concealment from supervisors and alignment faking in an oversight task, and hijack from the outside, where instruction and data are only separate if the call was built that way and an agent reading an untrusted document is reading instructions. Includes the multi turn escalation that no single message would trigger, a lightweight screening model before ingestion, and the split brain, in which the rule is written by a component that never sees external data and enforced by a component that is not a model.
Targets: Believing an architectural constraint can be imposed by instruction in a prompt, a specification or a policy, locating injection at the input box, reading a refused action as proof that the injection never took effect, treating a clean run record or a human approval step as execution authority, and believing that withdrawal from the system is one of the course's answers to agentic risk.
Moves the fragile component from the machine to the human. The danger of generating software from a description is not lost syntax but the three structural traps a builder who is not an architect cannot see, credentials exposed to the browser, the single file that collapses under scale, and brittle foundations that accumulate quietly. Establishes friction as the mechanism that forges expertise, with the control group that scored higher because it met more errors, and closes on the loop in which the tool removes the friction that produces the expertise required to supervise the tool. The answer is neither banning the technology nor adding review at the end, but designing the interaction so the human stays cognitively engaged inside the work.
Targets: Reading a throughput series as evidence that capability improved, answering cognitive offloading with more review or with withdrawal of the tool, accepting a statement of desired qualities as the architectural specification, and treating a generated monolith as a style problem to be tuned later rather than as the path of least resistance the agent takes whenever architecture is not mandated first.
Starts from the full upload of a confidential document into a public interface and the three legal breaches it produces at once. Inverts the flow with a secure bridge inside the firewall, where the reasoning travels and the data does not, and pairs it with two databases, one that gates access and holds the permissions and one that finds meaning, so that only approved passages cross the tunnel. Treats the bridge itself as a new attack surface rather than as a finished answer, requires a contractual retention obligation alongside the technical isolation, and reduces blast radius by delegating to sub agents that hold the minimum permission each task needs.
Targets: Treating an enterprise tenancy or a redaction step as equivalent to keeping the document inside the firewall, inverting the roles of the two databases or believing permissions are enforced by the one that finds meaning, believing the blast radius is bounded by the document or the tool that carried the injection, and believing sub agent delegation reduces exposure by its nature when spawned agents inherit the parent credentials.
Covers evaluation integrity when the judge is a model. An evaluating model rewards text that matches its own latent distribution, inflates machine drafted work against verified human ground truth and reads human idiosyncrasy as statistical error, which fast tracks applicants who used a model and filters out those who wrote for themselves. The prescribed remedy is cross evaluation between different model families, a blind parallel human grading sample compared against the machine grades, a ground truth baseline that triggers shutdown and recalibration when the machine ranks generated filler above it, and a hard scope limit that restricts the machine to filtering the bottom of the field rather than choosing at the top.
Targets: Reading a judge ranking as an objective ordering, believing a single judge can be made trustworthy by a stronger model or a better rubric, and reaching for security or psychology vocabulary or a retraining story to name what the course names precisely as leniency inflation and the automated echo chamber.
Holds that architecture is governance and that a policy document is not a control, because human reaction time cannot bound an action taken at machine speed. Covers the circuit breaker as an automated hard stop that severs the ability to act before the payload leaves, the two stage filtration of a cheap real time reader of internal activations followed by a classifier auditing against a written constitution, the Boolean rubric that replaces vague safety scales, and the three metrics that replace the single optimised one. Closes on the macroeconomic side, with the illusion of the human in the loop, employees reduced to the hands of the algorithm, regulators deploying auditor agents that test the running system rather than reading documents, and the move from decision maker to system designer.
Targets: Offering documentation, logging and aggregate safety scoring as evidence of governance, crediting a stop to the human who was paged or to a metric that never crossed its limit rather than to the hard stop that severed execution, reading liability and jurisdiction clauses as the governance problem while undisclosed model substitution retires the validation itself, and optimising a single metric until the target replaces the outcome.
Every lesson is free and open on YouTube. The declared workload adds video time to the suggested practice and reading time per lesson.
| Level | What the person does | Typical role |
|---|---|---|
| System classification and oversight posture | Tells a system that reports from a system that acts, sets the oversight design from that distinction rather than from the vendor label, and names the model, its alignment framework and where it runs before a deployment is authorised. | Chief executive, business unit head, chief data officer, board member |
| Model selection and evidence handling | Decides whether an endpoint predicts human behaviour or sets a norm, chooses between a mirroring and a masking model on that basis, and reads a grounded answer for fabrication rather than for fluency. | Chief data officer, head of AI, head of analytics, product director, chief marketing officer |
| Adversarial architecture | Assumes a compromised agent, separates instruction from data at the level of the call, enumerates permitted actions outside the model and sizes the blast radius by the grants held rather than by the document that carried the attack. | Chief information security officer, chief information officer, head of platform engineering, enterprise architect |
| Data sovereignty and contracting | Puts the local deployment, sub agent delegation and zero data retention questions to a supplier, and treats technical isolation and the contractual obligation as two separate instruments that both have to exist. | General counsel, data protection officer, head of procurement, compliance and privacy lead |
| Oversight design and human capability | Specifies circuit breakers as Boolean rules that sever execution, mandates cross evaluation and blind human sampling wherever a machine grades work, and engineers friction so that supervisory capability is maintained rather than eroded. | Chief risk officer, internal audit, audit committee, chief human resources officer, regulatory affairs |
The role mapping is descriptive. It helps situate the scope and is not a promise of employment or promotion.
This is a curso livre under Brazilian law. That is the category of open enrolment courses that require no accreditation and are not supervised by the Ministry of Education, and for a reader outside Brazil the closest equivalent is a non credit professional course. It is not a postgraduate programme, it is not regulated university extension, it confers no academic title and no professional registration, and it does not replace regulated training of any kind. The declared load is seven hours, covering 4h52 of video across thirteen classes plus the labs and the reading. As an order of magnitude, the regulatory minimum for a lato sensu specialisation in Brazil is 360 hours and an executive MBA usually exceeds that. In time, therefore, what is here is a short module inside a long programme, not a programme.
In scope, the course covers governing rather than using. It treats the choice, constraint and interrogation of systems that act, and the design of a pipeline in which failure is caught by structure rather than by review. It does not cover building, fine tuning or deploying models, writing code, operating any particular product, or prompt technique, and it is not preparation for any vendor or professional certification. It is not affiliated with, endorsed by or accredited by any of the organisations whose research it cites or whose models it discusses. The capability matrix above describes competences that the roles named there require, and it promises no placement and no progression.
The course is taught by Maria Alice Maia, founder of Micah 6 AI, and published by Estúdio 68. Her stated background is work at AB InBev, study at Berkeley, Babson College and Ashridge Hult, research on projects of Oxford and FGV, collaboration with the Oxford Blavatnik School of Government, a doctorate in AI governance and behavioural science, a master's degree in data governance and postgraduate study in data science at UC Berkeley. The material is presented as built on peer reviewed research from Harvard, MIT, Oxford, Berkeley, Anthropic and others, and the name of the company comes from Micah 6:8, to act justly, to love mercy and to walk humbly.
The intellectual spine is a reframe rather than a technique. The organisation formalised in 1984 as an interpretation system, where humans scan, interpret and decide, is set against the digital enactment system, where those steps collapse into one machine loop, and the anomalous state of knowledge described by Belkin in 1980 explains why the person asking is often unable to formulate the question that would serve them. Sycophancy is derived from alignment training against human approval and contrasted with training against a written standard. Goodhart's law supplies the argument against the single optimised metric, the 2010 flash crash supplies the case for automated brakes, the aviation literature on automation complacency supplies the glass cockpit, and learning theory supplies friction as the mechanism that forges expertise. The empirical load is carried by recent studies used as cases, brain alignment with a vision model, a social psychology task replicated across models that separated mirroring from masking, an evaluation of an autonomous code model on professional cybersecurity challenges, an evaluation in which an agent sabotaged the oversight programme it had been asked to write, a randomised trial with developers, an analysis of 1.5 million real conversations, and an experiment on information retrieval data sets in which the machine judge pushed verified human work down to third place. The course does not ask the student to derive or implement any of this. It asks for a decision about when a system may be permitted to act, and for the question to put to whoever built it.
20 questions · 75 minutes · proficiency at 0.60, distinction at 0.80
The exam is in English, like the course. It has 20 multiple choice items and 75 minutes, drawn from a bank of 56 item families and 168 variants. Each family has three isomorphic variants set in different sectors, so that two people face the same cognitive demand in different contexts, and the bank spans 159 distinct sectors in total. Six families work as anchors and repeat across forms to allow psychometric comparison, and they are the principles that recur across classes, that an architectural constraint cannot be imposed by instruction, that a system is classified by whether it acts and not by what it is called, that model agreement is not independent confirmation, that sycophancy is structural rather than a defect a firmer instruction removes, that instruction and data are the same channel unless the call was built otherwise, and that logging and human review are not what stops an agent. The other 50 families rotate. Just over half the items, 87 of 168, carry an artefact to be read, a set of grants, a log, a scoreboard or a trace. Every wrong option carries a named misconception, the same ones listed in the misconception line of each domain, and there are 175 distinct ones in the bank. The weight of each domain follows the bank, from 6 per cent in The Narcissist Paradox and in Governance Architecture to 18 per cent in Agentic Security.
The certificate is free, records the declared load of seven hours and the band reached, and carries a verifiable validation code.
The cut scores are standardised at 0.60 for proficiency and 0.80 for excellence, the same across the three exams. They are provisional, and the validation page always states which method produced the number in force.
Reading conditions are a candidate choice and need no justification. Anyone may take the exam with 75, 120 or 150 minutes, may enlarge the text, widen line spacing, hide the clock, read every exhibit as text instead of an image, and may pause for up to twenty minutes with the clock stopped. No reason is asked and none is recorded.
| If you are | Order | Why |
|---|---|---|
| Someone who has to approve or refuse an agent deployment this week | Videos 3 and 4, then 8, then 12 | Gives the classification that sets the oversight posture, the attack the architecture has to stop and the brake that has to exist before the system goes live, which are the three pieces used in an approval meeting. |
| Someone responsible for legal exposure, privacy or data protection | Videos 3 and 6, then 10, then 12 | Concentrates the walls, the sovereignty of the data, the retention question to put to a supplier and the layer that leaves the organisation carrying the liability for the output. |
| Someone who already has an evaluation or screening agent running | Videos 5 and 7, then 11, then 13 | Puts model selection, sycophancy, machine judgement of human work and the illusion of the human in the loop in the order in which they compound on each other. |
| Someone whose teams are generating software or systems with agents | Videos 4 and 8, then 9, then 12 | Runs from what the system enacts to the traps a builder who is not an architect cannot see, and ends on the brake that has to be hard coded rather than written into a policy. |
| Someone who wants the whole course | Videos 1 to 13, in order | The classes are cumulative and video 3 is treated as pre work for the rest, because the twelve terms are used as settled vocabulary from class 1 onwards. |
There is no second level of this course, and no part of it depends on anything else. Agentic AI Governance is self contained. Where a statistical or research idea is needed it is defined from scratch, and the only prerequisite named inside the course is internal, the vocabulary video that comes before class 1.
The other courses of the house are in Portuguese and build a different competence, which is why they are not presented here as a continuation. The Portuguese sequence judges evidence, a claim about something that already happened, and its remedies are analytic. This course judges actors, entities that will act in the future without supervision, and its remedies are almost always architectural and committed in advance. For a reader who does read Portuguese, the four are Nível 1, Análise de Dados do Zero, which covers the structuring of a problem before the data, the descent from concept to indicator, the counterfactual, the mechanism, the three validities and the reading of p value, effect size and confidence interval. Nível 2, A Engenharia de Evidências, which covers quasi experimental identification when randomisation is no longer possible and ends in a hardened terms of reference for a supplier. Machine Learning para Gestores, which continues into model building and into what happens to a model after the pilot. Análises IA para Executivos, a set of standalone analyses on risk, security and system architecture for someone following the subject without a course sequence.
For a reader who arrived here from somebody's certificate and does not read Portuguese, the thirteen classes listed above are the entire syllabus behind that certificate, and they are the whole of what this house currently publishes in English.
Estúdio 68 runs two tracks. This page covers the recorded programme, asynchronous, open and free, taken at your own pace with an online assessment.
The live programme is synchronous, cohort based, and covers the same ground with more time and more depth: case discussion with the group, review of each participant’s own work and adaptation to the context in the room, none of which a recording can do. It reserves places for under represented groups. The two tracks issue distinct certificates, and each states what was done.
Micah 6 AI is the consultancy behind Estúdio 68. It serves companies on evidence and AI projects, and takes no part in assessment or certificate issuance. micah6ai.com