Built from the NAIO AI Governance Bill public-consultation fact sheets (copy in this folder: AI_Governance_Bill_Fact_Sheet.md). Status caveat for decks: the fact sheets are consultation documents — the Government is not bound by them; verify current Bill status the week of delivery and keep slide language as "proposed."
The proposed national framework and the capstone guideline are the same governance pattern at two scales. Teach the mapping explicitly in S6 — it converts "write a policy" from committee chore into applied national governance:
"Your institution's guideline is the proposed AI Bill scaled to a faculty: principles over rigid rules, obligations proportional to risk, incidents reported and learned from, a named authority that maintains the framework. Same logic, smaller jurisdiction."
The Bill proposes five AI Principles that developers/deployers must have "due regard" for across the AI lifecycle. They align almost one-to-one with the Floridi/AI4People lens taught in S2:
| Bill principle (NAIO) | Course principle (S2) | Guideline component it feeds |
|---|---|---|
| 1. Human Dignity, Agency, and Rights | Autonomy (+ beneficence) | Principles; permission architecture |
| 2. Transparency and Explainability | Explicability | Disclosure standard |
| 3. Accountability and Redress | The responsibility triad; justice | Integrity procedure; ownership |
| 4. Safety, Security, and Robustness | Non-maleficence | Assessment design; crutch-effect guardrails |
| 5. Responsible Data Stewardship | Justice + privacy risk | Data & privacy rules (PDPA) |
Landing line: participants aren't adopting a foreign framework — the national direction and the classroom ethics converge on the same five ideas.
The Bill anchors regulation on harm (death, injury incl. mental, unlawful deprivation of liberty, contravention of written law) and evaluates risk by likelihood, severity/scale, duration/reversibility. Three tiers:
| Bill tier | Obligations | Course-level equivalent |
|---|---|---|
| Tier 1 — Unacceptable risk | Prohibited (manipulation, exploitative targeting, unlawful social scoring…) | Uses that corrupt the credential itself (AI sitting a licensure exam) — 🔴 plus procedural bar |
| Tier 2 — High risk | Mandatory measures: risk assessment, documentation, traceability, human oversight, testing, monitoring, incident notification | Anything touching grades, references, admissions, records: human decision, AI second-reader at most, records kept, disclosure mandatory |
| Tier 3 — Low risk | Baseline duties + "due regard" + voluntary instruments | Ordinary coursework — 🟡 permitted-with-disclosure; 🟢 where fluency is the outcome |
Note the Tier-2 obligation list — risk assessment, documentation, traceability, human oversight, monitoring — is the EAI-CMM Governance pillar and the verification-log habit from S4, at institutional scale.
The Bill's Principle 5 (Responsible Data Stewardship) sits on top of existing law. PDPA 2010 governs personal data in commercial transactions; operationally for educators:
[LOCAL] slot names the DPO/compliance owner. 2024-era amendments (breach notification, DPO requirements) raise the bar — verify current state at delivery.[LOCAL] slots the guideline owner must fill