ITIL and AI
ITIL asks two questions about AI: what it does, and how its use is governed
Everything this domain covers hangs on two questions ITIL asks about artificial intelligence (AI): what can AI do for the work, and how do we keep that use responsible? The first question is about AI's capabilities and where they help; the second is about directing and controlling that use, which ITIL calls AI governance. Keep the two apart and the rest of the domain falls into place. AI itself is an umbrella term, not a single technology (ITIL Version 5 Foundation: What's New guide): generative AI (GenAI) creates new content such as text, code, or summaries, while agentic AI pursues goals with autonomy, and both are kinds of AI that sit under it. The trap the exam sets again and again is to blur these lines: treating fixed-rule automation as AI (it is not, because AI learns and reasons rather than following a set script), equating using AI with governing it, or confusing the ITIL AI Capability Model, which describes what an AI does, with governance, which controls how it is used.
The domain unfolds in two steps
Two subtopics take the domain in order. Introduction to AI defines the vocabulary — AI, AI maturity (how capably and responsibly an organization uses AI), GenAI, and agentic AI — separates AI from traditional fixed-rule automation, and shows AI assisting and automating work across the eight ITIL Product and Service Lifecycle activities and across the value chain that turns demand into value. ITIL AI Governance then turns to control: it defines AI governance, separates governing AI from merely using it, covers the risk, compliance, accountability, and human-oversight guardrails, and introduces the ITIL AI Capability Model, PeopleCert's 6C model, which names the six capabilities an AI can perform and maps each to its own risks (ITIL AI governance for organizations). Reach for the first subtopic when a question defines a term or asks where AI helps in the work; reach for the second when it asks who stays accountable, how AI use is kept responsible, or which capability the 6C model names.
When two answers both work, keep the human accountable
One instinct wins most questions in this domain: AI supports people, it does not replace them or run unchecked. Across both subtopics ITIL is consistent that AI operates within the boundaries and objectives set by people, and that accountability for outcomes stays with people, even when AI automates a step or acts with autonomy. AI maturity follows the same logic, since a higher-maturity organization uses AI more responsibly and better governed, not simply more widely. So when two options both look workable, prefer the one that keeps a human accountable and able to intervene, and be wary of any answer where AI removes human oversight or takes over responsibility.
Which question you are being asked, and where it is covered
| If the question is about… | The ITIL move | Drill into |
|---|---|---|
| What AI is and where it helps: defining AI, GenAI, agentic AI, and AI maturity, and how AI assists and automates across the lifecycle and value chain | Apply AI's capabilities to the work | Introduction to AI |
| Keeping AI use responsible: AI governance, risk, compliance, human oversight, and the six-capability AI Capability Model | Direct and control that use | ITIL AI Governance |