Sector-Specific & Emerging
Operational controls for sector-specific & emerging, with maturity levels, evidence requirements, and implementation guidance.
Get the free AI Governance Control Tracker
Get the free Excel tracker for all 132 governance controls. Score maturity, assign owners, and set deadlines, including the 9 sector-specific & emerging controls on this page.
- 132 controls in Excel
- Score maturity and assign owners
- Track deadlines and regulation coverage
Includes AI Governance Weekly every Thursday. Unsubscribe anytime.
9 controls
Anthropomorphic and Companion AI Safeguards
Set design requirements and reviews for AI that simulates personality, emotional connection, or companionship. Address psychological influence, protections for minors, and disclosure duties for ongoing interpersonal interaction.
Clinical AI Governance Committee Charter
Create a healthcare AI committee with clinical and technical expertise. Define quorum, decision rights, and escalation authority over clinical support and patient-care systems. Schedule reviews around applicable FDA Software as a Medical Device (SaMD) guidance and state clinical standards.
Critical Infrastructure AI Risk Assessment and Containment
Assess AI risks in energy, water, transport, and financial market infrastructure. Cover limiting AI's reach into operational technology, consequences of failure, and dependencies across sectors. Address these alongside standard enterprise AI risks.
Insurance Sector AI Documentation Standards
Set documentation standards for AI in underwriting, claims, pricing, and fraud detection. Meet applicable state insurance examination expectations, National Association of Insurance Commissioners (NAIC) model bulletin requirements, and algorithmic accountability duties.
National Security and Dual-Use AI Risk Assessment
Assess AI systems and research with both commercial and national security or weapons applications. Address export controls from the US Commerce Department's Bureau of Industry and Security (BIS), defense-related ITAR arms export duties, dual-use research protocols, and monitoring for foreign adversarial misuse.
Self-Hosted Open-Weight AI Model Governance
Set intake rules for AI model files (weights) downloaded from public repositories and hosted internally. Check integrity, licensing, and safety before deployment. Manage ongoing updates separately from vendor-hosted AI procurement.
Consumer and External AI Tool Acceptable Use Policy
Set acceptable-use rules for employees and contractors using consumer or externally hosted AI. Cover public assistants, browser tools, and AI features in cloud software. Define permitted uses, data restrictions, access controls, and onboarding attestations to manage shadow AI (unsanctioned AI use).
AI-Specific External Complaints and Redress Mechanism
Provide a formal complaints process for customers, employees, affected individuals, and the public. Give timely responses and human review of AI-assisted decisions on request. Provide meaningful redress when decisions are incorrect or unfair.
AI System Algorithm Register
Maintain a register of internal and public-facing AI systems. Record purpose, decision scope, risk classification, data inputs, and accountability contacts. Address applicable requirements under the EU AI Act, NYC Local Law 144, Amsterdam-model registers, and equivalent frameworks.
