Sector-Specific & Emerging
Operational controls for sector-specific & emerging, with maturity levels, evidence requirements, and implementation guidance.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →9 controls
Anthropomorphic and Companion AI Safeguards
Set design requirements and reviews for AI that simulates personality, emotional connection, or companionship. Address psychological influence, protections for minors, and disclosure duties for ongoing interpersonal interaction.
Clinical AI Governance Committee Charter
Create a healthcare AI committee with clinical and technical expertise. Define quorum, decision rights, and escalation authority over clinical support and patient-care systems. Schedule reviews around applicable FDA SaMD guidance and state clinical standards.
Critical Infrastructure AI Risk Assessment and Containment
Assess AI risks in energy, water, transport, and financial market infrastructure. Cover operational technology containment, consequences of failure, and dependencies across sectors. Address these alongside standard enterprise AI risks.
Insurance Sector AI Documentation Standards
Set documentation standards for AI in underwriting, claims, pricing, and fraud detection. Meet applicable state insurance examination expectations, NAIC model bulletin requirements, and algorithmic accountability duties.
National Security and Dual-Use AI Risk Assessment
Assess AI systems and research with both commercial and national security or weapons applications. Address BIS export controls, defense-related ITAR duties, dual-use research protocols, and monitoring for foreign adversarial misuse.
Self-Hosted Open-Weight AI Model Governance
Set intake rules for model weights downloaded from public repositories and hosted internally. Check integrity, licensing, and safety before deployment. Manage ongoing updates separately from vendor-hosted AI procurement.
Consumer and External AI Tool Acceptable Use Policy
Set acceptable-use rules for employees and contractors using consumer or externally hosted AI. Cover public assistants, browser tools, and AI-enabled SaaS. Define permitted uses, data restrictions, access controls, and onboarding attestations to manage shadow AI.
AI-Specific External Complaints and Redress Mechanism
Provide a formal complaints process for customers, employees, affected individuals, and the public. Give timely responses and human review of AI-assisted decisions on request. Provide meaningful redress when decisions are incorrect or unfair.
AI System Algorithm Register
Maintain a register of internal and public-facing AI systems. Record purpose, decision scope, risk classification, data inputs, and accountability contacts. Address applicable requirements under the EU AI Act, NYC Local Law 144, Amsterdam-model registers, and equivalent frameworks.
Sector-Specific & Emerging, tracked weekly
New sector-specific & emerging controls and the regulatory developments driving them, plus everything else changing in AI governance. Every Thursday.
