AI Governance Institute
← News
Research2026-07-12

Ten-Step Enterprise AI Governance Framework from Fisher Phillips Puts Governance Committees, Bias Audits, and Vendor Due Diligence at the Center

What happened

Fisher Phillips published AI Governance 101: The First 10 Steps Your Business Should Take on September 20, 2025, offering a structured ten-step framework for US-based enterprises beginning or maturing their AI governance programs. The guide covers the formation of cross-functional AI governance committees, formal documentation of approved and prohibited use cases, implementation of bias-detection and fairness protocols, and the establishment of vendor audit processes requiring evidence of diverse training datasets. It also mandates annual employee training on governance policies and periodic internal audits of AI systems in production. The guide does not cite a single regulatory trigger but is designed to help organizations stay ahead of proliferating US state-level requirements and align with emerging best practices. Its timing coincides with growing regulatory activity across multiple jurisdictions, including the Colorado AI Act SB205 and the NIST Artificial Intelligence Risk Management Framework Playbook, both of which share structural overlap with several of the guide's recommended steps.

Why it matters

  • ·Organizations lacking a formal governance committee and documented use-case policy may struggle to demonstrate reasonable care if challenged under state AI statutes such as the Colorado AI Act SB205 or bias-related claims before the FTC AI Enforcement Policy, which increasingly scrutinizes inadequate algorithmic oversight.
  • ·The guide's vendor audit requirements, specifically demanding evidence of diverse training datasets, operationalize a due diligence standard that compliance teams must now build into procurement contracts and third-party risk assessments, creating a concrete gap for any organization without vendor-specific AI risk clauses.
  • ·Annual employee training mandates described in the guide set an expectation benchmark that regulators and plaintiffs' counsel may reference when assessing whether an organization took adequate precautions, raising the organizational risk profile for firms that rely solely on informal or ad hoc AI awareness efforts.

Governance controls affected

What to do now

  • ☐Assess whether your organization has a formally chartered AI governance committee with documented decision rights, membership, and escalation paths, and close that gap before the next board risk review cycle.
  • ☐Review all AI vendor contracts to confirm they include a clause requiring vendors to provide evidence of diverse and representative training datasets, and add this requirement to the standard procurement template.
  • ☐Map your current AI inventory against a defined use-case policy that explicitly classifies approved, restricted, and prohibited applications, and obtain sign-off from legal and compliance on that classification.
  • ☐Schedule or confirm that annual AI governance training for employees is on the compliance calendar, includes scenario-based content for high-risk use cases, and generates completion records that can be produced in an audit.
  • ☐Establish a periodic audit cadence for AI systems in production, specifying audit scope, frequency, responsible function, and documentation standards so results can be used to demonstrate ongoing due diligence.

What to watch next

Compliance teams should monitor whether state legislatures in Texas, Colorado, and other active jurisdictions incorporate governance committee and vendor audit requirements as affirmative defenses or safe harbor conditions in forthcoming AI legislation, which would elevate the Fisher Phillips framework from best practice to legal baseline. The Commerce Department Evaluation of State AI Laws is expected to produce findings that may influence federal preemption debates, and its conclusions could reset which state-level obligations enterprises must track. Enforcement patterns from the FTC and state attorneys general in employment discrimination and consumer protection matters involving AI will also serve as a proxy for how rigorously the committee-formation and bias-audit steps in guides like this one will be tested in adversarial proceedings.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-09-30

DraftKings AI Model Targets Chronic Losing Gamblers With Promotional Ads

DraftKings is training machine learning models on customer betting records to identify chronic losing gamblers, then serving them promotional advertising to drive re-engagement. The Electronic Frontier Foundation published an analysis naming DraftKings and framing the practice as AI-amplified consumer harm enabled entirely by first-party data. The case illustrates that existing data-minimization and consent frameworks do not prevent companies from using lawfully collected data in ways that systematically harm vulnerable customers.

Enforcement2026-09-30

SBA's AI Fraud Pilot Never Classified as High-Impact, OIG Finds

The SBA's Office of Inspector General found that a Palantir-powered AI fraud detection pilot for COVID-19 loan programs was never classified as a high-impact use case under OMB guidance. As a result, required safeguards including impact assessments, human oversight mechanisms, and borrower appeals processes were never put in place. The OIG issued six recommendations, including establishing a formal process for identifying and documenting high-impact AI use cases.

Research2026-09-28

Six-Pillar AI Governance Model Sets Enterprise Program Maturity Benchmark

Concurrency, a technology consulting firm, has published a practitioner framework organizing enterprise AI governance into six pillars: inventory, validation, monitoring, explainability, fairness testing, and incident response. The framework targets enterprises that have deployed AI but lack structured approval gates, continuous monitoring, or audit evidence. It provides a replicable operating model that compliance teams can use to measure and close program gaps.