AI Governance Institute

How to run AI governance at scale

Find answers to the AI governance questions your team faces at work. These guides cover implementation for compliance officers, lawyers, GRC teams, and risk managers.

Compare AI governance tools by control domain when you need software. Use the AI governance maturity model to assess your program.

Answer three questions to get a compliance action plan for your organization.

What applies to me?
1

How do we inventory and classify AI systems by risk level?

Catalog your AI tools, including shadow AI. Assess each system’s data sensitivity, decision impact, and regulatory exposure.

2

Who owns AI governance within the organization?

Assign AI governance responsibilities across Legal, IT, Risk, and any dedicated AI function. Document who approves decisions and handles escalations.

3

How do we ensure third-party AI vendors meet our standards?

Review AI vendors for model transparency, data handling, bias testing, and contractual liability for their outputs.

4

What are our obligations under emerging AI regulations?

Map AI compliance requirements across EU rules, US executive orders, SEC guidance, and sector regulations.

5

How do we detect and mitigate algorithmic bias?

Test AI used in hiring, lending, and customer decisions. Keep audit trails that support your response to discrimination claims.

6

What does meaningful human oversight look like for high-risk AI decisions?

Define human review responsibilities and the level of oversight required. Keep records showing how reviewers meet those requirements.

7

How do we handle AI-generated content and hallucinations?

Assign responsibility for inaccurate AI outputs used in contracts, reports, or customer communications. Set controls to prevent harm.

8

How should employees be trained on acceptable AI use?

Set rules for approved tools, permitted input data, and AI-assisted work in regulated industries.

9

How do we maintain data privacy compliance when using AI?

Review training data sources, data minimization, cross-border transfers, and applicable explanation duties under GDPR and the California Consumer Privacy Act (CCPA).

10

How do we document AI decision-making for auditability?

Use logs, version control, and model cards to explain AI decisions when regulators or litigants request evidence.

11

How do we ensure human-in-the-loop review is actually effective?

Design oversight that counters automation bias. Give reviewers authority and practical ways to override AI decisions.

12

Is our training data compliant with global privacy laws?

Check rights to training data and identify personal information in datasets. Review GDPR and EU AI Act data obligations.

13

How do we measure and mitigate algorithmic bias?

Choose metrics for testing discrimination against protected groups. Define what happens when testing finds bias.

14

What is our explainability standard for AI decisions?

Match transparency requirements to system risk. Build the technical tools and review procedures needed to meet them.

15

How are we managing third-party AI risks?

Govern external AI APIs and models embedded in vendor software. Review data handling, documentation, and ongoing monitoring.

16

Do we have a complete AI inventory?

Maintain a registry of AI tools, including shadow AI found through procurement reviews, network checks, and employee surveys.

17

How does the EU AI Act affect our global operations?

Assess how EU requirements affect organizations outside Europe. Decide whether to use its risk-based approach as a global internal standard.

18

What is our process for model drift monitoring?

Assign owners and review schedules for deployed models. Monitor performance degradation, changes in behavior, and emerging bias.

19

How do we handle intellectual property and copyright in AI?

Review ownership of AI-generated work, copyright exposure from training data, and contractual protections for AI-assisted outputs.

20

Is our AI red-teaming rigorous enough?

Set pass/fail criteria for testing high-risk AI before deployment. Cover toxicity, data leakage, jailbreaking, and misuse.

21

How do we govern AI agents that take autonomous actions?

Govern agents that browse websites, execute code, send messages, and use external services. Set controls for their autonomous actions.

22

How do we apply a three lines of defense model to AI risk?

Adapt the three lines of defense to AI. Assign business ownership, risk oversight, and independent assurance responsibilities.

23

How do we build and maintain an AI model registry?

Keep a model registry with production status, owners, training data, risk classifications, and review dates.

24

What does audit-ready AI documentation look like in practice?

Keep evidence of responsible AI development, deployment, and monitoring. Prepare for regulatory scrutiny, board questions, and litigation throughout the lifecycle.

25

How do we comply with the EU AI Act?

Work through EU AI Act classification, high-risk obligations, GPAI requirements, and phased enforcement dates.

26

What does AI governance look like for a company with under 50 employees?

Build a startup governance program around essential protections. Keep the process manageable for an early-stage team.

27

How do we perform an AI risk assessment?

Assess data sensitivity, decision impact, and regulatory exposure before deployment. Match controls to each system’s risk level.

28

What AI regulations apply to a US-based SaaS company?

Identify federal, state, and international AI requirements for a US SaaS business. Map obligations by use case and customer location.

29

How do we build an AI governance program from scratch?

Start an AI governance program with a system inventory. Follow the steps through to ongoing operations.

30

What AI documentation do we actually need?

Identify legally required AI documentation by risk tier. Distinguish those duties from useful voluntary records and unnecessary paperwork.

31

How do we audit an AI system for compliance?

Audit an individual AI system for compliance. Review evidence and write findings that give owners specific remediation work.

32

How do we manage third-party AI vendors safely throughout the vendor lifecycle?

Manage AI vendors from due diligence through monitoring. Review data handling, contractual protections, and the response to model changes.

33

What do we do when an AI system causes harm or fails?

Respond to AI failures through detection, containment, investigation, and regulatory notification. Use findings to prevent recurrence.

34

How do we prepare for AI regulation over the next 12 months?

Identify regulations becoming enforceable in your jurisdictions over the next year. Assess gaps and fund a remediation plan.

35

How do we report AI risk to the board and audit committee?

Choose what AI risks to report to the board and how often. Set thresholds for urgent notification between scheduled reports.

36

How do we intake and govern open-weight and self-hosted AI models?

Review open-weight models before downloading, fine-tuning, or self-hosting them. Set deployment and maintenance controls suited to those responsibilities.

37

How do we map AI compliance obligations across multiple jurisdictions?

Map overlapping AI obligations across jurisdictions and resolve conflicts. Build a coordinated program around the strictest applicable requirements.

38

How do we govern AI models from preview release through retirement?

Govern models from preview evaluation through production approval and retirement. Define reassessment triggers throughout their working life.

39

How do we monitor voluntary AI safety commitments and respond when they change?

Track AI vendors’ voluntary safety commitments. Reassess relationships when providers weaken, abandon, or fail to honor those commitments.

40

How do we govern our AI supply chain and manage upstream model dependencies?

Review upstream AI dependencies, including foundation models, datasets, development tools, and compute infrastructure. Treat them as supply chain components.

41

How do we disclose AI governance maturity to investors and regulators?

Prepare evidence of governance maturity for investors, regulators, and boards. Decide what to disclose and how to support each claim.

42

How do we build and maintain a multi-framework AI risk register?

Combine AI risks from the EU AI Act, NIST AI RMF, GDPR, ISO 42001, and sector rules. Retain framework-specific requirements.

43

How do we engage regulators and standards bodies proactively on AI governance?

Engage regulators through consultations, standards work, and direct dialogue. Use those channels to contribute to emerging AI governance requirements.

44

How do we build director-level AI literacy for effective board oversight?

Give board directors enough AI knowledge to question management, assess risks, and carry out oversight without technical expertise.

45

How do we comply with China's AI regulations?

Review requirements for AI services accessible in China. Cover CAC regulation, security assessments, content labels, and differences from Western approaches.

46

How do we govern agentic coding assistants and AI developer tools?

Review coding assistants and AI developer tools before approval. Examine codebase access, data boundaries, and separate transmission and retention settings.

47

How do we govern MCP servers and other agent tool connections?

Govern MCP servers and connectors that provide agents with tools and data. Review intake, scoped credentials, and separation between content and instructions.

48

What are the biggest AI governance challenges, and how do we address them?

Address shadow AI, overlapping jurisdictions, ineffective oversight, and resource gaps. Sequence the work to unblock your governance program.

49

Should we hire an AI governance consultant, or build the program in-house?

Decide which governance work needs external help. Structure consulting engagements so your team can run the program afterward.

50

How do we audit our AI governance program, not just individual AI systems?

Audit the governance program against maturity levels. Define what internal audit should test and which evidence supports each rating.

51

What does AI governance leadership look like at the board and executive level?

Assign governance responsibilities from the board through executives and functional owners. Check how leaders exercise oversight after receiving reports.

52

What are the AI governance best practices that actually hold up in practice?

Review practical lessons across inventory, human oversight, monitoring, and vendor risk. Prepare your program to function during incidents and audits.

53

What AI agent security controls do we need as agent autonomy expands?

Review security before expanding agent autonomy. Cover multi-agent trust, agent identities, emergency-stop testing, and governance approval.

New guidance, every week

We publish practical guidance as governance questions come up in the field, plus everything else changing in AI regulation. Every Thursday.

Powered by Buttondown.