AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

How to run AI governance at scale

A practical guide for compliance officers, general counsel, GRC teams, and risk managers navigating the operational realities of enterprise AI governance. Questions every compliance team needs to answer.

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Audit & Logging×
10

How do we document AI decision-making for auditability?

Meeting regulatory and litigation demands for explainability through logging, version control, and model cards.

14

What is our explainability standard for AI decisions?

Defining how much transparency is required at different risk levels, and building the technical and procedural infrastructure to deliver it.

17

How does the EU AI Act affect our global operations?

Understanding the Brussels Effect on non-EU organizations, and evaluating whether to adopt the EU risk-based framework as a global internal standard.

24

What does audit-ready AI documentation look like in practice?

Organizations facing regulatory scrutiny, board inquiries, or litigation need to produce evidence that AI systems were built, deployed, and monitored responsibly. Audit readiness is not a documentation exercise. It is an evidence-management discipline built into the AI lifecycle.

25

How do we comply with the EU AI Act?

A step-by-step compliance guide covering risk tier classification, high-risk system obligations, GPAI model requirements, and the phased enforcement timeline.

26

What does AI governance look like for a company with under 50 employees?

A lean governance framework for startups that covers the essentials without the overhead — focused on what actually protects you at an early stage.

28

What AI regulations apply to a US-based SaaS company?

Mapping the federal, state, and international AI regulatory requirements that apply to US SaaS companies offering AI features, based on use case and customer location.

29

How do we build an AI governance program from scratch?

A sequenced guide to standing up an AI governance program — from initial inventory through ongoing operations — for organizations that are starting with nothing.

30

What AI documentation do we actually need?

A practical guide to which AI documentation is legally required, which is best practice, and which is unnecessary overhead — organized by risk tier.

31

How do we audit an AI system for compliance?

A methodology for conducting compliance audits of individual AI systems — what to review, what evidence to collect, and how to write findings that actually drive remediation.

34

How do we prepare for AI regulation over the next 12 months?

A forward-looking compliance planning guide: identifying what regulations become enforceable in your jurisdictions over the next year, assessing your current gaps, and building a funded remediation roadmap.

45

How do we comply with China's AI regulations?

A compliance guide for organizations deploying AI systems accessible to users in China — covering the four-layer regulatory stack administered by the CAC, security assessment obligations, content labeling requirements, and the practical differences between China's framework and Western AI governance regimes.

New guidance, every week

We publish practical guidance as governance questions come up in the field — plus everything else changing in AI regulation. Every Thursday.

Powered by Buttondown.