How to run AI governance at scale
A practical guide for compliance officers, general counsel, GRC teams, and risk managers navigating the operational realities of enterprise AI governance. Questions every compliance team needs to answer.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →What does meaningful human oversight look like for high-risk AI decisions?
Defining what "in the loop" means in practice, what level of review satisfies regulatory standards, and how to document it.
How does the EU AI Act affect our global operations?
Understanding the Brussels Effect on non-EU organizations, and evaluating whether to adopt the EU risk-based framework as a global internal standard.
What is our process for model drift monitoring?
Defining ownership and cadence for ongoing monitoring of deployed AI models to detect performance degradation, behavioral shifts, and emerging bias after deployment.
How do we govern AI agents that take autonomous actions?
Agentic AI systems that can browse the web, execute code, send messages, and interact with external services require governance controls that traditional policy frameworks were never designed to handle.
How do we apply a three lines of defense model to AI risk?
The three lines of defense model translates directly to AI governance, with first-line business ownership, second-line risk oversight, and third-line independent assurance each requiring AI-specific adaptations.
How do we comply with the EU AI Act?
A step-by-step compliance guide covering risk tier classification, high-risk system obligations, GPAI model requirements, and the phased enforcement timeline.
How do we build an AI governance program from scratch?
A sequenced guide to standing up an AI governance program — from initial inventory through ongoing operations — for organizations that are starting with nothing.
What do we do when an AI system causes harm or fails?
A structured incident response process for AI failures — from initial detection through containment, root cause investigation, regulatory notification, and prevention.
How do we prepare for AI regulation over the next 12 months?
A forward-looking compliance planning guide: identifying what regulations become enforceable in your jurisdictions over the next year, assessing your current gaps, and building a funded remediation roadmap.
How do we report AI risk to the board and audit committee?
A structured approach to surfacing material AI risk at the board level — defining what to report, how often, and what escalation thresholds trigger immediate notification outside the normal cycle.
How do we map AI compliance obligations across multiple jurisdictions?
A structured process for organizations operating AI systems across multiple regulatory environments — identifying overlapping obligations, resolving conflicts, and building a unified compliance posture that satisfies the most stringent applicable requirements.
How do we govern AI models from preview release through retirement?
A lifecycle governance framework covering every stage of an AI model's production life — from evaluating preview releases, through controlled promotion to general availability, to scheduled re-assessment triggers and formal retirement.
How do we build and maintain a multi-framework AI risk register?
A practical approach to consolidating AI risks from multiple regulatory frameworks (EU AI Act, NIST AI RMF, GDPR, ISO 42001, sector-specific) into a single, actionable risk register — without duplicating effort or missing framework-specific requirements.
How do we engage regulators and standards bodies proactively on AI governance?
A framework for organizations that want to move beyond reactive compliance — engaging regulators through comment processes, standards participation, and direct dialogue to shape governance requirements and demonstrate good-faith leadership.
How do we comply with China's AI regulations?
A compliance guide for organizations deploying AI systems accessible to users in China — covering the four-layer regulatory stack administered by the CAC, security assessment obligations, content labeling requirements, and the practical differences between China's framework and Western AI governance regimes.
New guidance, every week
We publish practical guidance as governance questions come up in the field — plus everything else changing in AI regulation. Every Thursday.
