AI Governance Institute
Topics

AI in Government and Public Sector

Government agencies using AI for benefits administration, law enforcement, border control, welfare eligibility, and public service delivery face some of the most stringent governance obligations globally. The EU AI Act prohibits several government AI applications outright and classifies others as high-risk with mandatory conformity requirements. Public sector AI also carries heightened civil rights, transparency, and accountability expectations that exceed those applied to comparable private sector deployments.

Key board-level questions

  • 1.Which of our AI systems are classified as high-risk or prohibited under applicable law, and what is our compliance timeline?
  • 2.Do affected individuals have meaningful recourse when AI systems make or inform decisions about them?
  • 3.How do we document and publish AI systems in line with government transparency and accountability obligations?
  • 4.Are our AI vendors under contractual obligations consistent with public sector data protection and procurement requirements?

Regulatory frameworks

EU

EU AI Act (Regulation (EU) 2024/1689)

The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.

US

America's AI Action Plan

America's AI Action Plan is the White House's AI policy agenda, released on 23 July 2025. It sets out more than 90 federal actions under three pillars: accelerating AI innovation, building American AI infrastructure, and leading in international AI diplomacy and security. It favors removing regulatory barriers over adding new rules.

US

Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence

Executive Order 14179, signed on 23 January 2025, set a policy of sustaining US AI leadership through reduced regulation. It ordered a review of actions taken under the revoked EO 14110 and called for an AI Action Plan, which the White House released on 23 July 2025.

US

NIST AI Risk Management Framework (AI RMF 1.0) and Playbook

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.

Global

OWASP Top 10 for Large Language Model Applications

OWASP's Top 10 for LLM Applications lists the most critical security risks in applications built on large language models. The current 2026 edition, published in August 2026, puts prompt injection, sensitive information disclosure, and excessive agency at the top. Development and security teams use it to prioritize safeguards.

Playbook guidance