Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
AI Governance Advisory

What AI governance is, which frameworks define it, and what organizations must be able to demonstrate.

Artificial intelligence entered most organizations before any policy, inventory, or risk assessment existed to govern it. Employees adopted consumer AI tools, vendors embedded AI features in products already in service, and business systems began producing AI-assisted decisions. AI governance is the management discipline that establishes what AI the organization actually uses, what risk that use creates, and what records demonstrate the use is managed. This page explains the current regulatory landscape in the European Union and the United States, including the state statutes now in force, the three principal frameworks, the areas a governance program has to cover, and how the discipline connects to cybersecurity, management systems, and insurance.

Scope of the Work

What an AI governance assessment examines

  • Actual AI use across the organization
  • Embedded AI in vendor products and services
  • Data flows into and out of AI systems
  • Policy, oversight, and approval structure
  • Regulatory and contractual exposure
  • Records, evidence, and sustainment
Fundamentals

What AI governance is and what it is not.

AI governance is the set of structures, policies, processes, and records through which an organization directs and controls its use of artificial intelligence. In practice it answers a sequence of management questions: which AI systems and tools are in use, what data they receive and produce, what decisions they influence, who is accountable for them, what rules govern their use, and what evidence shows those rules operate. The term is often grouped with adjacent disciplines under the heading of GRC for AI, meaning governance, risk, and compliance applied to artificial intelligence.

Three distinctions keep the subject clear. AI governance is not AI ethics, which concerns the values a system should embody; governance is the management machinery that makes any chosen standard operative and demonstrable. It is not model development practice, which concerns how AI systems are built; most organizations govern AI they buy and use rather than AI they build. And it is not a replacement for information security; it extends the same disciplines of inventory, access, data protection, vendor management, and evidence to a new class of systems. An organization with a functioning security and compliance program already has the skeleton of an AI governance program. What it usually lacks is the AI-specific inventory, the policy decisions, and the records.

The obligation to have this discipline is arriving from several directions at once: binding law in the European Union, voluntary frameworks that function as de facto expectations in the United States, contract and flowdown clauses, insurance underwriting questions, and existing rules that already reach AI use, such as the safeguarding requirements for Controlled Unclassified Information in the Defense Industrial Base. The sections below take these in order.

Current Regulatory Status

Where AI regulation stands in 2026.

On June 16, 2026, the European Parliament gave final approval to the Digital Omnibus amendments to the EU AI Act. The amendments defer obligations for stand-alone high-risk AI systems under Annex III from August 2, 2026 to December 2, 2027, and obligations for high-risk AI embedded in regulated products under Annex I to August 2, 2028. The transparency obligations in Article 50 and the Commission's enforcement powers over general-purpose AI models were not deferred and apply from August 2, 2026. In the United States, no comprehensive federal AI statute exists; the NIST AI Risk Management Framework functions as the de facto baseline, and a growing set of state statutes, summarized in the next section, now carries binding obligations of its own.

What Changed

The EU high-risk timeline deferred by 16 months.

Use-based high-risk systems, including those in employment, credit, education, and access to essential services, now face a December 2, 2027 compliance date rather than August 2, 2026. The deferral reflects unfinished harmonized standards and national enforcement structures, not a change in the requirements themselves.

What Remains

Transparency and GPAI obligations apply now.

Organizations providing EU-facing chatbots, generating synthetic media for EU audiences, or deploying general-purpose AI models carry obligations that took effect on August 2, 2026. A US company with EU customers or EU-facing systems is not outside the regulation's reach.

What It Means Here

US organizations are governed by frameworks, contracts, and carriers.

Absent a federal statute, the practical drivers in the United States are the NIST AI RMF, customer and prime contractor flowdown requirements, cyber insurance application questions, and sector rules that already reach AI use, including the CUI safeguarding obligations that apply in the Defense Industrial Base.

State AI Regulation

The state patchwork and where its boundaries actually reach.

In 2025, every US state introduced AI legislation for the first time. With no comprehensive federal statute in place, the operative AI law in the United States is a patchwork of state measures, enacted on different legal theories and effective on different dates. A December 2025 federal executive order directed agencies to pursue preemption of state AI laws, and litigation and legislative activity continue, but no federal preemption has been enacted. The table below summarizes the principal measures as of mid 2026; the state AI laws page maintains the full reference, and the Texas TRAIGA page covers the one comprehensive statute now in force in depth.

JurisdictionInstrumentStatusWhat It Regulates
TexasTRAIGA (HB 149)In effect since January 1, 2026.Intent-based prohibitions on AI deployed to discriminate, manipulate, or harm, with disclosure rules for state agency AI use. Substantial compliance with the NIST AI RMF provides a safe harbor defense.
ColoradoSB 24-205, replaced by SB 26-189The 2024 AI Act, the first comprehensive state AI statute, was repealed and replaced in May 2026; the successor automated decisionmaking transparency obligations begin January 1, 2027.Transparency and consumer notice for automated decisionmaking technology used in consequential decisions affecting Colorado residents.
CaliforniaSB 53 and AB 2013Both effective January 1, 2026; separate CPPA automated decisionmaking regulations phase in beginning 2027.SB 53 imposes transparency and safety framework obligations on large frontier AI developers; AB 2013 requires generative AI training data disclosure.
UtahAI Policy Act (SB 149, 2024)In effect since May 1, 2024.Disclosure that a consumer is interacting with generative AI, on request generally and affirmatively in regulated occupations.
IllinoisHB 3773In effect since January 1, 2026.Amends the Illinois Human Rights Act to prohibit employer AI use that discriminates against protected classes, with notice requirements.
New York CityLocal Law 144In force since 2023.Annual independent bias audits and candidate notice for automated employment decision tools used for NYC roles.

The boundary problem. State AI statutes generally attach to the residents a system affects rather than to the location of the company that deploys it. This means an AI system does not need to be developed, hosted, or operated in a regulated state to fall within that state's reach. A hiring tool that screens an applicant living in Illinois, a chatbot that serves Texas consumers, an automated decision that touches a Colorado resident, or a job posting that draws New York City candidates places the system inside the corresponding regime, regardless of where the organization or its infrastructure sits. In practice, an AI system wanders across regulated state boundaries through its users, its applicants, and its data subjects, and it does so silently: nothing in the system's operation announces that it has begun processing residents of a state whose statute now applies.

Two consequences follow for governance. First, the AI use inventory has to record not only what each system does but whose residents it can reach, because jurisdictional exposure is a property of the user population, not the server location. A remote workforce, a national applicant pool, or an ecommerce customer base can each carry a system across a boundary without any technology change. Second, the patchwork rewards framework-based governance over statute-by-statute compliance. Texas has already made this explicit by treating substantial compliance with the NIST AI RMF as a safe harbor, and a program built on the frameworks described below positions the organization to answer most state obligations from one body of records rather than maintaining fifty parallel analyses.

The Framework Landscape

The three principal instruments and what each one governs.

AI governance work in the United States draws on three principal instruments. They are frequently discussed as if interchangeable. They are not. One is a voluntary risk framework, one is a certifiable management system standard, and one is binding law with extraterritorial reach.

InstrumentPublisherNatureStatusCentral Question
NIST AI RMF 1.0NISTVoluntary risk management framework organized into four functions: Govern, Map, Measure, Manage. Supplemented by the Generative AI Profile, NIST AI 600-1.Published January 2023; Generative AI Profile published July 2024.Is AI risk identified, measured, and managed as part of enterprise risk management?
ISO/IEC 42001:2023ISO/IECCertifiable AI management system standard, structured in parallel with ISO/IEC 27001 and designed to integrate with an existing information security management system.Published December 2023; certification bodies actively issuing certificates.Does the organization operate a governed, auditable management system for its AI activities?
EU AI ActEuropean UnionBinding regulation, Regulation (EU) 2024/1689, with risk-tiered obligations and extraterritorial application to providers and deployers whose systems reach the EU market.In force since August 1, 2024; obligations apply in staggered phases, with high-risk dates deferred to December 2, 2027 and August 2, 2028 by the 2026 Digital Omnibus amendments.Does the specific AI system meet the legal requirements for its risk tier?

The relationship among the three mirrors a structure this practice already works in daily. The NIST AI RMF plays the role C2M2 plays in cybersecurity: a maturity-oriented framework for understanding and improving capability without a pass and fail verdict. ISO/IEC 42001 plays the role ISO/IEC 27001 plays: a certifiable management system that institutionalizes the program. The EU AI Act plays the role regulation always plays: binding obligations that attach to specific systems and uses. An organization that understands which instrument answers which question avoids both overbuilding and false confidence.

What AI Governance Covers

The six areas an AI governance program has to cover.

An AI governance assessment is not a technology evaluation. It is an examination of how the organization uses AI, what that use touches, and whether the governance around it would hold up under regulatory, contractual, or underwriting scrutiny. Six areas define the work.

01 AI use inventory

Which AI systems, embedded AI features, and consumer AI tools are actually in use, by whom, and for what. In most organizations the inventory that emerges from interviews and observation is substantially larger than the one management would have written down, and the difference is where the ungoverned risk lives.

02 Data boundaries

What information flows into AI systems and where it goes. Customer data, employee data, proprietary designs, and regulated information such as CUI each carry different consequences when they enter a model, a prompt, or a vendor's training pipeline. The data boundary question is where AI governance and information security become the same discipline.

03 Policy and acceptable use

Whether the organization has decided what AI use is permitted, prohibited, and subject to approval, and whether that decision is written, communicated, and followed. A policy that does not match observed practice is a finding here for the same reason it is a finding in every framework this practice supports.

04 Vendor and embedded AI due diligence

What AI capabilities vendors have added to products the organization already runs, what the contract terms say about data use and model training, and what representations the organization is relying on. Embedded AI arrives through product updates, not procurement decisions, which is why it routinely escapes review.

05 Oversight and accountability

Who is responsible for AI decisions, what human review exists over AI-assisted outputs, and how leadership is informed. The governance function in every major framework begins with assigned responsibility, and its absence is the most common condition in organizations that adopted AI tools before adopting AI governance.

06 Records and evidence

Whether the inventory, risk assessments, approvals, training, and vendor reviews exist as records the organization could produce to a regulator, a prime contractor, an insurance carrier, or its own board. A governance program is demonstrated through its records, and counterparties from prime contractors to insurance carriers are increasingly asking for that demonstration.

The method is the same one this practice applies to cybersecurity: examine the operation as it actually runs, compare it to what the documentation claims, and report the difference with evidence.
Where AI Governance Meets This Practice

How AI governance connects to cybersecurity, management systems, and insurance.

Each established practice area already contains AI governance questions. The four intersections below are where the work is grounded in analysis this practice has already published or performs today, rather than in general commentary about artificial intelligence.

Defense Industrial Base

AI tools and the CMMC assessment boundary

When employees or business systems pass CUI through AI tools, those tools and their vendors enter the safeguarding analysis under NIST SP 800-171 and DFARS 252.204-7012, and potentially the assessment scope. This practice published a white paper on embedded AI and the CMMC assessment boundary and continues that analysis through the CMMC consulting practice and the white paper library.

Unauthorized Use

Shadow AI as a control failure, not a novelty

Employees moving company information into unapproved consumer AI tools is the current form of a problem security frameworks have always addressed: identifying unauthorized use of organizational systems and information. The analysis this practice published on SI.L2-3.14.7 applies directly, which is why shadow AI is treated here as a governance and control question with an evidence trail, not a cultural debate.

Management Systems

From ISO/IEC 27001 to ISO/IEC 42001

ISO/IEC 42001 was deliberately structured in parallel with ISO/IEC 27001, sharing the management system clause architecture so that an organization with an ISMS can extend it rather than build a second program. As a certified ISO 27001 auditor and implementer, I approach 42001 readiness from the management system side, where the two standards were designed to meet.

Cyber Insurance

AI questions on the application

Carriers have begun adding AI usage and AI governance questions to cyber insurance applications and renewals. Those answers become representations, and the discipline of supporting application answers with evidence is exactly the discipline of the cyber insurance readiness assessment. AI governance records are becoming part of the underwriting file.

The common thread is that AI governance currently reaches most US organizations through mechanisms that already apply to them, including contract clauses, framework assessments, insurance underwriting, and the obligation to protect regulated information, rather than through AI-specific regulators. Organizations that treat AI governance as an extension of existing GRC discipline are answering the question the way it is actually being asked.
Services

AI Governance Services

The services below follow the structure used across the practice: independent, evidence-based, and delivered in the client's actual operating environment. The work is independent advisory and does not include certification services or software sales.

01

AI Governance Assessment

An independent assessment of how AI is actually used across the organization, the risks that use creates, and the current state of policy, oversight, and records. Management receives an evidence-based picture of where the organization stands and which gaps carry consequence.

02

AI Use Inventory and Risk Assessment

A documented inventory of AI systems, embedded AI features, and employee AI tool use, with each entry analyzed for data exposure, regulatory and contractual implications, and operational dependency. The inventory becomes the foundation record for every subsequent governance decision.

03

Policy and Program Development

Development of the acceptable use policy, governance structure, review and approval process, and recordkeeping that turn AI governance from a stated intention into an operating program. The deliverables are written for the organization that has to run them, not for a binder.

04

NIST AI RMF Alignment

Structuring the AI governance program around the Govern, Map, Measure, and Manage functions of the NIST AI Risk Management Framework, including the Generative AI Profile where applicable. The framework provides the vocabulary and structure most US counterparties expect to see.

05

ISO/IEC 42001 Readiness

Readiness work for organizations operating or pursuing ISO/IEC 27001 that need to extend the management system to AI. The work uses the parallel clause structure of the two standards to build one integrated program rather than two competing ones.

06

AI Vendor and Model Due Diligence

Independent review of AI vendors and embedded AI features: data handling and training terms, security posture, the representations in the contract, and whether they support what the organization must in turn represent to its own customers, regulators, and carriers.

How the Work Is Structured

The same three phases used across the practice.

AI governance work follows the discipline established in the cybersecurity practice areas. The scope, depth, and duration of each project are set by the organization, its AI use, and its obligations rather than by a fixed schedule.

Phase One

Discovery and Scope

  • Confirm objectives and applicable frameworks
  • Review existing policies and vendor contracts
  • Conduct leadership and technical interviews
  • Define the systems, tools, and data flows in scope
  • Plan the onsite work
Phase Two

Assessment

  • Build the AI use inventory from the actual environment
  • Interview the people who use and administer the tools
  • Trace data flows into and out of AI systems
  • Compare observed practice to policy and contract terms
  • Identify governance, regulatory, and evidence gaps
Phase Three

Program and Sustainment

  • Deliver executive findings
  • Prioritize remediation and policy decisions
  • Develop or refine the governance program
  • Assign ownership and sequencing
  • Conduct periodic validation as AI use changes
Publications

GRC for AI Research

A series of white papers and reference pages on governance, risk, and compliance for artificial intelligence is in development in the GRC for AI white paper hub, following the same practitioner standard as the existing library: cited sources, evidence-based analysis, and free PDF availability. Current published work that addresses AI directly includes the analysis of embedded AI and the CMMC assessment boundary in the white paper library. The Daily Cybersecurity Brief covers AI-related advisories and regulatory developments as they occur.
Get In Touch

Discuss Your AI Governance Position

Inquiries may involve an AI governance assessment, an AI use inventory, policy development, NIST AI RMF or ISO/IEC 42001 alignment, vendor due diligence, or the AI questions arriving in contracts and insurance applications. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT
Travel
I travel to client sites nationally.

Discuss an Assessment

Whether the question is what AI the organization is actually using, how to answer the AI questions now appearing in contracts and applications, or how to build a governance program that will hold up to scrutiny, the first conversation carries no commitment and no pitch.

Discuss an Assessment →