Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
AI Governance / GRC for AI White Papers

Research on governance, risk, and compliance for artificial intelligence.

This is the hub for the GRC for AI white paper series. The papers follow the same practitioner standard as the rest of this site's library: evidence-based analysis, cited primary sources, and free PDF availability, with no gating and no sales material. Three papers are available now: Agentic AI Governance, AI in Defense Manufacturing, and How to Build an AI Governance Program; this page lists each paper as it publishes, and the reference pages below carry the maintained analysis behind the series.

The Series

What the GRC for AI series will cover

  • The framework landscape: NIST AI RMF, ISO/IEC 42001, and the EU AI Act
  • State AI statutes and the multi-state boundary problem
  • AI inside the CMMC assessment boundary
  • Agentic AI and the governance of authority to act
  • Shadow AI and the AI use policy in practice
  • AI vendor due diligence and embedded AI
  • AI questions arriving in insurance and contracts
The Standard

The same practitioner standard, applied to a newer field.

The existing library on this site was built over several years of sustained research in Defense Industrial Base cybersecurity, and every paper in it cites its sources and is available as a free PDF. The GRC for AI series applies that standard to a field that currently lacks it: most published AI governance material is either vendor marketing or legal alerting, and very little of it is written from the seat of an independent practitioner who has to make the frameworks operate inside real organizations. Papers publish here as they complete, and each is announced through the Daily Cybersecurity Brief.

The Papers

The papers in the series.

New in August 2026: Agentic AI Governance: Before an AI Agent Gets Authority to Act, an executive control framework for the moment an AI system can act in the company's name. The paper defines the governance trigger as delegated authority, examines the three paths by which agents arrive, with particular attention to the vendor update that adds an agentic capability to a tool the company already approved, and presents eight management decisions covering read and action authorization, approval thresholds, identity and privilege, logging and monitoring, vendor responsibility, shutdown and rollback, and risk-based reauthorization. The framework is applied end to end at the 50-person manufacturer from the earlier papers, producing a completed and signed AI Agent Authority Decision Record. Free PDF, available here with no registration.

Also from August 2026: AI in Defense Manufacturing: A Management Framework for Governed AI Deployment Under CMMC, DFARS, and Export Controls, written for the owners and executives of small and midsize defense manufacturers. The paper is a staged deployment plan ordered by data class: the five kinds of AI by where the data goes, the low-risk wins deployed first, the tool review and the FCI line, the full Stage Three analysis of AI against CUI including the SSP and audit consequences, the export control question, and the plan run at a 50-person shop across three quarters. Free PDF, available here with no registration.

The first paper in the series, How to Build an AI Governance Program: A Records-Based Guide for Small and Midsize Organizations That Use AI (August 2026), describes the full build in sequence: the management mandate, the AI use inventory, the eight decisions of the use policy, NIST AI RMF and ISO/IEC 42001 alignment at deployer depth, AI vendor and embedded AI oversight, and the sustainment rhythm, closing with the program profiled at a fifty person manufacturer. Every claim is hyperlinked to its canonical source, and the paper is a free PDF with no registration.

Available Now

Current AI-relevant work and the cluster reference set.

Published research that addresses AI directly today includes the analysis of embedded artificial intelligence and the CMMC assessment boundary, available in the main white paper library, which examines how AI capabilities inside business software interact with CUI safeguarding obligations and assessment scope. That paper is the bridge between this site's established Defense Industrial Base research and the AI governance work this section develops.

While the series builds, the reference pages of this cluster carry the current analysis: the AI governance overview for the regulatory landscape and the program architecture, the NIST AI RMF and ISO/IEC 42001 pages for the two principal frameworks, the shadow AI and AI use policy pair for unauthorized use and its governance, the state AI laws reference and the Texas TRAIGA analysis for the statutory patchwork, and AI vendor due diligence for the AI the organization buys. Each page is maintained, and the perishable ones carry review dates.

Get In Touch

Discuss the Research or the Work Behind It

Inquiries may involve the research itself, a question a paper raises for your organization, or the advisory work the analysis supports across AI governance, CMMC, maritime cybersecurity, and cyber insurance readiness. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT
Travel
I travel to client sites nationally.

Discuss an Assessment

If a topic in this series bears on a decision your organization is facing, the first conversation carries no commitment and no pitch.

Discuss an Assessment →