Research on governance, risk, and compliance for artificial intelligence.
This is the hub for the GRC for AI white paper series. The papers follow the same practitioner standard as the rest of this site's library: evidence-based analysis, cited primary sources, and free PDF availability, with no gating and no sales material. The series is in development; this page lists each paper as it publishes, and the reference pages below carry the current analysis in the meantime.
What the GRC for AI series will cover
- The framework landscape: NIST AI RMF, ISO/IEC 42001, and the EU AI Act
- State AI statutes and the multi-state boundary problem
- AI inside the CMMC assessment boundary
- Shadow AI and the AI use policy in practice
- AI vendor due diligence and embedded AI
- AI questions arriving in insurance and contracts
The same practitioner standard, applied to a newer field.
The existing library on this site was built over several years of sustained research in Defense Industrial Base cybersecurity, and every paper in it cites its sources and is available as a free PDF. The GRC for AI series applies that standard to a field that currently lacks it: most published AI governance material is either vendor marketing or legal alerting, and very little of it is written from the seat of an independent practitioner who has to make the frameworks operate inside real organizations. Papers publish here as they complete, and each is announced through the Daily Cybersecurity Brief.
Current AI-relevant work and the cluster reference set.
Published research that addresses AI directly today includes the analysis of embedded artificial intelligence and the CMMC assessment boundary, available in the main white paper library, which examines how AI capabilities inside business software interact with CUI safeguarding obligations and assessment scope. That paper is the bridge between this site's established Defense Industrial Base research and the AI governance work this section develops.
While the series builds, the reference pages of this cluster carry the current analysis: the AI governance overview for the regulatory landscape and the program architecture, the NIST AI RMF and ISO/IEC 42001 pages for the two principal frameworks, the shadow AI and AI use policy pair for unauthorized use and its governance, the state AI laws reference and the Texas TRAIGA analysis for the statutory patchwork, and AI vendor due diligence for the AI the organization buys. Each page is maintained, and the perishable ones carry review dates.
Discuss the Research or the Work Behind It
Inquiries may involve the research itself, a question a paper raises for your organization, or the advisory work the analysis supports across AI governance, CMMC, maritime cybersecurity, and cyber insurance readiness. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.
Discuss an Assessment
If a topic in this series bears on a decision your organization is facing, the first conversation carries no commitment and no pitch.
Discuss an Assessment →