AI Governance Library

AI Governance Library  

Responsible AI materials from standards, risk fram…

How well do you know enterprise AI control points?. Build an educational quiz around practical control choices across the AI lifecycle. Focus on scenario-style distinctions such as what belongs in an AI inventory, what incident response must define, and when decommissioning requires dependency and retention planning.

Q1. A project team is building an AI system inventory. Which item belongs in the inventory according to the NIST sources? - A list of the system's artifacts, such as incident response plans, data dictionaries, source code links, and AI actor contact information - A marketing summary of the model's b...

View

What AI Act dates should compliance teams know?. Lay out the EU AI Act timeline from entry into force through the 2025, 2026, and 2027 application milestones. For each date, connect the timing to the relevant obligation category, including prohibitions, AI literacy, general-purpose AI duties, high-risk systems, and enforcement posture.

The EU AI Act did not arrive all at once. It entered into force on 1 August 2024, then rolled out in waves through 2025, 2026, and 2027[[cite:1]][[cite:2]]. First wave: 2 February 2025. That is when prohibitions and AI literacy obligations entered into application, including Article 4 AI literacy du...

View

Which AI governance standards are ready, and which still need science?. Create five cards that distinguish ready-for-standardization topics from areas still needing more scientific or foundational work. Emphasize the practical consequence: some governance topics can be standardized now, while others should be treated as evolving measurement problems.

Risk-based AI governance is ready for immediate standardization. Security, privacy, transparency, incident response, recovery, training-data practices, terminology, and taxonomy are near-term standards candidates. TEVV procedures can be standardized now, but TEVV metrics and scientific validity stil...

View

What does lifecycle AI governance actually require?. Synthesize the recurring lifecycle model across NIST and the EU AI Act: govern, map, measure, manage, document, test, monitor, manage suppliers, and decommission. Separate voluntary guidance from binding obligations so readers can see what is a governance best practice versus a legal compliance requirement.

Lifecycle AI governance: what NIST and the EU AI Act together require The NIST AI RMF and its Playbook treat AI governance as a **full lifecycle control system** spanning govern, map, measure, and manage, with supporting practices such as documentation, testing, monitoring, supplier oversight, and d...

View
  • 1(current)