4 Guides
AI Governance Explained
The EU AI Act, ISO 42001, and NIST AI RMF as one program, plus AI policies and the AI section of a security review.
Ship an AI feature and you take on a new set of obligations at once: a law you must follow (the EU AI Act), a standard you can be certified against (ISO/IEC 42001), and a voluntary playbook that shapes expectations (the NIST AI RMF). AI governance is the work of reconciling them into one program instead of three silos.
These guides serve two readers at once: the privacy team writing the AI policy and disclosures, and the security team proving your AI posture in a customer's review. AI rules move faster than any other area of compliance, so treat every date and threshold here as current guidance to re-verify.
AI Governance Guides
- 1EU AI Act, ISO 42001, and NIST AI RMF: How the Three Fit TogetherComparisonA mandatory law, a certifiable standard, and a voluntary playbook, what each one is and how to run them as a single AI governance program.8 min read
- 2What Is the EU AI Act (and What's Actually in Force Now)GuideThe EU's risk-based AI law, which obligations apply today versus which are still phasing in, and the penalties for getting it wrong.8 min read
- 3What Is an AI Policy (and Why You Need One)GuideWhat an AI use policy covers, how it differs from a privacy policy, and why generic policies do not address how AI actually behaves.6 min read
- 4ISO 42001 vs NIST AI RMF: Which Should You PursueComparisonA certifiable AI management standard versus a voluntary US risk framework, what each offers, and when to use one or both.7 min read