Generative AI does not need a separate governance program. It needs the same program with several things added, because a handful of its risks either do not arise with other kinds of AI or arrive with a different shape.
This page covers what changes. The general structure is the AI governance framework, and the per-use-case method is AI risk assessment.
What NIST identifies as distinctive
In July 2024 NIST published the Generative AI Profile, a companion to the AI Risk Management Framework addressing risks unique to or exacerbated by generative AI.
It names twelve. In NIST's own terms they cover CBRN information or capabilities; confabulation; dangerous, violent or hateful content; data privacy; environmental impacts; harmful bias and homogenization; human-AI configuration; information integrity; information security; intellectual property; obscene, degrading or abusive content; and value chain and component integration.
Most organizations will find perhaps five of those material. The value of the list is that it is somebody else's, produced through a public process, so an internal argument about whether a risk is real can be settled by reference rather than by seniority.
Confabulation, and why the word matters
NIST uses confabulation for output that is fluent, plausible and wrong. It is a better term than hallucination because it describes what the system is doing: producing well-formed content that fits the shape of an answer without being grounded in anything.
The governance question is not whether it happens, because it does, at a rate that varies by task and cannot be driven to zero. It is whether anything downstream would catch it before it reached someone. That reframing is the single most useful move available in generative AI governance, because it turns an unsolvable technical problem into an answerable process question.
Three places to ask it. Where output goes to a customer or the public. Where output enters a record that will be relied on later. Where output informs a decision about a person. Everywhere else, the cost of an occasional wrong answer is genuinely low, and treating it as high is how organizations end up reviewing meeting summaries.
Human oversight, and the authority clause
Generative systems produce output that reads as authoritative regardless of whether it is correct, which changes what a reviewer needs.
A reviewer needs enough information to disagree, which usually means access to the source material rather than only the output, and enough time that reviewing is not nominal. They also need actual authority to overturn. A reviewer who cannot in practice reject a recommendation is a rubber stamp, and describing them as human oversight in a policy is worse than claiming none, because it transfers accountability to someone who did not have the power to exercise it.
Write down which outputs require review before they take effect, keyed to consequence rather than to volume, and record who the reviewer is.
Disclosure
Decide whether people are told when generative AI was involved in producing something they receive, and write the decision down.
There is no single right answer and practice is moving. What is clearly wrong is deciding by omission, because the position an organization ends up defending is then whatever happened rather than what it chose. The narrower version of the question is easier to settle and covers most of the exposure: is AI-assisted material identified when it goes to a customer, when it enters a formal record, and when it forms part of a decision communicated to someone.
Intellectual property, in both directions
Two separate questions that get conflated.
What goes in: whether your staff are putting material into a system that they do not have the right to share, including customer material under confidentiality terms, licensed third-party content and unreleased work.
What comes out: what rights, if any, you have in generated output, and what the supplier's terms say about it. This is contract territory and it varies by supplier and by tier.
Both belong in the data rule and in supplier review rather than in a separate policy, and the supplier side is covered in AI vendor risk assessment.
The security risks that are specific rather than general
Generative systems introduce attack shapes that conventional application security does not anticipate.
Prompt injection. Instructions hidden in content the system processes, causing it to behave as the content directs rather than as the operator intended. It matters most where a system reads material the organization does not control.
Data leakage through the interface. A system with broad access answering a question using material the asker should not see. This is access inheritance rather than a breach, and it is covered in AI data governance and privacy.
Excessive agency. A system permitted to take actions rather than only produce text, where the permissions granted exceed what the task requires. This is the risk that grows fastest as agentic tooling spreads.
Supply chain and component integration. Models, plugins, extensions and retrieval sources are dependencies, and NIST names value chain and component integration among the twelve for that reason.
MITRE ATLAS catalogues adversary tactics and techniques against AI-enabled systems, organized into fourteen tactics, and is the reference for threat modelling. OWASP publishes a widely used list for LLM applications; its current edition was published in August 2026 and supersedes earlier versions, so check which edition a source is quoting before relying on item numbers. The broader risk picture is in the AI cybersecurity risks to assess before deployment.
Information integrity, and the risk that is not about your own output
NIST names information integrity among the twelve, and it is the risk organizations most consistently read as somebody else's problem. It is not only about generating misinformation deliberately. It is about the reliability of the information environment an organization now operates in.
Two practical forms of it. The first is homogenization: where many people in an organization draft with the same assistant, output converges, and the range of framings that would once have surfaced in a review narrows without anyone deciding it should. The effect is subtle and cumulative rather than dramatic, and the mitigation is editorial rather than technical.
The second is inbound. Material arriving at your organization, in applications, submissions, correspondence and supplier documentation, is increasingly generated too. Processes designed on the assumption that producing a plausible document takes effort now rest on an assumption that no longer holds. That is a governance question about your own controls rather than about anyone's AI, and it is worth asking of any process where volume was previously a filter.
Agentic use raises the stakes on decisions you have already made
Where a generative system is allowed to act rather than only to draft, every earlier decision matters more.
The questions do not change: what can it reach, what can it do, who reviews, what is logged, and what stops it. What changes is the cost of having answered them loosely. A drafting assistant with over-broad access produces an awkward answer; an agent with the same access performs an action.
The practical governance position is to treat the ability to take an action as a separate approval from the ability to produce text, even in the same product, and to require an explicit decision for the former.
A note on scoping the approval. Many products expose acting and drafting through the same interface, so the distinction has to be drawn in your own policy rather than found in the vendor's product boundaries. The workable line is whether an output changes something outside the conversation: sends, files, schedules, purchases, updates a record, or triggers another system.
What to add to an existing program
Six additions, and none of them is a new document.
- A confabulation position: where output must be checked before it takes effect.
- A disclosure position: when people are told AI was involved.
- An intellectual property line in the data rule, covering what may go in.
- A prompt-injection consideration wherever a system reads untrusted content.
- Separate approval for the ability to act, not only to draft.
- A shorter review cycle, because generative capabilities change faster than other software.
If the underlying program does not exist yet, these additions have nothing to attach to. The order to build it in is how to create an AI governance program, and where you currently stand is the checklist.
LABUSA covers generative and agentic governance within our generative AI governance work, including the awkward middle case of a generative feature switched on inside a product bought years ago. If that is the situation in front of you, get in touch.