Resources

What to ask an AI supplier, what to look for in the agreement, and how to review AI capability that arrived inside software you already own.
Fifty-seven checkable statements across fifteen areas, answered yes or no, to establish where an AI governance program actually stands and what to do first.
What the NIST AI Risk Management Framework is, its four functions, the Generative AI Profile, what it is not, and how to use it without adopting it wholesale.
Voluntary risk guidance versus a certifiable management system. What each instrument is for, how they work together, and language that stays accurate.
Prompts, retrieved context, embeddings, logs and outputs are data your privacy program probably does not map. What to rule on first, and where the data goes.
What generative AI adds to a governance program: confabulation, disclosure, intellectual property, prompt injection, and separate approval for the ability to act.
The twelve decisions an AI acceptable use policy has to make, why it should be a page, and the two sentences that do more work than the rest of the document.
Governing AI in a school district: the inventory, a data rule about student information, approved tools, student use, vendors and what to tell families.
The documents a governance engagement hands over, who owns them, what makes them acceptable, and what happens to them when the person who commissioned the work leaves.
Five measures that show whether AI governance is working, four that mislead, how long each takes to mature, and why the baseline has to be taken before the work starts.