> For the complete documentation index, see [llms.txt](https://handbook.harmonic.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://handbook.harmonic.security/reference/governance-and-frameworks.md).

# Governance & Frameworks

Frameworks, regulations, and program-level guidance for enterprise AI security - covering NIST AI RMF, NIST CSF 2.0, EU AI Act, DORA, ISO 42001, acceptable use policy, and ownership models.

*Last reviewed: August 18, 2026*

{% hint style="info" %}
Effective AI governance ties policy to controls, owners, and evidence. Use this section to translate the handbook's technical controls into the frameworks used by auditors, regulators, legal teams, and executives.
{% endhint %}

The handbook tells security teams what to control across identity, supply chain, runtime, data, threats, observability, and rollout. These reference pages connect those controls to common frameworks, regulations, ownership models, and policy records.

Start with G.1 if you need one crosswalk for the whole program. Start with G.6 and G.7 if the immediate problem is that employees are already using AI tools and nobody owns the rules. Start with G.2, G.3, G.4, or G.9 when legal or compliance is asking how a specific regulation affects AI deployment.

## Articles in this section

1. [G.1 Map your controls to NIST AI RMF and CSF 2.0](/reference/governance-and-frameworks/g.1-map-your-controls-to-nist-ai-rmf-and-csf-2.0.md)
2. [G.2 EU AI Act obligations for deployers](/reference/governance-and-frameworks/g.2-eu-ai-act-obligations-for-deployers.md)
3. [G.3 DORA and AI resilience in financial services](/reference/governance-and-frameworks/g.3-dora-and-ai-resilience-in-financial-services.md)
4. [G.4 Colorado AI Act and the US state patchwork](/reference/governance-and-frameworks/g.4-colorado-ai-act-and-the-us-state-patchwork.md)
5. [G.5 SANS Critical AI Security Guidelines mapping](/reference/governance-and-frameworks/g.5-sans-critical-ai-security-guidelines-mapping.md)
6. [G.6 Write an AI Acceptable Use Policy that holds up](/reference/governance-and-frameworks/g.6-write-an-ai-acceptable-use-policy-that-holds-up.md)
7. [G.7 Ownership and RACI for AI security](/reference/governance-and-frameworks/g.7-ownership-and-raci-for-ai-security.md)
8. [G.8 ISO/IEC 42001 AI management system](/reference/governance-and-frameworks/g.8-iso-iec-42001-ai-management-system.md)
9. [G.9 HIPAA controls for AI systems handling PHI](/reference/governance-and-frameworks/g.9-hipaa-controls-for-ai-systems-handling-phi.md)

## How to use this section

Use these pages as reference material, not legal advice. They help security teams prepare evidence and work with legal, compliance, privacy, procurement, and platform owners. Counsel should confirm scope, deadlines, and legal duties for each use case.

For each AI workflow, keep four records:

* Use case: what the AI system does, who uses it, and whose data or rights it may affect.
* Control posture: which handbook controls apply and which exceptions were approved.
* Owner: who is accountable for the system, the vendor, the data, and incident response.
* Evidence: settings exports, logs, risk assessments, test results, approvals, and review dates.

## Frequently asked questions

### What is the difference between NIST AI RMF and NIST CSF 2.0 for AI security?

NIST AI RMF is built for AI risk across the AI lifecycle. It gives teams a language for governance, context mapping, measurement, and risk management. NIST CSF 2.0 is the broader cybersecurity framework used to organize cyber risk outcomes across Govern, Identify, Protect, Detect, Respond, and Recover. Use AI RMF to describe the AI-specific risk program, then use CSF 2.0 to connect it to the rest of security reporting.

### Do deployers have obligations under the EU AI Act?

Yes. Once the relevant high-risk provisions apply, deployers have duties around following instructions for use, assigning competent human oversight, monitoring operation, keeping relevant logs, escalating risks and serious incidents, and informing affected people when covered high-risk systems support decisions about them. Article 27 also requires a fundamental rights impact assessment for specified deployers and uses.

### Where should an AI governance program start?

Start with ownership and inventory. Name the accountable business owner, security owner, data owner, platform owner, and incident-response owner for each approved AI surface. Then map each workflow to the control matrix and decide what evidence proves the controls are working.

### What is the fastest way to put an AI acceptable use policy in place?

Use the G.6 template as a baseline, but do not stop at a policy document. Pair the policy with tenant restrictions, SSO, approved-tool lists, data handling rules, connector review, and a reporting path for incidents and exceptions.

### Which framework should we use if we only pick one?

Start with NIST AI RMF when the goal is to organize AI risk across the lifecycle. Add NIST CSF 2.0 to connect cybersecurity controls to the wider security program. If the organization wants a certifiable management system, evaluate ISO/IEC 42001.

## Further reading

The links below are the primary framework, law, regulator, standards-body, or official maintainer sources used for this page.

* [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)
* [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework)
* [NIST AI RMF Generative AI Profile](https://doi.org/10.6028/NIST.AI.600-1)
* [Regulation (EU) 2024/1689, Artificial Intelligence Act](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng)
* [European Commission AI Act implementation overview](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)
* [Regulation (EU) 2022/2554, Digital Operational Resilience Act](https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng)
* [Colorado SB26-189, Automated Decision-Making Technology](https://leg.colorado.gov/bills/SB26-189)
* [SANS Critical AI Security Guidelines](https://github.com/sans-community/ai-guidelines)
* [HHS summary of the HIPAA Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html)
* [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)

## Related handbook guidance

* [AI Security Handbook](/ai-security-handbook.md)
* [G.1 Map your controls to NIST AI RMF and CSF 2.0](/reference/governance-and-frameworks/g.1-map-your-controls-to-nist-ai-rmf-and-csf-2.0.md)
* [G.6 Write an AI Acceptable Use Policy that holds up](/reference/governance-and-frameworks/g.6-write-an-ai-acceptable-use-policy-that-holds-up.md)
* [G.7 Ownership and RACI for AI security](/reference/governance-and-frameworks/g.7-ownership-and-raci-for-ai-security.md)
* [7.4 The vendor-neutral control matrix](/handbook/7.-rollout-and-operations/7.4-the-vendor-neutral-control-matrix.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://handbook.harmonic.security/reference/governance-and-frameworks.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
