Governance & Frameworks
Frameworks, regulations, and program-level guidance for enterprise AI security - covering NIST AI RMF, NIST CSF 2.0, EU AI Act, DORA, ISO 42001, acceptable use policy, and ownership models.
Last reviewed: August 18, 2026
The handbook tells security teams what to control across identity, supply chain, runtime, data, threats, observability, and rollout. These reference pages connect those controls to common frameworks, regulations, ownership models, and policy records.
Start with G.1 if you need one crosswalk for the whole program. Start with G.6 and G.7 if the immediate problem is that employees are already using AI tools and nobody owns the rules. Start with G.2, G.3, G.4, or G.9 when legal or compliance is asking how a specific regulation affects AI deployment.
Articles in this section
How to use this section
Use these pages as reference material, not legal advice. They help security teams prepare evidence and work with legal, compliance, privacy, procurement, and platform owners. Counsel should confirm scope, deadlines, and legal duties for each use case.
For each AI workflow, keep four records:
Use case: what the AI system does, who uses it, and whose data or rights it may affect.
Control posture: which handbook controls apply and which exceptions were approved.
Owner: who is accountable for the system, the vendor, the data, and incident response.
Evidence: settings exports, logs, risk assessments, test results, approvals, and review dates.
Frequently asked questions
What is the difference between NIST AI RMF and NIST CSF 2.0 for AI security?
NIST AI RMF is built for AI risk across the AI lifecycle. It gives teams a language for governance, context mapping, measurement, and risk management. NIST CSF 2.0 is the broader cybersecurity framework used to organize cyber risk outcomes across Govern, Identify, Protect, Detect, Respond, and Recover. Use AI RMF to describe the AI-specific risk program, then use CSF 2.0 to connect it to the rest of security reporting.
Do deployers have obligations under the EU AI Act?
Yes. Once the relevant high-risk provisions apply, deployers have duties around following instructions for use, assigning competent human oversight, monitoring operation, keeping relevant logs, escalating risks and serious incidents, and informing affected people when covered high-risk systems support decisions about them. Article 27 also requires a fundamental rights impact assessment for specified deployers and uses.
Where should an AI governance program start?
Start with ownership and inventory. Name the accountable business owner, security owner, data owner, platform owner, and incident-response owner for each approved AI surface. Then map each workflow to the control matrix and decide what evidence proves the controls are working.
What is the fastest way to put an AI acceptable use policy in place?
Use the G.6 template as a baseline, but do not stop at a policy document. Pair the policy with tenant restrictions, SSO, approved-tool lists, data handling rules, connector review, and a reporting path for incidents and exceptions.
Which framework should we use if we only pick one?
Start with NIST AI RMF when the goal is to organize AI risk across the lifecycle. Add NIST CSF 2.0 to connect cybersecurity controls to the wider security program. If the organization wants a certifiable management system, evaluate ISO/IEC 42001.
Further reading
The links below are the primary framework, law, regulator, standards-body, or official maintainer sources used for this page.
Related handbook guidance
Last updated
Was this helpful?