Side profile of a person merging into data dashboards, charts, and network graphics, representing human oversight of AI governance
AI Governance

Your AI governance program is a binder.Your auditors want a system.

Most AI governance shipped in the last two years is a deck and a policy. Neither survives an enterprise security review, an ISO audit, or an EU supervisory authority asking for evidence. We build the operating system instead.

Scope a Governance Diagnostic
NIST AI RMF aligned
ISO/IEC 42001 ready
EU AI Act mapped

The Shape of the NIST AI RMF

4

NIST Functions

Govern · Map · Measure · Manage

19

Categories

Across the AI lifecycle

72

Subcategories

Each with an audit artifact

12

GenAI Risks

NIST AI 600-1 profile

Last reviewed August 2026. Regulatory dates change. This page is re-verified quarterly.

Frameworks

Three frameworks. One operating system.

They do not overlap perfectly. They overlap meaningfully. Run them as one program.

NIST AI Risk Management Framework 1.0

Published by the US National Institute of Standards and Technology on January 26, 2023. Voluntary, non-prescriptive, and built around 4 functions, 19 categories, and roughly 72 subcategories. The framework tells you what to achieve. It deliberately does not tell you how. That gap is the work, and that gap is also why it has become the de facto standard for US enterprise procurement, federal-adjacent buyers, and any vendor questionnaire that mentions AI.

One thing to plan around: AI RMF 1.0 is currently under revision as part of the White House AI Action Plan. The four-function structure is stable and the subcategories are the working unit, so a program built on them will survive the revision. Sector profiles are where the near-term movement is. NIST released a concept note in April 2026 for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, and a Cyber AI Profile is in draft.

Who needs it

Any company selling to US enterprise or federal-adjacent buyers. Any company whose security questionnaire from a customer references AI governance, model lineage, or automated decision-making. Treat the voluntary label as misleading: federal procurement, ISO 42001 audits, and enterprise vendor reviews all anchor to it.

Common gap

Treating Measure as a model performance exercise instead of a risk quantification exercise. The Playbook's suggested actions are the fastest route to closing this gap.

How the four functions relate to each other

Think of it as a continuous operating loop, not a linear sequence. GOVERN is the permanent foundation. It is always on and infused through everything. MAP, MEASURE, and MANAGE cycle continuously throughout the AI system's lifecycle.

G
Govern

Culture, policies, accountability, oversight. The only function that spans the entire organization at all times. Enables the other three to be repeatable.

M
Map

Scope and context. Identify which AI systems exist, who they affect, and what the risk landscape looks like before measuring anything.

Me
Measure

Quantify and track. Use testing, evaluation, verification, and validation (TEVV) to assess identified risks with rigor. Not intuition.

Turn non-determinism into evidence. That's what TEVV is for.

Mg
Manage

Respond. Allocate resources to prioritized risks. Mitigate, transfer, avoid, or accept risk. Build incident response. Monitor continuously.

The key insight for your advisory practice: The framework is intentionally non-prescriptive. It tells organizations WHAT outcomes to achieve but rarely says HOW in concrete terms. That gap is exactly where a Sophizo engagement sits. We provide the implementation that translates NIST subcategories into board-ready procedures, controls, and KPIs.

Risk Lens

Two lenses. Same discipline.

The 12 GenAI risks tell you what can go wrong. The 7 characteristics tell you what good looks like. Both anchor every Measure and Manage decision.

NIST AI 600-1 · Generative AI Profile · July 2024

Top three for B2B operators

Confabulation

Confidently stated, factually wrong output. The number one risk for enterprise copilots and customer-facing deployments. Requires TEVV baselines, confidence flagging, and human review gates.

Value Chain & Component Integration

Third-party models, APIs, datasets, and infrastructure introduce risk the deployer does not fully control. The most systemic and underappreciated category. Invisible until failure.

Human-AI Configuration

Workflow design risk, not a model risk. Automation bias, over-automation, anthropomorphism. No model-level control fixes this. Human-in-the-loop checkpoints and override mechanisms do. Most of your stack should stay deterministic software. A smaller layer is model judgment. A smaller layer still is human approval. The failure mode isn't using AI, it's not knowing which of the three a given decision belongs to.

All 12 categories

CBRN Information

Confabulation

Dangerous, Violent, or Hateful Content

Data Privacy

Environmental Impacts

Harmful Bias & Homogenization

Human-AI Configuration

Information Integrity

Information Security

Intellectual Property

Obscene, Degrading, or Abusive Content

Value Chain & Component Integration

One program, not three.Three audit-ready extensions.

NIST AI RMF, ISO/IEC 42001, and the EU AI Act are not three competing programs. They are one operating discipline with three compliance extensions. The right sequencing is the difference between framework fatigue and a program that compounds.

01

Build NIST AI RMF first

The four-function structure is the most flexible. It maps cleanly onto both EU AI Act obligations and ISO 42001 requirements without framework-specific constraints. This is your operating discipline.

02

Use ISO 42001 to formalize

The certifiable wrapper makes the program auditable and durable for enterprise sales and procurement. If you already hold ISO 27001, the shared Annex SL structure makes 42001 a meaningfully smaller lift.

03

Apply EU AI Act categories to triage

Run every in-scope system through the Act's risk-tier categorization. The output tells you which systems require full high-risk compliance treatment. The Digital Omnibus moved high-risk obligations to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I. The extra runway is real. The triage is not optional, because classification is what tells you which clock you are on.

04

Layer NIST AI 600-1 wherever GenAI is in production

Twelve GenAI risk categories. 200+ suggested actions. All mapped back to the four base functions. Treat it as a modular extension, not a separate program.

The framing that lands with CFOs and General Counsel: one foundational governance program with three compliance extensions. Not three separate programs competing for the same team bandwidth and the same budget line.

Current State

The dates most governance decks still get wrong.

The EU AI Act timeline changed in July 2026. Half the obligations moved. Half did not. Guides written before June are actively misleading.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026, six days before the original August 2 high-risk deadline. It deferred the heaviest compliance regime and left the most broadly applicable obligations exactly where they were. If your compliance calendar was built before June 2026, parts of it are wrong in both directions.

In force now

  • Article 50 transparency. Chatbot disclosure, machine-readable marking of AI-generated content, and deepfake labeling applied from August 2, 2026 and were not deferred. Enforced by national market surveillance authorities.
  • GPAI enforcement powers. Obligations on general-purpose AI model providers applied from August 2, 2025. From August 2, 2026 the European Commission, through the AI Office, can investigate, demand model access, and impose penalties.
  • Prohibited practices. Article 5 has applied since February 2025.
  • Penalty ceiling. Article 50 and GPAI breaches sit in the same tier: the greater of 15 million euros or 3 percent of worldwide annual turnover.

Deferred or pending

  • December 2, 2026. Article 50(2) marking obligation reaches generative systems already on the market before August 2, 2026. New Article 5 prohibitions also apply, including AI-generated non-consensual intimate imagery and CSAM.
  • August 2, 2027. GPAI models placed on the market before August 2, 2025 must be brought into full compliance.
  • December 2, 2027. High-risk obligations for standalone Annex III systems. Recruitment screening, credit scoring, employee monitoring.
  • August 2, 2028. High-risk obligations for AI embedded in regulated products under Annex I.

The delay is real and it is narrow. Article 50 reaches every customer-facing chatbot you run. That obligation is live today and most teams filed it under 2027.

United States

There is no federal AI law. There are fifty state legislatures.

For a US B2B SaaS company, the binding obligations are state, not federal and not European.

More than 2,000 AI-related bills have been introduced across the states. A December 2025 executive order directed federal agencies to pursue preemption of state AI laws, and a Department of Justice AI Litigation Task Force was stood up in January 2026 to challenge them. The White House followed with a National Policy Framework for Artificial Intelligence on March 20, 2026, a set of non-binding legislative recommendations to Congress. No federal statute or court has preempted any state AI law. Until one does, the state patchwork is the operative rule set, and planning against its disappearance is speculation rather than strategy.

Texas: TRAIGA (HB 149), effective January 1, 2026

Intent-based statute. Bans deliberately developing or deploying AI to manipulate, unlawfully discriminate, or infringe rights. The broad high-risk impact assessment regime was cut from the final bill. Enforced by the Texas Attorney General.

Organizations substantially complying with the NIST AI RMF gain safe-harbor protection against enforcement. Documented RMF alignment is now a legal defense in Texas, not just good practice.

Colorado: repealed and replaced

The 2024 Colorado AI Act (SB 24-205) was repealed and reenacted as SB 26-189, signed May 14, 2026, before it ever took effect. The replacement is a narrower automated decision-making transparency regime centered on consumer notices, adverse-outcome explanations, and human review rights. Substantive obligations start January 1, 2027. Note what did not survive: the original framework safe harbor for NIST AI RMF or ISO 42001 compliance is gone.

California: live since January 1, 2026

SB 53, the Transparency in Frontier Artificial Intelligence Act, targets developers training models above a compute threshold. AB 2013 requires training-data disclosure and applies far more broadly, to any generative AI developer making a system available in California. SB 942 adds content-provenance obligations for large-scale generative systems. CPPA automated decision-making regulations phase in through 2027 and beyond.

Employment is the hot zone

Illinois HB 3773 amended the Illinois Human Rights Act to cover AI in employment decisions, effective January 1, 2026. New York City Local Law 144 has required bias audits for automated employment decision tools since 2023. If your product touches hiring, promotion, or performance evaluation, you are already in scope somewhere.

The practical answer is not fifty compliance programs. It is one NIST-anchored operating discipline with jurisdictional overlays, re-checked quarterly.

Free Strategy Brief

The NIST AI Risk Strategy

A board-ready brief on operationalizing NIST AI RMF without hiring a binder writer.

How to translate four functions, 19 categories, and 12 GenAI risks into a 90-day execution plan your CFO and General Counsel will sign off on. Read it before your next AI risk committee meeting.

What is inside:

  • Board-ready framing. How to position AI risk to a board that does not want another binder.
  • Function-by-function execution plan. What Govern, Map, Measure, and Manage produce in the first 90 days.
  • GenAI Profile triage. Which of the 12 NIST AI 600-1 risks actually matter for your stack, and which are noise.
  • Vendor and procurement playbook. The questions enterprise security teams are about to start asking your AI vendors.
No paywall. No sales sequence. Email used only to send the brief.

Send me the brief.

Tell us where to send it. Opens instantly in a new tab.

Operating System

If you can't show them what the agent did, they will never trust it. An audit trail isn't a compliance checkbox, it's the artifact that earns trust.

Six artifacts. One source of truth.

Build once. Maintain as discipline. Security, ISO, EU supervisory authority, LP, board: all read from the same evidence.

AI Inventory and Risk Register

Every AI system in production, shadow AI included. Risk tier, owner, review cadence. Refreshed quarterly.

Written AI Policy

Two pages. What may be used, what data is off-limits, what review is required, who escalates. Two pages is the adoption ceiling.

Vendor Assessment Framework

One-page checklist every new AI vendor signs. Data, lineage, certifications, termination return. Kills shadow procurement.

Quarterly Board Review Cadence

Standing fifteen-minute slot. Inventory delta, incidents, top use cases. Builds board literacy without burning the agenda.

Incident Response Runbook

What happens when an AI system causes harm, leaks data, or fails oversight. Owner, classification, comms, regulator triggers. Tested in a tabletop.

Agent Action Log

Every autonomous decision, timestamped and traceable: what the agent saw, what it decided, and why. The record your security review, your board, and your own team need before they'll trust the output. This is no longer a nice-to-have. Singapore's IMDA published a Model AI Governance Framework for Agentic AI in January 2026, the first comprehensive governance framework built for autonomous agents, and it requires each agent to carry a verifiable digital identity and an audit trail of which agent acted under whose authorization.

Agentic Layer

The agent standards landed in the last nine months.

No single standard governs autonomous agents yet. Four converging references now do most of the work, and none of them existed when your governance policy was written.

  • NIST AI Agent Standards Initiative. Launched by the Center for AI Standards and Innovation on February 17, 2026. Organized around industry-led standards, open-source protocol development, and security and identity research. The accompanying NCCoE concept paper covers agent authentication, authorization, auditing, non-repudiation, and prompt injection mitigation.

  • OWASP Top 10 for Agentic Applications 2026. Published December 10, 2025. The most operationally specific reference available, because it names attack mechanics rather than risk categories: goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, cascading multi-agent failure.

  • Singapore IMDA Model AI Governance Framework for Agentic AI. January 2026. Verifiable agent identity and authorization audit trail as baseline requirements.

  • Berkeley CLTC Agentic AI Risk-Management Standards Profile. February 2026. The most comprehensive agentic risk taxonomy currently available, structured as an extension of the NIST AI RMF across Govern, Map, Measure, and Manage.

EU AI Act Article 14 on human oversight and Article 15 on accuracy, robustness, and cybersecurity apply directly to autonomous agents in high-risk domains. The obligation lands on the deployer, not the model vendor.

By Industry

The framework stack flexes by sector. HIPAA in healthcare. GLBA and FCRA in financial services. FERPA in education. Bar guidance in legal. C2PA for media. The operating discipline holds across all of them. See sector deep-dives

Engage

Pick the entry point.

Three shapes. Different commitment. Same operating discipline.

Every engagement moves the same way: controlled environment, then shadow mode, then increasing autonomy, then production. Risk goes down at every step, which is why boards approve it.

Governance Diagnostic

2 to 4 weeks

Scored gap assessment across the three frameworks. Named bottleneck, prioritized roadmap, cost-to-green estimate.

Best for: Teams that need a baseline before they invest.

Scope a diagnostic

Most chosen

Governance Build

90 days

The full six-artifact operating system. Inventory, policy, vendor framework, board cadence, incident runbook, agent action log.

Best for: Teams preparing for enterprise sales, an ISO audit, or a board review.

See the Governance Accelerator

Governance Operate

Ongoing retainer

Fractional AI governance ownership. Quarterly board reporting, vendor reviews, incident response, regulator-readiness.

Best for: Teams without the internal capacity to run governance as a discipline.

Talk to us

Questions operators actually ask

Make governance the operating advantage.

Book a 30-minute scoping call. We tell you which framework bites first, what 90 days looks like for your stack, and where security and privacy already do half the work.

Schedule Free Call

Guidance, not legal advice. EU AI Act, NIST AI RMF, and ISO/IEC 42001 evolve. Regulatory timelines changed materially in 2026 and continue to move. ISO 42001 certification is issued by accredited certification bodies, not by Sophizo. Engage qualified legal counsel and a certification body for jurisdiction-specific work.