- AI Control Layer
- An AI control layer is software that sits between an organization's people, applications, and data and the AI models they call. It routes each request, retrieves only permitted sources, applies access rules and guardrails, and writes an audit record of the call.
- Knowledge Spaces
- AI Governance
- AI governance is the way an organization decides which AI systems it will use, who may use them, and how each one is checked while it is in service. It assigns decision rights, sets policy, and produces records that auditors, oversight bodies, and boards can inspect.
- AI Governance Is Not Optional: A Practical Framework
- AI Inventory
- An AI inventory is a maintained record of every AI system an organization uses or is developing, with its owner, purpose, data, and status. It is the reference for risk assessment, monitoring, and periodic recertification of each system.
- Federal AI Governance: A Practical Agency Roadmap
- AI Policy
- An AI policy is a written rule for how an organization and its staff may use AI. A policy set typically covers staff use of generative AI, data handling, transparency notices, human review, third-party AI services, and AI output used in decisions or as evidence.
- AI Governance and Policy Services
- AI Risk Register
- An AI risk register lists the risks attached to an organization's AI systems, each with a rating, a control, an owner, and a review date. Review depth follows a risk tier set by the system's potential impact, so higher-impact systems receive fuller assessment.
- AI Governance Roadmap for Mid-Market Enterprises
- AI Sandbox
- An AI sandbox is a controlled environment for testing AI tools before production use. It needs an approved data policy, named users, budget limits, restricted tools, and a clear exit path, and testing starts with public or approved test material.
- How to Build a Governed AI Sandbox
- AI Use Case Intake
- AI use case intake is the standard form and approval path that every proposed use of AI passes through before work begins. The form records the use case, data sources, owner, and intended users, and each approved use is entered in the AI inventory.
- Audit Log
- An audit log is a time-ordered record of actions taken in a system. For an AI system, each entry records the actor, the action, the resource, the status, and the time, so a reviewer can establish who did what and when.
- Building Audit Trails for Agentic AI Workflows
- Evaluation Run
- An evaluation run tests an AI system against a set of questions with recorded correct answers and scores the results. Runs are repeated when a prompt, a model, or a source changes, so a team can compare results before and after the change.
- Guardrail
- A guardrail is a configurable rule applied to what goes into or comes out of an AI system. Guardrails limit an assistant to allowed topics, block disallowed outputs, add required disclaimers, and escalate a request to a person when a rule is triggered.
- The Security Review Checklist for Enterprise AI Tools
- Human Review
- Human review is an approval step in which a person examines an AI system's proposed output or action before it takes effect. A review design defines who may request the action, what the reviewer sees, and what the system does after approval or rejection.
- How to Design Human Review for Agentic Automation
- Model Routing
- Model routing sends each request to the AI model suited to it, based on task complexity, cost, and latency. Routing across providers lets an organization change or add models without rebuilding the applications that depend on them.
- The Executive Guide to Multi-Model AI Operations
- NIST AI Risk Management Framework
- The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework from the National Institute of Standards and Technology for managing the risks of AI systems. It is organized around four functions: Govern, Map, Measure, and Manage. The NIST Generative AI Profile (NIST AI 600-1) applies it to generative AI.
- NIST AI Risk Management Framework at nist.gov
- Performance and Drift Monitoring
- Performance and drift monitoring is the scheduled measurement of an AI system in production against set thresholds for accuracy, fairness, and drift in inputs and outputs. When a threshold is crossed, the check opens a ticket with a named owner.
- Prompt Injection
- Prompt injection is an attack in which text placed in a user message or a retrieved document instructs an AI system to disregard its rules. Defenses include source trust rules, isolation, allowlists, testing, output filtering, and audit logs.
- How Prompt Injection Enters Enterprise Retrieval Systems
- Responsible AI Framework
- A responsible AI framework is the set of policies, roles, and controls an organization uses to decide which AI systems it will run and to keep them safe, fair, and effective while they are in use. A complete framework covers ethics and integrity standards, use case intake, an inventory of AI systems, risk assessment, performance and drift monitoring, staff training, and a governance body with defined decision rights.
- Retrieval Grounding
- Retrieval grounding is the practice of answering from documents retrieved at the time of the question, in addition to what the model learned in training. A grounded answer cites the passages it used, so a reader can inspect the source that supports each claim.
- Building AI Systems That Can Cite Their Sources
- Role-Based Access Control
- Role-based access control (RBAC) grants permissions according to a user's assigned role. In an AI system it determines which assistants, knowledge sources, and administrative functions a person can reach, so an assistant answers only from material that person is permitted to see.
- Data Governance for AI Programs With Sensitive Information