Part VII: Organizational AI governance
An organization needs to know which AI systems it uses, who can make decisions about them, and which risks justify further security work.
A control can be effective in one application while other AI uses remain unknown. Chapter 20 connects approved and unapproved uses to accounts, connectors, data, suppliers, and review dates. Chapter 21 assigns decision authority and examines duties that depend on the organization and its setting. Chapter 22 compares exposure, expected outcomes, uncertainty, and cost to support security investment. These decisions depend on the technical evidence established in the earlier Parts.
Chapters in this part
- Shadow AI and unmanaged use: An organization-wide adoption process connects visible AI uses to acceptable-use rules, account and connector controls, and employee support.
- Responsibility and legal duties: A responsibility map assigns decisions and evidence across developers, providers, deployers, data owners, purchasers, and affected people.
- Prioritizing security investment: An investment decision connects measures, evidence, responsible owners, review dates, and remaining risk to staff, money, and time.