Curated Knowledge Base

Policy & Governance Resources

A curated library of frameworks, regulatory documents, case studies, and academic work the author endorses as worthwhile reading for readers of the paper.

Who's Responsible for Agentic AI?

Clifford Chance’s survey of who bears responsibility when autonomous AI agents cause harm — the global consensus is to keep humans in charge and accountable rather than grant AI legal personhood.

Topic · Legal & Liability

The Ethics and Challenges of Legal Personhood for AI

A Yale Law Journal Forum essay on the ethics and challenges of granting AI legal personhood — scholarly grounding for treating AI as a tool whose accountability stays with humans, not a separate legal entity.

Topic · Legal & Liability

The Duty of Supervision in the Age of Generative AI

The ABA’s account of the board/executive/legal duty of supervision over generative AI — an organization and its leaders remain accountable for AI use, the accountability principle in a professional-conduct frame.

Topic · Legal & Liability

Redefining the Standard of Human Oversight for AI Negligence (Harvard JOLT)

Argues that “human in the loop” mandates fail on automation bias and vigilance decrement, and names the “liability sponge” — a person absorbing responsibility for a system they lack the capacity to supervise. The legal case for why an operator cannot personally stand in for a harness the work required.

Topic · Legal & Liability

No Legal Personhood for AI

A peer-reviewed argument that AI lacks the agency and accountability that legal personhood would require — scholarly grounding for the chapter’s rejection of AI as a separate, liable entity.

Topic · Legal & Liability

Germany: Court Rules Chatbot Operators Liable for AI Hallucinations

A German court (OLG Hamm, May 2026) held a company liable for its own AI chatbot’s misleading answers — the chatbot is corporate communication, like an employee’s statement. Accountability for AI output flows to the deploying organization.

Topic · Legal & Liability

Germany: Court Holds Google Liable for Incorrect AI Overviews

A German court (Munich, May 2026) held Google directly liable for false statements in its AI Overviews — the AI summary is content attributable to the company. A fresh marker that organizations own their AI’s output.

Topic · Legal & Liability

Generative AI Tools: ABA Formal Opinion 512

An analysis of ABA Formal Opinion 512 by an ABA ethics-committee member: lawyers must understand AI’s limits and independently verify its output, retaining full professional accountability — the principle applied to a regulated profession.

Topic · Legal & Liability

AI in Litigation: Gen-AI Sanctions Update (2026)

A 2026 update on U.S. court sanctions for AI-hallucinated filings — courts uniformly reject “the AI did it”; the responsible attorney owns every citation regardless of the tool. The accountability principle enforced through 2026.

Topic · Legal & Liability

AI Hallucinations in Court Filings: A 2025 Review of Sanctions

A 2025 survey of court sanctions for AI-fabricated citations, documenting how repeatedly judges reject the “the AI made the mistake” defense — the accountability principle enforced in practice.

Topic · Legal & Liability

Updated OECD Definition of an AI System

The updated OECD definition of an AI system (2023) with its explanatory memorandum — the intergovernmental reference definition many regulators build on.

Topic · Governance, Risk & Compliance

Three Lines of Defense Against Risks from AI (Schuett)

Adapts the Institute of Internal Auditors’ Three Lines model — a framework for assigning and coordinating risk roles — to AI, arguing it closes coverage gaps and lets boards oversee management. The scholarly case for supplementing existing control functions rather than standing up a parallel one.

Topic · Governance, Risk & Compliance

Technical Standard Scope and Definitions

The Language of Trustworthy AI: In-Depth Glossary (NIST)

NIST’s in-depth glossary of trustworthy-AI terms, aligned to the AI RMF — an authoritative vocabulary for the definitions an organization must agree on.

Topic · Governance, Risk & Compliance

Risk Tiering AI Use Cases: A Practical Guide (Google Cloud Office of the CISO)

Tiers AI use cases by autonomy, architectural agency, data and IAM boundaries, and blast radius, then attaches controls to each tier — automated guardrails and a stop control at the autonomous end, human approval plus anti-automation-bias measures in the middle. Insists the controls be technically enforced rather than documented.

Topic · Governance, Risk & Compliance

OpenAI — Hugging Face Model-Evaluation Security Incident

OpenAI’s disclosure of a security incident in a Hugging Face model-evaluation workflow — a concrete case of risk inside the AI evaluation pipeline itself, reinforcing why higher-trust tiers require stronger verification and tighter harnessing.

Topic · Governance, Risk & Compliance

OECD AI Principle: Accountability

The intergovernmental accountability standard: organizations and individuals developing, deploying, or operating AI are accountable for its proper functioning, by role and context — a near-verbatim statement of this chapter’s principle.

Topic · Governance, Risk & Compliance

OECD — Drawing the AI / Non-AI Boundary

OECD’s explainer on drawing the AI / non-AI line — the intergovernmental consensus definition and the “continuum, no red line” framing any boundary test must reckon with.

Topic · Governance, Risk & Compliance

NIST AI RMF: Agentic Profile (Cloud Security Alliance)

An industry profile extending the NIST AI RMF to autonomous agents that independently arrives at a Tier 1 (supervised) through Tier 4 (fully autonomous) classification — with oversight boundaries set per deployment, tool-use risk modeled by consequence scope and reversibility, and delegation registers naming the responsible human.

Topic · Governance, Risk & Compliance

Human-in-the-Loop Artificial Intelligence: A Systematic Review of Concepts, Methods, and Applications

An open-access systematic review that organizes human-in-the-loop systems into a unified taxonomy by loop placement, interaction granularity, and temporal characteristics — a scholarly map of the ground between a human gating every action and a human supervising an autonomous process.

Topic · Governance, Risk & Compliance

How Internal Audit Can Adapt to AI (EY)

Maps AI oversight onto the three lines — operational teams, then risk and compliance, then internal audit — and names who owns what, up through the chief audit executive and the board. Argues for trigger-based coverage tied to high-impact deployments rather than a static annual plan.

Topic · Governance, Risk & Compliance

Examining Human Reliance on Artificial Intelligence in Decision Making (Scientific Reports)

Peer-reviewed evidence that people do discriminate useful AI guidance from bad — but that a positive attitude toward AI measurably degrades that discrimination, and that AI-derived guidance biases judgement in a way equivalent human guidance does not.

Topic · Governance, Risk & Compliance

Detecting and Correcting Reference Hallucinations in Commercial LLMs and Deep Research Agents

Measures fabricated citations at scale — 3–13% of citation URLs hallucinated across ~221,000 URLs and ten models — and finds that deep research agents cite more sources than search-augmented models while hallucinating at a higher rate. The empirical weight behind checking a grounded system’s sources rather than trusting them.

Topic · Governance, Risk & Compliance

An Autonomy-Based Classification: AI Agents, Liability and Lessons from the Automated Vehicles Act

A five-level autonomy spectrum for AI agents — graded by generality of function, control allocation, and environmental access — in which liability shifts toward the provider as the user’s control diminishes. A policy-side counterpart to classifying deployments by the constraint around them.

Topic · Governance, Risk & Compliance

AI Board Governance Roadmap (Deloitte)

Directs boards to establish who in management owns AI, to assign oversight to a named body or committee, and to require risk reporting upward — the board-level counterpart to naming a single policy owner distinct from a governance council.

Topic · Governance, Risk & Compliance

A Decoupled Human-in-the-Loop System for Controlled Autonomy in Agentic Workflows

Proposes treating human oversight as an independent component of the agent operating environment rather than logic hard-coded into each workflow, with a four-dimension design framework covering when humans engage, who decides, and through what channel. An architecture for where the gate lives.

Topic · Governance, Risk & Compliance

European Commission Guidelines on the Definition of an AI System

The European Commission’s official guidelines (Feb 2025) on how to determine whether a software system is an “AI system” under the AI Act — the practical boundary test behind the Article 3 definition.

Topic · EU Regulation

EU Draft Guidelines on Classifying High-Risk AI Systems

The Commission’s draft guidelines on classifying high-risk AI systems — which categories of AI system draw heightened obligations, a comparative reference for defining the scope a policy governs.

Topic · EU Regulation

EU AI Act Article 3, Annotated (Future of Life Institute)

A readable, recital-linked annotation of EU AI Act Article 3 (68 defined terms including “AI system”), maintained by the Future of Life Institute — a convenient reader reference (unofficial machine translation).

Topic · EU Regulation

EU AI Act — Article 3: Definitions

The EU AI Act’s binding legal definition of an “AI system” (Article 3(1)), on the Commission’s official Act Service Desk — the authoritative anchor for what a policy governs and where the boundary sits.

Topic · EU Regulation

EU AI Act — Article 14: Human Oversight

The legal spine of a domain custodian’s veto. On the Commission’s official Act Service Desk, Article 14 requires that human oversight be assigned to natural persons with the necessary competence, training and “authority” — empowered to disregard, override or reverse an AI system’s output and to interrupt its operation.

Topic · EU Regulation

Regulatory

Colorado Artificial Intelligence Act (SB 24-205)

The first comprehensive US state AI law: a duty of reasonable care on developers and deployers of high-risk systems making consequential decisions. Effective June 30, 2026.

Topic · US Regulation

Regulatory

California Transparency in Frontier AI Act (SB 53)

California’s frontier-model transparency law — published safety frameworks, critical-incident reporting, transparency reports, and whistleblower protections for large frontier developers.

Topic · US Regulation

Framework

UK Government — Artificial Intelligence Playbook

The UK government’s practical playbook for safe, effective AI adoption across public-sector teams — a strong, concrete comparator for enterprise policy.

Topic · Public Sector

Templates

GovAI Coalition — AI Policy Templates & Resources

A reusable, NIST-aligned toolkit — policy template, governance handbook, incident-response plan, and vendor agreement — built by public-sector practitioners for direct adaptation.

Topic · Public Sector

Academic

GAO-25-107653 — Generative AI Use at Federal Agencies

A comparative GAO study of generative-AI use and management across 12 federal agencies — a rigorous inventory of how large institutions are actually governing AI.

Topic · Public Sector

Academic

CDT — AI in Local Government

The Center for Democracy & Technology’s comparative analysis of AI governance across roughly 20 counties and cities — strong orientation reading on the public-sector layer.

Topic · Public Sector

Case Study

Moffatt v. Air Canada (2024)

A tribunal held the company liable for its chatbot’s inaccurate information — establishing that organizations own what their AI tells customers.

Topic · Legal & Liability

Case Study

Mata v. Avianca (S.D.N.Y. 2023)

The landmark sanctions case where attorneys filed ChatGPT-fabricated citations — the canonical cautionary tale on unverified generative output in professional work.

Topic · Legal & Liability

Regulatory

HHS HTI-1 Final Rule — Algorithm Transparency (FAVES)

Introduces “Predictive Decision Support Interventions” and the FAVES criteria (Fair, Appropriate, Valid, Effective, Safe) — the key transparency rule for AI in healthcare.

Topic · Healthcare

Framework

Singapore Model AI Governance Framework for Generative AI

The most influential non-EU AI governance framework — a practical, principles-based model for governing generative AI, widely referenced by regulators and enterprises internationally.

Topic · Governance, Risk & Compliance

Technical Standard

NIST Generative AI Profile (NIST AI 600-1)

NIST’s companion profile applying the AI RMF specifically to generative AI — the most current and directly applicable NIST guidance for GenAI deployments.

Topic · Governance, Risk & Compliance

Technical Standard

NIST AI Risk Management Framework (AI RMF 1.0)

The foundational US framework for identifying, measuring, and managing AI risk across the system lifecycle — the reference most enterprise governance programs map back to.

Topic · Governance, Risk & Compliance

Case Study

In re Knight Capital — SEC Enforcement Order (2013)

The $440M automated-trading failure — a deployment and rollback gone wrong. The SEC order is the primary account of how an untested change cascaded in minutes.

Topic · Financial Services

Templates

FS-ISAC — Acceptable Use Policy Framework for External GenAI

A financial-services-flavored template for an external generative-AI acceptable-use policy — a useful starting point for the Financial Services overlay.

Topic · Financial Services

Regulatory

FINRA Regulatory Notice 24-09 — Generative AI

FINRA’s technology-neutral position: existing supervision, communications, and books-and-records rules apply directly to AI use in financial services.

Topic · Financial Services

Regulatory

EU Artificial Intelligence Act (Regulation 2024/1689)

The world’s first comprehensive, risk-tiered AI regulation. High-risk obligations phase in through 2026–2027; the high-risk provisions are the priority read for enterprises.

Topic · EU Regulation

Case Study

EEOC v. iTutorGroup (2023)

The EEOC’s first AI hiring-discrimination settlement — automated screening that rejected applicants by age. A marker for algorithmic-bias liability in employment.

Topic · Employment

Institutional Intelligence Brief

Receive updates on new chapters, critical policy shifts, and emerging AI governance frameworks directly in your inbox.

A double opt-in confirmation keeps the list clean; unsubscribe anytime.