Curated Knowledge Base

Policy & Governance Resources

A curated library of frameworks, regulatory documents, case studies, and academic work the author endorses as worthwhile reading for readers of the paper.

Updated OECD Definition of an AI System

The updated OECD definition of an AI system (2023) with its explanatory memorandum — the intergovernmental reference definition many regulators build on.

Topic · Governance, Risk & Compliance

Three Lines of Defense Against Risks from AI (Schuett)

Adapts the Institute of Internal Auditors’ Three Lines model — a framework for assigning and coordinating risk roles — to AI, arguing it closes coverage gaps and lets boards oversee management. The scholarly case for supplementing existing control functions rather than standing up a parallel one.

Topic · Governance, Risk & Compliance

Technical Standard Scope and Definitions

The Language of Trustworthy AI: In-Depth Glossary (NIST)

NIST’s in-depth glossary of trustworthy-AI terms, aligned to the AI RMF — an authoritative vocabulary for the definitions an organization must agree on.

Topic · Governance, Risk & Compliance

Risk Tiering AI Use Cases: A Practical Guide (Google Cloud Office of the CISO)

Tiers AI use cases by autonomy, architectural agency, data and IAM boundaries, and blast radius, then attaches controls to each tier — automated guardrails and a stop control at the autonomous end, human approval plus anti-automation-bias measures in the middle. Insists the controls be technically enforced rather than documented.

Topic · Governance, Risk & Compliance

OpenAI — Hugging Face Model-Evaluation Security Incident

OpenAI’s disclosure of a security incident in a Hugging Face model-evaluation workflow — a concrete case of risk inside the AI evaluation pipeline itself, reinforcing why higher-trust tiers require stronger verification and tighter harnessing.

Topic · Governance, Risk & Compliance

OECD AI Principle: Accountability

The intergovernmental accountability standard: organizations and individuals developing, deploying, or operating AI are accountable for its proper functioning, by role and context — a near-verbatim statement of this chapter’s principle.

Topic · Governance, Risk & Compliance

OECD — Drawing the AI / Non-AI Boundary

OECD’s explainer on drawing the AI / non-AI line — the intergovernmental consensus definition and the “continuum, no red line” framing any boundary test must reckon with.

Topic · Governance, Risk & Compliance

NIST AI RMF: Agentic Profile (Cloud Security Alliance)

An industry profile extending the NIST AI RMF to autonomous agents that independently arrives at a Tier 1 (supervised) through Tier 4 (fully autonomous) classification — with oversight boundaries set per deployment, tool-use risk modeled by consequence scope and reversibility, and delegation registers naming the responsible human.

Topic · Governance, Risk & Compliance

Human-in-the-Loop Artificial Intelligence: A Systematic Review of Concepts, Methods, and Applications

An open-access systematic review that organizes human-in-the-loop systems into a unified taxonomy by loop placement, interaction granularity, and temporal characteristics — a scholarly map of the ground between a human gating every action and a human supervising an autonomous process.

Topic · Governance, Risk & Compliance

How Internal Audit Can Adapt to AI (EY)

Maps AI oversight onto the three lines — operational teams, then risk and compliance, then internal audit — and names who owns what, up through the chief audit executive and the board. Argues for trigger-based coverage tied to high-impact deployments rather than a static annual plan.

Topic · Governance, Risk & Compliance

Examining Human Reliance on Artificial Intelligence in Decision Making (Scientific Reports)

Peer-reviewed evidence that people do discriminate useful AI guidance from bad — but that a positive attitude toward AI measurably degrades that discrimination, and that AI-derived guidance biases judgement in a way equivalent human guidance does not.

Topic · Governance, Risk & Compliance

Detecting and Correcting Reference Hallucinations in Commercial LLMs and Deep Research Agents

Measures fabricated citations at scale — 3–13% of citation URLs hallucinated across ~221,000 URLs and ten models — and finds that deep research agents cite more sources than search-augmented models while hallucinating at a higher rate. The empirical weight behind checking a grounded system’s sources rather than trusting them.

Topic · Governance, Risk & Compliance

Institutional Intelligence Brief

Receive updates on new chapters, critical policy shifts, and emerging AI governance frameworks directly in your inbox.

A double opt-in confirmation keeps the list clean; unsubscribe anytime.