Curated Knowledge Base

Policy & Governance Resources

A curated library of frameworks, regulatory documents, case studies, and academic work the author endorses as worthwhile reading for readers of the paper.

Updated OECD Definition of an AI System

The updated OECD definition of an AI system (2023) with its explanatory memorandum — the intergovernmental reference definition many regulators build on.

Topic · Governance, Risk & Compliance

Risk Tiering AI Use Cases: A Practical Guide (Google Cloud Office of the CISO)

Tiers AI use cases by autonomy, architectural agency, data and IAM boundaries, and blast radius, then attaches controls to each tier — automated guardrails and a stop control at the autonomous end, human approval plus anti-automation-bias measures in the middle. Insists the controls be technically enforced rather than documented.

Topic · Governance, Risk & Compliance

OECD AI Principle: Accountability

The intergovernmental accountability standard: organizations and individuals developing, deploying, or operating AI are accountable for its proper functioning, by role and context — a near-verbatim statement of this chapter’s principle.

Topic · Governance, Risk & Compliance

OECD — Drawing the AI / Non-AI Boundary

OECD’s explainer on drawing the AI / non-AI line — the intergovernmental consensus definition and the “continuum, no red line” framing any boundary test must reckon with.

Topic · Governance, Risk & Compliance

NIST AI RMF: Agentic Profile (Cloud Security Alliance)

An industry profile extending the NIST AI RMF to autonomous agents that independently arrives at a Tier 1 (supervised) through Tier 4 (fully autonomous) classification — with oversight boundaries set per deployment, tool-use risk modeled by consequence scope and reversibility, and delegation registers naming the responsible human.

Topic · Governance, Risk & Compliance

How Internal Audit Can Adapt to AI (EY)

Maps AI oversight onto the three lines — operational teams, then risk and compliance, then internal audit — and names who owns what, up through the chief audit executive and the board. Argues for trigger-based coverage tied to high-impact deployments rather than a static annual plan.

Topic · Governance, Risk & Compliance

An Autonomy-Based Classification: AI Agents, Liability and Lessons from the Automated Vehicles Act

A five-level autonomy spectrum for AI agents — graded by generality of function, control allocation, and environmental access — in which liability shifts toward the provider as the user’s control diminishes. A policy-side counterpart to classifying deployments by the constraint around them.

Topic · Governance, Risk & Compliance

AI Board Governance Roadmap (Deloitte)

Directs boards to establish who in management owns AI, to assign oversight to a named body or committee, and to require risk reporting upward — the board-level counterpart to naming a single policy owner distinct from a governance council.

Topic · Governance, Risk & Compliance

Framework

UK Government — Artificial Intelligence Playbook

The UK government’s practical playbook for safe, effective AI adoption across public-sector teams — a strong, concrete comparator for enterprise policy.

Topic · Public Sector

Framework

Singapore Model AI Governance Framework for Generative AI

The most influential non-EU AI governance framework — a practical, principles-based model for governing generative AI, widely referenced by regulators and enterprises internationally.

Topic · Governance, Risk & Compliance

Institutional Intelligence Brief

Receive updates on new chapters, critical policy shifts, and emerging AI governance frameworks directly in your inbox.

A double opt-in confirmation keeps the list clean; unsubscribe anytime.