Articles tagged: AI Governance
12 articles on AI Governance from the Top Floor insights library.
2026-08-25
Does the EU AI Act Require a Conformity Assessment for Your System?
Every high-risk AI system needs one, but for most of Annex III it is a self-assessment with no notified body. The notified body enters in two places only, and the deadline moved when the Digital Omnibus on AI took effect.
2026-08-23
How Long Does ISO 42001 Certification Take?
Four to nine months, and the audit is days of it. Stage 2 tests whether the AI management system operated rather than whether it was designed, which puts a floor under the calendar that no budget removes.
2026-08-23
How to Write an AI Acceptable Use Policy
Six sections and two pages. ISACA's 2026 research puts formal AI policy adoption at 38 percent against 90 percent believing employees already use AI, which means most organizations are governing the tools after the fact rather than before.
2026-08-23
Colorado's New AI Law: What SB 26-189 Requires
Colorado repealed its 2024 AI Act roughly seven weeks before its obligations were due to take effect and replaced it with a narrower disclosure regime. The impact assessments and duty of care are gone; notice, explanation and human review are in, from January 1, 2027.
2026-08-23
What Belongs in an AI System Inventory
Nine fields, one row per system, and a definition of system that includes the tools you did not buy. The inventory is the artifact every AI governance framework assumes you have and the one companies most often do not.
2026-08-22
What Does ISO 42001 Certification Actually Cost?
Published estimates for ISO 42001 run from a few thousand dollars to $650,000, and every one of them is defensible. Here is why they disagree, what the certification body actually charges, and how to place your own company on the range.
2026-08-22
California's ADMT Rules: Does Your AI Make a Significant Decision?
The trigger is not that you use AI. It is that a technology substantially replaces human decisionmaking about one of five listed outcomes, and compliance is required by January 1, 2027. The two-part test, the pre-use notice, and why most AI systems are out of scope.
2026-08-21
NIST AI RMF vs ISO 42001: Which Do You Need?
NIST AI RMF is a free voluntary US framework you align to; ISO 42001 is a certifiable international standard you get audited against. One question decides it: does anyone outside your company need proof?
2026-08-20
How to Answer the AI Questions on Security Questionnaires
Enterprise reviewers ask three AI questions, and you do not need a certificate to clear them. Four documented artifacts do most of the work: an AI policy, an AI system inventory, a sub-processor list that names your model providers, and a written framework alignment statement.
2026-08-19
AI Vendor Risk Assessment: The Questions That Matter
Six questions do most of the work in an AI vendor review. The standard instruments have caught up in form (CSA's AI-CAIQ runs to 320 questions) but length is not signal, and vendors still clear reviews that never press on the six.
2026-08-18
Does SOC 2 Cover AI? What Auditors Now Test
Not specifically. As of August 2026 the AICPA has published no AI-specific Trust Services Criteria, so an AI company reports against the same criteria set as any SaaS vendor: mandatory Security plus whichever of the four optional categories it selects. What changed is what auditors ask for as evidence.
2026-03-14
Understanding the EU AI Act: What US Companies Need to Know
The EU AI Act is the world's first comprehensive AI regulation, and its reach extends far beyond European borders. If your company develops, deploys, or distributes AI systems that touch the EU market, compliance is not optional. Here is what US organizations need to understand.