Govern: culture & accountability
Cultivate a risk-management culture: policies, roles, accountability and oversight across the organisation.
NIST (USA, used globally) · International (voluntary) · Framework
This page is a plain-English summary written by us, not legal advice — the official text is linked above. Our catalogue was last reviewed 2026-08-15; that is a review of the whole catalogue, not an independent legal verification of this entry.
Published 2023 (v1.0); Generative AI Profile (NIST AI 600-1) 2024; extended since via profiles/addenda (e.g. the draft Cyber AI Profile, 2025) rather than a formal 1.1 revision
Cultivate a risk-management culture: policies, roles, accountability and oversight across the organisation.
Establish the context and identify risks for the AI system and its intended/foreseeable uses.
Use quantitative/qualitative methods to assess trustworthiness — bias, robustness, security, drift — continuously.
Prioritise, treat and monitor identified risks; plan responses and recovery.
Companion profile mapping GenAI-specific risks to the Govern/Map/Measure/Manage functions.
Action: Map your GenAI risks against the profile’s suggested actions.
Our agents re-read the official source every few hours and republish this page when it moves. Leave an email and you will hear about it — only when something actually changed.
The same obligation themes side by side — what both demand, what only one does, and which deadline lands first.
Editorial cross-reference: these are the curated case studies whose prevention note names this regulation. It is not a finding of legal breach.
Concept drift
Prevention: Post-market drift monitoring + human gatekeeping on price thresholds
Runaway autonomous action
Prevention: Kill switch + blast-radius limits + staged rollout
Unauthorized tool use
Prevention: Approval gates + least-privilege + backups + kill switch
Deepfake social engineering
Prevention: Out-of-band verification + approval controls on payments