Domains / AI governance & standards
AI governance & standards
70 sites assessed. Not legal advice.
This Iowa Code chapter defines terms related to personal information security breach protection, outlining what constitutes a 'breach of security' and 'personal information' within the state's legal framework. It sets the groundwork for notification requirements and remedies concerning data breaches.
checked 8/5/2026
This advisory from the Washington State Office of the Insurance Commissioner reminds insurers that AI system use must comply with all applicable insurance laws, including those addressing unfair trade practices and discrimination. It outlines best practices for governing AI development and use, emphasizing fairness, accountability, and transparency.
checked 8/5/2026
- www.isaca.orgMIXED
This website provides information about COBIT (Control Objectives for Information Technologies) and ISACA's certifications, training, and resources related to IT governance, cybersecurity, and AI. It offers various certifications, including those focused on AI audit, security, and risk management, alongside training programs and membership opportunities.
checked 8/5/2026
- www.isa.orgMIXED
This page describes a standard for industrial automation and control systems security, and also includes a notice from ISA prohibiting the use of its intellectual property in AI tools. The site provides information on various standards, certifications, training, and publications related to automation and control systems.
checked 8/5/2026
- www.ilga.govMIXED
This Illinois General Assembly page details the Insurance Data Security Law (215 ILCS 215/), outlining standards for data security, cybersecurity event investigation, and notification requirements for licensees. The law aims to protect consumer data within the insurance industry in Illinois.
checked 8/5/2026
- www.globalreporting.orgUNKNOWN
This document outlines the GRI 404: Training and Education 2016 standard, which provides disclosures for organizations to report on their training and education-related impacts and management practices. It is part of the broader GRI Sustainability Reporting Standards, designed to help organizations report on their economic, environmental, and social impacts.
checked 8/5/2026
- www.gfsc.ggOPEN
This document outlines the Guernsey Financial Services Commission's Cyber Security Rules, 2021, which apply to all licensees under the Regulatory Laws. It details requirements for identifying, protecting, detecting, responding to, and recovering from cyber security events, with a focus on board responsibility and notification to the Commission.
checked 8/5/2026
This is a regulatory technical standard from the European Banking Authority (EBA) specifying elements related to threat-led penetration tests. It is part of the EBA's broader efforts to ensure the stability and effectiveness of the European financial system through harmonized rules and supervisory convergence.
checked 8/5/2026
- www.dfs.ny.govOPEN
This document provides guidance from the New York Department of Financial Services (DFS) regarding the adoption of an affiliate's cybersecurity program by DFS-regulated entities. It clarifies that while entities can adopt an affiliate's program, they remain solely responsible for compliance with the DFS Cybersecurity Regulation (23 NYCRR Part 500).
checked 8/5/2026
- www.coso.orgOPEN
This website provides guidance and resources on internal control frameworks, including specific applications for sustainability reporting, generative AI, and robotic process automation. It highlights the COSO Internal Control-Integrated Framework as a globally recognized standard for effective internal controls across various organizational objectives.
checked 8/5/2026
- www.wecc.orgOPEN
This PDF document outlines the VAR-501-WECC-4 Power System Stabilizer standard, categorized under Policy and Regional Reliability Standard by the Western Electricity Coordinating Council (WECC). It is an approved/final standard document related to reliability within the power grid.
checked 8/4/2026
- www.wvinsurance.govUNKNOWN
This West Virginia Insurance Bulletin reminds insurers that AI systems must comply with all applicable state insurance laws and rules, including those addressing unfair trade practices and discrimination. It recommends insurers develop a written program for the responsible use of AI systems, aligning with NAIC principles for fairness, accountability, and transparency.
checked 8/4/2026
- www.who.intMIXED
This document is Annex 4 of the WHO Technical Report Series, No. 1033, published in 2021. It provides guidelines on data integrity from the World Health Organization.
checked 8/4/2026
- www.theiia.orgMIXED
This website provides information on the 2024 Global Internal Audit Standards, which guide the worldwide professional practice of internal auditing. These standards are a mandatory component of the International Professional Practices Framework (IPPF) and are organized into five domains covering the purpose, ethics, governance, management, and performance of internal audit functions.
checked 8/4/2026
This website provides the full text and details of the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks, which outline principles for data transfer and protection. It serves as a resource for businesses and individuals regarding privacy regulations and compliance.
checked 8/4/2026
This is a chapter from the South Carolina Code of Laws, specifically Title 38, Chapter 99, known as the Insurance Data Security Act. It defines key terms related to cybersecurity and data protection within the insurance industry in South Carolina.
checked 8/4/2026
- www.pcpd.org.hkOPEN
This page describes Hong Kong's Personal Data (Privacy) Ordinance (PDPO), a comprehensive data protection law enacted in 1995 and amended in 2012 and 2021. It outlines the key principles and definitions of the PDPO, which applies to both private and public sectors and is technology-neutral.
checked 8/4/2026
- www.nmlegis.govOPEN
This New Mexico House Bill 15, introduced in 2017, proposes the "Data Breach Notification Act." It mandates notification to individuals, consumer reporting agencies, and the attorney general in the event of a security breach involving personal identifying information, and requires secure storage and disposal of such data.
checked 8/4/2026
- www.oid.ok.govOPEN
This bulletin from the Oklahoma Insurance Department reminds insurers that the use of Artificial Intelligence (AI) systems must comply with all applicable insurance laws and regulations, including those addressing unfair trade practices and discrimination. It outlines the Department's expectations for governing the development and use of AI technologies and the information it may request during investigations.
checked 8/4/2026
This website, part of the Unified Compliance Framework, provides detailed information and commentary on authority documents, citations, terms, and controls related to compliance. It appears to be a tool for managing and understanding various regulatory and governance standards.
checked 8/4/2026
This website provides access to SASB Standards and related resources for sustainability disclosure, including a materiality finder and industry classification system. It is maintained by the IFRS Foundation.
checked 8/4/2026
This is the beginning of the Nebraska Data Privacy Act, outlining its citation and defining key terms related to data privacy, such as biometric data, consent, consumer, and controller. It establishes the legal framework for data protection within the state.
checked 8/4/2026
- mca.legmt.govUNKNOWN
This Montana Code Annotated section outlines requirements for licensees and insurance-support organizations regarding computer security breaches involving personal information. It mandates notification to affected individuals and the insurance commissioner, and the development of information security policies.
checked 8/4/2026
- laws-lois.justice.gc.caUNKNOWN
This is the official Canadian government publication of the Privacy Act, a federal law governing the collection, use, and disclosure of personal information by government institutions. It includes the full text of the act, its amendments, and related regulations.
checked 8/4/2026
This bulletin from the Maryland Insurance Administration reminds insurers that the use of AI systems must comply with all applicable insurance laws and regulations, including those addressing unfair trade practices and discrimination. It outlines the Administration's expectations for governing AI development and use, emphasizing fairness, accountability, and transparency.
checked 8/4/2026
- itsupport.ou.eduOPEN
This document outlines the University of Oklahoma's IT Asset Management Standard, defining requirements for inventorying, tracking, and managing technology assets to maximize value and minimize risk. It details responsibilities, definitions, and procedures for effective IT asset governance within the university.
checked 8/4/2026
- gc.nh.govOPEN
This legal document outlines the Insurance Data Security Law, establishing state standards for data security, cybersecurity event investigation, and notification for insurance licensees. It defines key terms related to data security and cybersecurity within the insurance sector.
checked 8/4/2026
- doi.nebraska.govOPEN
This guidance document from the Nebraska Department of Insurance outlines expectations for insurers using AI systems, emphasizing compliance with existing insurance laws regarding unfair trade practices and discrimination. It highlights potential risks of AI and encourages adherence to NAIC's AI principles for fairness, accountability, and transparency.
checked 8/4/2026
- disb.dc.govMIXED
This bulletin from the D.C. Department of Insurance, Securities and Banking reminds insurers that AI system use must comply with all applicable insurance laws and regulations, including those addressing unfair trade practices and discrimination. It outlines the Department's expectations for governing AI development and use, emphasizing fairness, accountability, transparency, and risk management.
checked 8/4/2026
- doi.nv.govOPEN
This is the official website for the Nevada Division of Insurance, providing information and services related to insurance regulation in the state. It includes a bulletin regarding the use of artificial intelligence systems by insurers.
checked 8/4/2026
- csrc.nist.govOPEN
NIST Computer Security Resource Center: SP 800-series security standards.
checked 8/4/2026
The Cyber Risk Institute (CRI) released Profile version 2.1 and a new Maturity Model, providing updated resources for financial institutions to manage cybersecurity risks and benchmark their progress. These updates include additional mappings to global standards and an implementation guide for the EU's Digital Operational Resilience Act (DORA).
checked 8/4/2026
- codes.ohio.govMIXED
This Ohio Revised Code chapter outlines cybersecurity requirements for insurance companies, defining key terms related to data security and cyber events. It establishes legal obligations for licensees to protect nonpublic information and manage cybersecurity risks.
checked 8/4/2026
- cca.hawaii.govMIXED
This is a memorandum from the Hawaii Insurance Commissioner regarding the use of artificial intelligence systems in insurance. It likely outlines guidelines or regulations for the insurance industry concerning AI adoption.
checked 8/4/2026
Cloud Security Alliance: cloud and AI security frameworks and the STAR program.
checked 8/4/2026
This bill, known as the Insurance Data Security Law, mandates that insurance entities develop and maintain information security programs and report cybersecurity events to the Commissioner of Insurance. It establishes state standards for data security and cybersecurity event notification within the insurance sector.
checked 8/4/2026
- en.npc.gov.cn.cdurl.cnRESTRICTED
This document outlines the Personal Information Protection Law of the People's Republic of China, adopted in August 2021. It details regulations for personal information processing, individuals' rights, and legal liabilities to protect personal information within and outside China.
checked 8/4/2026
- style.mla.orgOPEN
This MLA Style Center article provides guidance on how to cite generative AI tools in MLA style, emphasizing the use of the MLA template of core elements for flexibility. It offers recommendations for citing AI-generated content, including text, images, and data, and provides specific examples for paraphrasing and quoting AI output.
checked 6/26/2026
- stratml.usUNKNOWN
This website describes the Strategy Markup Language (StratML), an XML vocabulary and schema designed to standardize strategic plans and performance reports. StratML aims to facilitate the sharing, linking, and analysis of strategic information, enabling organizations to meet open data requirements and improve strategic alignment and agility.
checked 6/26/2026
This European Parliament 'Legislative Train Schedule' page tracks the 'Digital Omnibus on AI' legislative package, detailing its progress and amendments to the AI Act. It outlines the proposed changes, including addressing implementation challenges, extending exemptions, and reinforcing the AI Office's powers.
checked 6/26/2026
- www.gpdp.itOPEN
The Italian Data Protection Authority (Garante Privacy) has temporarily blocked ChatGPT in Italy due to unlawful data collection and the absence of age verification systems for minors. The Authority has opened an investigation into OpenAI, the developer of ChatGPT, following a data breach that exposed user conversations and payment information.
checked 6/26/2026
- www.gao.govMIXED
This GAO report outlines an accountability framework for federal agencies and other entities using AI, focusing on principles like governance, data, performance, and monitoring. It aims to help ensure responsible AI use and address potential benefits and unwanted effects.
checked 6/26/2026
- www.pm.gc.caOPEN
The Prime Minister of Canada launched "AI for All," a new national AI strategy aimed at driving economic growth, creating jobs, and ensuring responsible AI adoption. The strategy focuses on building trust, creating opportunities, and reinforcing Canadian sovereignty through legislative modernization and investments.
checked 6/26/2026
This article discusses the termination of Canada's proposed Artificial Intelligence and Data Act (AIDA) and offers five key lessons for future AI regulation efforts. It highlights the importance of aligning Canadian AI regulations with international standards and engaging in thorough consultations with stakeholders.
checked 6/26/2026
- www.winston.comRESTRICTED
This article discusses the implications for the healthcare and life sciences industry after the federal budget bill did not include a moratorium on state AI laws. It highlights how states like California, Utah, Colorado, and Texas are enacting their own regulations on AI use in healthcare.
checked 6/26/2026
- www.crowell.comMIXED
This article discusses Colorado's new AI law, SB 26-189, which replaces a previous, unenforced law and narrows the scope of AI regulation to automated decision-making technologies impacting consequential decisions. It outlines key changes, compliance deadlines, and implications for vendor contracts.
checked 6/26/2026
- www.hunton.comOPEN
This article discusses revised policies from the White House's Office of Management and Budget (OMB) regarding federal agencies' use and procurement of AI. The new policies aim to accelerate AI adoption, reduce bureaucratic barriers, and emphasize American-made AI tools and talent.
checked 6/26/2026
- leg.colorado.govOPEN
This Colorado General Assembly bill, SB26-189, concerns the use of automated decision-making technology (ADMT) in consequential decisions, building upon previous legislation. It defines ADMT and consequential decisions, and outlines requirements for developers and deployers regarding documentation, notifications, record retention, and consumer notice.
checked 6/26/2026
- www.afcea.orgOPEN
This article discusses a new framework from the Government Accountability Office (GAO) for the responsible development and use of artificial intelligence (AI) within federal agencies and other organizations. The framework focuses on actionable practices and procedures for accountability and oversight, rather than high-level ethical guidelines.
checked 6/26/2026
- rm.coe.intOPEN
This document is the Preamble to the Council of Europe's Framework Convention on Artificial Intelligence, outlining the motivations and principles behind establishing a legal framework for AI systems. It emphasizes the need to protect human rights, democracy, and the rule of law while fostering innovation and addressing potential risks associated with AI.
checked 6/26/2026
- unesco.orgMIXED
This is the official website for UNESCO, an organization dedicated to promoting peace through education, science, culture, and communication. It highlights their work on AI governance, emphasizing the need for equitable and inclusive development of AI technologies.
checked 6/24/2026
- deepl.comOPEN
DeepL offers an AI-powered language platform providing translation, writing enhancement, and real-time voice translation services. It caters to businesses and individuals, emphasizing accuracy, security, and efficiency across various industries and use cases.
checked 6/24/2026
- greenhouse.ioMIXED
Greenhouse is an applicant tracking software and hiring platform that uses AI-powered tools to streamline the hiring process. The platform emphasizes responsible AI, focusing on structured hiring and human judgment while offering features like AI Notetaker, Candidate Question Agent, and Real Talent for fraud detection and identity verification.
checked 6/24/2026
- wiley.comMIXED
Wiley provides resources and insights on the impact of AI in academic research and publishing, offering tools and guidelines for researchers and institutions. The site highlights how AI is transforming the research landscape and offers solutions for navigating this evolution.
checked 6/24/2026
Thomson Reuters offers AI-powered legal and tax solutions, including CoCounsel, Westlaw, and Practical Law, to enhance efficiency and accuracy for legal and accounting professionals. These tools leverage AI for research, drafting, matter management, and compliance, aiming to streamline workflows and improve outcomes.
checked 6/24/2026
- iptc.orgMIXED
IPTC: Generative AI opt-out best-practice recommendations (media standards body).
checked 6/24/2026
- genai.owasp.orgOPEN
OWASP GenAI: the Top 10 for LLM Applications and AI security guidance.
checked 6/24/2026
The Secure Controls Framework (SCF), a free metaframework of cybersecurity and privacy controls.
checked 6/22/2026
Center for Threat-Informed Defense: security control mappings (NIST 800-53, ATT&CK).
checked 6/22/2026
- cr-cmm.orgOPEN
Cyber Resilience Capability Maturity Model framework.
checked 6/22/2026
- www.nist.govOPEN
This NIST publication provides a cross-sectoral profile and companion resource for the AI Risk Management Framework (AI RMF 1.0) specifically for Generative AI, in response to President Biden's Executive Order 14110. It aims to help organizations integrate trustworthiness into the design, development, use, and evaluation of AI products and systems.
checked 6/22/2026
UK government asset host (GOV.UK); hosts the AI Management Essentials self-assessment tool.
checked 6/22/2026
- nvlpubs.nist.govOPEN
NIST technical series publications.
checked 6/22/2026
- csrc.nist.ripOPEN
Unofficial archive mirror of the NIST Computer Security Resource Center.
checked 6/22/2026
This Executive Order from the White House aims to remove barriers to American leadership in Artificial Intelligence by revoking existing AI policies and directives. The policy emphasizes sustaining and enhancing America's global AI dominance for human flourishing, economic competitiveness, and national security, while ensuring AI systems are free from ideological bias.
checked 6/22/2026
- www.ncsc.gov.ukMIXED
This NCSC page outlines the Cyber Essentials scheme, a government-backed certification designed to protect organizations from common cyber threats. It details the five technical controls and provides resources for businesses to achieve certification.
checked 6/22/2026
This website provides information on the CIS Critical Security Controls, a prioritized set of cybersecurity best practices designed to help organizations protect against cyber threats. It also offers various tools, resources, and memberships for implementing these controls and improving overall cybersecurity posture.
checked 6/22/2026
- doi.orgUNKNOWN
This academic article from Springer Nature discusses the challenges of human oversight in AI governance, particularly under the EU AI Act. It proposes a new taxonomy for human oversight roles and principles to institutionalize distrust in AI oversight for more democratic governance.
checked 6/22/2026
- thefrontierfounder.comRESTRICTED
This research paper introduces the 4D AI Fluency Framework, arguing that firms often mistake prompt engineering for true AI competency. It outlines four key competencies—Description, Discernment, Delegation, and Diligence—essential for operationalizing AI effectively within organizations.
checked 6/22/2026
- www.cnil.frOPEN
France's data-protection regulator (CNIL); guidance on securing AI system development.
checked 6/22/2026
