top of page
Search

The AI Governance Stack Nobody Explained To You

Aug 8
2 min read

Every client conversation about AI governance starts the same way. Someone read that they need a framework, they googled it, and they came back with four names and no idea which one they actually need. So let me lay it out, because these stack rather than compete.


OECD AI Principles are your ethical foundation. Not operational, will not satisfy an auditor, but it gives you the vocabulary everything else assumes you have.


NIST AI RMF 1.0 is your operational risk model. Voluntary on paper, effectively mandatory if you touch federal contracts. Four functions: Govern, Map, Measure, Manage. If you already live in 800-53 or CSF, this maps onto infrastructure you built. Pair it with the Generative AI Profile, NIST AI 600-1, where the LLM specific risk taxonomy lives.


ISO/IEC 42001:2023 is the certifiable layer. An AI Management System, structurally close to 27001, and the only one here that gets you a certificate from an accredited body after a two stage audit. Annex A is where your evidence obligations live. Sister standard 42005:2025 handles impact assessments.


The EU AI Act, Regulation 2024/1689, is the only one that is actual law. Risk tiered. High risk systems require conformity assessment. November 2025 Digital Omnibus amendments are still moving.


Practical assembly. Build one AI system register and make it do triple duty. Capture purpose, EU risk classification, which RMF functions you applied and how deeply, which 42001 Annex A controls are in scope, accountable owner, gaps, and where evidence lives. That artifact satisfies 42001 Clause 8, feeds RMF Map and Govern, and gives you the inventory the EU Act demands.


Now the part that should worry you. None of the three major frameworks was designed for agentic AI. Singapore published the only document in January 2026 addressing autonomous agents directly. Everything else assumes a model that responds when called. Your agents chain calls, hold state, and act.


So extend the register into an agent inventory. Per agent: named human owner, authorized scope stated narrowly, every tool and credential it holds, data read and write access, autonomy level, which agents it invokes and which invoke it, where its actions log, and who can kill it and how fast. The chaining and logging fields are the ones nobody has. When agent A calls agent B which writes to production and the outcome is wrong, you need to know which decision caused it.


Do not start by asking what agents you have. Ask which non-human identities hold API credentials, then work backward. The shadow inventory shows up in your identity system long before anyone admits it exists.


What does your agent inventory actually look like right now, and who owns it?


Reach out to discuss.

 
 

Recent Posts

See All
Reconnaissance Is Not an Incident

Every statement out of the water sector this week says the same thing. Contained. Water is safe. Operators handled it. That is an after action report written by the wrong side. Twelve states now. More

 
 

Timcke Risk Management, LLC

660 Massachusetts Ave

6th Floor, Boston, MA 02118

 

© 2025 by Timcke Risk Management, LLC

 

bottom of page