Category
AI Governance articles
The AI governance writing in this category covers the operational work of running generative AI safely in regulated US contexts: NIST AI RMF implementation, ISO/IEC 42001, state AI law (Colorado, NYC, California), AI vendor and DPA diligence, Copilot governance, and the audit-ready evidence that proves it. Written by the team that builds AI governance programs across the EFROS client portfolio.
Articles about AI governance and US AI regulation
Securing Copilot and ChatGPT at a Small Business: A One-Page AI-Use Policy
A practical one-page AI-use policy for small businesses: control shadow AI, stop data leakage in prompts, set an approved-tool list, and fix M365 Copilot permission sprawl.
AI Vendor Risk Assessment: What Goes in the DPA
What a real AI vendor DPA looks like in 2026: training data carve-outs, sub-processor disclosure, model-update notification, and the deletion clauses every mid-market US company should be insisting on.
AI Policy Templates for Mid-Market US Companies
Three foundational AI policies every mid-market US company should have in place: an acceptable-use policy, a vendor policy, and an incident response policy. The exact clauses we use with EFROS clients.
AI Incident Response: What's Different from Cyber
AI incidents aren't traditional security incidents. They have different triggers, different forensics, different stakeholders, and different remediation paths. Here's what changes, and what doesn't.
AI Bias Auditing: A Practical Framework for US Mid-Market
Vendor-neutral framework for auditing AI systems for bias: what to measure, how often, what to document, and what to do when you find something. Built for US mid-market, not academic research.
FTC AI Enforcement Actions: 2025 Tracker
The FTC AI enforcement actions of 2025 that mid-market US companies should learn from: what was alleged, what was settled, and what to change in your own AI program as a result.
Microsoft 365 Copilot Governance Checklist for SMB
Practical Microsoft 365 Copilot governance checklist for small and mid-sized businesses: what to configure, what to document, what to train, and what to monitor before and after deployment.
AI in Healthcare: HIPAA + Section 1557 Implications
Healthcare AI sits at the intersection of HIPAA (privacy and security of PHI) and Section 1557 (nondiscrimination). Here's what the overlap means for mid-market healthcare organizations using AI in clinical or administrative decisions.
AI Third-Party DPA Review: 10 Clauses to Look For
Concrete contract language for the ten clauses that matter most when reviewing an AI vendor's data processing agreement: what to insist on, what to negotiate, and what to walk away from.
Building an AI Inventory: From Spreadsheet to Living Registry
How mid-market US companies move from a static spreadsheet of AI tools to a living AI inventory that drives governance, vendor management, and compliance, without buying enterprise software.
Prompt Injection Defense: 7 Patterns That Actually Work
Seven defensive patterns for prompt injection that hold up in production AI systems: input handling, context isolation, output validation, and the architectural decisions that matter most.