---
title: "AI Governance articles — NIST AI RMF, ISO 42001, US AI law | EFROS"
description: "EFROS AI governance writing: NIST AI RMF, ISO/IEC 42001, Colorado SB 26-189 and US state AI law, HIPAA + Section 1557 for clinical AI, SR 11-7 model risk, AI vendor and DPA review, and Microsoft 365 Copilot governance for regulated US organizations."
canonical: https://efros.com/blog/category/ai-governance/
---

- [Home](https://efros.com/)
- /[Blog](https://efros.com/blog/)
- /AI Governance

Category

# AI Governance articles

The AI governance writing in this category covers the operational work of running generative AI safely in regulated US contexts: NIST AI RMF implementation, ISO/IEC 42001, state AI law (Colorado, NYC, California), AI vendor and DPA diligence, Copilot governance, and the audit-ready evidence that proves it. Written by the team that builds AI governance programs across the EFROS client portfolio.

## Articles about AI governance and US AI regulation

[AI Governance ### Securing Copilot and ChatGPT at a Small Business: A One-Page AI-Use Policy A practical one-page AI-use policy for small businesses: control shadow AI, stop data leakage in prompts, set an approved-tool list, and fix M365 Copilot permission sprawl.9 min readRead →](https://efros.com/blog/securing-copilot-chatgpt-smb-ai-policy/) [AI Governance ### AI Vendor Risk Assessment: What Goes in the DPA What a real AI vendor DPA looks like in 2026: training data carve-outs, sub-processor disclosure, model-update notification, and the deletion clauses every mid-market US company should be insisting on.8 min readRead →](https://efros.com/blog/ai-vendor-risk-assessment-dpa/) [AI Governance ### AI Policy Templates for Mid-Market US Companies Three foundational AI policies every mid-market US company should have in place: an acceptable-use policy, a vendor policy, and an incident response policy. The exact clauses we use with EFROS clients.9 min readRead →](https://efros.com/blog/ai-policy-templates-mid-market-us/) [AI Governance ### AI Incident Response: What's Different from Cyber AI incidents aren't traditional security incidents. They have different triggers, different forensics, different stakeholders, and different remediation paths. Here's what changes, and what doesn't.9 min readRead →](https://efros.com/blog/ai-incident-response-different-from-cyber/) [AI Governance ### AI Bias Auditing: A Practical Framework for US Mid-Market Vendor-neutral framework for auditing AI systems for bias: what to measure, how often, what to document, and what to do when you find something. Built for US mid-market, not academic research.9 min readRead →](https://efros.com/blog/ai-bias-auditing-practical-framework/) [AI Governance ### FTC AI Enforcement Actions: 2025 Tracker The FTC AI enforcement actions of 2025 that mid-market US companies should learn from: what was alleged, what was settled, and what to change in your own AI program as a result.8 min readRead →](https://efros.com/blog/ftc-ai-enforcement-actions-2025-tracker/) [AI Governance ### Microsoft 365 Copilot Governance Checklist for SMB Practical Microsoft 365 Copilot governance checklist for small and mid-sized businesses: what to configure, what to document, what to train, and what to monitor before and after deployment.9 min readRead →](https://efros.com/blog/microsoft-365-copilot-governance-checklist-smb/) [AI Governance ### AI in Healthcare: HIPAA + Section 1557 Implications Healthcare AI sits at the intersection of HIPAA (privacy and security of PHI) and Section 1557 (nondiscrimination). Here's what the overlap means for mid-market healthcare organizations using AI in clinical or administrative decisions.9 min readRead →](https://efros.com/blog/ai-healthcare-hipaa-section-1557/) [AI Governance ### AI Third-Party DPA Review: 10 Clauses to Look For Concrete contract language for the ten clauses that matter most when reviewing an AI vendor's data processing agreement: what to insist on, what to negotiate, and what to walk away from.9 min readRead →](https://efros.com/blog/ai-third-party-dpa-review-10-clauses/) [AI Governance ### Building an AI Inventory: From Spreadsheet to Living Registry How mid-market US companies move from a static spreadsheet of AI tools to a living AI inventory that drives governance, vendor management, and compliance, without buying enterprise software.8 min readRead →](https://efros.com/blog/building-ai-inventory-spreadsheet-to-registry/) [AI Governance ### Prompt Injection Defense: 7 Patterns That Actually Work Seven defensive patterns for prompt injection that hold up in production AI systems: input handling, context isolation, output validation, and the architectural decisions that matter most.9 min readRead →](https://efros.com/blog/prompt-injection-defense-7-patterns/)

## Other categories

[Cybersecurity](https://efros.com/blog/category/cybersecurity/) [Compliance](https://efros.com/blog/category/compliance/) [Cloud](https://efros.com/blog/category/cloud/) [IT Management](https://efros.com/blog/category/it-management/) [All articles](https://efros.com/blog/)
