Layer researchGovernance, risk and sovereignty
Governance, risk & sovereignty
Status: complete (published 2026-08-19). Scope finalized at Batch B kickoff with maintainer POV; see brief.md, findings.md, vendors.md, sources.md.
Scope inventory (v0)
- Regulatory map: EU AI Act obligations and timeline, NIST AI RMF, DORA, NIS2, sector regimes per vertical (HIPAA, FedRAMP, NERC CIP, RBI, DPDPA), cross-border transfer mechanisms
- Operating governance: AI council and use-case intake, risk tiering, impact assessments (DPIA/AIA), model risk management, third-party and procurement risk for agent vendors
- Records and accountability: retention and eDiscovery for agent memory and outputs, evidence packs for regulators, liability and the Sponsor pattern, insurance
- Sovereignty: deployment spectrum (managed API to air-gapped), classification-based routing, localization requirements
Challenged-default candidates
AI governance platforms vs extending GRC tooling; sovereign cloud offerings vs region pinning with contractual controls. Each track proposes its final list at kickoff.
Files
brief.md, findings.md, vendors.md, sources.md are created from ../_TEMPLATE/ at kickoff.
Source: research/R11-governance-risk-sovereignty/README.md in the evidence repository behind this site.