Establish accountable AI governance
Govern AI use and intake
2 person-daysCritical
Approve intended and prohibited AI use
Govern AI use and intake
2 person-daysCritical
Inventory AI systems and dependencies
Govern AI use and intake
3 person-daysCritical
Classify AI risk and required assurance
Govern AI use and intake
2 person-daysCritical
Create cross-functional applicability intake
Govern AI use and intake
2 person-days
Govern AI data rights and provenance
Design secure AI controls
3 person-daysCritical
Assess models, services, and suppliers
Design secure AI controls
3 person-days
Threat-model each material AI system
Design secure AI controls
3 person-daysCritical
Constrain AI identities, tools, and agency
Design secure AI controls
3 person-daysCritical
Set security and privacy requirements
Design secure AI controls
2 person-daysCritical
Define evaluations and release thresholds
Evaluate oversight and transparency
4 person-daysCritical
Design meaningful human oversight
Evaluate oversight and transparency
2 person-days
Secure deployment and change control
Deploy, monitor, and assure AI
3 person-daysCritical
Monitor behavior, controls, and resource use
Deploy, monitor, and assure AI
3 person-daysCritical
Communicate use, limits, and recourse
Evaluate oversight and transparency
2 person-days
Prepare AI incident, rollback, and retirement
Deploy, monitor, and assure AI
3 person-daysCritical
Run a bounded pilot and adversarial assessment
Deploy, monitor, and assure AI
4 person-daysCritical
Approve operation and recurring review
Deploy, monitor, and assure AI
2 person-daysCritical