AI/SI Governance Checklist: Policies, Vendors and Agent Inventory
The AI-to-SI rename is a good moment to check your AI governance basics. Use this checklist to cover policies, vendors and agents.
Policies
- AI acceptable use policy exists and is acknowledged by staff.
- Definitions cover AI and SI terminology.
- Policy maps to at least one framework (NIST AI RMF, ISO/IEC 42001) and relevant laws (EU AI Act, state laws, sector rules).
- Data handling rules for AI tools specified (what data can and can't be used).
Inventory
- AI systems inventoried: copilots, agents, models, AI features in SaaS.
- Each has an owner, purpose, data sources and permissions.
- Shadow AI usage monitored (Defender for Cloud Apps discovery, Purview DSPM for AI).
Agents
- Each agent has its own identity with least privilege.
- Network egress restricted by default.
- High-impact actions require human approval.
- Kill switch tested.
- Agent activity logged.
Vendors
- AI vendors assessed for data use, model training on your data, security and incident notification.
- Contracts include both AI and SI terms.
- Third-party AI features in existing SaaS reviewed.
Incidents
- Incident response plan covers AI-caused incidents (including harm to third parties).
- Notification timelines and verified contacts for regulators and partners defined.
- AI incident scenario exercised.
Oversight
- AI risk reported to leadership or the board regularly.
- Named executive accountable for AI governance.
Sources
- AI Is Now 'Super Intelligence' in Federal Documents (Sept 2026): What the Rename Does and Doesn't Change Platform Changes
- How to Update AI/SI Terminology in Security Policies, Contracts and Risk Registers How-To & Hardening
- CIO Brief: 'SI' Is a Label, Not a Law — What Security Leaders Should Do CIO Briefings