The CISOs Guide to AI Governance

Somewhere in the last eighteen months, AI governance was added to your job. Almost nothing else changed: the teams adopting AI still report elsewhere, the data belongs to other owners, and in most organizations the budget conversation never happened at all. The surveys put the pattern beyond doubt. 96% of CISOs now carry responsibility for AI governance and risk management, only 5% of organizations name security as their primary AI governance function, and fewer than half of security executives can identify every AI agent running in their environment.
This 18-page guide is written for the CISO working in that gap. It covers what to own outright and what to decline in writing, how to negotiate a mandate that arrives with real authority, how to see an estate that grows every time a vendor ships a feature, and how to build the evidence that answers a regulator's four questions after an incident. Inside you will find an ownership map across eight domains, a first-90-days sequence with exit criteria, a board one-pager, and the shared control library approach that lets one piece of governance work answer the EU AI Act, ISO/IEC 42001, and the NIST AI RMF at once.