Where to start
If you are building an AI governance program, these are the sources worth reading first. All are free or low cost.
Each entry notes what the resource covers and where it stops. None were written for consumer goods, which is the gap The Governed Enterprise fills, but all are foundational and you should not build without them.
Last reviewed August 2026.
Frameworks
NIST AI Risk Management Framework
The best starting point. Voluntary, free, and organized around four functions: Govern, Map, Measure, and Manage. The Generative AI Profile, released July 2024, is the companion worth reading alongside it. Deliberately sector-agnostic, so it will not tell you what to do about a label claim or a plant floor deployment. Version 1.0 is being revised, and NIST released a concept note in April 2026 for a profile on trustworthy AI in critical infrastructure.
NIST Trustworthy and Responsible AI Resource Center
The implementation companion to the framework, including the AI RMF Playbook and a use case library showing how other organizations have applied it.
ISO/IEC 42001
The international standard for AI management systems, published December 2023. Certifiable, which NIST is not. Treat it as the inspection standard once governance architecture exists rather than as a starting point. The standard itself costs CHF 225, and certification is a multi-year effort for most mid-market companies.
Regulation
EU AI Act, full text
Published in the Official Journal on 12 July 2024. This site offers the complete text, an explorer, and a summary for readers who do not need all several hundred pages. Enforcement by the Commission's AI Office and national authorities begins 2 August 2026.
Navigating the AI Act
The Commission's own FAQ. More useful than the statute if you are working out whether a specific deployment falls in scope.
Article 73: serious incident reporting
Providers of high-risk AI systems must report serious incidents to national authorities. The Commission's draft guidance and the reporting template are both downloadable here. The consultation that produced them closed in November 2025; the obligation applies from August 2026.
FDA
No AI-specific guidance exists for most CPG contexts. FSMA preventive controls, current good manufacturing practices, and MoCRA adverse event reporting apply to AI-assisted decisions today regardless.
FTC
Advertising substantiation guidance. AI-generated claims meet the same evidentiary standard as human-generated ones.
Security
OWASP Top 10 for LLM Applications
First released in 2023 and updated for 2025, with prompt injection holding the top position for a second consecutive edition. The most widely referenced security framework for LLM applications, and the one to hand a security team that has not worked on AI before.
OWASP Top 10 for Agentic AI Applications
A companion framework released in late 2025, covering risks specific to autonomous systems that use tools and make multi-step decisions. Directly relevant to anyone deploying agents against ERP or procurement.