Notes on how AI governance frameworks apply to real systems — written as I work through them, in study and in practice.
Why this page exists
I’m building AI governance expertise on top of 20 years in security and risk. This is where that process is visible: how EU AI Act obligations map onto existing security programs, how NIST AI RMF fits alongside frameworks I already use, where the gaps are.
What’s here now
A working methodology — Inventory → Classify → Map → Assess → Roadmap — for bringing AI systems under existing governance structures rather than building something parallel.
What’s coming
Sample assessments and case notes as they’re ready.