NIST AI RMF
How GOVERN 1.2 shows up in practice: the mapped risk classes in this atlas, the documented incidents that prove it's real, and the scenarios and controls to learn and defend against it.
Mapped risks
Risk classes in this atlas that map to GOVERN 1.2 — click through for the full definition, attack surface and controls.
Controls & guardrails that address this
4Guardrails across the risks mapped to GOVERN 1.2, grouped by control function. Filter by control category below.
Pausing to ask a person before doing anything big or hard to undo — sending money, deleting data, emailing customers.
Live dashboards and alarms that notice unusual behaviour — spikes in errors, weird actions, sudden data access.
Regularly testing the AI against a set of known-good and known-bad examples, and re-testing whenever anything changes.
The organisational habits around the AI: assessing risks before launch, actively trying to break it, and having a plan for when something goes wrong.