Guest session. Reports live only in this browser. Close the window and they are gone. Create account or sign in to keep them.
Generation

Draft a new AI governance policy

Give organizational context and your intent per control. You will get a full policy aligned to the PXB playbook and cross-referenced to NIST AI RMF, OWASP LLM Top 10, OWASP Agentic Top 10, and MITRE ATLAS.

00
Organization context
01
Discovery and Inventory
PXB-01.1 · Estate inventory

List the AI platforms, licences, and model endpoints your organization intends to use or already uses (clouds, SaaS AI features, self-hosted models).

The single most common gap. Without this, no policy above it holds.

NIST AI RMF · MAP 1.1NIST AI RMF · MAP 3.4NIST AI RMF · GOVERN 1.6 OWASP LLM · LLM03 OWASP Agentic · T9 MITRE ATLAS · AML.TA0002 ReconnaissanceMITRE ATLAS · AML.TA0000 ML Model Access
PXB-01.2 · Egress monitoring

Which network egress controls (proxy, firewall, SSE, SASE) are available for tagging and filtering traffic to model endpoints?

Set proxy or firewall filters for major LLM API endpoints and tag traffic by business unit.

NIST AI RMF · MEASURE 2.6NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM02 OWASP Agentic · T8 MITRE ATLAS · AML.TA0010 Exfiltration
PXB-01.3 · Shadow AI discovery

Which CASB / SaaS discovery capability do you have available to surface shadow AI?

Employees route around bans within a week without a sanctioned path.

NIST AI RMF · MAP 4.1NIST AI RMF · MANAGE 3.1 OWASP LLM · LLM02 OWASP Agentic · T3 MITRE ATLAS · AML.TA0002 Reconnaissance
PXB-01.4 · Embedded AI features

Which existing enterprise tools (CRM, ITSM, analytics, IDE, collaboration) have AI features you will need to review?

Features get switched on without an intake and become part of your estate.

NIST AI RMF · MAP 1.1NIST AI RMF · MAP 3.4 OWASP LLM · LLM03 OWASP Agentic · T3 MITRE ATLAS · AML.TA0001 Initial Access
02
Data Classification
PXB-02.1 · Data tiers defined

What data classification scheme does your organization use, and which classes exist? (e.g. Public / Internal / Confidential / Regulated)

Governance follows data sensitivity, not enthusiasm for a use case.

NIST AI RMF · GOVERN 1.1NIST AI RMF · MAP 2.3NIST AI RMF · MEASURE 2.10 OWASP LLM · LLM02OWASP LLM · LLM04 OWASP Agentic · T1 MITRE ATLAS · AML.TA0009 Collection
PXB-02.2 · DLP on the prompt path

Which DLP platform (Purview, Netskope, Zscaler, Symantec, other) is available or in place, and does it currently inspect the prompt path?

The major DLP platforms all inspect the prompt path now.

NIST AI RMF · MANAGE 2.2NIST AI RMF · MEASURE 2.10 OWASP LLM · LLM02OWASP LLM · LLM05 OWASP Agentic · T8 MITRE ATLAS · AML.TA0010 Exfiltration
PXB-02.3 · Retention terms in writing

For each provider you plan to use, do you have (or can you negotiate) zero-data-retention terms?

Default APIs often retain data. Close it contractually, do not assume.

NIST AI RMF · GOVERN 6.1NIST AI RMF · GOVERN 6.2 OWASP LLM · LLM02OWASP LLM · LLM03 OWASP Agentic · T8 MITRE ATLAS · AML.TA0010 Exfiltration
PXB-02.4 · Training clause review

Do you require providers to contractually exclude your data from model training on the tier you will purchase?

Consumer terms and some enterprise tiers still permit provider use for model improvement.

NIST AI RMF · GOVERN 6.1NIST AI RMF · MAP 4.1 OWASP LLM · LLM04 OWASP Agentic · T1 MITRE ATLAS · AML.T0020 Poison Training Data
03
Tiered Approved Tools
PXB-03.1 · Tier 1 self-service defined

Which sanctioned Tier 1 tools do you want to offer employees for day-to-day AI use?

If the sanctioned tool is painful and the public one is easy, you lose.

NIST AI RMF · GOVERN 1.1NIST AI RMF · MANAGE 1.3 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-03.2 · Tier 2 registered use

How will you require teams building custom RAG or agent applications to register their use case?

Registered use, not ungoverned use.

NIST AI RMF · MAP 1.1NIST AI RMF · GOVERN 3.2 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T3
PXB-03.3 · Tier 3 high-risk review

What Tier 3 use cases (customer-facing, autonomous, high-value decision) are on your near-term roadmap that will require a full review?

Tier 3 is where the actual damage lives.

NIST AI RMF · MAP 5.1NIST AI RMF · MEASURE 2.7NIST AI RMF · MANAGE 2.1 OWASP LLM · LLM06OWASP LLM · LLM09 OWASP Agentic · T2OWASP Agentic · T6OWASP Agentic · T7OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-03.4 · Sanctioned path is the easy path

How will you ensure the sanctioned path is the path of least resistance for employees (SSO, defaulted tools, one-click access)?

Behavioral truth. If the safe path is painful, adoption collapses.

NIST AI RMF · GOVERN 4.1 OWASP LLM · LLM02 OWASP Agentic · T3
04
Intake Process
PXB-04.1 · Use case + decision authority

Should the intake form capture use case and decision authority explicitly? (Recommended: yes.)

Advisory and autonomous systems carry very different risk.

NIST AI RMF · MAP 1.1NIST AI RMF · MAP 5.1 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T6
PXB-04.2 · Data classes on I/O and fine-tune

Which data classes do you expect AI use cases will touch on input, output, and any fine-tuning?

Fine-tuning bakes data into weights and cannot be unlearned cleanly.

NIST AI RMF · MAP 2.3NIST AI RMF · MEASURE 2.10 OWASP LLM · LLM02OWASP LLM · LLM04 OWASP Agentic · T1 MITRE ATLAS · AML.T0020 Poison Training Data
PXB-04.3 · Model, hosting, retention

For each use case, will you require model selection, hosting region, and retention terms to be recorded?

You cannot audit what you did not record.

NIST AI RMF · MAP 3.4NIST AI RMF · GOVERN 6.1 OWASP LLM · LLM03
PXB-04.4 · Human-in-the-loop points

For each expected use case, where should humans be inserted for review or approval?

HITL is a control only if it is documented and enforced.

NIST AI RMF · MANAGE 1.3NIST AI RMF · MEASURE 3.3 OWASP LLM · LLM06OWASP LLM · LLM09 OWASP Agentic · T6OWASP Agentic · T7OWASP Agentic · T10
PXB-04.5 · Failure mode, rollback, kill switch owner

Will you require every AI use case to name a kill-switch owner and document a rollback procedure?

A kill switch without a named owner is a claim, not a control.

NIST AI RMF · MANAGE 2.4NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-04.6 · Bias and fairness scope

Which of your intended use cases touch HR, lending, healthcare, legal, or other domains where bias and fairness are automatically in scope?

Automatic yes for HR, lending, healthcare, legal.

NIST AI RMF · MAP 5.1NIST AI RMF · MEASURE 2.11 OWASP LLM · LLM09 OWASP Agentic · T7
05
Technical Controls
PXB-05.1 · Identity on every agent

Which identity platform (Entra ID, IAM roles, Workload Identity) will you use to give each agent its own least-privilege identity?

Without this, everything else in this section is unenforceable.

NIST AI RMF · MANAGE 1.3NIST AI RMF · MANAGE 2.2 OWASP LLM · LLM06 OWASP Agentic · T3OWASP Agentic · T9 MITRE ATLAS · AML.TA0004 PersistenceMITRE ATLAS · AML.TA0007 Discovery
PXB-05.2 · Tool and action allowlists

Which agent actions will you permit, and where will you enforce allowlists and rate limits?

Blast radius is set here.

NIST AI RMF · MANAGE 2.2NIST AI RMF · MANAGE 2.4 OWASP LLM · LLM06OWASP LLM · LLM10 OWASP Agentic · T2OWASP Agentic · T4 MITRE ATLAS · AML.TA0005 Defense EvasionMITRE ATLAS · AML.TA0011 Impact
PXB-05.3 · Prompt injection defences

How will you handle untrusted content reaching your models, and what is the maximum permitted blast radius if injection succeeds?

The right question is: what does the agent lose access to when it happens?

NIST AI RMF · MANAGE 2.2NIST AI RMF · MEASURE 2.7 OWASP LLM · LLM01OWASP LLM · LLM05OWASP LLM · LLM07 OWASP Agentic · T1OWASP Agentic · T6OWASP Agentic · T12 MITRE ATLAS · AML.T0051 LLM Prompt Injection
PXB-05.4 · Logging as forensic surface

Which log platform (SIEM, log analytics) will hold prompts, responses, tool calls, and retrieval; what retention; and how will you access-control the log data?

The logs will contain the same regulated data as the prompts. Treat them accordingly.

NIST AI RMF · MEASURE 2.8NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM02OWASP LLM · LLM05 OWASP Agentic · T8 MITRE ATLAS · AML.TA0009 Collection
PXB-05.5 · Rate and spend limits

What per-agent and per-tenant rate and spend limits will you enforce, and at which layer?

Unbounded consumption is both a cost problem and a DoS risk.

NIST AI RMF · MANAGE 2.4 OWASP LLM · LLM10 OWASP Agentic · T4 MITRE ATLAS · AML.TA0011 Impact
PXB-05.6 · Output validation

Where will you validate, sandbox, or sanitise model outputs before acting on them or rendering them?

Do not eval() model output. Do not run generated SQL without a read-only role.

NIST AI RMF · MANAGE 2.2NIST AI RMF · MEASURE 2.7 OWASP LLM · LLM05 OWASP Agentic · T2OWASP Agentic · T11 MITRE ATLAS · AML.T0050 Command and Scripting Interpreter
PXB-05.7 · Ongoing evaluation, not just launch review

Which evaluation tooling (Promptfoo, custom harnesses, Azure AI evals, Bedrock evals) will you use to run scheduled regressions on prompts and models?

A launch red team is a snapshot, not evaluation. Models drift.

NIST AI RMF · MEASURE 2.3NIST AI RMF · MEASURE 2.6NIST AI RMF · MEASURE 4.2 OWASP LLM · LLM01OWASP LLM · LLM04OWASP LLM · LLM09 OWASP Agentic · T5OWASP Agentic · T7 MITRE ATLAS · AML.T0043 Craft Adversarial Data
06
Third Party and Supply Chain
PXB-06.1 · AI-aware vendor questionnaire

What AI-specific questions should your vendor questionnaire include? (Provider, training use, retention, sub-processors, evaluations, change notice.)

Every SaaS vendor now claims to be AI-powered.

NIST AI RMF · GOVERN 6.1NIST AI RMF · GOVERN 6.2NIST AI RMF · MAP 4.1 OWASP LLM · LLM03 OWASP Agentic · T1 MITRE ATLAS · AML.T0010 ML Supply Chain Compromise
PXB-06.2 · Pin and scan self-hosted models

Which self-hosted models (if any) will you run, and what artefact scanning will you apply?

HuggingFace pickle exploits are real. This is a documented supply chain vector.

NIST AI RMF · GOVERN 6.1NIST AI RMF · MANAGE 3.2 OWASP LLM · LLM03OWASP LLM · LLM04 OWASP Agentic · T1 MITRE ATLAS · AML.T0010 ML Supply Chain CompromiseMITRE ATLAS · AML.T0018 Backdoor ML Model
PXB-06.3 · Contract for change

Will you require notice, rollback, and re-evaluation rights when providers rev their models?

Providers rev their models. Your paper should keep pace.

NIST AI RMF · GOVERN 6.1NIST AI RMF · MANAGE 4.2 OWASP LLM · LLM03
07
People and Ownership
PXB-07.1 · Named accountable owner per system

How will you assign a single accountable owner per deployed AI system?

This is the Govern function of NIST AI RMF in one sentence.

NIST AI RMF · GOVERN 2.1NIST AI RMF · GOVERN 2.2 OWASP Agentic · T8OWASP Agentic · T13
PXB-07.2 · AI champions in each business unit

How will you identify and empower AI champions in each business unit?

They know the real use cases before central governance does.

NIST AI RMF · GOVERN 3.2NIST AI RMF · GOVERN 5.1
PXB-07.3 · Training at three levels

Which training tracks will you build for (a) all staff, (b) developers, (c) executives?

Same skill areas, three different depths.

NIST AI RMF · GOVERN 2.2NIST AI RMF · GOVERN 2.3 OWASP LLM · LLM02OWASP LLM · LLM05 OWASP Agentic · T10
08
Regulatory Posture
PXB-08.1 · EU AI Act scope and readiness

Does your organization offer AI services or products that touch users in the EU, and if so which risk categories apply?

Prohibited and GPAI rules are already enforceable. High-risk timing may shift under the Digital Omnibus package; verify current status.

NIST AI RMF · GOVERN 1.1NIST AI RMF · GOVERN 4.1 OWASP LLM · LLM09 OWASP Agentic · T7
PXB-08.2 · NIST AI RMF alignment

Do you want the resulting policy explicitly cross-referenced to NIST AI RMF (AI 100-1) and the Generative AI Profile (AI 600-1)?

Voluntary framework, but de facto US baseline and often required in federal contracts.

NIST AI RMF · GOVERN 1.1
PXB-08.3 · Sector and state rules

Which sectors and jurisdictions do you operate in that will bring AI-specific obligations?

The state-level list grows quarterly. Map only what touches you.

NIST AI RMF · GOVERN 1.1NIST AI RMF · GOVERN 4.1 OWASP LLM · LLM09 OWASP Agentic · T7
PXB-08.4 · ISO 42001 posture

Are you planning to pursue ISO 42001 certification, and on what timeline?

Worth pursuing if you want a certifiable AI management system.

NIST AI RMF · GOVERN 1.1
09
Incident Readiness
PXB-09.1 · AI-specific incident playbooks

Which AI-specific incident scenarios do you want playbooks drafted for?

Assume something will go wrong and rehearse it.

NIST AI RMF · MANAGE 2.4NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM01OWASP LLM · LLM02OWASP LLM · LLM04OWASP LLM · LLM09 OWASP Agentic · T1OWASP Agentic · T2OWASP Agentic · T5OWASP Agentic · T6OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-09.2 · Kill switch documented and tested

How will you require the kill switch for every autonomous agent to be documented and tested on a schedule?

An untested kill switch is a claim, not a control.

NIST AI RMF · MANAGE 2.4NIST AI RMF · MANAGE 4.3 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-09.3 · Tabletop with legal and comms

Will you commit to at least one annual AI-incident tabletop that includes legal and communications?

The response is as much legal and reputational as it is technical.

NIST AI RMF · GOVERN 4.3NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM09 OWASP Agentic · T7OWASP Agentic · T10
PXB-09.4 · Evidence preservation

Which storage and process will you use to preserve model version, system prompt, tool config, and session logs at the moment of an incident?

Providers roll models forward. If you did not capture state, you cannot reconstruct what happened.

NIST AI RMF · MEASURE 2.8NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM03 OWASP Agentic · T8 MITRE ATLAS · AML.TA0009 Collection
10
Metrics
PXB-10.1 · Activity metrics tracked

Which activity metrics do you want the policy to require reporting on?

Activity metrics tell you the program is running.

NIST AI RMF · MEASURE 1.1NIST AI RMF · MEASURE 4.2
PXB-10.2 · Outcome metrics tracked

Which outcome metrics do you want the policy to require reporting on?

Outcome metrics tell you the program is working. Cost per BU makes finance an ally.

NIST AI RMF · MEASURE 2.7NIST AI RMF · MEASURE 4.2NIST AI RMF · MANAGE 1.4 OWASP LLM · LLM02 OWASP Agentic · T4
CAD
Cadence and Phasing
PXB-CAD.1 · Weeks 1 to 4

Which of the weeks-1-to-4 baseline actions do you already have in place, and which need to be commissioned?

The foundation that everything else assumes.

NIST AI RMF · GOVERN 1.1NIST AI RMF · MAP 1.1 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-CAD.2 · Months 2 to 3

Which of the months-2-to-3 milestones are realiztic on that timeline for you?

The point at which the program becomes operational.

NIST AI RMF · MANAGE 1.3NIST AI RMF · MAP 1.1 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-CAD.3 · Quarter 2

Which quarter-2 milestones can you commit to?

The point at which the technical controls become the enforced default.

NIST AI RMF · MANAGE 2.2NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T3
PXB-CAD.4 · Ongoing

What ongoing cadence will you commit to for vendor, board, and regulatory reviews?

The bit programmes forget to build.

NIST AI RMF · GOVERN 1.5NIST AI RMF · GOVERN 6.2NIST AI RMF · MEASURE 4.2 OWASP LLM · LLM03
AP
Anti-Pattern Check
PXB-AP.1 · Policy first, discovery never

Are you at risk of publishing policy before completing discovery?

A published policy over an unmapped estate is decoration.

NIST AI RMF · MAP 1.1 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-AP.2 · Banning the public tools and hoping

Do you plan to enforce a ban without offering employees a sanctioned alternative?

Employees route around bans within a week.

NIST AI RMF · GOVERN 1.1NIST AI RMF · MANAGE 3.1 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-AP.3 · One-off vendor questionnaire

Will you commit to continuous vendor assurance rather than a one-off gate?

AI features ship monthly. Assurance has to keep pace.

NIST AI RMF · GOVERN 6.1NIST AI RMF · GOVERN 6.2 OWASP LLM · LLM03 MITRE ATLAS · AML.T0010 ML Supply Chain Compromise
PXB-AP.4 · Launch red team as evaluation

Will you resource ongoing evaluations, not just launch red teams?

Models drift. A one-time review ages out in weeks.

NIST AI RMF · MEASURE 2.3NIST AI RMF · MEASURE 4.2 OWASP LLM · LLM01OWASP LLM · LLM04 OWASP Agentic · T5 MITRE ATLAS · AML.T0043 Craft Adversarial Data
PXB-AP.5 · Kill switch on paper

Will you require drilled, not just documented, kill switches?

If no one has pulled it in a drill, it does not exist.

NIST AI RMF · MANAGE 2.4NIST AI RMF · MANAGE 4.3 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-AP.6 · Governing the model, not the surfaces

Will your policy focus effort on the surfaces around the model rather than on model prompting alone?

Prompt engineering does not compensate for missing identity, logging, or allowlists.

NIST AI RMF · MANAGE 2.2 OWASP LLM · LLM01OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T9
of fields captured