Georgia State University — J. Mack Robinson College of Business PATH — Pathways for AI Training & Hiring CIS 4394 Agentic AI  ·  Fall 2026  ·  Dr. Xinyu Fu
02 · Trust & governance

Two documents every AI professional should know.

One is voluntary and American and tells you how to organize the work. One is binding and European and tells you what you owe, based on how risky your system is. Neither is hard. Being the person in the room who has actually read them is a career advantage that costs you one afternoon.

Honest note before anything else: this area is moving. Frameworks get revised, profiles get added, and the application dates and details of the EU regulation are phased and have been subject to political argument. Nothing on this page is legal advice, and no slide is a citation. When something rides on it — a job, a client, a grade on Milestone II — cite the primary document and check the date on the version you read. Both primary sources are linked below, free.
Interactive · click a function

NIST AI Risk Management Framework

AI RMF 1.0 (NIST AI 100-1, published January 2023) is a voluntary framework from the US National Institute of Standards and Technology. It is a public-domain US Government work — you may adapt it freely with citation, which is why it is the safest backbone for a company policy or a capstone appendix. Its whole structure is four functions. Click each one.

GOVERNthe culture & the owner MAPcontext & what could go wrong MEASUREanalyze, test, track MANAGEact on the risks The loop, togetherwhy this is not a checklist

CertMike explains the AI RMF

A clean seven-minute walkthrough of the four functions from a well-known certification instructor — useful if you want the framework in someone else's words before you open the PDF. (Mike Chapple; approx. 7 minutes — verify the runtime on the page.)

Go to the source

NIST — AI Risk Management Framework (landing page) ↗
The hub: the framework, the companion Playbook, and the profiles NIST has published alongside it.

AI RMF 1.0 — the full PDF ↗
Around 40 pages of readable prose, no mathematics. Skim the four function sections; you will recognize most of it from your systems courses.

Why it is safe to reuse: as a US Government work it is in the public domain. You can lift its structure into your Milestone II appendix, with a citation, and no licence follows you home. That is not true of every framework on this page.
Interactive · click a tier

The EU AI Act

Regulation (EU) 2024/1689 is binding law, not guidance, and it is structured around a simple idea: obligations scale with risk. The same technology sits in a different tier depending on what you point it at. Click each band.

Unacceptable High risk Limited risk · transparency Minimal risk

Tier diagram drawn for this course from the structure described in the Act. Placement of any specific product is a legal question answered from the text, not from a lecture diagram.

Go to the source

The AI Act — readable structure and article-by-article text ↗
A navigable presentation of the regulation. Useful for finding which article or annex actually governs a use case.

Key facts to keep straight: it is Regulation (EU) 2024/1689, published in the Official Journal in July 2024 and in force since 1 August 2024. Its obligations do not all start at once — different duties apply from different dates, and the schedule has been actively debated. Read the dates in the text you are citing, and say which version you read.

“But we are in Georgia.”

Three reasons this is still your problem. One: whether the Act reaches a given US-built product is a scoping question you answer from the regulation, not from a rule of thumb — and the answer is often yes for anything sold into or used from Europe. Two: big vendors comply globally because maintaining two products is expensive, so the requirements arrive in your procurement questionnaires either way. Three: the tier structure — obligations proportional to consequence — is simply a good way to think, and it is the structure US regulators, insurers, and enterprise buyers are converging on regardless of what any single legislature does next.

Side by side

Same agent, two lenses

NIST AI RMF 1.0EU AI Act — Reg (EU) 2024/1689
Who issues itNIST, a US standards agency (Dept. of Commerce). Developed openly with industry input.The European Parliament and Council. It is legislation.
Binding?No — voluntary. Its force comes from contracts, procurement, insurers, and courts asking whether you followed a recognized practice.Yes — binding regulation, with supervisory authorities and penalties. Consult the text for what applies and when.
What it asks of youOrganize the work: govern it, map the context, measure what you claim, manage what you find. It tells you the process, not the answer.Classify the system by risk, then meet the duties attached to that tier — documentation, data and human-oversight requirements, transparency to the people affected.
Unit of analysisYour organization and lifecycle. Who owns this, and how do risks get found and handled over time?The system and its use case. What is this thing pointed at, and who bears the consequence?
Licence to reusePublic domain (US Government work) — adapt with citation.Official EU text — cite and link with attribution; not an open remix licence.
What it means for your capstoneUse its four functions as the headings of your Milestone II security section. It is free structure that a reviewer recognizes.State the tier you believe your agent lands in and why, in one paragraph, citing the article or annex you relied on. Being wrong with reasoning beats being silent.
The one-line version: the RMF gives you the structure; the Act gives you the obligation. Mature governance uses both — a security taxonomy and a legal taxonomy look at the same agent and see different things, and you need both views to answer “are we allowed to ship this, and would we know if it went wrong?”
Concept check

Which tier? Which function?

Why managers care

You already built most of this

The uncomfortable secret of AI governance is how little of it is new. Strip the vocabulary and it is the control environment your information-systems courses already taught, applied to a system that happens to hold a language model.

What you built in this courseWhat the control is actually calledWhat governance adds
Tool inventory — every function the agent may call, with its scope (Week 5)Asset inventory and least-privilege access controlA named owner per tool and a review date. An inventory nobody owns is a document, not a control.
Human gate before irreversible actions (Weeks 4–5)Maker–checker / segregation of dutiesWritten criteria for what needs approval, and evidence that approvals actually happened.
Egress allow-list and output screening (page 01)Data-loss preventionA list of approved destinations that changes through a request, not a code commit.
Full step trace in the Week 2 evidence formatAudit trailRetention, tamper-resistance, and someone whose job includes reading it.
Your eval harness and regression suite (Week 8)Testing and control monitoringA threshold that means “do not ship,” agreed before the number comes back.
Max-iteration guard, budget cap, kill switch (Week 4)Operational limits and incident responseA documented plan for who gets paged, who can stop the agent, and what gets told to whom.
Governance is mostly writing down what you built and naming who owns it. That is why MIS graduates are unusually well positioned here: the scarce skill is not training models, it is being able to sit between the engineers and the auditors and speak both languages. Very few people can.
Discussion questionYour startup has eight engineers and no compliance function. A prospective enterprise customer asks: “What is your AI governance process?” What do you say — and what would make the answer credible instead of aspirational?
Do not claim a program you do not have; enterprise buyers have heard that and can tell. Say what is true and show the artifacts: (1) we map to the NIST AI RMF and here are our four sections; (2) here is our tool inventory, with an owner per tool and the scope of each credential; (3) these actions require human approval and here is a sample approval record; (4) here is our trace format and retention period, and here is a real trace with the sensitive fields removed; (5) here is our eval suite, its pass threshold, and the last run; (6) this named person owns the agent's behavior and here is how to reach them during an incident. Six artifacts, all of which you can produce in a week if you built the system properly, and none of which require a compliance department. Credibility comes from evidence and a named owner, not from a policy document — the artifacts are the answer, the policy just describes them.
← Previous01 · How agents get attacked