# AIPMO.co > Practical AI governance for delivery teams: translate NIST AI RMF, EU AI Act, and ISO 42001 requirements into project artifacts, checkpoints, and controls. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [About AIPMO.co](https://aipmo.co/about.md) - Practical AI governance guidance for project managers, SMBs, and consultants. AI adoption is accelerating. Governance guidance hasn’t kept up — at least not for the teams that actually need it. Most AI governance resources are written for large enterprises with dedicated compliance teams, legal dep… - [AI Transparency](https://aipmo.co/ai-transparency.md) - How AIPMO.co uses AI: the models behind the Advisor, Document Customizer, and Aidan, what happens to your data, and what these systems deliberately do not do. - [Billing Policy](https://aipmo.co/billing.md) - AIPMO billing policy — plans, pricing, payment methods, cancellation, and refunds. - [Contact](https://aipmo.co/contact.md) - Get in touch Have a question about AI governance? Interested in consulting services? Just want to connect? Email: info@aipmo.co - [Cookie Policy](https://aipmo.co/cookies.md) - Cookie Policy Last updated: June 3, 2026 This Cookie Policy explains how AIPMO.co ("we," "us," or "our") uses cookies and similar browser storage technologies when you visit our websites at aipmo.co and app.aipmo.co. What Are Cookies Cookies are small text files placed on your device when you visit… - [Find Your Path](https://aipmo.co/find-your-path.md) - How to use AIPMO based on who you are and where your organization is - [Home Page](https://aipmo.co/home.md) - The AI governance advisor built for project managers. Ask anything about NIST AI RMF, EU AI Act, ISO 42001, and more — get grounded answers with real framework citations. Free to start. - [Podcasts](https://aipmo.co/podcasts.md) - AI governance discussions powered by NotebookLM — deep dives into frameworks, regulations, and PM practice. - [Privacy Policy](https://aipmo.co/privacy.md) - Privacy Policy Last updated: June 3, 2026 AIPMO.co ("we," "us," or "our") operates the websites aipmo.co and app.aipmo.co. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our websites and services. We take privacy seriously — particularly… - [Billing & Payment FAQ](https://aipmo.co/support-billing-faq.md) - Answers to common billing and payment questions — plans, pricing, payment methods, refunds, and how to manage your subscription. - [Contact Support](https://aipmo.co/support-contact.md) - Get in touch with the AIPMO support team by email. We aim to respond within one business day, Monday through Friday Eastern Time. - [Frequently Asked Questions (FAQ)](https://aipmo.co/support-faq.md) - Answers to common questions about plans, billing, the Advisor, and account access. Can’t find what you need? Email info@aipmo.co. Plans & Pricing What plans does AIPMO.co offer? AIPMO.co has three tiers. Essential is free and includes template downloads and limited Advisor access. Professional at $… - [Getting Started with AIPMO](https://aipmo.co/support-getting-started.md) - New to AIPMO? Learn how to get the most out of the platform — from your free account to the Advisor, templates, and Document Customizer. - [How to Manage or Cancel Your Subscription](https://aipmo.co/support-manage-subscription.md) - Learn how to manage or cancel your AIPMO subscription using the Stripe Customer Portal — no need to contact support. - [Support](https://aipmo.co/support.md) - Find answers to common questions about AIPMO, billing, and your account — or get in touch with our support team. - [Terms & Conditions](https://aipmo.co/terms.md) - Terms and Conditions Last updated: July 16, 2026 These Terms and Conditions ("Terms") govern your use of the AIPMO.co websites at aipmo.co and app.aipmo.co, and all related services (collectively, the "Service") operated by AIPMO.co ("we," "us," or "our"). By accessing or using the Service, you agr… - [Topics](https://aipmo.co/topics.md) - [Welcome to AIPMO Consultant](https://aipmo.co/welcome-consultant.md) - You have everything you need to deliver AI governance across your entire client portfolio. * Everything included in Professional * Multiple organization profiles with independent maturity assessments * Per-client governance playbooks * Client dashboard with project switcher Where to start The Consu… - [Welcome to AIPMO](https://aipmo.co/welcome-essential.md) - You're in. Here's what's included with your Essential membership: * Access to all framework guides and explainer articles * Downloadable static governance templates * AI Governance Advisor chat (limited usage) Where to start If you're new to AI governance, it can feel overwhelming — there are dozen… - [Welcome to AIPMO Professional](https://aipmo.co/welcome-professional.md) - You now have the full toolkit to manage AI governance within your organization. * Everything included in Essential * Organization profile with automatic maturity assessment * Multiple projects under your organization * Project-specific governance playbooks * AI-powered document generation tailored… ## Posts - [A Policy is Not a Control](https://aipmo.co/agentic-ai-governance-guardrails.md) - An autonomous AI agent breached Hugging Face on its own. For PMs, the lesson is blunt: a policy is not a control. Five guardrails that make governance real. - [NAIC AI Bulletin Adoption: Q2 2026 State-by-State Status](https://aipmo.co/naic-ai-bulletin-q2-2026-status.md) - Twenty-nine jurisdictions now regulate insurer AI use. Here's where every state stands as of Q2 2026, what the NAIC's January-September Evaluation Tool pilot means for market conduct exams, and where multi-state carriers should focus. - [The Banking Sector Got Mythos First. Here's What That Means for Its PMs.](https://aipmo.co/finserv-mythos-bank-pm-playbook.md) - JP Morgan, Goldman, Citi, BofA, and Morgan Stanley all got Mythos first — and the Treasury Secretary convened them to discuss using it. For FinServ PMs inside Project Glasswing and outside it, the governance implications are immediate, regulator-facing, and not covered by SR 11-7 as written. - [The Mythos Signal: Why a Model You Can't Use Should Change Your AI Governance](https://aipmo.co/emerging-mythos-pm-governance.md) - Anthropic shipped Mythos to a closed partner list, then a contractor environment was breached. PMs won't use the model, but the release pattern — gated tiers, vendor-mediated exposure, capability migrating downward — is the new default. Here's what to update in your governance stance now. - [The AI Project Charter for Agile Teams: Governance that Enables Agility, Not Bureaucracy](https://aipmo.co/ai-project-charter-agile.md) - Agile teams don't skip chartering — they just do it badly. The AI governance questions that must be answered before sprint 1 don't care about your methodology. Here's how to meet them without importing waterfall into your backlog. - [Law Enforcement and Criminal Justice AI: The Highest-Stakes Deployment](https://aipmo.co/law-enforcement-ai.md) - Facial recognition has put innocent people in prison. Risk tools score individuals on group statistics. Predictive policing amplifies historical bias at scale. The stakes have no equivalent in government AI. Neither do the governance obligations. - [Due Process and Automated Government Decisions](https://aipmo.co/due-process-and-automated-decisions.md) - Robodebt. SyRI. MiDAS. Three countries, three systems, one failure: automated consequences without human review. When government AI affects citizens' rights, due process is not a feature to add later. It is the acceptance criterion. - [Procuring AI for Government: What the Contract Needs to Include](https://aipmo.co/procuring-ai-for-government.md) - Procuring AI from a vendor doesn't transfer accountability. The agency still owns the due process obligation, the legal liability, and the reputational damage. Here's what every government AI contract actually needs to include. - [AI Governance in Government: What Project Managers Need to Know](https://aipmo.co/ai-governance-in-government.md) - The same governance failure played out in Australia, the Netherlands, the US, and across democratic governments worldwide. The pattern is identical. The PM lesson is too. Here's what responsible government AI deployment actually requires. - [Model Risk Management and SR 11-7: The Framework That Already Governs AI](https://aipmo.co/model-risk-management-and-sr-11-7.md) - SR 11-7 was written for statistical models. Federal banking examiners are using it to evaluate machine learning in credit, trading, and risk management today. Here's how to adapt model risk governance for the AI era without rebuilding from scratch. - [GenAI in Financial Services: New Capabilities, Familiar Governance Risks](https://aipmo.co/genai-in-financial-services.md) - FINRA's 2026 Annual Report documented AI hallucinations in compliance workflows and unauthorized use of non-compliant tools. Generative AI introduces failure modes that traditional model risk management wasn't designed to catch. Here's the gap analysis. - [Fair Lending and Credit AI: When the Algorithm Discriminates](https://aipmo.co/fair-lending-and-credit-ai.md) - The CFPB's adverse action notice requirement doesn't care whether a denial came from a human or a gradient-boosted tree. Proxy discrimination in credit AI is as illegal as direct discrimination. Here's the governance framework that keeps models compliant. - [Adverse Action Notices and Explainability in Financial AI](https://aipmo.co/adverse-action-notices-and-explainability.md) - An AI that can't explain why it denied credit doesn't meet Regulation B. The CFPB's "specific reasons" requirement applies regardless of model complexity. Explainability is not a model architecture preference — it's a legal obligation. - [AI Governance in Financial Services: What Project Managers Need to Know](https://aipmo.co/ai-governance-in-financial-services.md) - SR 11-7, the EU AI Act, FINRA's 2026 GenAI guidance — financial services has the most mature AI governance regulatory stack of any industry. Here's what it means for PMs managing AI in banking, lending, and investment management. - [Coverage Denial AI: When Algorithms Ration Care](https://aipmo.co/coverage-denial-ai.md) - Lokken v. UnitedHealth allowed class claims to proceed against an AI denying post-acute care to elderly patients. California banned solely algorithmic coverage denial. When AI rations care, the governance obligations are clinical, not administrative. - [Clinical Validation of Healthcare AI: Evidence Standards Across Jurisdictions](https://aipmo.co/clinical-validation-of-healthcare.md) - A regulatory clearance says an AI met an evidence standard at a point in time. It does not say the AI works in your hospital, with your patients, in your workflow. Independent validation in your deployment environment is a separate obligation. - [Ambient AI and Consent in Healthcare: What the NHS Anima Case Changed](https://aipmo.co/ambient-ai-and-consent-in-healthcare.md) - In July 2025, NHS Annie hallucinated diabetes and heart disease for a healthy patient. In December 2025, Sharp Healthcare faced a consent lawsuit over AI scribe recording. Three governance failures. One article on what they require you to change. - [Algorithmic Bias in Clinical AI: The Health Equity Risk](https://aipmo.co/algorithmic-bias-in-clinical-ai.md) - Over half of published clinical AI models use data from the US or China. Skin cancer AI performs worse for darker-skinned patients. AI scribes misrepresent Black and non-English-speaking patients. The bias is documented. The governance is law. - [AI Governance in Healthcare: What Project Managers Need to Know](https://aipmo.co/ai-governance-in-healthcare.md) - Clinical AI that influences diagnosis, treatment, or care decisions is a medical device in every major jurisdiction. The NHS Anima hallucination, California's SB 1120, Lokken v. UnitedHealth — 2025 defined what governance failures look like. - [AI in Insurance Underwriting: Governance for Pricing and Risk Classification](https://aipmo.co/ai-in-insurance-underwriting.md) - External consumer data creates proxy discrimination even when protected characteristics are excluded from the model. ZIP codes encode segregation. Credit scores encode wealth gaps. The FCA found UK insurers using datasets correlating with race. Testing is required. - [GenAI in Insurance: Governance for the Next Generation](https://aipmo.co/genai-in-insurance.md) - Traditional insurance AI governance doesn't transfer to large language models. GenAI outputs are probabilistic, not deterministic. Inputs can't be audited like gradient-boosted features. EIOPA identified three specific governance gaps. Here's how to close them. - [AI in Insurance Claims: Governance for Automation and Denial](https://aipmo.co/ai-in-insurance-claims.md) - Lokken v. UnitedHealth granted full discovery into insurer AI use. California SB 1120 banned solely algorithmic coverage denial. Courts are treating AI denial without genuine human review as bad faith. The governance implications apply to every line of business. - [Algorithmic Bias in Insurance AI: The Discrimination Problem](https://aipmo.co/algorithmic-bias-in-insurance.md) - A 2025 NAIC survey found one in three health insurers still don't regularly test their AI for bias. The EU AI Act makes bias testing a legal requirement. Colorado makes discriminatory outcomes a prohibitable offense regardless of intent. Time is short. - [AI Governance in Insurance: What Project Managers Need to Know](https://aipmo.co/ai-governance-in-insurance.md) - The NAIC Model Bulletin is now law in ~25 states. EU AI Act Annex III designates life and health pricing AI as high-risk with an August 2026 deadline. Lokken opened AI governance to litigation discovery. The window for proactive compliance is now. - [The White House Just Published a National AI Framework. Don’t Rewrite Your Governance Program Yet.](https://aipmo.co/the-wh-national-ai-framework.md) - The Trump administration released its National Policy Framework for AI on March 20, 2026. It's ambitious in scope, thin on substance, and still needs Congress to act. Here's what it actually means for your AI program. - [LLM Safety Benchmarking: What PMs Need to Know About Evaluating AI Model Safety](https://aipmo.co/llm-safety-benchmarking.md) - Your vendor says the model scored 94% on safety benchmarks. But what was actually tested — and what does that score obligate you to do? Here's how NIST MEASURE, the EU AI Act, and Singapore's Project Moonshot translate into PM accountability. - [Open-Source AI: The Governance Challenges You Didn't See Coming](https://aipmo.co/open-source-ai.md) - Open-source AI transfers governance responsibility to you. What your commercial vendor handled in the background — safety testing, documentation, incident response — now sits on your project plan. Here's what the EU AI Act and NIST say you're accountable for. - [Episode 001: Translating AI Frameworks into Project Management Workflow](https://aipmo.co/podcasts/podcast-001-translating-ai-frameworks-pm-workflow.md) - AI adoption is accelerating, but governance frameworks don't speak PM language. In this pilot episode, we explore how to translate AI governance into practical project management workflows. - [The Dangerous Gap in AI Project Delivery](https://aipmo.co/dangerous-gap-ai-project-delivery.md) - Why project managers are the missing link between AI governance frameworks and real-world AI delivery. - [AI in Insurance: A PM's Guide to a High-Stakes Sector](https://aipmo.co/ai-insurance.md) - Insurance AI is making decisions about who gets coverage, how much they pay, and whether claims are approved. EU AI Act Annex III classifies health and life insurance risk assessment as explicitly high-risk. Here's what NIST MEASURE 2.11, the NAIC Model Bulletin, and state regulators require of you. - [Agentic AI: What Project Managers Need to Know](https://aipmo.co/agentic-ai.md) - Traditional AI advises. Agentic AI acts — autonomously browsing, calling APIs, executing code, and delegating to other agents. The shift from output to action changes everything about how you govern AI projects. Here's what EU AI Act Article 14, NIST MANAGE 2.4, and Singapore's IMDA require of you. - [Change Management for AI Projects: Preparing People for a New Way of Working](https://aipmo.co/ai-change-management.md) - AI change management goes beyond training people on a new tool. It requires helping them develop new mental models for working with probabilistic systems — and addressing the trust, accountability, and expertise questions that conventional IT change management was never designed to handle. - [Third-Party AI and Vendor Management: Risks You Don't Control](https://aipmo.co/third-party-ai-vendor-management.md) - When you deploy third-party AI, you deploy the decisions its developer made about training data, fairness testing, and risk mitigation — and you remain accountable for the outcomes regardless of who built the system. Here's what PMs need to know before signing the contract. - [Monitoring AI Systems in Production: The Work After Go-Live](https://aipmo.co/ai-monitoring-production.md) - AI systems degrade in production even when no one touches the code. Post-deployment monitoring is not optional: for high-risk AI it's a legal requirement, and for all AI it's the only way to know whether the system is still doing what it was designed to do. - [Testing and Validation for AI Systems: More Than Accuracy](https://aipmo.co/ai-testing-validation.md) - Every AI project needs testing — but the test plan looks nothing like traditional software QA. The NIST AI RMF TEVV framework requires testing across five dimensions: accuracy, fairness, robustness, safety, and explainability. A system can pass every conventional test and still discriminate. - [Stakeholder Engagement for AI Projects: Beyond the Usual Suspects](https://aipmo.co/stakeholder-engagement-ai.md) - AI systems affect people who never appear on a traditional stakeholder register — and under the EU AI Act, informing them and giving them a mechanism to contest decisions is a legal obligation. Here's how to build a stakeholder approach that goes beyond the usual suspects. - [Human Oversight in AI Systems: Designing for Control](https://aipmo.co/human-oversight-ai.md) - Human oversight of AI isn't a design preference — it's a legal requirement. EU AI Act Article 14 mandates five specific capabilities in every high-risk AI system. As PM, each one is a project deliverable, not a governance aspiration. - [Model Cards and Datasheets: Documentation That Matters](https://aipmo.co/model-cards-datasheets.md) - AI projects need documentation that doesn't exist in conventional IT: model cards, datasheets, and system cards. Under the EU AI Act, technical documentation must exist before deployment — and be retained for 10 years. Here's what each document must contain and why. - [AI Risk Registers: Beyond Traditional Risk Management](https://aipmo.co/ai-risk-registers.md) - AI risk registers use the same mechanics as conventional ones — identify, assess, mitigate, monitor. What changes is the taxonomy of risks, how likelihood behaves at scale, and the fact that the register doesn't close at deployment. Here's what needs to extend. - [The AI Project Charter: What's Different](https://aipmo.co/ai-project-charter.md) - The AI project charter covers the same fundamentals as any charter — plus questions that conventional projects never ask: Why AI rather than an alternative? Who might be harmed? What decisions will never be automated? What data is this project permitted to use? - [AI Governance for U.S. Projects: What Actually Applies?](https://aipmo.co/us-ai-governance.md) - The US has no comprehensive federal AI law. What applies to your project depends on your sector, your use cases, and which states your users are in. Here's how to navigate a landscape built from executive orders, voluntary standards, existing law, and accelerating state regulation. - [What the EU AI Act Means for Your Project Timeline](https://aipmo.co/eu-ai-act-timeline.md) - The EU AI Act's August 2026 general application date is a statutory deadline, not a target. Here's what high-risk AI systems must actually deliver, how the conformity assessment pathways work, what the transitional provisions mean for systems already in service, and where the penalties sit. - [AI Risk Classification: How to Use the EU AI Act Framework for Project Scoping](https://aipmo.co/ai-risk-classification.md) - The EU AI Act's four-tier risk framework is a project scoping tool, not just a compliance checklist. This article covers all four tiers, the Article 6(3) downward self-classification mechanism, the profiling override that closes the most common gap, and how classification drives planning decisions. - [OECD AI Principles: What They Mean for Your Project](https://aipmo.co/oecd-ai-principles.md) - The OECD AI Principles are the source document behind most AI governance frameworks — including the EU AI Act, NIST AI RMF, and ISO 42001. Understanding the five principles, including the 2024 updates, helps PMs understand why downstream requirements are what they are. - [ISO 42001 for Project Managers](https://aipmo.co/iso-42001-guide.md) - ISO 42001 is a certifiable AI management system standard — not a risk framework or a checklist. Its AI-specific requirements in Clauses 6 and 8 generate concrete PM deliverables: risk assessments, impact assessments, lifecycle controls, and supply chain governance. - [The PM's Guide to NIST AI RMF](https://aipmo.co/nist-ai-rmf-guide.md) - The NIST AI RMF isn't a checklist — it's 72 subcategories across four functions that you're meant to select from based on your system's risk level. Here's what each function actually requires a project team to do, and where most AI projects currently have gaps. - [AI Impact Assessments: Running Them Like a PM](https://aipmo.co/ai-impact-assessment.md) - An AI impact assessment asks who could be harmed by this system — not just what could go wrong with it. Those are different questions. Here's what the frameworks actually require, why the PM needs to own it, and how to run one that produces decisions rather than paperwork. ## Optional - [RSS Feed](https://aipmo.co/podcasts/rss/) - [Sitemap](https://aipmo.co/sitemap.xml) - [Full content of pages and posts](https://aipmo.co/llms-full.txt)