AI SecurityHow-To & HardeningNews

AI/SI Governance Checklist: Policies, Vendors and Agent Inventory

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

The AI-to-SI rename is a good moment to check your AI governance basics. Use this checklist to cover policies, vendors and agents.

Policies

  • AI acceptable use policy exists and is acknowledged by staff.
  • Definitions cover AI and SI terminology.
  • Policy maps to at least one framework (NIST AI RMF, ISO/IEC 42001) and relevant laws (EU AI Act, state laws, sector rules).
  • Data handling rules for AI tools specified (what data can and can't be used).

Inventory

  • AI systems inventoried: copilots, agents, models, AI features in SaaS.
  • Each has an owner, purpose, data sources and permissions.
  • Shadow AI usage monitored (Defender for Cloud Apps discovery, Purview DSPM for AI).

Agents

  • Each agent has its own identity with least privilege.
  • Network egress restricted by default.
  • High-impact actions require human approval.
  • Kill switch tested.
  • Agent activity logged.

Vendors

  • AI vendors assessed for data use, model training on your data, security and incident notification.
  • Contracts include both AI and SI terms.
  • Third-party AI features in existing SaaS reviewed.

Incidents

  • Incident response plan covers AI-caused incidents (including harm to third parties).
  • Notification timelines and verified contacts for regulators and partners defined.
  • AI incident scenario exercised.

Oversight

  • AI risk reported to leadership or the board regularly.
  • Named executive accountable for AI governance.

Sources

  1. Source
ai si governance checklistAI renamed SI2026

More on this story