AccuSights
PartnersBlogAbout
Book my 30-minute demo

AI governance assessment and transformation roadmap

AI is already inside your business. Govern it before it governs you.

Nearly half of employees now use AI on work devices, and two thirds of them do it through personal accounts your security team cannot see. The companies that get the value without the breach do one thing first: they put a framework around AI before they scale it. Our assessment measures where you stand against NIST and ISO, and the roadmap takes you from policy to a private model enclave in twelve defined steps, with your data classified, your people trained and the attackers priced in.

Take the 3-minute AI readiness check
NIST AI RMF and ISO/IEC 42001 alignedShadow-AI inventory from your own logsTwelve steps, three phases, one roadmap
People, process and technology arranged around classified data, with one evidence set
45%of employees are regular AI users on corporate devices, up from 15% a year earlier; 67% of them use non-corporate accountsSource: Verizon 2026 Data Breach Investigations Report
43%of breaches involved shadow AI, up from 20%, at an average cost of $5.39 million; 68% of breached organizations had no AI use policySource: IBM Cost of a Data Breach Report 2026
34.8%of the data employees put into AI tools is sensitive, and more than 60% of it moves through personal accountsSource: Cyberhaven AI Adoption and Risk Report 2026
223generative-AI data policy violations per month in the average organization, double the prior year; 54% involve regulated dataSource: Netskope Cloud and Threat Report 2026

Where are you on the curve?

The AI train left the station. The question is whether your data is on it without a ticket.

Four stages, drawn from the transformations we have assessed. Most businesses sit at stage one and believe they are at stage two. Pick a stage to see what it looks like, what it exposes, and the next move.

AI transformation maturity curve with four stages, from adoption without boundaries to a private model enclave

Where most businesses are today

What it looks like

Staff use whatever AI tool answers fastest. Customer records, contracts and source code go into personal accounts. Nobody has written down what is allowed.

What it exposes

Regulated data leaves through browsers you do not manage. A breach here is also a notification event, and the 68% of companies without an AI policy discover that in the incident report.

The next move

An acceptable-use policy this month, a shadow-AI inventory from your firewall and proxy logs, and a short list of approved tools with company accounts.

The transformation roadmap

Twelve steps, three phases, one evidence set.

Policy before tools, data classification before models, testing before customers. Every step maps to a NIST AI RMF function and an ISO/IEC 42001 control, so the work you do for adoption is the same work that proves governance to a customer, an insurer or a regulator.

Twelve-step AI transformation roadmap in three phases: people and process controls, feasibility and data readiness, then build, test and measure

Foundational people and process controls

  1. AI acceptable-use policy. Define acceptable and unacceptable AI use across the company, by data type and role, and put it in front of every employee.
  2. Governance framework and roles. Assign ownership, decision rights and risk management for AI adoption, mapped to the NIST AI RMF Govern function.
  3. Data governance and GenAI allow-list. Classify data into regulated, confidential and internal; align the classification with your security stack and approve the tools that may touch each class.
  4. Security and privacy awareness training. Train the workforce on AI-specific risks: prompt injection, data leakage, deepfake fraud and the rules in step one.

AI feasibility, data readiness and responsibility

  1. AI data readiness and cleansing. Scan and categorize data by type, location and sensitivity; recommend and run the cleansing needed before any model sees it.
  2. Front-office feasibility. Evaluate readiness for customer-facing assistants: chat, voice, messaging and the customer-experience data behind them.
  3. Back-office feasibility. Define requirements and assess readiness for a private model enclave that automates internal workflows.
  4. Responsible-impact assessment, before and after. Audit the AI ecosystem for transparency, explainability, compliance, security and privacy, mapped to the NIST Map and Measure functions.

Build, test, measure

  1. Private model enclave, build and train. Develop and test private models in a controlled environment, with your data classification enforced at the boundary.
  2. AI ecosystem security and privacy risk assessment. Assess the models, plugins, agents and vendors in the ecosystem against ISO/IEC 42001 controls and the CIS AI companion guides.
  3. Chatbot and prompt-engineering penetration test. Simulate attacks on the assistant using MITRE ATLAS techniques and the OWASP Top 10 for LLM Applications, then fix what breaks.
  4. ROI and cost-benefit analysis. Align AI outcomes with business goals and set the KPIs the management review will track every quarter.

The AI threats that hit before you know

Six ways AI becomes the breach, and the control that stops each.

LLM01Prompt injection

A customer, a document or a web page tells your assistant to ignore its instructions, and it does. Still the number one risk in the OWASP 2026 list.

The control: Input and output filtering, least-privilege tool access for the model, and a penetration test that tries it before an attacker does.

Shadow AIData leaving through personal accounts

Source code is the top data type leaked to AI tools, and shadow AI is now the third most common insider action in DLP data, four times last year.

The control: A GenAI allow-list enforced at the proxy, company accounts for approved tools, and DLP that watches the browser, not only email.

ASIExcessive agency

An agent with a mailbox, a payment API and a vague instruction is an insider with no judgment. OWASP moved this to number three for 2026.

The control: Scoped credentials per agent, human approval for money and access changes, and audit logs you actually read.

Phishing 2.0AI-assisted phishing and deepfake fraud

Phishing accounts for 44% of AI-assisted initial access in the 2026 DBIR; cloned voices now approve wire transfers.

The control: Phishing-resistant MFA, callback rules for any payment change, and training that uses the real lures.

Supply chainPoisoned models, plugins and packages

Model weights, prompt libraries and agent plugins are software you did not write. This year’s npm and Rust incidents showed how fast trust can be rented.

The control: A bill of materials for AI components, signature checks, and the same vendor review your other software gets.

Governance gapNo policy, no owner, no evidence

68% of breached organizations had no AI policy and 92% of those with AI-related breaches lacked adequate AI access controls.

The control: Steps one to four of the roadmap. They cost the least and remove the most.

Sources: OWASP Top 10 for LLM Applications 2026; Verizon 2026 DBIR; IBM Cost of a Data Breach 2026; Cyberhaven and Netskope 2026 reports. Figures verified 2 September 2026.

What the assessment measures against

NIST for the structure, ISO for the controls, OWASP and MITRE for the test.

NIST AI Risk Management Framework 1.0

The spine of the assessment: Govern, Map, Measure, Manage. Each of our scoring areas maps to one function.

NIST, January 2023; the Generative AI Profile (NIST AI 600-1, July 2024) adds the GenAI-specific risks.

ISO/IEC 42001:2023

The management-system standard for AI. We use its Annex A controls as the control catalogue so the roadmap can lead to certification if a customer or regulator asks.

Certifiable; adopted in Europe as EN ISO/IEC 42001:2026.

OWASP Top 10 for LLM Applications, 2026

The test plan for anything that takes a prompt. Prompt injection remains number one; excessive agency is now number three.

OWASP GenAI Security Project, 4 August 2026; the Agentic Applications Top 10 (December 2025) covers agents.

MITRE ATLAS

The adversary playbook for AI systems, in the same shape as ATT&CK. Our penetration test in step eleven is built from it.

Data release v5.4.0, February 2026, with agentic techniques added.

CIS Controls v8.1.2 with the AI companion guides

The security baseline the AI program sits on: asset and software inventory, data protection, access control, logging.

CIS AI and LLM Companion Guide; AI Agents Companion Guide, April 2026.

NIST Cybersecurity Framework Profile for AI (IR 8596)

How AI risk folds into the security program you already run: secure AI components, defend with AI, thwart AI-enabled attacks.

Preliminary draft, December 2025; we track it and do not present it as final.

The rules already in force

AI regulation is not coming. It is here, state by state.

Texas Responsible AI Governance Act (HB 149)
In force since 1 January 2026
Prohibits AI built or used to discriminate, manipulate toward self-harm or crime, or produce unlawful deepfakes; healthcare providers must disclose AI use to patients; attorney-general enforcement with a 60-day cure period.
Any business deploying AI in Texas
Illinois Human Rights Act amendment (HB 3773)
In force since 1 January 2026
Bars AI that produces discriminatory effects in employment decisions, bans zip-code proxies, and requires notice to applicants and employees.
Employers using AI in hiring, promotion, discipline or pay
California FEHA regulations on automated-decision systems
In force since 1 October 2025
Employers are liable for the AI tools they use in employment decisions and must keep automated-decision records for four years.
California employers and their vendors
California CCPA regulations: ADMT, risk assessments, cybersecurity audits
Effective 1 January 2026; ADMT obligations from 1 January 2027
Notice and opt-out for automated decision-making technology, documented risk assessments for higher-risk processing, and phased cybersecurity audits from 2028.
Businesses subject to the CCPA
Colorado SB 26-189
Effective 1 January 2027
Replaces the 2024 Colorado AI Act with a narrower transparency and disclosure framework after the earlier law was enjoined in April 2026.
Developers and deployers of automated decision-making technology in Colorado
HHS Section 1557 rule, patient-care decision support tools
Compliance since 1 May 2025
Identify and mitigate discrimination risk from AI and algorithmic tools used in patient care; reinforced by OCR’s January 2025 letter.
Healthcare providers and plans receiving federal funds
NYDFS industry letters on AI cybersecurity risk
October 2024 and May 2026
How AI-enabled social engineering, deepfakes and AI-driven attacks fall under 23 NYCRR Part 500: risk assessment, access controls, training and vendor management.
New York licensed financial institutions
SEC and FTC enforcement on AI claims
Ongoing; AI is a named 2026 examination priority
"AI washing" cases against advisers and vendors; FTC Operation AI Comply. Say only what your AI actually does.
Any company marketing AI capabilities
EU AI Act
GPAI duties since 2 August 2025; high-risk obligations deferred to 2 December 2027
Prohibited practices apply now; the Digital Omnibus (Regulation 2026/1744) moved Annex III high-risk deadlines; transparency duties keep their original dates.
US companies selling AI-enabled products or services into the EU

Dates verified 2 September 2026 against the primary instruments. Colorado’s 2024 act was enjoined in April 2026 and replaced by SB 26-189, and the EU deferred its high-risk obligations to December 2027.

Three ways to start

Assess, roadmap, or test what you already built.

Fixed fee, scoped in 30 minutes

AI Governance Framework Assessment

Companies at stage one or two that need to know where they stand before the next tool gets approved.

  • Scored assessment against NIST AI RMF and ISO/IEC 42001 Annex A
  • Shadow-AI inventory from 30, 60 or 90 days of your firewall and proxy logs
  • Data-classification readiness and the GenAI allow-list
  • Policy pack: acceptable use, governance roles, training outline
  • Gap register and a 90-day plan

Fixed fee, scoped in 30 minutes

AI Transformation Roadmap

Companies ready to move from policy to production without losing control of their data.

  • Everything in the assessment
  • Front-office and back-office feasibility, data readiness and responsible-impact assessment
  • The twelve-step roadmap with owners, dates and KPIs
  • Vendor and model review for the tools you have chosen
  • Quarterly management review for the first year

Fixed fee, scoped in 30 minutes

AI Security Testing and Private Enclave Readiness

Companies deploying assistants, agents or a private model that must not become the next breach.

  • Chatbot and prompt-engineering penetration test (OWASP 2026, MITRE ATLAS)
  • AI ecosystem security and privacy risk assessment
  • Private model enclave architecture review with our enclave partner
  • Continuous monitoring of AI components inside your existing program

The 3-minute AI readiness check

Six questions. Your stage on the curve, and the first thing to fix.

1. Do you have a written AI acceptable-use policy that employees have been trained on?

2. Do you know which AI tools your staff actually use, including personal accounts?

3. Is your data classified (regulated, confidential, internal) with rules for what may go into AI tools?

4. Does someone own AI risk, with decision rights and a review cadence?

5. Have your AI assistants or agents been tested for prompt injection and data disclosure?

6. Can you show a customer or regulator evidence of your AI controls today?

Answer all six to see your stage. No email needed for the score.

Questions owners ask

We are small. Does any of this apply to us?
The 2026 DBIR counts 45% of employees as regular AI users on work devices; that number does not shrink with headcount. Steps one to four cost days, not months, and they are where most of the exposure sits. The rest of the roadmap scales with your ambition.
Which framework should we follow?
NIST AI RMF for the structure, ISO/IEC 42001 for the controls and the certificate if you need one, OWASP and MITRE ATLAS for testing. The assessment maps you to all of them at once so you never redo the work.
Will you tell us to stop using AI?
No. We will tell you which tools may touch which data, and put the guardrails in so the answer to most requests becomes yes.
What is a private model enclave?
An environment you control where a model can be grounded on or trained with your documents without those documents leaving your boundary. We assess readiness and architecture with a partner who builds them; we do not resell one.
How long does the assessment take?
Two to three weeks from kickoff, most of it waiting for logs. The 90-day plan arrives with the report.
Does this fit with our existing compliance program?
Yes, that is the point of building it this way. The controls land in the same evidence set as SOC 2, HIPAA, CMMC or the state rules you already answer to, so AI governance becomes part of the program you run rather than a second one beside it.

Talk about your AI transformation before it is too late.

Thirty minutes with an engineer who has assessed AI programs inside banks and hospitals. Bring the tools your staff already use, and leave with your stage, your first three steps and a fixed-fee scope. For Protect clients, the AI controls land in the same console that watches everything else.

Take the readiness check first