We’re rapidly embedding AI into core workflows, but I still see many orgs treating AI risk as a “feature” under generic IT or data risk instead of a dedicated domain with its own controls and lifecycle. With NIST’s AI RMF and upcoming AI regulations, it feels like the minimum bar now is clear ownership, model + data governance, and continuous monitoring of AI systems, not just a one-off review.
How are you structuring AI governance in practice: separate AI risk domain in your GRC, or folded into existing model/tech risk? What’s working (or not) for you?