How boards, executives, and counsel put responsible AI into practice — governance frameworks, board AI oversight, D&O liability, risk management, and the controls that let organizations scale AI safely. Conversations and analysis from the leaders building the guardrails.
What "AI governance and risk" really means
AI governance and risk is the discipline of deploying artificial intelligence so that an organization can move quickly and stay accountable — covering how AI systems are reviewed before launch, how risk is tiered, who oversees outputs, and how responsibility is assigned when something goes wrong. It is the operating tension at the center of this show: velocity versus accountability.
Most coverage of this topic is either abstract principle ("be responsible") or dense legal reference. This hub is neither. It collects what senior operators — chief privacy officers, state CIOs, general counsel, finance and enterprise leaders — actually do to govern AI, in their own words, from the AI in Chicago interview archive. If you're responsible for getting AI into production without getting your organization into trouble, start here.
Start with the playbooks
Two evergreen guides distill the operator consensus across dozens of conversations:
The questions this hub answers
How do you govern AI without slowing the business down?
Treat governance as a GPS, not a roadblock. Bring legal, security, and privacy in at project inception, tier scrutiny to real impact, and let low-risk work move fast. See the governance playbook, anchored in NielsenIQ CPO Elena Vekilov's framework.
What foundations do you need before scaling AI?
Identity and access, data governance, and cybersecurity — the unglamorous infrastructure that the exciting use case sits on top of. Illinois State CIO Brandon Ragle makes the case from the scale of 13 million residents.
What should you actually measure?
Outcomes, not engagement. Reed Smith's Richard Robbins frames the real maturity test as whether you can govern a tool responsibly at scale — not whether you can launch it.
Who owns AI governance?
Not IT alone. It's a cross-functional business responsibility spanning legal, privacy, security, data, and the business line — a point Gianne James makes pointedly from financial services.
Are AI risk assessments political?
The inputs are. Northwestern's Nick Diakopoulos measured 42,853 news articles across 27 countries and found that which AI harms get covered varies with the political lean of the outlet — and that existential risk, the premise of every frontier-AI statute, accounts for just 7.2% of coverage. If your risk register inherits its priorities from public discourse, it inherits that sorting too.
Governance by sector
The principles are shared, but the stakes and specifics shift by industry. These conversations show governance under real constraints:
- Enterprise & data — Elena Vekilov on risk tiering and privacy as infrastructure across 90+ markets
- Public sector — Brandon Ragle on foundations-first governance at state scale
- Law — Richard Robbins on effective, responsible AI use aligned to firm strategy
- Finance — Gianne James on why AI governance can't live inside IT
- Healthcare & sensitive data — Tim Turner on data-readiness, bias review, and human oversight
Where governance meets the law
Governance doesn't happen in a vacuum — it happens under a fast-moving regulatory regime, and Illinois is one of the most active states in the country. For the policy and regulation side of this story — the notice regime, mental-health AI rules, and public-sector AI strategy — see the Illinois AI Policy hub and conversations with the people who wrote and enforce the rules, including Rep. Bob Morgan and policy advisor Jason Rosensweig.
Related topics