ai-governance-researchlisted
Install: claude install-skill themarmack/research-bot
# ai-governance-research
Companion to `financial-regulator-watch`. Where the regulator-watch covers the *financial-services regulator* lens, this skill covers the *AI-specific governance* lens — frameworks that apply to AI tooling regardless of industry, but with practical implications for how the org uses AI dev tools (Copilot, internal LLM gateways, agentic SDLC features).
## When to use
- Question about whether a specific AI framework applies to internal dev tooling (the user's domain).
- Mapping a org's existing AI risk posture to NIST AI RMF / ISO 42001 / EU AI Act categories.
- Background research before a policy decision (e.g., "should our AI tool catalog require model cards?").
- Comparing posture across frameworks (NIST AI RMF + EU AI Act + state law).
## When NOT to use
- Financial-services regulator guidance → `financial-regulator-watch`.
- Specific Copilot / GitHub / vendor questions → `copilot-deep-dive` or `github-platform-watch`.
- AI-tool vendor evaluation — that's [`vendor-security-eval`](../vendor-security-eval/SKILL.md).
## Source taxonomy
Tier-1 primary sources:
| Framework | Authoritative source |
|-----------|----------------------|
| NIST AI RMF (1.0 + Generative AI Profile) | nist.gov |
| EU AI Act | EUR-Lex (Regulation 2024/1689 + Annexes) |
| US Executive Orders on AI | whitehouse.gov, federalregister.gov |
| ISO 42001 | iso.org (standard text often gated; use ISO's public summaries + commentary) |
| State AI laws | state legislative trackers