Incluu · AI Governance

The AI Governance Essentials Guide

The three gaps that put organizations at risk, the regimes that apply, and what to do first — distilled from the diagnostic framework Dr. Dédé Tetsubayashi uses with Fortune 100 executives.

If AI is already in your product or operations, governance is no longer optional — a board question, a customer security review, or a regulator inquiry can arrive at any time. The good news: most exposure traces to three fixable gaps. Here is the essentials version.

The three governance gaps

1

No inventory — you can’t govern what you can’t see

Most organizations cannot produce a current list of the AI systems they run, who owns each one, what data it touches, and what decisions it influences. Shadow AI (tools adopted by teams without review) compounds the blind spot. Governance starts with a living inventory: every model, vendor API, and embedded feature, mapped to an owner and a risk tier.

2

No bias & human-oversight controls on high-stakes decisions

When AI influences hiring, lending, healthcare, benefits, or criminal-justice outcomes, the absence of a bias audit and a documented human-in-the-loop is both a fairness failure and a legal exposure. The gap is rarely intent — it is that no one has tested the system against protected classes or defined who can override it.

3

No documented data-governance policy or accountable owner

A written AI data-governance policy — covering what data trains and feeds each system, retention, consent, and transparency — plus a named governance lead is the difference between “we’re working on it” and an answer a board or regulator will accept. Distributed, unowned governance is the most common reason readiness stalls.

The regimes that apply

You are almost certainly in scope for more than one. Which ones depends on your industry, your data, and where your users are — the essentials to check first:

EU AI Act
Any AI touching EU users or markets; risk-tiered obligations for high-risk systems.
EEOC / Title VII
AI used in employment decisions in the US — disparate-impact liability applies.
NYC Local Law 144
Automated employment decision tools used for NYC hiring/promotion — bias audit + notice required.
Colorado SB 21-169 & CO AI Act
Insurance and consequential-decision AI — anti-discrimination and disclosure duties.
HIPAA
AI handling protected health information — privacy, security, and access controls.
GDPR / CCPA
Automated decision-making and profiling on personal data — rights, DPIAs, opt-out.

What to do first

  1. 1Build the inventory: list every AI system, its owner, the data it uses, and whether it influences decisions about people.
  2. 2Flag the high-stakes systems and confirm a human can review and override each one.
  3. 3Run (or commission) a bias check on the highest-risk system in the past 24 months — not just once.
  4. 4Write the one-page AI data-governance policy and name a single accountable governance lead.
  5. 5Map each system to the regimes above so every control traces to a regulation that actually applies to you.

Start here — free

See where you stand in about 2 minutes

The free 6-question AI Governance Quick-Scan gives you an instant score out of 100 and your top governance gaps — mapped to the essentials above.

Take the free Quick-Scan →

Go deeper

The 5-Day AI Governance & Equity Diagnostic ($10,000)

Over five business days, Dr. Dédé delivers a full industry-specific governance-gap report, a prioritized remediation roadmap, and a board-ready readout — every finding cited to the regulations that apply to your industry. The discovery call is the fastest way to scope it.

Book a discovery call →

Guide by Dr. Dédé Tetsubayashi, Incluu LLC. This guide is informational guidance — not legal advice.