Do this
- Pick one person responsible for each AI tool your team uses.
- Have that person track what the tool can do and who uses it.
- Put security and data protection duties in writing in every AI vendor contract.
Sources
- IMDA Singapore, Model AI Governance Framework for Agentic AI, Version 1.5 (2026), section 2.2.1, clear allocation of responsibilities, including vendor contracts (pp. 25–28); section 2.4.2, named human contact points (p. 47)
- NIST AI Risk Management Framework 1.0 (NIST AI 100-1), GOVERN 2.1, documented roles and responsibilities
