Same questions, denser rooms. Go when you are ready — not as a test of seriousness.
How to manage, not only name
U.S. National Institute of Standards and Technology
A voluntary framework for putting AI risk into an organisation's ordinary risk practice. Widely referenced; not a law.
You are past 'what can go wrong' and need a cycle: govern, map, measure, manage.
Laws and policies against risks
MIT × Georgetown CSET
More than a thousand governance documents, mapped to the same risk shelves. Filter by domain, sector, lifecycle, and who in the value chain is named.
You need to see which risks a law, standard, or policy actually covers — and which it misses.
Health-specific guidance
World Health Organization
WHO's 2024 guidance on large multimodal models in health: consent, evidence, equity, and the duties that remain with clinicians and states.
The question is not 'is AI risky?' but 'what does care require of this tool?'