AI Governance in Practice: Mapping, Measuring and Monitoring, Adine Mitrani, Fenwick & West
In this session, we’ll engage in a focused discussion on the practical realities of AI governance, centering on how organizations can identify, measure, and monitor risks inherent to advanced AI systems in light of existing and upcoming U.S. AI laws and regulations. We’ll examine the core issues those regimes aim to address, such as transparency, bias, and hallucinations — challenges that, if unmitigated, can erode reliability and stakeholder trust. The conversation will also address emerging risks associated with AI agents, including agents authorized to take autonomous actions (including automated decisions) beyond content orchestration, the potential for cascading errors, and the expanded surface area these systems create for operational control and security risks.
This roundtable is designed to promote candid exchange and practical takeaways across a diverse audience, including governance leads, engineers, risk managers, and product owners
A few specific points you'll address during the session:
- Mapping AI-Inherent Risks to NIST Standards and Regulatory Requirements:
Discuss aligning risk identification, measurement, and monitoring with the NIST AI Risk Management Framework (AI RMF) and mapping internal controls to U.S. legal and regulatory expectations that increasingly reference or support NIST-aligned practices. We will discuss control design for developers and deployers, including performance and robustness testing, human-in-the-loop checkpoints and logging, particularly as these measures are included as requirements in AI Addenda for large enterprise customers. - AI Agent Risks and Technical Mitigations:
Examine how AI agents introduce legal and operational risk, including questions around authorization, allocation of responsibility between providers and deployers, and litigation and enforcement exposure. Outline how OWASP guidance (e.g., the OWASP Top 10 for AI Agents) can be operationalized through policies, layered monitoring and incident response playbooks.