AI governance, minus the marketing
Reference material on what the law requires, what the frameworks ask for, and what works in practice. Written for the person who will have to take it to legal, to the committee or to the auditor — not to generate a lead. Nothing here asks for a signup.
Research: one in five AI tools we catalogued no longer exists →
What is Shadow AI?
11 minThe definition, why banning fails, and what to do instead.
Does Brazil's LGPD ban AI at work?
13 minArticle by article: legal basis, records of processing, international transfers, and what becomes an audit finding.
What should an AI usage policy contain?
15 minTen sections, the suggested wording for each, and why every clause is there.
How do you build an AI inventory (AI-BOM)?
13 minThe document every framework assumes and almost no company has. Fields, sources and the order to build it.
What does ISO/IEC 42001 require in practice?
14 minStructure, Annex A controls, what carries over from ISO 27001, and the road to certification.
Does the EU AI Act apply to companies outside Europe?
13 minWhy it reaches companies that do not sell to Europe, the four risk tiers, and the calendar.
What does the NIST AI RMF ask for, and where do you start?
9 minThe four functions in plain language, and why the AI inventory comes first.
Does SOC 2 cover AI tools?
8 minSOC 2 is an attestation, not a certification, and what you are asked when employees use AI.
Is it safe to use ChatGPT at work?
8 minIt depends on the plan and what you paste: what changes between Free, Plus, Business and Enterprise.
Can employees use ChatGPT and other AI tools with patient data under HIPAA?
10 minBAAs, de-identification, minimum necessary, and why you cannot prove what you never saw.
Missing a topic?
These guides are reviewed every six months and the list grows with the questions we get. If there is an AI governance topic that should be here, write to contato@tangerinai.com.