1.AI governance as a business function, not just compliance.
2.The regulatory landscape - EU AI Act risk tiers, US sectoral rules, and any local requirements.
3. Role clarity: provider vs deployer vs modifier.
4. Risk-based classification of AI use cases - not all AI use carries the same stakes.
5. Human oversight requirements.
6. Data provenance and IP exposure
7. Model accountability chains
8. Transparency and disclosure obligations
9. Incident response for AI failures
10. Governance as an iterative process, not a one-time policy