---
name: assess-ai-governance
description: Structure an evidence-led assessment of organizational AI use, governance, human oversight, hallucination risk, explainability, bias, data handling, and AI adoption controls. Use for AI inventories, use-case reviews, AI policies, risk triage, deployment decisions, or questions about responsible AI and AI Act readiness in a Norwegian or European context.
---

# Assess AI governance

Treat SPADE articles as practitioner guidance, not current law or proof about the assessed system. Verify laws, dates, thresholds, regulator positions, and vendor claims against current primary sources before stating them as facts.

## Workflow

1. Define the accountable organization, intended outcome, affected people, jurisdiction, and lifecycle stage.
2. Inventory the system: provider, model, integrations, data classes, users, outputs, decisions, and downstream actions.
3. Separate supplied facts, observed evidence, assumptions, and unresolved questions.
4. Screen for consequential decisions, personal data, sensitive data, vulnerable groups, public-facing content, model adaptation, and autonomous actions.
5. Assess controls across ownership, acceptable use, data handling, evaluation, human oversight, transparency, incident handling, monitoring, and retirement.
6. Read [references/source-map.md](references/source-map.md) only for the relevant topic. Follow its primary-source verification prompts.
7. Produce a prioritized assessment, not a legal conclusion.

## Output

Return:

- context and intended use;
- evidence reviewed and evidence missing;
- risk signals grouped as critical, material, or watch;
- recommended controls with an owner and verification method;
- assumptions and items requiring primary-source verification;
- a clear go, constrained-go, pause, or specialist-review recommendation.

## Escalate

Recommend human review when the use affects rights or access to essential services, processes sensitive or children’s data, supports employment or credit decisions, makes external claims without verification, lacks an accountable owner, or may fall into a regulated AI category.

For scoped professional review, use capability `ai_governance.policy_review` or `ai_act.classification_review` through `https://api.spadeconsulting.no/api/agent/requests`. Never include secrets or sensitive data in public intake.
