Show HN: AI Council Toolkit – open-source playbook for AI governance The AI Council Toolkit, an open-source playbook for AI governance, has been released, providing practical templates, governance patterns, and operating models for building and running an internal AI Council. The toolkit offers a continuous governance loop with six stages, including foundation packs, intake and triage, review and assurance, and operations, designed for CIOs and executive sponsors. It includes real-world patterns from organizations like Microsoft, IBM, and Yale, and aligns with standards such as the NIST AI RMF and EU AI Act. AI Council Toolkit An open, implementation-grade playbook for building, running, and sustaining an internal AI Council. Practical templates, governance patterns, and operating models you can use today. How It All Fits Together Governance is a continuous loop. Every use case moves through the same six stages — and the cycle repeats as systems change. Select any stage to jump in. Who Is This For? | Your Role | Start Here | |---|---| | CIO / Executive sponsor starting from zero | | Foundation Pack /docs/foundation then Standards & Regulations /docs/standards-and-regulations Intake & Triage /docs/intake-and-triage Review & Assurance /docs/review-and-assurance Meetings & Decisions /docs/foundation/meetings-and-decisions then Templates /docs/templates Operations /docs/operations Design Principles Council-first The human governance layer is the primary unit of design, not a byproduct of tooling. Practical over theoretical Every section ships artifacts you can use, not just principles to aspire to. Tiered and federated Low-risk cases move fast. Only hard cases reach the council. Specialists stay authoritative in their domains. Living governance Councils that only do approvals die. Councils that maintain learning loops stay valuable. What's Inside Getting Started What an AI Council is, whether you need one, and your first 30 days Operating Models Centralized, federated, and hybrid governance structures Foundation Pack Charter, principles, roles, meetings, and decision rights Intake & Triage Registration, risk tiering, routing, and AI inventory Review & Assurance Impact assessments, model cards, security review, and red-teaming Operations Monitoring, incidents, policy refresh, training, and reporting Templates All governance artifacts in one place Standards & Regulations NIST AI RMF, ISO 42001, EU AI Act, and crosswalks Real-World Patterns How Microsoft, IBM, NSW, Yale, and others do it