The short answer
Paloren compiles AI governance statistics and public frameworks from cited sources so teams can design controls rather than copy a policy nobody can follow.

AI governance evidence includes OECD.AI, which covers more than 80 jurisdictions and organisations, and NIST, which publishes the voluntary AI Risk Management Framework and playbook. Companies still need workflow-specific controls.
What this can change for your team
- Practical controls
- Named owners
- Review cycle
01 / 03AI governance statistics
How many jurisdictions track AI policy?
OECD.AI covers more than 80 jurisdictions and organisations.
How we make this work
OECD.AI describes its policy navigator as a living repository from more than 80 jurisdictions and organisations. It is updated by official contact points and OECD.AI experts. This is a useful source for understanding public policy coverage, but it does not tell a company what internal controls are sufficient for its workflow.
- More than 80 jurisdictions and organisations
- Living public repository
- Policy initiatives database
02 / 03AI governance statistics
What governance framework does NIST provide?
The AI Risk Management Framework and playbook.
How we make this work
NIST provides the AI Risk Management Framework, a voluntary framework to help organisations manage risks to individuals, organisations and society associated with AI. It includes a playbook and related resources. NIST has also released a generative AI profile. These resources support design decisions such as governance, measurement and risk handling.
- AI Risk Management Framework
- Public playbook
- Generative AI profile
AI governance evidence
Public frameworks support design; internal owners still matter.
| Source | What it provides | Link |
|---|---|---|
| OECD.AI Policy Navigator | Public AI policies and initiatives from more than 80 jurisdictions and organisations | https://oecd.ai/en/dashboards |
| NIST AI RMF | Voluntary risk-management framework, playbook and generative AI profile | https://www.nist.gov/itl/ai-risk-management-framework |
Source: OECD.AI and NIST public pages.
03 / 03AI governance statistics
How should a company use governance statistics?
To compare scope, not to replace controls.
How we make this work
Policy and framework statistics help teams understand external context. They do not replace workflow-specific governance. Paloren recommends mapping AI use cases, data access, approval routes, quality checks, audit evidence and named owners. This creates controls people can follow in the actual workflow.
- Use-case inventory
- Access and approvals
- Audit and owners
Make the next decision
What to do with this
Use-case inventory
Risk map
Control matrix
Approval routes
Audit plan
Owner register
- 01
Inventory AI use
List systems, data and decisions.
- 02
Assess risk
Identify access and failure points.
- 03
Design controls
Define approvals and evidence.
- 04
Assign owners
Name accountability and review.
| Stage | What it changes |
|---|---|
| Inventory AI use | List systems, data and decisions. |
| Assess risk | Identify access and failure points. |
| Design controls | Define approvals and evidence. |
| Assign owners | Name accountability and review. |
Which AI use cases need controls?
Tell Paloren the systems, data and approval owners.
Reply from the team within one business day. No deck, no technical brief needed.
Before we begin
Questions we get asked, answered with numbers
How many jurisdictions does OECD.AI cover?
OECD.AI describes its policy navigator as covering more than 80 jurisdictions and organisations.
What is the NIST AI Risk Management Framework?
A voluntary framework to help organisations manage AI-related risks, with a public playbook.
Does a public framework make a company compliant?
No. It supports design. Legal and regulatory interpretation remains with qualified advisers.
What should internal governance include?
Use-case inventory, access rules, approval routes, quality checks, audit evidence and owners.
Which AI use cases need controls?
