You were handed the hardest assignment in the building.
Adopt AI fast, leadership says. Stay defensible, oversight demands. Between those two pressures stands you - with no proven playbook, a shifting regulatory landscape, and auditors who will arrive before you feel ready.
The Defensible AI Program is the operational field manual for that job. Written for Chief AI Officers, CISOs, compliance leaders, and AI program directors in federal agencies and regulated enterprises, it walks you through a four-phase governance lifecycle - Stand Up, Operate, Mature, Defend - telling you exactly what to implement, in what order, and how to defend it when oversight arrives.
Inside you'll find:
- One unified control set - NIST AI RMF, ISO/IEC 42001, the EU AI Act, and OMB M-25-21 reconciled into 28 controls you can actually run, with a crosswalk that answers any framework-specific question in minutes
- A 90-day stand-up sequence that survives first contact with oversight - honest about what is and isn't done at day 90
- The AI agent and non-human identity gap your IAM program never planned for
- AI-specific incident response for the failures traditional playbooks miss: model drift, adversarial inputs, hallucination harm, training data exposure, and agents acting outside their scope
- A five-stage maturity model that diagnoses why programs plateau at "compliant on paper" - and the advancement criteria that break through
- The evidence discipline that separates programs that survive scrutiny from programs that only photograph well
Plus the companion toolkit: working templates - governance charter, risk-tiering worksheet, the framework crosswalk matrix, incident response playbook, and board-ready reporting - free and maintained as the frameworks change, at dasadvisorygroup.com/toolkit.
Dr. Derek A. Smith has lived the oversight this book prepares you for. As technical program manager and deputy director on DHS's HART biometric identity program, his program's status went to Congress every month. Thirty years across federal law enforcement, the IRS, Booz Allen Hamilton, and DHS taught him the lesson this book delivers: a defensible AI program is not a perfect program. It is a documented, reasoned, evidence-based one - built before you need it.
The clock is already running. This is your playbook.