What Is AI Governance?
Many organizations adopted AI before they decided who decides about it. AI governance is the system of decision rights, accountability, policies, controls and oversight that closes that gap. Designed in proportion to impact, it makes adoption faster and safer, not slower.
After this chapter you can
- Define AI governance as a system of decision rights, accountability, policies, controls and oversight.
- Distinguish governance from policy, compliance, risk management and strategy.
- Explain why informal AI decisions stop working as adoption scales.
- Recognize that governance and legal duties cover bought and built AI across the whole lifecycle.
- Argue that proportionate governance enables adoption, and that a ban is not governance.
Every year IBM and the Ponemon Institute study several hundred organizations that have suffered a data breach. Their 2026 report, covering 602 breaches between March 2025 and February 2026, found that AI use had grown again. Oversight had not. Only 32 percent of the breached organizations had policies in place to manage AI and prevent shadow AI, down from 37 percent a year earlier; the other 68 percent had none or were still writing them. Fewer required strict approval before an AI system was deployed, 38 percent against 45 percent, and only 19 percent of organizations said their AI governance and security teams coordinated their work at all1.
That is the contradiction at the center of this chapter. Organizations are using more AI every year and deciding less about it. And the figures make a second, subtler point. Many organizations, with or without a policy, had no approval step and no link between the people who write the rules and the people who defend the systems. A policy says what should happen. It does not say who decides, who checks, or who can stop something when it goes wrong. That missing part is governance.
The core idea
AI governance is the system of decision rights, accountability, policies, controls and oversight that makes sure AI is developed and used responsibly and in line with the organization’s objectives. Put more simply, it answers four questions for every AI use that matters: who may decide, under what rules, who answers for the outcome, and how we will know whether it is working.
The position matters. Governance is not a review bolted on after a system is built, and it is not a separate track run by the legal department. It is the layer that connects what the organization wants AI to do with what its teams actually do. Strategy chooses where AI should create value. Management gets the work done. Governance decides who decides, which rules apply and how oversight works.
The leading frameworks put it in the same place. The NIST AI Risk Management Framework has four functions, Govern, Map, Measure and Manage, and describes Govern as a cross-cutting function that is infused throughout the other three. Its accountability category expects executive leadership to take responsibility for decisions about AI risk2. Governance, in other words, is not a specialist activity at the edge of AI work. It is the frame around all of it.
A system, not a document
In any organization, governance is how decisions get made, authority is assigned, expectations are set, risk is managed, performance is monitored and people are held to account. AI governance applies that discipline to AI systems and the activities around them. Like any system, it has parts.
The parts depend on each other. A policy without a process is a wish. A process without a control is a habit, and a control without monitoring is a guess. This is why ISO/IEC 42001, the first international standard for an AI management system, published in December 2023, is written as a management system standard. It sets requirements for establishing, implementing, maintaining and continually improving an AI management system, in the same family as the quality and information-security standards many organizations already hold3. The emphasis on continual improvement is deliberate. AI systems change after launch, and so do the people and data around them, so governance cannot be a one-off approval.
None of this means governance is one committee, one tool or one checklist. The committee, the office and the operating model each have their own chapters later in this module. Here the point is narrower and more important: if any of the six parts is missing, an organization can believe it is governed and not be.
Why informal decisions stop working
Every organization already makes AI decisions. The question is whether it makes them on purpose. When one employee uses AI to summarize internal notes, an informal decision is good enough. When the same organization uses AI to screen customers, generate production code, process contracts and run agents that take actions, informal decisions stop scaling. Each use touches different data, different people and different obligations.
And the use is already wide. In Microsoft and LinkedIn’s 2024 survey of 31,000 people in 31 countries, 75 percent of knowledge workers said they used generative AI at work, and 78 percent of those users brought their own tools rather than waiting for their employer’s4. As AI Is Already Inside Your Organization showed, much of this use is invisible to the people who would be accountable for it.
Without a common way to decide, the pattern is predictable. One team adopts one tool, another team a different one, a third uses a free public service and a fourth builds its own. The result is duplication, inconsistent standards and data going where nobody approved. The risks themselves were the subject of Module 06: confidential data in prompts is covered in Privacy and Confidential Data, vendor exposure in Model and Third-Party Risk, and systems that act on their own in Agentic AI and Autonomous Actions. Governance is how an organization decides, consistently, what to do about all of them.
Decision rights come first
If governance is a system, its first part is decision rights. For every important AI system, someone must be able to answer seven questions.
Who can propose it? Who can build or buy it? Who can approve it, deploy it and change it? Who can stop it? And who is accountable for what it does? Where these answers are unclear, governance is ambiguous, and ambiguity is where incidents grow. A model starts giving poor answers or a tool starts moving data it should not, and nobody is sure who has the authority to switch it off. The right to stop is the easiest one to leave blank, because nobody thinks about it until the moment it is needed.
Executives already know how to do this, because they do it with money. Almost every organization has a delegation of authority: a schedule that says who may sign a contract, approve a purchase or commit spending of a given size. A team lead approves small amounts, a function head larger ones, and only the board approves the largest. Nobody calls that bureaucracy. It is what lets thousands of spending decisions happen every day without each one reaching the chief financial officer.
AI governance applies the same habit to a new kind of decision. The analogy has a limit: a purchase is approved once, while an AI system keeps changing after it is approved, which is why the rights to change and to stop belong on the list. Assigning these rights to named roles is the work of AI Roles, Ownership and Accountability. Here it is enough to know that the rights must exist and be written down before they are needed.
The board’s place in this picture is familiar too. The Institute of Internal Auditors’ Three Lines Model separates the governing body’s oversight, management’s ownership of risk, and internal audit’s independent assurance5. AI does not need a different model. It needs to be inside the one the organization already runs.
Broader than policy, compliance, risk or strategy
Executives often use neighboring words as if they meant governance. Each one names a part, not the whole.
A policy states what is required and what is prohibited; governance adds who enforces it, who approves exceptions and who escalates. Compliance asks whether the organization meets its obligations; governance asks who answers for that, and how decisions are made where the law says nothing yet, which for AI is often. Risk management asks what can go wrong, how likely it is and how bad it would be; governance decides who owns each risk and who has the authority to accept it. Strategy might say “use AI to improve customer onboarding”; governance decides which onboarding uses are permitted, who approves them, what controls they need and how their performance is watched.
Responsible AI principles relate to governance in the same way. The OECD AI Principles, adopted by dozens of governments and updated in 2024, say that organizations developing, deploying or operating AI should be held accountable for its proper functioning6. A principle like that is necessary and not sufficient. Governance is what turns it into decisions, owners, controls and evidence. The principles themselves are the subject of AI Governance Principles, and the chain from principle to evidence is drawn in AI Policy vs AI Governance.
Bought or built, from idea to retirement
Governance does not begin at deployment. It covers the whole life of an AI system: the idea, design, the decision to build or buy, testing and approval, deployment and operation, monitoring and change, and finally retirement.
It also applies when the organization did not build the model. A software service with AI inside, a coding assistant or a document platform is still a decision the organization makes about its own process. Buying AI moves the engineering to a vendor. It does not move the accountability.
The law draws the same line. The EU AI Act distinguishes the provider, who develops a system and places it on the market, from the deployer, an organization that uses an AI system under its own authority, and gives deployers duties of their own7. Existing law applies too. The GDPR already governs many AI uses that involve personal data, including decisions made solely by automated means and the impact assessments required for high-risk processing8.
How governance works at each stage of that cycle is the subject of AI Lifecycle Governance. The point for now is scope: governance covers every AI system the organization relies on, from first idea to last day, whoever built it.
Proportion is what makes governance an enabler
A common belief is that governance means a central team approves everything. That does not scale, and it is not the goal. Both extremes slow an organization down.
At one end, too much governance: every experiment waits for a committee, people stop asking, and AI use moves out of sight. At the other end, too little: no visibility, then an incident, then a loss of trust, and then a sudden clampdown on the whole program. The clampdown is common: Samsung banned generative AI tools in one of its largest divisions in May 2023, after staff uploaded sensitive source code to a public chatbot9. A ban like that is a reasonable emergency measure. It is not governance. It buys time, but it does not say who may approve which use, and as Privacy and Confidential Data showed, bans tend to push use out of sight rather than end it.
The stance that works sits between the extremes. Low-impact uses get light, local decisions. High-impact uses get more review and stronger monitoring. A sandbox with approved tools, non-sensitive data and a small group of users can move quickly; governance tightens as a use moves toward production, customers and consequential decisions. How to sort uses into tiers is the work of AI Inventory and Risk Classification. The principle belongs here: good governance should raise people’s confidence to use AI, not lower it.
Story: the audit question nobody could answer
The case below is an illustrative composite, not a real company, built from a pattern common among suppliers that hold their customers’ confidential data. Read the situation and decide what you would do before reading on.
You lead a tire maker with plants and test tracks in many countries, developing tires for car makers who guard their vehicle designs closely. AI has arrived as it does everywhere. A sales team drafts quotes with a general-purpose AI assistant. Development engineers paste a car maker’s load and handling specifications into a free public tool to check their calculations. One regional plant has built its own agent to search old test reports. There is an AI policy, written last year. There is no list of what is in use and no common approval process.
Then a major car maker sends an audit question. Its supply contract forbids sharing its design data with third parties without consent. Which AI tools have touched our data? Nobody can answer.
You have three options. You could ban every AI tool until a full policy is written. You could set up a governance committee, write a thorough policy and answer the customer when that is done. Or you could, within two weeks, find out what is in use, name an owner for each use, and pause only the uses that put customer data into unapproved tools.
The third option is the governance answer. A ban would push use out of sight, exactly when the company needs to see it, and would not answer the customer’s question about the past. A committee would be useful later, but it would keep the customer waiting for a structure when what it asked for was a fact. In the third option, every site declares its AI use, with no penalty for honesty. Each use gets a named owner. The uses that put customer data into public tools are paused, and the engineers move to an approved assistant with clear data rules. The company can then answer the car maker with evidence, and its teams keep using AI.
Notice what the company did not need. It did not need a thicker policy; it already had one. It needed visibility, owners and the authority to pause, which are three of the seven decision rights.
What this means for leaders
The first lesson is that a policy is not proof of governance. When a board asks whether AI is governed, the answer is not a document but a demonstration: for the AI uses that matter, the organization can pass the hundred-uses test below. The second is that governance should be built into structures the organization already trusts, its delegation of authority, its risk ownership and its lines of assurance, rather than invented beside them. The third is that proportion is not a concession; it is what makes governance work at all.
Check yourself
- AI governance is really just compliance with AI law.
- An organization can have an AI policy and still have no AI governance.
- Good governance means a central committee approves every AI use.
- Buying AI from a vendor moves the accountability to the vendor.
- In the NIST AI Risk Management Framework, Govern is a cross-cutting function.
- Banning AI tools is a form of AI governance.
What comes next
Governance is the system for making AI decisions responsibly at scale. That raises a prior question: why should an organization care about responsible AI beyond meeting the rules? The next chapter, Why Responsible AI Matters, connects it to trust, business outcomes, stakeholder expectations and long-term value.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
General Data Protection Regulation · EU
Regulation (EU) 2016/679
Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.
- 2018-05-25 — Applies
Last verified 2026-10-08 · official text
NYC Local Law 144 (automated employment decision tools) · US - New York City
NYC Local Law 144 of 2021; DCWP rules
An automated tool that substantially assists hiring or promotion decisions needs an independent bias audit within the past year, a published summary of results, and notice to candidates at least ten business days before use. Penalties USD 500 to 1,500 per violation.
- 2023-07-05 — Enforcement began
Last verified 2026-10-06 · official text
US federal AI policy and state-law preemption push · US - federal
Executive Order 14365 (11 Dec 2025); White House National Policy Framework for AI (20 Mar 2026)
The federal government is seeking to override "burdensome" state AI laws and has asked Congress for a national framework. These are executive actions and recommendations, not a federal AI statute. State laws such as NYC LL144 still apply until changed by law or the courts.
Last verified 2026-10-06
References
- IBM and Ponemon Institute. Cost of a Data Breach Report 2026: The AI tipping point. IBM. 2026.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
- ISO/IEC. ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system. International Organization for Standardization. 2023.
- Microsoft and LinkedIn. 2024 Work Trend Index Annual Report: AI at Work Is Here. Now Comes the Hard Part. Microsoft. 2024.
- The Institute of Internal Auditors. The IIA's Three Lines Model: An update of the Three Lines of Defense. The IIA. 2020.
- OECD. Recommendation of the Council on Artificial Intelligence (OECD AI Principles), updated 2024. OECD. 2024.
- European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024.
- European Parliament and Council of the European Union. Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union. 2016.
- Mark Gurman. Samsung Bans ChatGPT, Google Bard, Other Generative AI Use by Staff After Leak. Bloomberg. 2023.
Further reading
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
- ISO/IEC. ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system. International Organization for Standardization. 2023.
- The Institute of Internal Auditors. The IIA's Three Lines Model: An update of the Three Lines of Defense. The IIA. 2020.
Sources last verified 2026-10-10.