As AI spreads from a few pilots to dozens of teams, organisations need a way to say yes to valuable uses while managing legal, security and reputational risk. Good AI governance is not a brake — it is what lets you scale with confidence.
Why AI governance matters now
Three forces have made governance urgent. Employees are already using generative AI tools, sanctioned or not. Agentic systems can now take actions, not just make suggestions. And regulation is arriving: the EU AI Act entered into force in August 2024 and applies in stages, with prohibitions on certain practices applying from February 2025, obligations for general-purpose AI models from August 2025, and most remaining obligations phased in from 2026 onward. Timelines for some provisions have been subject to proposed adjustments, so check the current position for your use cases.
Useful reference frameworks
- EU AI Act — a risk-based regulation that classifies AI systems (prohibited, high-risk, limited-risk, minimal-risk) and sets obligations accordingly. Relevant to any organisation placing AI systems on the EU market or using them in the EU.
- ISO/IEC 42001 — an international standard for an AI management system, similar in spirit to ISO 27001 for information security. Certifiable.
- NIST AI Risk Management Framework — voluntary US guidance organised around four functions: Govern, Map, Measure and Manage, with a companion profile for generative AI.
You don’t need to implement all three separately. A single internal framework mapped to the ones that apply to you is easier to run.
A practical framework in six parts
- Policy and principles. An acceptable-use policy for staff, plus principles for building AI: transparency, human oversight, privacy, security, fairness and accountability.
- Inventory. A register of every AI system and model in use — internal builds, vendor features and SaaS tools — with an owner for each.
- Risk classification. A simple tiering (for example low, medium, high) based on impact on people, decisions automated, data sensitivity and regulatory exposure.
- Controls by tier. Proportionate requirements: low-risk tools get lightweight approval; high-risk systems need impact assessments, testing for bias and robustness, human oversight and documentation.
- Technical guardrails. A shared AI platform that enforces data protection, logging, content filtering, evaluation and cost controls by default — so teams get compliance “for free”.
- Monitoring and review. Ongoing measurement of quality, drift and incidents, with periodic reviews and a clear process for retiring systems.
Who owns AI governance?
Effective programmes are cross-functional: a small steering group with technology, security, legal/compliance, data protection and business leadership, supported by an AI Center of Excellence that provides templates, tooling and advice. The goal is to make the safe path the easy path.
Getting started in 90 days
- Days 1–30: publish an interim acceptable-use policy, start the AI inventory and name owners.
- Days 31–60: agree risk tiers and controls; assess your highest-risk use cases.
- Days 61–90: stand up shared guardrails on your AI platform, train staff and set up regular reporting.
Our Enterprise AI practice helps organisations design governance that fits their size and risk profile — and builds the platform controls that make it practical.
This article is general information, not legal advice. Consult qualified counsel for your specific obligations.
Frequently asked questions
What is ISO/IEC 42001?
ISO/IEC 42001 is an international standard specifying requirements for an AI management system — the policies, processes and controls an organisation uses to develop or use AI responsibly. Organisations can be certified against it.
Does the EU AI Act apply to companies outside the EU?
It can. The Act applies to providers placing AI systems on the EU market and to deployers using AI systems in the EU, regardless of where the company is based. Seek legal advice for your situation.
Where should an AI governance programme start?
Most organisations start with an acceptable-use policy, an inventory of AI systems with named owners, and a simple risk-tiering approach, then add proportionate controls.