AI governance: how a company keeps control of the AI it builds and uses
By the E-Solutions Web editorial team. Published , updated . How we write
The short answer
AI governance is the set of roles, rules and controls a company uses to decide which AI systems it runs and under which safeguards. It rests on an inventory of AI uses, an owner for each, a risk classification, controls before and after go-live, and trained staff. In the EU, the AI Act makes parts of it mandatory; ISO/IEC 42001 and the NIST AI RMF structure the rest.
This guide is not legal advice. It describes how a company can organize the governance of its AI systems, and cites the official texts as we read them on October 1, 2026. For the detail of the EU AI Act, its risk levels and its calendar, see our EU AI Act guide.

What AI governance covers
AI governance answers four questions for every AI system in the company: who decided to use it, what it is allowed to do, how you know it works, and who acts when it does not. It covers the tools bought off the shelf as well as the systems built in-house, and the AI features switched on inside software you already use.
It is often confused with compliance. Compliance is meeting the rules that apply to you, from the EU AI Act to the GDPR and your sector’s regulations. Governance is the organization that makes compliance routine, and that decides on everything the law leaves open: which chatbot staff may use with customer data, which model can read contracts, what quality level an agent must reach before it touches the ERP.
The usual starting point is uncomfortable. A company bans public AI tools, and people keep using them on their phones because nothing else is offered. Governance that only forbids pushes the use out of sight. Governance that works gives people an approved tool, a clear rule and a quick way to ask for a new use.
Why AI governance matters now
Since February 2, 2025, every company that uses AI in the EU has had at least one duty under the AI Act, and the list grows until 2028. According to the European Commission, the regulation entered into force on August 1, 2024. The bans on prohibited practices and the AI literacy duty applied from February 2, 2025; the rules on general-purpose AI models from August 2, 2025; general application from August 2, 2026. The rules for high-risk systems in the areas of Annex III, such as employment or credit, apply from December 2, 2027, and those for AI built into regulated products from August 2, 2028.
Those last two dates come from the digital omnibus on AI, Regulation (EU) 2026/1744, adopted on July 8, 2026 and in force since July 27, 2026, which moved them back. The Commission also notes that from August 2, 2026, the AI Office and the member states’ authorities are responsible for supervising and enforcing the regulation.
The omnibus rewrote Article 4 on AI literacy. Providers and deployers must now “take measures to support the development of AI literacy of their staff” and of the other people who operate AI systems on their behalf, taking their knowledge and the context of use into account. It is a duty of means: the text does not require a guaranteed level for each person. You still have to be able to show what you did, and keeping that record is a governance task.
The building blocks of an AI governance framework
A workable framework has eight blocks, and each can start small. The table gives the question each block answers and the lightest version that still holds up.
| Block | The question it answers | A minimum version that holds up |
|---|---|---|
| Owner and roles | Who decides, and who answers for each system? | A sponsor in senior management, and a named business owner per AI system |
| Use policy | What may staff do with AI tools today? | One page: approved tools, forbidden data, how to request a new use |
| Inventory | Which AI systems run in the company, and for what? | A register: system, supplier, purpose, data used, people affected, owner |
| Risk classification | How much control does each use need? | Each entry placed in an AI Act level, with a note on GDPR and sector rules |
| Controls before go-live | How do you know it works before relying on it? | Tests on your own cases, an acceptance threshold, a written approval |
| Controls in operation | How do you know it still works? | Logs, human review where it matters, a monthly look at errors |
| Incidents | What happens when it goes wrong? | A channel to report, a person who decides to suspend, a record of each case |
| Literacy and suppliers | Do people and contracts keep up? | Training tied to the tools in use, contract terms on data and on change |
The inventory is the block to start with, because every other one depends on it. It is also where surprises tend to appear: AI features switched on by a software update, a team that built its own automation, a supplier that added a model to a service nobody reviewed.
For systems that process personal data, the GDPR adds two checkpoints. Article 35 requires a data protection impact assessment “where a type of processing in particular using new technologies” is “likely to result in a high risk to the rights and freedoms of natural persons,” before the processing starts. Article 22 gives people the right “not to be subject to a decision based solely on automated processing” that produces legal or similarly significant effects, with limited exceptions. Both fit naturally into the risk classification block.
AI Act, ISO/IEC 42001, NIST AI RMF: which framework does what
The AI Act is law, ISO/IEC 42001 is a management system standard, and the NIST AI RMF is a voluntary method; a company in Europe can use the first as the floor and borrow structure from the other two. They do not compete. They answer different questions.
| Criterion | EU AI Act | ISO/IEC 42001:2023 | NIST AI RMF 1.0 |
|---|---|---|---|
| What it is | A regulation, Regulation (EU) 2024/1689 | An international standard for an AI management system | A voluntary risk management framework |
| Who publishes it | The European Union | ISO and IEC, committee JTC 1/SC 42 | The US National Institute of Standards and Technology |
| Binding | Yes, in the EU, with duties by role and risk level | No, adopted by choice | No, “intended for voluntary use” |
| Date | In force since August 1, 2024, applied in stages to 2028 | First edition, December 2023 | January 26, 2023; Generative AI Profile, July 26, 2024 |
| What it gives you | The obligations, and the list of prohibited and high-risk uses | Requirements to establish, run and continually improve AI governance | Four functions to organize the work: Govern, Map, Measure, Manage |
ISO describes ISO/IEC 42001 as a standard that “specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System” and addresses it to “organizations of any size involved in developing, providing, or using AI-based products or services.” It is the natural choice when your customers or your board want your AI governance to follow a recognized structure. ISO also sells it together with ISO/IEC 42005:2025, in a package it presents as covering responsible AI governance and impact.
The NIST framework is lighter to start with and useful as a checklist. NIST states on its page that the AI RMF 1.0 “is being revised as part of the White House AI Action Plan,” so check for a new version before building on its details.
Who owns AI governance in the company
Senior management owns the decisions, and each AI system has a business owner who answers for it; IT, security, the data protection officer and legal support them. Governance fails when it belongs to one department alone. Left to IT, it becomes a list of blocked websites. Left to legal, it becomes a policy nobody reads.
A structure that works in a mid-sized company:
- A sponsor in senior management, who sets what the company accepts and arbitrates.
- A business owner per system, usually the manager of the team that uses it, who answers for its purpose, its quality and its users.
- IT and security, who approve tools, access rights, hosting and logs.
- The data protection officer, who checks personal data, impact assessments and information to the people concerned.
- A short monthly review, where new requests, incidents and changes to the inventory are decided.
In a company of fifty people, these can be three people and one meeting a month. The AI Act adds one requirement to this list for high-risk uses: under Article 26, the people assigned to human oversight must have “the necessary competence, training and authority, as well as the necessary support.”
Getting started: a first version in four steps
A first version of AI governance fits in four things: an inventory, a one-page policy, an owner per system and a date to review them. The order below keeps each step useful on its own.
- List what runs today. Ask each team which AI tools and features they use, including free tools and features inside existing software. Record purpose, data and supplier.
- Write the one-page policy. Which tools are approved, which data must never go into them, and how to request something new. Give people an approved tool at the same time, or the policy will be ignored.
- Classify and assign. Place each system in an AI Act risk level, flag those that process personal data, and name a business owner for each.
- Set the controls and the review date. For each system above minimal risk, decide what is tested before use, what is logged and who reviews errors. Put the first review in the calendar.
Our free AI readiness check is a quick way to see where your company stands before step one. For a full inventory and classification, done with your teams, the AI readiness assessment produces the register and a ranked plan. Training tied to the tools your teams actually use, such as our AI training for teams, covers the literacy duty with something you can document.
Governance built into the AI systems themselves
The cheapest controls are the ones designed into the system from the start: access rights, logs, human approval and sourced answers. Adding them after go-live costs more and is rarely complete.
Every AI agent we build logs each action, runs with the least access it needs and waits for a person before anything sensitive. Assistants that answer from company documents show the passage each answer comes from, which makes errors visible to the user; our knowledge assistant demo shows it on a fictional company’s policies. When data must not leave your infrastructure, a private LLM hosted in Europe or on your servers settles the hosting question in the design itself.
If you are choosing a supplier to build AI systems for you, ask how each of these controls is delivered and documented. Our guide on how to choose an AI agency lists the questions to ask before you sign.
Your first governance register, started with us
A first register shows what AI is really in use in your company, and that is where control starts. In a free 30-minute assessment, we look at the AI your teams use today, the systems you plan, and the one or two controls to put in place first. If you want the full register, the AI readiness assessment builds it with your teams, usually in two to three weeks, with the scope and price fixed in writing before we start.
Book your free 30-minute assessment: describe where AI is used in your company today, and we reply within one business day.
Frequently asked questions
What is the difference between AI governance and AI compliance?
Compliance is meeting the rules that apply to you, such as the EU AI Act or the GDPR. Governance is the way the company organizes itself to meet them and to decide on everything the law does not cover: which tools are allowed, who approves a new use, how quality is checked. With governance in place, a compliance check becomes a review of documents that already exist.
Is ISO/IEC 42001 mandatory?
No. ISO/IEC 42001:2023 is a voluntary international standard that specifies requirements for an AI management system. The EU AI Act does not require it. Companies adopt it when they want a recognized structure for their AI governance, or when customers ask for evidence that their AI is managed.
Does the EU AI Act require an AI governance framework?
It does not use the term for every company, but several of its duties amount to one. All providers and deployers must take measures on AI literacy. Deployers of high-risk systems must assign human oversight to competent people, monitor the systems and keep their logs. Providers of high-risk systems need a risk management system and a quality management system.
Who is responsible for AI governance in a company?
Senior management owns it, because it sets what the company accepts. Day to day, each AI system needs a business owner who answers for its use, supported by IT and security, the data protection officer and legal. In a small company, one person can hold the coordination role, as long as it is written down.
What is the NIST AI Risk Management Framework?
It is a voluntary framework published by the US National Institute of Standards and Technology on January 26, 2023. It organizes AI risk management into four functions: Govern, Map, Measure and Manage. A Generative AI Profile followed on July 26, 2024, and NIST states that the framework is being revised.
Sources
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), EUR-Lex, Official Journal of the European Union, published 2024-07-12, accessed 2026-10-01.
- Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), EUR-Lex, Official Journal of the European Union, adopted 2026-07-08, accessed 2026-10-01.
- AI Act, European Commission, Shaping Europe’s digital future, updated 2026-08-03, accessed 2026-10-01.
- ISO/IEC 42001:2023 Information technology, Artificial intelligence, Management system, International Organization for Standardization (ISO), published 2023-12, accessed 2026-10-01.
- AI Risk Management Framework, National Institute of Standards and Technology (NIST), accessed 2026-10-01.
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 22 and 35, EUR-Lex, Official Journal of the European Union, published 2016-05-04, accessed 2026-10-01.