What is AI Governance?
Learn what AI governance covers and who does the work. This guide is for enterprise compliance, legal, and risk teams.
By Cody Maxwell · AI Governance Institute · Published May 2026 · Reviewed monthly
The short definition
AI governance sets policies, processes, and controls for how an organization uses AI. It defines expected behavior, legal duties, and accountability to affected people. The work covers design and training through deployment, monitoring, and retirement. Technical controls include model documentation, bias tests, and audit logs. Organizational controls assign risk tiers, human review, and incident response. Legal work maps binding duties and voluntary standards to the systems in use. Examples include the EU AI Act, ISO 42001, and the NIST AI Risk Management Framework. Binding AI requirements now exist in the EU, China, and several US states.
What it covers
Technical controls help teams observe and correct AI behavior. They include model documentation, bias testing, explainability requirements, and audit logs. Organizational controls assign responsibility through risk classification, human oversight, and incident response. Legal and regulatory work covers binding laws, voluntary standards, and customer or partner contracts. The EU AI Act creates legal duties; ISO 42001 and NIST AI RMF provide voluntary approaches. Teams need to maintain these areas together. Technical safeguards need accountable owners, and compliance commitments need controls that work when a system behaves unexpectedly.
How it differs from general IT governance
IT governance covers data security, system availability, and change management. AI adds risks from consequential decisions, difficult-to-explain outputs, and performance differences between populations. A working hiring algorithm can still disadvantage protected groups because of patterns in its historical training data. A credit-scoring model can perform well on average while producing discriminatory outcomes for particular groups. Bias testing, model documentation, and human oversight help teams examine those problems. Existing IT controls may need additional documentation and oversight procedures. Check requirements under applicable laws, including the EU AI Act.
Who is responsible
Several functions share AI governance work. Legal and compliance teams map regulations, set policy, and identify required documentation. Engineering and data science teams maintain technical controls, model cards, bias reports, and audit logs. Risk and audit teams test whether systems continue behaving as expected after deployment. Business owners remain accountable for decisions made through their AI systems. Executives need to sponsor the program and provide resources for ongoing work. Assigning a lead function still requires cooperation across these teams.
The global regulatory context
AI requirements differ by jurisdiction, sector, and use case. The EU AI Act entered into force in 2024 and phases in obligations over time. It regulates high-risk systems sold or used in the EU. Certain violations can attract fines reaching €35 million or 7% of worldwide annual turnover. China regulates algorithmic recommendations, deepfakes, and generative AI, including services reaching Chinese users. US requirements include sector rules and state legislation. Federal agencies involved include the FTC, CFPB, EEOC, and financial regulators. Cross-border programs must track differing classifications, documentation requirements, and enforcement timelines.
Where to start
Start by listing your AI systems, including tools adopted without approval. Classify their risks and map applicable regulations and standards. NIST AI RMF organizes work through Govern, Map, Measure, and Manage. ISO 42001 provides an AI management system standard with certification options. Teams can use these frameworks to organize governance work and demonstrate their processes to auditors or customers. Add model cards for material systems and impact assessments for high-risk applications. Review third-party vendors and monitor deployed systems for drift or behavioral changes. Regulated organizations should identify sector obligations early because these define minimum program requirements.
Related guides
Follow AI regulation across jurisdictions
We track AI regulations, frameworks, guidelines, and enforcement actions daily across the EU, US, UK, and Asia-Pacific.
Browse the directory