Clef · Try the live demo →
Glossary

AI governance

AI governance is the standing arrangement around AI use: who is accountable, how use cases are classified, how evidence is produced, and how a new tool gets approved. The word suggests a programme; in a mid-sized organisation it is four artefacts that fit on a few pages. What makes it work is not their completeness but whether the approval path is fast enough to be used instead of bypassed.

What the smallest workable version contains

Four things. A register of the systems actually in use, each with an owner and a purpose. A classification per use case with a short written reason. A place where evidence accumulates — briefings, sign-offs, review notes. And a described route by which a new tool gets approved.

That is enough to start and, for most organisations, enough permanently. What is missing shows up at the first audit; what is excessive does not get maintained and is stale within a year, which is worse than absent because it implies a rigour that is not there.

Why the approval route is the load-bearing piece

Because it determines whether the other three stay true. Without a described route, departments procure on their own — not out of defiance, but because they have work to do and nobody told them how to ask.

An approval that takes a week gets used. One that takes three months gets routed around, and at that point the system register is fiction. The speed of approval is therefore not an administrative detail but the precondition for every other record being accurate.

What regulation actually requires

Not governance as such. The EU AI Act requires outcomes: a defensible classification, human oversight where decisions affect people, transparency under Article 50, and measures supporting AI literacy under Article 4. No particular organisational form is prescribed, and no officer has to be appointed — unlike the data protection officer under the GDPR.

The value of a lean arrangement is that those outcomes are produced as a by-product and can be found again. Article 99 obliges authorities to weigh the measures taken when setting a penalty, and the gap between "assessed and documented" and "never considered" is wider in effect than the gap between two categories of infringement.

What it is not to be confused with

ISO/IEC 42001

A voluntary management-system standard. It is not a conformity route under the EU AI Act and is not required by it. For organisations already working to ISO standards it structures the work sensibly; for everyone else it is substantial effort without direct legal effect.

A data protection management system

The inventory step overlaps almost entirely. Running the two separately means maintaining two lists that diverge within months. One survey, two evaluations is the right split.

Frequently asked

At what size does an organisation need AI governance?+

As soon as more than one tool is in use and more than one department uses them. It is not a headcount question: a twelve-person law firm running three tools has the need; a two-hundred-person company with one approved system largely does not.

Do we need to appoint an AI officer?+

No such role is required by law — the AI Act contains nothing equivalent to Article 37 GDPR. Naming someone is still sensible, because the obligations attach to an ongoing state rather than a one-off project, and without an owner the classification is out of date within a year. It is usually part of an existing job rather than a new one.

How long does it take to set up?+

Two to three weeks for an organisation with standard tools, and the expensive part is not the documentation but the honest inventory. It routinely surfaces tools IT has never heard of — which is uncomfortable and precisely why it is necessary.

Do we need software for this?+

Not at the start. Four artefacts fit in a spreadsheet and a folder, and that version gets maintained. Tooling earns its place once several people update concurrently; before that it adds an implementation project to a problem that does not yet exist.

Related terms

What should exist at the end of week one

A list of the tools actually in use — not the ones approved. The difference between those two lists is the real task, and it cannot be delegated.

Request a test