"AI governance" is used to mean a policy document, a committee, a software platform and a job title, often in the same conversation. That vagueness is expensive, because it lets an organisation buy a thing and believe it has governance.

A more useful definition: AI governance is the structure that decides who may deploy what, on what evidence, and who answers for it when it goes wrong.

The test is simple. When something does go wrong — a wrong determination, a leaked document, a discriminatory outcome — can you say who was accountable, and what they were supposed to have checked? If the answer is a shrug or a committee name, you have documentation rather than governance.

Three terms that are not synonyms

TermAnswersLooks like
AI ethics What ought we do? Principles, debate, values. Necessary and insufficient.
AI governance Who decides, and who answers? Decision rights, escalation paths, named owners, records.
Responsible AI How is the risk actually managed? Testing, monitoring, documentation, review after deployment.

They stack. Ethics without governance produces a values statement nobody can act on. Governance without ethics produces a process that efficiently approves things it should have questioned. Both without responsible AI practice produce paperwork describing systems nobody has tested. Our guide to what responsible AI means covers the third in depth.

The five components that carry the weight

1. An inventory of what you actually have

Everything else depends on this, and almost nobody has it. The obstacle is that most AI does not arrive through procurement — it appears when a staff member opens a browser tool, or when a vendor adds a feature to software you already bought.

So the inventory cannot be built from your contract list. It is built by asking people, and you get honest answers only if asking is not an accusation. Amnesty first, inventory second. Our guide to building an AI system inventory covers how to ask, what to record, and how to stop the list decaying into fiction.

2. A classification of what matters

Not every system needs the same scrutiny, and pretending otherwise guarantees that either everything is over-governed or nothing is.

Classify by decision, not by technology. The question is not "does this use machine learning?" but "does this system take part in a decision that materially affects someone?" — benefits, hiring, credit, housing, enforcement, pricing, access to services. A simple scoring rule can be in scope; a sophisticated model summarising meeting notes may not be.

This framing also survives contact with regulation better, because that is increasingly how statutes are drafted. Colorado's replacement act regulates automated decision-making technology in consequential decisions rather than "AI systems", and federal guidance tiers obligations around high-impact AI.

3. A named owner for each system that matters

A person, not a committee. Committees deliberate; they do not answer for outcomes. If a system is significant enough to classify, someone should be identifiable as accountable for its behaviour, and should know that they are. On which person, see who should own AI risk in your organisation — the answer separates three responsibilities that usually get conflated.

4. Proportionate review before deployment

What "review" means should scale with classification. For a low-stakes use, a one-page record of what it does and who owns it. For a consequential one: what it was tested against, what its known failure modes are, what the human review actually consists of, and what happens when it is wrong.

The failure mode here is review that exists nominally. A reviewer with a recommendation, a confidence score and two hundred cases in a queue is approving, not reviewing. See human oversight that is more than a rubber stamp for the four conditions that make review real.

5. A route for problems to surface

Governance that only runs before deployment learns nothing. You need a way for a caseworker, a customer or an engineer to say "this is producing bad output" and have that reach someone with authority to stop it.

A useful diagnostic: if nothing has ever been refused, and no output has ever been overridden, the programme is not governing anything. A governance function that has approved everything it has seen is measuring its own throughput.

Where frameworks fit — and where they do not

Frameworks give you vocabulary and a defensible structure. They do not make decisions for you, and adopting one is not the same as governing.

  • NIST AI RMF — free, voluntary, organised around govern, map, measure and manage. No certification exists. Good for building internal process quickly at no cost.
  • ISO/IEC 42001 — a management-system standard that a third party can certify. Costs the standard plus audit fees and staff time. Good for proving to outsiders that the discipline exists.

They answer different questions, and for most organisations the decision is sequencing rather than exclusivity. Our comparison of NIST AI RMF and ISO/IEC 42001 works through which to start with and why.

One thing worth knowing: voluntary does not mean inconsequential. Texas frames an affirmative defence around an internal review process that substantially complies with NIST's Generative AI Profile — so a free framework can carry legal weight through a statute that points at it.

Where to go next

Depending on what you are trying to do:

What good looks like at small scale

If you have no compliance function and no budget, a credible programme is smaller than most guidance implies:

  1. A spreadsheet listing every AI system in use, its owner, and whether it touches a consequential decision.
  2. A named person accountable for the ones that do.
  3. A one-page record per consequential system: what it does, what it was checked against, what human review consists of.
  4. A stated route for reporting bad output, and evidence that route has been used.
  5. A review date, so the list does not quietly become fiction.

That is not a mature programme. It is a real one, and it is dramatically better than a comprehensive policy nobody has read. Maturity is what you build once the basics are producing information — including the uncomfortable information that something should not have been approved.

Nothing here is legal advice. Whether a specific statute reaches your organisation is a question for counsel qualified in the relevant jurisdiction.