What is AI governance?

Deciding what your AI may do, who answers for it, and being able to show how you decided. The law that binds you, any standard you follow and your own rules all meet here.

The short answer

AI governance is how an organisation decides what its AI may be used for and who answers for each use, and keeps a record of those decisions that it can show to someone else.

It is not a product, and it does not need a dedicated team. For most UK organisations with ten or more staff it comes down to five things, kept current:

  • A list of the AI tools and systems in use, including the AI that arrived inside software you already license and the tools staff adopted on their own, which the shadow AI guide covers.
  • A named owner for each one, and a person who can approve or refuse a new one.
  • A written AI policy that tells staff what is allowed. The AI policy template gives you a starting point.
  • A short assessment before a new tool or use is approved. The AI risk assessment template takes one tool or use at a time.
  • A record of what was decided, by whom and when, so the answers hold up when a client questionnaire or an auditor asks for them.

Everything else, from frameworks to certification, is a more formal way of doing those five things. The AI governance framework guide sets out how they fit together once there is more to manage.

Where this usually starts

Almost nobody sets out to do AI governance. People arrive at it through a narrower question: whether a law reaches them, whether a standard is worth certifying to, or whether the policy someone wrote last year still describes what staff are actually doing.

Those turn out to be the same question asked from different ends, and the answers have to agree with each other. A policy that contradicts a duty you are under is worse than no policy, because it tells people the wrong thing with authority. Keeping the separate answers consistent is the whole job, and it is done with decisions and records you already own.

Who does it in a UK organisation

Accountability sits with leadership. The board or the senior team agrees the policy and how much risk the organisation will accept from AI, even where the day-to-day work is handed to someone else.

The day-to-day work usually lands with whoever already owns risk, information security, data protection or operations. You do not need a new hire to start. Add AI to the remit of an existing owner, give them the authority to refuse a tool, and make sure staff know they are the person to ask. Who is responsible for AI governance covers the other roles, what the owner keeps and when a committee is worth having.

Four things get called AI governance, and they are not interchangeable

The EU AI Act is law. Where it reaches you it binds you, and whether it reaches you at all is settled by Article 2 rather than by where you are registered.

ISO/IEC 42001 is a voluntary management system standard, and the one instrument here an accredited body can certify you against (ISO/IEC 42001:2023). Choosing it is a decision about how you want to run and evidence your AI governance, not a way of discharging a legal duty.

EN 18286 is the European standard written around the quality management system the Act requires. CEN-CENELEC ratified it on 12 July 2026 and BSI has issued it in the UK as BS EN 18286:2026 (CEN-CENELEC on the publication of EN 18286). It has not been cited in the Official Journal yet, so nobody can claim a presumption of conformity from it so far.

The NIST AI Risk Management Framework is voluntary too, and has no certification machinery behind it at all (the NIST AI Risk Management Framework (NIST AI 100-1)). It is a way of thinking about AI risk that many organisations run inside a management system built to the standard.

The distinction that matters most across all four: conformity with a standard is not compliance with a law. The standard-versus-Act guide works through where the two meet and where they do not.

If you are in the UK

There is no UK equivalent of the EU AI Act, and no UK law that requires AI governance as such. Existing law still applies to the way you use AI, and for most organisations the live one is data protection: the ICO's guidance on AI and data protection sets out how UK GDPR applies when AI systems process personal data, including when a data protection impact assessment is needed. The DPIA screening test for AI tools applies it to five common uses.

The EU AI Act can still reach a UK organisation. It works on what your AI touches and where its output is used, which is why the scope test in Article 2 is the first thing worth settling. Plenty of UK organisations are caught through outputs used in the EU without having any EU presence at all, and whether the EU AI Act applies to the UK works through that test properly.

Governance is how you show you have met whichever of these applies. A client questionnaire, a tender or an insurance renewal asking about your AI is usually the first time anyone asks to see it.

Where to start

Start with the list of AI in use, because every other decision depends on it. Then settle whether the EU AI Act reaches any of it, which the EU AI Act check works out one system at a time.

Write the policy next, from the template or from a draft the policy generator builds round six answers. From then on, assess each new tool before it is approved and keep the assessment with the approval. If you want the first few moves without the detail, where to start with AI governance sets them out, and do we actually need an AI policy? answers the question most people ask first.

Primary sources

Start with what binds you

The EU AI Act check works through the scope rules and tells you which duties reach the systems you named, and when each one applies.

Run the check

Common questions

What is AI governance in simple terms?
Deciding what your organisation’s AI may be used for and who answers for each use, and keeping a record of those decisions that you can show to someone else.
Is AI governance a legal requirement in the UK?
No UK law requires AI governance as such. Existing law still applies to the way you use AI, data protection above all, and the EU AI Act can reach a UK organisation whose AI output is used in the EU. Governance is how you show you have met whatever does apply.
What is the difference between AI governance and an AI policy?
The policy is one document inside it. Governance also covers who owns each tool, how a new one is assessed and approved, and how those decisions are recorded and reviewed.
Do we need ISO 42001 to have AI governance?
No. ISO/IEC 42001 is a voluntary standard for running AI governance as a management system, and it is the one an accredited body can certify you against. Certifying is a separate decision about how you want to evidence your governance.
Who should own AI governance?
Leadership is accountable for it. Day to day it usually sits with whoever already owns risk, information security, data protection or operations, and that person needs the authority to refuse a tool.