Glossary
AI governance
Last updated
Part of our topic guide on AI Governance & Data Strategy.
AI governance is the set of policies, roles and controls an organisation puts in place to make sure its use of AI is safe, fair, compliant and accountable: it covers how AI systems are chosen, built, deployed and monitored. It's the practical answer to "who decides what our AI is allowed to do, and how do we check it's doing it properly?"
That question unpacks into three a board actually asks, so this page is organised around them.
Who owns AI decisions here?
The first thing a governance programme establishes is accountability: who owns AI decisions, who signs off a new use case, and who's accountable if it goes wrong. Without a named owner, the failure modes aren't hypothetical: a hiring algorithm that quietly discriminates, a chatbot that leaks customer data, a model whose output no one can explain to a regulator. With one, AI becomes something the business can trust and scale, rather than a tool a few people use nervously and everyone else avoids.
How does a new use case get approved?
Through a risk assessment before it goes live: checking the system for bias, safety, data-protection and reliability risks, against the internal policy on acceptable use, data handling and vendor selection. Two named frameworks give this a structure without your needing to master their detail: ISO/IEC 42001, the international standard for an AI management system, and the NIST AI Risk Management Framework, a widely referenced voluntary framework from the US National Institute of Standards and Technology. Both are scaffolding to build a programme around rather than starting from a blank page.
On regulation: the UK has no single statutory "AI Act". It regulates AI through existing sector regulators (such as the ICO for data protection) under a principles-based approach. The EU AI Act can still apply to a UK organisation, though, where an AI system's output is used in the EU or the system is placed on the EU market, so check whether your use of AI touches EU customers or data before assuming it doesn't.
How do we know a live system still behaves?
Monitoring and audit: ongoing checks that a system in production still behaves the way it did when it was approved. Models drift, data changes, and usage spreads beyond the approved case, so approval is a start line, not a certificate.
The part the documents can't do
Our view, backed by the data: capability is usually the real bottleneck, not the technology. MIT NANDA's 2025 research into generative AI pilots found 95% delivered no measurable return on investment, and named learning, not infrastructure, regulation or talent, as the core barrier (MIT NANDA, "The GenAI Divide: State of AI in Business 2025", fieldwork Jan to Jun 2025). Governance without people who understand what they're governing is paperwork. That's why we treat AI governance as a capability to build in people (policy owners, reviewers, the people actually running the models), not just a document to file. In our experience, the businesses that do this well treat spotting a risky use case as a skill their people hold, not a folder their intranet does.
There's a funded way to build that capability, and we deliver it, so take the disclosure with the fact: there is no AI-governance apprenticeship standard as such, but the Level 4 Data Protection and Information Governance Practitioner standard is the funded vehicle for this ground, and our Data & AI Governance apprenticeship teaches AI governance within it.