Organizational AI governance
AI-generated text. This page was generated using artificial intelligence.
Organizational AI governance is the set of responsibilities, decisions and ongoing controls through which an organization oversees AI systems it develops, procures or uses. It connects technical evaluation with legal obligations, institutional accountability and the effects on people who use or are affected by a system.[1][2]
Responsibilities and system inventory
Governance begins by identifying who can approve an AI use, who owns its risks, who monitors it and who can intervene. NIST's Govern function calls for documented roles, leadership accountability, training, policies and inventories of AI systems. The UK toolkit calls for a multidisciplinary risk-management team with governance, technical, security, legal and domain expertise; one person or a smaller team may carry several responsibilities.[1][2]
An inventory helps an organization know where AI is used, what each system is meant to do, which data and third-party components it depends on, and which people may be affected. The inventory and assigned owners can be updated as systems and uses change.[1]
Assessing and deciding on risk
NIST's Map function asks teams to document the intended use, deployment setting, capabilities, limits and possible effects. Measure calls for suitable testing and monitoring, including uncertainty in the available evidence. Manage turns those findings into decisions about mitigation, acceptance, transfer or avoidance of risk, with residual risk documented. Its four functions are iterative rather than a one-time sequence.[1]
The UK toolkit provides questions and a workbook for identifying risks, their treatment, owners and changes over time. It covers legal compliance, fairness, transparency, accountability, security and contestability. Its stated primary setting is UK government and public-sector AI projects; organizations elsewhere can read it as an example without treating it as a universal legal rule.[2]
Before and after deployment
Governance spans procurement and development, pre-deployment testing, live monitoring, incident response and retirement. An organization may need to revisit an assessment when a model, data source, vendor, use case or legal requirement changes. NIST addresses third-party risks, feedback from affected people, incident response and plans to override, disengage or deactivate systems when necessary. The UK toolkit likewise calls for continuing reassessment throughout the system lifecycle.[1][2]
Records of the system's purpose, risk decisions, tests, limitations, human oversight and corrective actions allow later review. They also help connect organizational practice to specific duties under applicable laws. A framework may guide this work, while the underlying statute or regulation determines a binding legal obligation.[1][2]
Frameworks and legal context
The NIST AI Risk Management Framework is voluntary U.S. guidance for many kinds of AI systems. The NIST Generative AI Profile adapts it to generative-AI risks. The UK AI Risk Management Toolkit offers public-sector risk tools. ISO/IEC 42001:2023 specifies requirements and guidance for an AI management system within an organization; its IEC publication record describes the scope, while the complete standard is sold separately.[3]
The Legislation and Regulation directory covers specific legal instruments by jurisdiction. Policy compares public choices about oversight. Governance practice may help an organization identify and carry out applicable duties; the legal status of each requirement must be checked against the relevant instrument and jurisdiction.
Related articles
- Governance — Directory of frameworks and applied guidance.
- AI Law by Topic — Subject routes to legal instruments.
- AI Systems — Relevant system profiles.
References
- ↑ 1.0 1.1 1.2 1.3 1.4 1.5 NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023, sections 1–2 and 5.
- ↑ 2.0 2.1 2.2 2.3 2.4 UK Department for Science, Innovation and Technology, AI Risk Management Toolkit: guidance, September 8, 2026, Purpose and Using these tools.
- ↑ IEC, ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system, publication record and abstract, December 18, 2023.