An initiative by Solutive AG
solutive.ag
AI Governance

AI Governance: Fundamentals, Requirements, and Operational Implementation

AI governance manages the use of AI in companies. It is not a sub-area of IT governance, but a distinct framework.
April 28, 2026
min Lesezeit
13

What AI governance is and how it differs from data and IT governance

AI governance refers to the framework used by an organization to manage the development, deployment, operation, and decommissioning of AI systems. This framework encompasses policies, roles, processes, controls, and documentation requirements. The goal is to derive value from AI while minimizing risks to individuals, organizations, and society.

AI governance overlaps with data governance, IT governance, and risk governance, but it is not identical to them. Data governance regulates how data is collected, managed, and used. IT governance manages IT resources and strategy. AI governance additionally addresses the specific characteristics of AI systems: their probabilistic behavior, reliance on training data, the challenge of explainability, and the potential impact of automated decisions on people.

An AI governance framework answers at least four questions. First: Which AI systems is the company using, and for what purpose? Second: What risks do these systems pose, and how are they assessed? Third: Who is responsible for their safe and compliant operation? Fourth: How is compliance verified and documented?

Regulatory pressure, stakeholder expectations, and operational risks in 2026

In 2026, AI governance is no longer a voluntary discipline. Three forces make it mandatory:

Regulatory pressure. The EU AI Act has been in effect since August 2024, with staggered applicability. Prohibitions have applied since February 2025, obligations for general-purpose AI models since August 2025, and high-risk requirements from August 2026. Additionally: NIS2 with enforcement from October 2026, DORA active since January 2025, and ISO 42001 as a voluntary standard increasingly required by clients.

Stakeholder expectations. Customers, investors, and authorities are increasingly asking: How does the AI system make decisions? Who is liable? How is it ensured that the system is fair and secure? Companies without robust answers risk losing contracts and market access.

Operational risks. AI systems can discriminate, misclassify, hallucinate, or produce safety-critical errors. Without governance, there are no mechanisms in place to detect, contain, and document such errors early on.

AI inventory, risk framework, and integration into the change process

AI governance is implemented through three operational instruments:

AI inventory. The inventory records all AI systems used within the company: name, purpose, technical basis, data used, affected individuals, risk classification, provider, and deployer. The inventory is the foundation for all further governance measures. Without an inventory, reliable compliance is impossible.

Risk framework. Based on the EU AI Act (four risk classes: unacceptable risk, high risk, limited risk, minimal risk) and expanded by company-specific criteria. Every AI system in the inventory is classified. The classification determines the applicable requirements.

Integration into the change process. AI governance is not a parallel structure to change management. Every change to an AI system must go through the change process. This process includes AI-specific fields: Is there a change in risk classification? A change in training data? A change in intended purpose? These fields drive the approval workflow and documentation requirements.

Governance as a checkbox and the 40 percent classification gap

Governance documents without lived governance. Many companies have created AI policies and adopted AI ethics principles. These documents exist, but they are not operationalized. There is no inventory, no risk classification, and no change process for AI modifications. The result is a compliance-ready facade without robust governance underneath.

Classification gap. The European Commission promised guidelines for classification under Article 6 of the EU AI Act. They have not been released (as of April 2026). For a significant portion of enterprise AI systems, the risk classification remains unclear. Without guidance, companies must classify systems themselves, carrying the risk of misclassification in either direction.

Shadow AI. Employees are using AI services outside of the official inventory. These systems are not classified, not monitored, and not captured in the change process. Shadow AI is the largest governance gap in most companies.

Framework before the first project, ISO 42001 as an operational guide

Governance framework before the first AI project. The most common mistake is to start using AI and then try to catch up with governance. This creates compliance technical debt: systems that went live without documentation must be retroactively classified, documented, and assessed. This is time-consuming and error-prone.

Using ISO 42001 as a structured framework. ISO/IEC 42001:2023 is the first international standard for AI Management Systems (AIMS). It is built on the High Level Structure also used by ISO 27001 and ISO 9001. This allows for integration into existing management system landscapes. ISO 42001 can be used as a framework without necessarily pursuing certification. Certification is an optional next step.

Governance documentation as a byproduct of the process. A well-designed AI governance process generates documentation as a byproduct: inventory entries, risk classifications, change records, test protocols, and monitoring logs. Documentation is created through the process, not through separate audit preparation. Every approval, risk assessment, and monitoring event is systematically recorded and retrievable.

Tool Landscape

Summary

AI governance is the overarching framework for the use of AI in companies. In 2026, it becomes a legal requirement under the EU AI Act. An inventory, a risk framework, and integration into the change process are the three operational building blocks.

Autor:
Christian Steiger