AI Governance
The accountability structure that decides who can approve, deploy, and stop an AI system — the discipline that makes every other compliance effort actually hold up under pressure.
AI governance is what determines whether a company's compliance program is real or decorative. Risk management identifies and mitigates specific risks in a specific system; governance is one level above that — it's the decision rights, review processes, and named accountability that determine who has the authority to say a risk is acceptable, and who gets to stop a deployment before it happens.
A governance framework that can't name who has the authority to say no to a specific system isn't a governance framework yet, regardless of what the policy document calls it. This hub covers the structural pieces: inventory, risk tiering, accountable ownership, and review gates placed early enough to actually change an outcome.
Featured
Recently updated
Frequently asked questions
- What is AI governance, in practical terms?
- The set of decision rights, review processes, and accountability structures that determine how an organization builds, buys, and deploys AI systems — and who is responsible when one of them fails. See our full governance framework checklist for how to build this in the order that tends to hold up.
- Who should own AI governance at a company?
- For consequential systems, someone whose job description would credibly include "explain this system's behavior to a regulator" — usually a risk or product owner close enough to the system to actually understand it, and senior enough to stop its deployment. A committee alone rarely works, because committees can't be held individually accountable the way a named owner can.
- How is AI governance different from AI risk management?
- Risk management is about identifying and mitigating specific risks in a specific system. Governance is about who has the authority to decide a risk is acceptable in the first place, and at what point in the deployment process that decision gets made — the structural layer risk management operates inside of.