What Is AI Governance?
AI governance is the set of policies, processes, and controls that determine how your organisation develops, deploys, and monitors AI systems. It covers who can use AI, what data it can access, how decisions are reviewed, and what happens when something goes wrong.
This is not about slowing innovation down. It is about knowing what AI systems you have, understanding the risks they create, and being able to demonstrate to regulators, clients, and your board that you are managing those risks responsibly.
For most UK organisations, AI governance means answering three questions: What AI are we using? What could go wrong? And can we prove we thought about it?
Why It Matters Now
Three things changed in the last 18 months that make AI governance unavoidable for UK businesses.
The EU AI Act is phasing in
The EU AI Act became law in August 2024, with obligations phasing in over the following years. The phase-in timeline has moved before and may move again, so check the EU's own published timeline for the current position rather than relying on a fixed date here. If your organisation offers services to EU customers, processes EU citizen data, or deploys AI systems that affect people in the EU, this applies to you — regardless of where you are headquartered.
The Act classifies AI systems into four risk tiers: unacceptable (banned), high-risk (heavy regulation), limited risk (transparency obligations), and minimal risk (largely unregulated). Most business AI falls into limited or high-risk. If you use AI for recruitment screening, credit scoring, or anything that affects individual rights, you are likely in high-risk territory.
The UK is tightening its approach
The UK government initially took a principles-based, pro-innovation stance through existing regulators (FCA, ICO, CMA, Ofcom). But the direction is shifting. The AI Safety Institute is expanding its remit, sector regulators are publishing AI-specific guidance, and the expectation is that formal regulation will follow. Organisations that build governance now will not need to scramble when it arrives.
Board liability is real
Directors have a duty of care over organisational risk. AI systems that make or influence decisions create legal exposure. If an AI system discriminates, leaks data, or produces harmful outputs, and the board cannot show it had oversight, personal liability follows. This is not hypothetical — the ICO has already fined organisations for automated decision-making failures under existing GDPR rules.
EU AI Act Risk Classification Explained
Understanding where your AI systems sit in the EU AI Act's risk framework is the first step in any governance programme. Here is a practical breakdown.
| Risk Level | Examples | Obligations |
|---|---|---|
| Unacceptable | Social scoring, real-time biometric surveillance (with exceptions) | Banned |
| High Risk | Recruitment tools, credit scoring, medical devices, critical infrastructure | Conformity assessment, risk management, human oversight, data governance, logging, transparency |
| Limited Risk | Chatbots, deepfake generators, emotion recognition | Transparency obligations — users must know they are interacting with AI |
| Minimal Risk | Spam filters, AI-assisted writing, game AI | No specific obligations (voluntary codes encouraged) |
Most organisations are surprised to find they have high-risk systems. AI that screens CVs, prioritises customer service tickets based on sentiment, or recommends treatment pathways can all qualify. The classification depends on the use case, not the technology.
What a Practical AI Governance Framework Looks Like
Enterprise governance frameworks run to hundreds of pages. Most SMEs do not need that. Here is what actually matters for organisations with 10 to 500 employees.
1. AI asset inventory
Before you can govern AI, you need to know what AI you have. This means cataloguing every AI system, tool, and API your organisation uses — including the ones individuals signed up for with their personal email. Shadow AI is the biggest governance gap in most organisations.
For each system, record: what it does, what data it accesses, who uses it, where data is processed, and whether it makes or influences decisions about people.
2. Risk classification
Map each AI system against the EU AI Act risk tiers. For high-risk systems, you need documented risk assessments. For limited-risk systems, you need transparency measures. This does not need to be complex — a spreadsheet with clear ownership and review dates is a valid starting point.
3. Acceptable use policy
Your staff need clear rules on what they can and cannot do with AI. This should cover: which AI tools are approved, what data can be input, what review is required for AI-generated outputs, and what the escalation process is for edge cases. Keep it short and practical — a 20-page policy nobody reads is worse than no policy.
4. Data governance for AI
AI governance sits on top of data governance. If you do not know what data you have, where it is, and who can access it, you cannot govern AI systems that process that data. For regulated industries (healthcare, legal, finance), this is non-negotiable. For everyone else, it is increasingly expected.
5. Human oversight and accountability
Every AI system that makes or influences decisions about people needs a named human who is accountable for those decisions. This is not about micromanaging — it is about ensuring there is always someone who can intervene, explain, and be held responsible. Automated decisions under GDPR Article 22 require meaningful human involvement, not rubber-stamping.
6. Incident response
What happens when an AI system produces a harmful, biased, or incorrect output? You need a playbook: how to detect it, who to notify, how to contain it, and how to prevent recurrence. This should integrate with your existing incident response procedures, not exist in a separate document.
Practical Steps to Take Now
You do not need to do everything at once. Here is a realistic sequence for an SME that is starting from zero.
Audit
Inventory every AI system in use. Survey department heads. Check credit card statements for SaaS AI subscriptions. You will find more than you expect.
Classify
Map each system against EU AI Act risk tiers. Identify your high-risk systems. These are your governance priority.
Policy
Draft an acceptable use policy. Keep it to 2-3 pages. Get it reviewed by legal. Communicate it to all staff with a 30-minute briefing.
Controls
Implement controls for high-risk systems: human review processes, logging, access controls, data handling procedures.
Review
Quarterly review of AI inventory (new tools appear constantly). Annual policy refresh. Board reporting on AI risk at least twice a year.
AI Governance Checklist
Use this as a starting point. If you can tick most of these, you are ahead of 90% of UK SMEs.
- Complete inventory of all AI systems in use (including shadow AI)
- Each system classified by EU AI Act risk tier
- Acceptable use policy published and communicated to all staff
- Named owner for each high-risk AI system
- Data processing agreements in place with all AI vendors
- Human review process for AI-influenced decisions about people
- Incident response playbook covering AI failures
- Logging and audit trail for high-risk AI decisions
- Regular review schedule (quarterly inventory, annual policy refresh)
- Board reporting on AI risk at least twice a year
Common Mistakes
“We only use ChatGPT, so we don't need governance.”
ChatGPT is the most common shadow AI risk. Staff paste client data, financial information, and personal data into it daily. Without governance, you have no visibility and no control.
“Our AI vendor handles compliance.”
Your vendor handles their compliance. You are responsible for how you use their system, what data you feed it, and what decisions you make based on its outputs. This is your governance, not theirs.
“We'll wait until the UK legislates.”
The EU AI Act already applies if you serve EU customers. GDPR already covers automated decision-making. Sector regulators are already publishing AI guidance. Waiting means catching up under pressure.
When to Get Help
You can build basic AI governance in-house if you have someone with the time and understanding to own it. But there are situations where external expertise pays for itself.
- High-risk AI systems are in scope and need a conformity assessment
- The work is in a regulated industry (healthcare, legal, finance)
- Custom AI is being deployed, not just SaaS tools
- Governance needs to be demonstrable to clients, investors, or auditors
- Getting it right the first time matters more than iterating through mistakes