GovernanceCore
Foundations

AI governance

Working definition

Reviewed 30 July 2026

AI governance is the organizational system for directing, monitoring, and holding people accountable for how AI is selected, built, bought, deployed, and retired. It connects principles and legal duties to named owners, operating controls, escalation paths, and evidence.

Context

Why it matters

Principles alone do not change system behavior. Governance turns an organization’s risk appetite and external obligations into repeatable decisions across the AI lifecycle.

Operating note

What this looks like in practice

  1. 01Assign an accountable business owner and independent risk challenge for each material AI use case.
  2. 02Set approval gates that scale with impact, affected people, autonomy, and legal exposure.
  3. 03Keep enough evidence to reproduce decisions, monitor outcomes, and explain exceptions.

Sources & further research

Primary authority anchors the definition. Research links add conceptual or operational depth. External sources may update independently; always verify legal duties against the current official text.

  1. Official source

    Artificial Intelligence Risk Management Framework 1.0

    The Govern function describes cross-cutting policies, roles, accountability, and organizational culture.

    NIST
    2023
    Open source ↗
  2. Standard

    ISO/IEC 42001:2023 — AI management systems

    Requirements for establishing, implementing, maintaining, and continually improving an AI management system.

    ISO
    2023
    Open source ↗
  3. Research paper

    AI Governance: A Research Agenda

    A foundational research agenda covering the political, strategic, and institutional governance of AI.

    Allan Dafoe, Centre for the Governance of AI
    2018
    Open source ↗