Skip to content

Glossary

AI Governance

AI governance is the system of policies, responsibilities, controls, and evidence an organization uses to decide how AI may be developed, deployed, and used.

The term describes an organizational arrangement. It identifies who can make decisions about AI, what those decisions cover, how they take effect, and how the organization reviews them. Its scope includes the model and the context in which people or software use it.

Why it matters

An approval needs a meaning that survives beyond the meeting where it was granted. Teams need to know its conditions, who can change them, and what happens when the use changes. Governance makes those responsibilities explicit so that “approved AI” is a decision with a defined scope.

The NIST AI RMF Playbook, GOVERN 1.2 recommends connecting AI governance with existing organizational governance, risk controls, and data policies. AI therefore needs to fit into the organization's decision processes, including those for systems acquired from third parties.

How it works

Governance begins with a decision that has an owner, a purpose, and boundaries. A review establishes the conditions for a particular use, such as permitted data and access, and identifies who can approve an exception. The level of review should reflect the risks of that use.

Procedures and technical controls then put those conditions into operation. A condition requiring review of an output needs a review process; a restriction on access needs an effective permission boundary. Documenting a condition and implementing it are separate responsibilities, even when the same team handles both.

Evidence supports checking whether the decision remains appropriate and whether its conditions were followed. That can include evaluation records, approvals, relevant activity, and findings. Missing evidence remains a gap to investigate. Governance also needs a way to revise or withdraw a decision when the use, risks, or available evidence change.

What the term does not mean

A policy document expresses rules. Model approval records a decision about suitability. A software tool can support particular controls or records. Each can be part of AI governance, but none represents the whole arrangement. Buying a tool does not assign accountability or determine which uses the organization should accept.

  • AI agent governance focuses on authority delegated to agents: their access, tools, and actions, with applicable approvals and evidence.
  • Shadow AI describes AI usage outside organizational approval or management, bringing the scope of the governance program into question.

The AI governance pillar explains how these decisions connect across enterprise workflows, from model suitability to the permissions used in execution.