Skip to content
atlas

AI governance

Also known as: AI management system, responsible AI

The rules, roles and checks an organisation uses to decide which AI it uses and to keep that use safe, lawful and fair.

Draft - this entry has not been reviewed yet.

Formal

The part of governance that sets policy, ownership and oversight for AI systems across their whole life, from approval to retirement, typically built on the NIST AI Risk Management Framework (Govern, Map, Measure, Manage) or an ISO/IEC 42001 management system.

In plain English

Like the house rules for a shared workshop - who may use which machines, who trains newcomers, who checks the safety guards, and who answers when something goes wrong.

In practice

A Danish region sets up an AI board that keeps a register of every AI tool in its hospitals, gives each an owner, requires a risk assessment before a tool is taken into use and reviews results for unfairness every quarter.

Why it matters

AI tools spread faster than anyone can track, and the EU AI Act places duties on organisations that use them; without clear rules and owners, nobody can show what is in use or who answers for it.

Technical deep dive

ISO/IEC 42001:2023 specifies an AI management system (AIMS) using the same harmonised structure as ISO/IEC 27001: clauses 4-10 cover context and scope, leadership and AI policy, planning (AI risk assessment in 6.1.2, AI risk treatment in 6.1.3, AI system impact assessment in 6.1.4), support, operation, performance evaluation and improvement. Annex A lists 38 reference controls grouped under nine objectives (A.2 to A.10) - policies, internal organisation, resources, impact assessment, AI system life cycle, data, information for interested parties, use of AI systems, and third-party relationships - and, as in 27001, applicability is justified in a Statement of Applicability. Supporting standards include ISO/IEC 23894:2023 for AI risk management, ISO/IEC 42005:2025 for impact assessment, and ISO/IEC 42006:2025, which sets requirements for bodies certifying against 42001.

The NIST AI Risk Management Framework (AI 100-1, January 2023) is voluntary and outcome-based. GOVERN is cross-cutting (policies, accountability, workforce diversity, third-party risk); MAP establishes context and identifies impacts; MEASURE applies quantitative and qualitative testing against trustworthiness characteristics (valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, fair with harmful bias managed); MANAGE prioritises and treats risks. The companion Playbook suggests actions per subcategory, and NIST AI 600-1 (2024) profiles the framework for generative AI.

For organisations in the EU, governance has to produce evidence for the EU AI Act. Providers of high-risk systems need a quality management system (Art. 17), risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11) and logging (Art. 12); deployers must assign competent human oversight, monitor operation and keep logs (Art. 26), and public bodies and certain others must perform a fundamental rights impact assessment (Art. 27). Art. 4 on AI literacy has applied since 2 February 2025, although the 2026 Digital Omnibus softened it to a duty to support literacy among staff. In Denmark, Digitaliseringsstyrelsen is the main market surveillance authority under the supplementary Danish AI act (Law no. 467 of 14 May 2025), alongside Datatilsynet and Domstolsstyrelsen for specific areas.

In practice the core artefact is an AI inventory: each system or embedded AI feature with owner, purpose, role (provider or deployer), AI Act risk class, data categories, supplier, model version and review date. Around it sit an intake gate for new use cases, a DPIA under GDPR Art. 35 where personal data is involved, pre-deployment evaluation and red teaming, change control for model updates, and monitoring for drift and incidents. A common failure mode is governance that only covers in-house models while AI arrives through SaaS feature updates and staff subscriptions, which is why governance is the principal control against shadow AI. It differs from AI safety research and alignment, which change model behaviour; governance decides whether, where and under which controls a system is used.

What to learn first

Everything this builds on, foundations first.

  1. Artificial intelligence (AI)
  2. →CIA triad
  3. →Threat
  4. →Asset
  5. →Vulnerability
  6. →Impact
  7. →Likelihood
  8. →Risk
  9. →Risk management
  10. →AI governance

Relationships

Part of
Governance
Mandated by
EU AI Act

Sources & further reading

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.