Skip to content

AI Governance & Risk

AI governance is not a renamed version of IT governance. IT governance focuses on infrastructure reliability, access controls, and project delivery. AI governance covers a different and messier set of problems: whether a model behaves as expected across the full range of real inputs, what liability flows from a vendor's choices about training data or safety tuning, how the organization demonstrates compliance with emerging regulations, and who inside the company has the authority to say yes or no to a new AI deployment. These are policy and risk problems as much as technical ones, and they require a function — or at minimum a set of accountabilities — that most enterprises did not build when AI was limited to narrow analytics use cases.

The urgency has increased sharply. The EU AI Act introduced binding requirements for high-risk AI systems, with phased enforcement dates that many organizations are only now tracking against their actual deployments. Agentic AI — systems that take sequences of actions with real-world consequences — has moved from research to production faster than governance frameworks have caught up. And the sheer volume of AI deployment across business units means that the old pattern of reviewing each system individually is no longer tractable; organizations need standing policy infrastructure, not one-off reviews. The reputational and regulatory cost of getting this wrong has also grown: a model producing harmful outputs at scale, or a vendor quietly changing terms around data retention, are no longer edge cases confined to tech companies.

This track builds the governance capability in layers. The core framework establishes the conceptual foundation — risk taxonomy, accountability structures, the relationship between governance and the AI strategy decisions covered in AI Strategy & Leadership. Three practitioner guides cover the operational work: standing up the governance function, writing and maintaining acceptable use policy, and running AI incident response. The tooling landscape page maps the vendor and open-source options for model risk monitoring, policy enforcement, and audit logging. The track closes with an assessment that lets a team score its current governance maturity and identify the highest-leverage gaps to close first.

Leaders who want the headline picture before going deeper should start with the executive summary, which distills the core argument and the two or three decisions most executives need to make.

In this section

Page Last updated
Executive Summary
A one-page synthesis of AI Governance & Risk — for board members and senior leaders deciding whether to fund a governance program.
Updated 2026-06-16
AI Governance Framework
Model risk, vendor risk, regulatory compliance, and the internal policy layer that governs AI deployment.
Updated 2026-06-16
Tooling Landscape
AI governance platforms, model monitoring and observability tools, regulatory compliance management, and audit and explainability tools.
Updated 2026-06-16
Practitioner Guide: AI Incident Response
AI incident taxonomy, severity tiers, response playbook, escalation paths, regulatory notification requirements, and how agentic AI changes the incident response calculus.
Updated 2026-06-17
Practitioner Guide: AI Policy and Acceptable Use
How to write and maintain an AI acceptable use policy — risk tiering, prohibited and permitted use categories, human-in-the-loop requirements, data classification, and EU AI Act alignment.
Updated 2026-06-17
Practitioner Guide: Standing Up an AI Governance Function
How to design, staff, and operationalize an AI governance function — org models, key roles, 90-day launch sequence, and governance structures for agentic AI.
Updated 2026-06-17
Assessment: Governance Maturity Scoring
A six-dimension diagnostic that scores the maturity of an organization's AI governance function — structure, policy, model risk, regulatory readiness, incident response, and vendor risk.
Updated 2026-06-16