Section 26: AI Governance

Why AI Governance Matters

Effective AI governance helps organizations:

Structuring AI Governance

AI Center of Excellence (CoE)

An AI CoE may oversee the organization’s AI initiatives by:

Hub-and-Spoke Model

This structure balances:

AI Handoffs

Successful AI operations require coordination among:

Organizations typically progress through maturity stages, evolving from informal AI experimentation to fully governed and optimized AI programs.

AI Policies and Procedures

Components of an AI Policy Framework

LayerRequired?Purpose
PoliciesYesDefine high-level principles and rules
StandardsYesSpecify mandatory technical or operational requirements
ProceduresYesProvide step-by-step compliance processes
GuidelinesNoRecommend best practices
Important AI Governance Questions

Organizations should clearly define:

AI governance frameworks should remain flexible and evolve alongside technology and regulations.

AI-Related Roles
AreaRoles
Data ModelingData Scientists, Data Engineers, ML Engineers
Architecture & PlatformsAI Architects, Platform Engineers, MLOps Engineers
Security & GovernanceAI Security Architects, Governance Engineers, Risk Analysts, AI Auditors

Organizations should establish clear responsibilities and separation of duties based on operational needs.

Section 27: AI Risks

Responsible AI Principles
PrincipleMeaning
FairnessPrevent discriminatory outcomes
Reliability & SafetyEnsure systems operate safely and predictably
TransparencyClearly communicate system behavior and limitations
PrivacyProtect personal and sensitive information
SecurityPreserve confidentiality, integrity, and availability
Differential PrivacyAdd controlled statistical noise to protect identities
ExplainabilityProvide understandable reasons for decisions
InclusivenessEnsure accessibility for diverse users
AccountabilityEnsure responsibility for AI outcomes
ConsistencyMaintain stable behavior across situations
Categories of AI Risk

AI risk is commonly evaluated using:

Risk = Impact × Exposure × Uncertainty

Risk TypeDescription
Bias IntroductionReinforcing societal inequalities or inaccurate assumptions
Accidental Data LeakageExposing confidential information unintentionally
Reputational DamageLoss of public trust after AI failures
Poor Accuracy or PerformanceIncorrect or delayed outputs
Intellectual Property RisksCopyright or ownership violations
Autonomous MisbehaviorAI acting beyond intended limits

Organizations should balance innovation and risk management rather than completely restricting AI adoption.

Bias Introduction

Bias occurs when AI systems reflect social or historical inequalities rather than objective patterns.

Bias Mitigation Approaches

Prevention Methods

Bias management requires continuous monitoring because risks evolve over time.

Accidental Data Leakage

Data leakage often results from collecting unnecessary or overly sensitive information.

Mitigation Strategies

Organizations should also establish dedicated incident response plans for AI-related data exposure.

Reputational Damage

Overstating AI capabilities can create trust failures when systems underperform.

Best Practices

Early reputational monitoring helps identify problems before they escalate.

Accuracy and Performance

Accuracy

Measures how often outputs are correct.

Performance

Measures speed and responsiveness, including:

Organizations should establish measurable benchmarks before deployment.

Canary Releases

A small percentage of live traffic is routed to a new model version before full deployment to limit operational risk.

Ongoing monitoring helps identify both performance degradation and model drift.

Intellectual Property (IP) Risks

Potential Issues

Mitigation Strategies

Autonomous Systems

AI autonomy exists on a spectrum ranging from fully human-controlled to fully autonomous.

Key Governance Questions

Monitoring and governance establish boundaries for autonomous actions and verify safe operation.

Shadow IT and Shadow AI

Shadow IT

Use of unauthorized hardware, software, or cloud services.

Shadow AI

Use of unapproved AI systems, such as employees submitting confidential information into public AI chatbots.

Recommended Approach

Instead of banning AI entirely, organizations should provide approved and secure AI alternatives to reduce unsanctioned use.

Awareness Training

Employees should receive training on responsible AI use and organizational expectations.

Target Audiences

Using realistic examples and storytelling improves training effectiveness.

Section 28: AI Compliance

EU AI Act

The EU AI Act classifies AI systems according to risk levels.

Risk TierRegulatory TreatmentExamples
Prohibited PracticesCompletely bannedGovernment social scoring
High-Risk SystemsStrict assessments and oversight requiredHiring systems, law enforcement AI
Limited-Risk SystemsTransparency obligations applyAI chatbots
Minimal-Risk SystemsFew mandatory requirementsSpam filters, game AI
General Purpose AI (GPAI)Broad transparency obligationsLarge language models

Violations may result in penalties reaching up to 7% of global annual revenue.

OECD AI Principles

The OECD introduced one of the first international AI governance frameworks.

Core Principles

The framework also encourages investment in research and workforce development.

ISO AI Standards
StandardPurpose
ISO 22989Defines AI terminology and concepts
ISO 23053Describes ML system frameworks and workflows
ISO 23894Provides AI risk management guidance
NIST AI Risk Management Framework (AI RMF)
FunctionPurpose
GOVERNEstablish accountability and governance structures
MAPIdentify and understand AI risks
MEASUREAssess risks through testing and evaluation
MANAGEImplement controls and continuous improvements

Example

A healthcare organization might:

Corporate AI Policies

Approved vs. Unapproved AI Tools

Sanctioned ToolsUnsanctioned Tools
Approved by IT, Legal, and SecurityNot formally reviewed
Risks are managedRisks are unknown
Example: Internal AI assistantExample: Public chatbot used with company data

Public vs. Private AI Models

Public ModelsPrivate Models
Hosted by third-party providersHosted internally or in private environments
Higher data exposure riskGreater organizational control
Best for non-sensitive tasksBest for regulated or confidential workloads

Organizations should define clear rules regarding what information may be used with public AI platforms.

Third-Party Compliance Assessments

Independent reviewers verify that AI solutions align with applicable regulations, standards, and organizational policies. The evaluation process generally involves:

Data Sovereignty

Data sovereignty establishes rules based on the geographic location where data is stored, managed, and processed, rather than solely on data ownership.

Primary Requirements:

AI technologies introduce additional sovereignty challenges because model training and inference operations may unintentionally route data through cloud environments spanning multiple jurisdictions.

Risk Reduction Measures: Implement data classification policies, data governance controls, and regional data management strategies to maintain compliance with sovereignty requirements