AI Governance guide
AI Governance: a practical guide.
AI governance is how an organisation makes sure the AI it builds, buys and uses is safe, lawful and accountable: knowing where AI is used, classifying the risk each system carries, putting controls and human oversight in place, and keeping the evidence to prove it. This guide sets out what that looks like in practice, which frameworks matter, what the EU AI Act requires and when, and the cheapest, highest-value place to start.
The landscape
Where AI governance fits.
- 01Governing the AI your people useFinding shadow AI, setting a clear acceptable-use policy, and stopping sensitive data leaking into public tools.
- 02Securing the AI you build or deployControls and testing around your own AI applications and agents, so they behave and hold up under attack.
- 03Assurance and accountabilityOur focusThe management system, risk assessments and evidence that satisfy ISO 42001, the EU AI Act and your board. This is where we focus.
The controls that enforce these policies (browser, device and network) sit within managed security. We join the two, so the policy on paper and the enforcement in the stack actually match.
Technology & SolutionsThe frameworks
Three names you will hear, and how they relate.
ISO 42001 and NIST AI RMF are how you build and run governance. The EU AI Act is what you must do where it applies. It helps to see them side by side.
| Framework | What it is | Mandatory? | Where it fits |
|---|---|---|---|
| ISO/IEC 42001 | International management-system standard for AI (an AIMS), structured like ISO 27001 | No. Voluntary, but increasingly expected in procurement | Proving AI is governed responsibly; certifiable through accredited assessment partners |
| NIST AI RMF | Voluntary risk-management framework built around Govern, Map, Measure and Manage | No | A practical structure for standing up an AI risk programme; widely referenced beyond the US |
| EU AI Act | EU law with extraterritorial reach and risk-tiered obligations | Yes, where you are in scope | The legal obligations themselves, for prohibited, high-risk and transparency-tier systems affecting the EU market |
ISO/IEC 42001
- What it is
- International management-system standard for AI (an AIMS), structured like ISO 27001
- Mandatory?
- No. Voluntary, but increasingly expected in procurement
- Where it fits
- Proving AI is governed responsibly; certifiable through accredited assessment partners
NIST AI RMF
- What it is
- Voluntary risk-management framework built around Govern, Map, Measure and Manage
- Mandatory?
- No
- Where it fits
- A practical structure for standing up an AI risk programme; widely referenced beyond the US
EU AI Act
- What it is
- EU law with extraterritorial reach and risk-tiered obligations
- Mandatory?
- Yes, where you are in scope
- Where it fits
- The legal obligations themselves, for prohibited, high-risk and transparency-tier systems affecting the EU market
In short: ISO 42001 and NIST AI RMF are how you build and run governance; the EU AI Act is what you must do where it applies. Holding ISO 42001 is a strong foundation, but it is not, on its own, legal compliance with the EU AI Act, and we do not present it as such.
The EU AI Act timeline
Runway, not a reprieve.
The Digital Omnibus adopted in June 2026 moved the high-risk dates back. That is runway to get governance in order, not a reason to wait: transparency duties still land in August 2026, and for finance clients the FCA already expects AI governance through SM&CR and Consumer Duty, whatever the EU timeline.
Feb 2025
Prohibited practices
Aug 2025
General-purpose AI
Aug 2026
Transparency duties
Next to land
Dec 2026
Watermarking, new prohibitions
Dec 2027
High-risk, standalone (Annex III)
The planning date
Aug 2028
High-risk in products (Annex I)
Shadow AI, in brief
You cannot govern what you cannot see.
Shadow AI is AI used across a business without oversight: staff pasting data into public chatbots, unapproved tools, AI features buried inside SaaS, and browser extensions. The risk is sensitive data leaving the organisation with no record of where it went.
Most organisations underestimate how widespread it already is, which is exactly why the first move is an inventory. Start with a clear picture of where AI is used, then classify the risk, then put the controls and documentation in place to match.
Why this matters now
AI is already in the building.
FAQ
Questions boards ask
Short, straight answers to what boards and buyers ask most. Still need a steer on your own situation?
Book a call- AI governance is how an organisation makes sure the AI it builds, buys and uses is safe, lawful and accountable. It means knowing where AI is used, classifying the risk of each system, putting controls and human oversight in place, and keeping evidence an auditor or regulator will accept.
- It can. The Act has extraterritorial reach, so a UK organisation that provides or uses an AI system affecting people in the EU can fall in scope, even with no EU office. For many UK firms it is a UK question, not only an EU one.
- In phases. Prohibited practices have applied since February 2025 and general-purpose AI rules since August 2025. Under the Digital Omnibus adopted in June 2026, high-risk obligations for standalone (Annex III) systems now apply from 2 December 2027, and for AI embedded in regulated products (Annex I) from 2 August 2028. Transparency obligations still apply from 2 August 2026, with watermarking and new prohibitions from 2 December 2026.
- ISO 42001 is a voluntary international standard: a management system for governing AI that you can be certified against. The EU AI Act is law: obligations that apply whether or not you hold any certificate. ISO 42001 helps you build the governance the Act expects, but holding it is not the same as being legally compliant with the Act.
- There is no legal requirement to hold it. It matters as a commercial signal, because procurement teams and customers increasingly ask for it as proof that AI is governed responsibly. If you already hold ISO 27001, much of the groundwork carries straight over because the two share the same management-system structure.
- Shadow AI is AI used across a business without oversight: staff pasting data into public chatbots, unapproved tools, AI features buried inside SaaS, and browser extensions. The risk is sensitive data leaving the organisation with no record of where it went. Most organisations underestimate how widespread it already is.
- No. ISO 42001 is a management-system standard and a strong foundation, but on its own it is not legal compliance with the EU AI Act. We are always clear about where readiness ends and legal advice begins.
- With an inventory. You cannot govern, classify or evidence AI you cannot see. Start with a clear picture of where AI is used across the business, then risk classification, then the controls and documentation that match. Most organisations still lack this baseline, which makes it the cheapest, highest-value place to begin.
Last reviewed: July 2026Reviewed by the Threat Protect Compliance Team
Keep reading
Get ahead of the board’s AI question.
Tell us how AI is showing up in your organisation. We’ll map a path to audit-ready governance and EU AI Act readiness.
Book a call