AI Governance guide

AI Governance: a practical guide.

AI governance is how an organisation makes sure the AI it builds, buys and uses is safe, lawful and accountable: knowing where AI is used, classifying the risk each system carries, putting controls and human oversight in place, and keeping the evidence to prove it. This guide sets out what that looks like in practice, which frameworks matter, what the EU AI Act requires and when, and the cheapest, highest-value place to start.

The landscape

Where AI governance fits.

  1. 01Governing the AI your people useFinding shadow AI, setting a clear acceptable-use policy, and stopping sensitive data leaking into public tools.
  2. 02Securing the AI you build or deployControls and testing around your own AI applications and agents, so they behave and hold up under attack.
  3. 03Assurance and accountabilityOur focusThe management system, risk assessments and evidence that satisfy ISO 42001, the EU AI Act and your board. This is where we focus.

The controls that enforce these policies (browser, device and network) sit within managed security. We join the two, so the policy on paper and the enforcement in the stack actually match.

Technology & Solutions

The frameworks

Three names you will hear, and how they relate.

ISO 42001 and NIST AI RMF are how you build and run governance. The EU AI Act is what you must do where it applies. It helps to see them side by side.

ISO/IEC 42001

What it is
International management-system standard for AI (an AIMS), structured like ISO 27001
Mandatory?
No. Voluntary, but increasingly expected in procurement
Where it fits
Proving AI is governed responsibly; certifiable through accredited assessment partners

NIST AI RMF

What it is
Voluntary risk-management framework built around Govern, Map, Measure and Manage
Mandatory?
No
Where it fits
A practical structure for standing up an AI risk programme; widely referenced beyond the US

EU AI Act

What it is
EU law with extraterritorial reach and risk-tiered obligations
Mandatory?
Yes, where you are in scope
Where it fits
The legal obligations themselves, for prohibited, high-risk and transparency-tier systems affecting the EU market

In short: ISO 42001 and NIST AI RMF are how you build and run governance; the EU AI Act is what you must do where it applies. Holding ISO 42001 is a strong foundation, but it is not, on its own, legal compliance with the EU AI Act, and we do not present it as such.

The EU AI Act timeline

Runway, not a reprieve.

The Digital Omnibus adopted in June 2026 moved the high-risk dates back. That is runway to get governance in order, not a reason to wait: transparency duties still land in August 2026, and for finance clients the FCA already expects AI governance through SM&CR and Consumer Duty, whatever the EU timeline.

  1. Feb 2025

    Prohibited practices

  2. Aug 2025

    General-purpose AI

  3. Aug 2026

    Transparency duties

    Next to land

  4. Dec 2026

    Watermarking, new prohibitions

  5. Dec 2027

    High-risk, standalone (Annex III)

    The planning date

  6. Aug 2028

    High-risk in products (Annex I)

See the full EU AI Act timeline and readiness steps

Shadow AI, in brief

You cannot govern what you cannot see.

Shadow AI is AI used across a business without oversight: staff pasting data into public chatbots, unapproved tools, AI features buried inside SaaS, and browser extensions. The risk is sensitive data leaving the organisation with no record of where it went.

Most organisations underestimate how widespread it already is, which is exactly why the first move is an inventory. Start with a clear picture of where AI is used, then classify the risk, then put the controls and documentation in place to match.

Why this matters now

AI is already in the building.

76%of employees reported using AI at work in 2025, up from 30% in 2023.McKinsey, 2026
1 in 5breached organisations suffered a breach involving shadow AI. Where shadow AI use was high, breaches cost around $670,000 more than where it was low or absent.IBM Cost of a Data Breach Report, 2025
21%of organisations keep a real-time registry of the AI agents running in their environment.Cloud Security Alliance, 2026

FAQ

Questions boards ask

Short, straight answers to what boards and buyers ask most. Still need a steer on your own situation?

Book a call
  • AI governance is how an organisation makes sure the AI it builds, buys and uses is safe, lawful and accountable. It means knowing where AI is used, classifying the risk of each system, putting controls and human oversight in place, and keeping evidence an auditor or regulator will accept.

Last reviewed: July 2026Reviewed by the Threat Protect Compliance Team

Keep reading

Get ahead of the board’s AI question.

Tell us how AI is showing up in your organisation. We’ll map a path to audit-ready governance and EU AI Act readiness.

Book a call