KI-Governance: So setzt Du künstliche Intelligenz sicher und regelkonform im Unternehmen ein.
A department introduces an AI assistant to process customer inquiries more quickly. The application accesses internal documents and formulates responses on its own. After a few weeks, it becomes clear that no one can say exactly what data is being processed, who is reviewing the results, or whether confidential information has been transferred to the provider.
We see this time and again: Such situations do not necessarily arise from flawed technology. Often, clear rules, responsibilities, and control processes are lacking. This is precisely where AI governance comes in.
AI governance establishes a binding framework for the secure, transparent, and legally compliant use of artificial intelligence. It integrates corporate governance, risk management, data protection, IT security, and technical development. As a result, governance becomes a central component of any viable AI strategy.
This guide shows you how to establish an AI governance framework, assess risks, and translate regulatory requirements—such as the EU AI Act—into practical processes.
What is AI governance?
AI governance refers to the totality of all rules, roles, processes, and technical controls that a company uses to manage its AI systems. It defines:
which AI applications may be used,
who makes decisions regarding the use of AI,
how risks are assessed and managed,
what data may be used,
how companies document AI systems,
when human oversight is required,
how models and results are monitored,
and how compliance with internal and legal requirements is demonstrated.
Governance does not mean slowing down every AI initiative with additional bureaucracy. Rather, effective governance establishes reliable guidelines. This ensures that teams know early on which requirements they must follow and who to contact if they have questions.
What are AI use cases in businesses?
AI use cases can be found in nearly every area of business today—from automated document processing and intelligent chatbots in customer service to sales forecasting and predictive maintenance in production. The use of AI increases efficiency and supports informed decision-making. This is precisely why clear AI governance is important: it ensures that AI applications are developed and used securely, transparently, and in accordance with legal and internal company guidelines.
Why do companies need appropriate governance when using AI?
Artificial intelligence often spreads within companies faster than the control structures put in place to manage it. Employees use generative AI to write texts, develop software, or analyze data. Business units test AI services without always involving IT, data protection, or procurement.
This gives rise to the following risks, among others:
Confidential information is disclosed to external providers,
results contain factual errors,
training data leading to discriminatory decisions,
AI applications infringe on copyrights,
responsibilities remain unclear,
systems do not meet the requirements of the EU AI Act,
Decisions cannot be traced later,
similar AI solutions are procured multiple times.
Stanford University’s AI Index Report 2025 documents both an increasing economic use of AI and a growing number of reported AI-related incidents. This makes it clear that as usage increases, so do the demands for control, transparency, and risk management. These are challenges we regularly encounter in our AI consulting work!
What are the 5 goals of AI governance?
Effective AI governance should not only meet compliance requirements. It pursues several interconnected goals.
Objective #1: Ensuring Security
AI systems must be protected against tampering, unauthorized access, and data loss. This applies to both internal models and external AI services.
Objective #2: Ensuring Compliance
The use of AI must align with applicable laws, contractual obligations, and internal policies. These include, in particular, the EU AI Act, the General Data Protection Regulation (GDPR), copyright law, and industry-specific regulations.
Objective #3: Establish Transparency
The company should know which AI systems exist, who is responsible for them, and for which use cases they are deployed. A central AI registry serves as the foundation for this.
Goal #4: Enable Responsible Decision-Making
AI must not operate in an organizational vacuum. Governance defines which decisions can be automated and when humans must review or approve results.
Goal #5: Foster trust
Transparent processes strengthen the trust of employees, customers, and business partners. They demonstrate that the company does not use AI in an uncontrolled manner, but rather according to transparent criteria.
What distinguishes AI governance from traditional IT governance?
IT governance fundamentally manages the use of information technology. It addresses, for example, IT architecture, investments, security, and service quality. AI governance builds on this foundation but takes into account the additional characteristics of artificial intelligence.
Traditional software typically operates according to hard-coded rules. AI models, on the other hand, derive results from data and statistical relationships. This creates specific challenges:
Results can be probabilistic and therefore subject to change.
Biased data can lead to unfair results.
Generative AI can produce false statements that sound convincing.
Model decisions are not always fully explainable.
A model’s performance may deteriorate due to changes in input data.
A model may be used outside its intended scope of application.
AI governance must therefore cover not only development and implementation, but the entire lifecycle of an AI system. If you’d like to implement AI in your company, we’re here to support you from the initial process analysis through reporting and performance monitoring!
How do you go about implementing AI governance?
Step 1: Analyze the Current Situation
Review existing AI applications, policies, roles, and control processes. Leverage existing structures related to data protection, information security, and risk management.
Step 2: Define Objectives and Risk Appetite
Determine which AI strategies the company is pursuing and which risks it can accept. A bank will need different guidelines than a manufacturing facility.
Step 3: Define Responsibilities
Designate a central coordinator, subject matter owners, and decision-making bodies. Document responsibilities, for example, in a RACI matrix.
Step 4: Build an AI registry
Record existing and planned AI use cases. Start with a few required fields and expand the registry gradually.
Step 5: Develop a risk classification system
Establish transparent criteria for low, medium, and high risks. Take into account the EU AI Act and other relevant laws.
Step 6: Implement guidelines and processes
Define rules for use, procurement, development, approval, monitoring, and decommissioning.
Step 7: Implement technical controls
Where possible, use workflows, access controls, logging, and automated checks. Governance should be embedded in existing tools.
Step 8: Train employees
Don’t just focus on what’s prohibited. Demonstrate specific, secure use cases and explain the intended approval processes.
Step 9: Measure effectiveness
Regularly verify whether controls are actually working and whether they are commensurate with the respective risk.
What is an AI Governance Framework?
An AI governance framework is a structured regulatory framework for the use of AI. It translates abstract principles into concrete responsibilities, guidelines, controls, and workflows. In practice, the framework typically consists of six pillars:
Strategy and Principles
Roles and Responsibilities
Inventory and Classification
Risk and Compliance Management
Technical and Organizational Controls
Monitoring and Continuous Improvement
Companies can use established standards as a guide. The NIST AI Risk Management Framework, for example, breaks down the management of AI risks into the functions “Govern,” “Map,” “Measure,” and “Manage.” ISO/IEC 42001 also provides an international standard for an artificial intelligence management system.
However, a framework should never be adopted unchanged. You must adapt it to your industry, company size, use cases, and existing governance structures. That’s why we always re-evaluate our clients’ specific circumstances!
What role does the EU AI Act play as the first AI law?
The EU AI Act, also known as the EU AI Regulation, is the first comprehensive legal framework for artificial intelligence in the European Union. The regulation takes a risk-based approach: the greater the potential risk posed by an AI system, the stricter the requirements.
The EU AI Act entered into force on August 1, 2024. Its provisions are being phased in:
As of February 2, 2025, provisions in effect include bans on certain AI practices and requirements for AI expertise.
As of August 2, 2025, key provisions for general-purpose AI models have been in effect.
Starting August 2, 2026, most other regulations will take effect according to the statutory timeline.
For certain high-risk systems that serve as safety components of regulated products, transition periods extend through 2027.
Companies should review the current legal situation and any potential changes to the timeline. The European Commission provides information and guidance on this topic on its AI Act platform.
What risk categories does the EU AI Regulation distinguish?
Put simply, the AI Act distinguishes between several risk levels.
Prohibited AI Practices
Certain applications are considered unacceptable. These may include, for example, manipulative systems, certain forms of social scoring, or specific biometric categorizations. The exact classification depends on the specific use case and statutory exceptions.
High-Risk AI Systems
This group may include AI systems used in sensitive areas, such as:
in personnel selection,
creditworthiness assessments,
in critical infrastructure,
in medical devices,
in education and testing,
in certain regulatory decisions.
Such AI systems are subject to extensive requirements regarding risk management, data quality, documentation, logging, human oversight, and robustness.
AI with Transparency Requirements
In certain applications, users must be able to recognize that they are interacting with an AI system. Labeling requirements may also apply to synthetically generated or manipulated content.
AI with Minimal Risk
Many everyday applications do not fall into a strictly regulated category. Nevertheless, data protection, information security, contract law, or internal policies may still be relevant.
What penalties apply for violations of the AI Act?
The potential penalties depend on the nature of the violation. For violations involving prohibited AI practices, the EU AI Act generally provides for fines of up to 35 million euros or 7 percent of global annual revenue. For other breaches of obligations, graduated maximum limits apply.
The specific penalties are determined, among other factors, by the company’s size, the severity, duration, and consequences of the violation. Special limitation rules apply to small and medium-sized enterprises. The provisions in Article 99 of the EU AI Act are decisive.
But what does this mean in practice? Companies need more than just legal assessments. They must translate these requirements into operational processes, technical controls, and documented responsibilities. This is precisely what AI governance achieves.
How are AI governance and data protection related?
AI systems often process personal data. In such cases, the GDPR remains applicable alongside the AI Act. Both sets of regulations pursue different, but partially overlapping, objectives.
Before deployment, you should check, among other things:
Is there a legal basis for the processing?
What personal data is fed into the AI system?
Is the purpose of use clearly defined?
Is data used to train an external model?
In which countries does the provider process the data?
How long are inputs and outputs stored?
Can data subjects exercise their rights?
Is a data protection impact assessment required?
Does the system make decisions with legal or similarly significant effects?
Data protection must not be assessed only shortly before the system goes live. It must be incorporated from the very beginning—during selection, design, and development. This approach is often referred to as “Privacy by Design.”
Why are transparency and explainability so important?
Transparency means that relevant stakeholders can understand where, why, and under what conditions AI is used. Explainability goes a step further: it describes the extent to which individual results or the general functioning of a system can be presented in an understandable way.
Not everyone needs the same information. A developer requires different details than a customer, a data protection officer, or senior management. Good AI governance therefore defines transparency tailored to specific target groups.
This includes, for example:
the purpose and limitations of the AI system,
the types of data used,
the responsible organizational unit,
key performance indicators,
known error risks,
Required human checks,
Labeling of AI-generated content,
complaint and escalation procedures.
Transparency also helps identify risks early on. If a company is not familiar with its AI applications, it cannot evaluate or monitor them.
What should be included in a central AI registry?
An AI registry documents all known AI systems and AI use cases within the company. It thus serves as an essential foundation for AI compliance and risk management.
For each entry, you should include at least the following information:
Name and description of the application,
business purpose,
responsible department,
technical operator,
manufacturer or external provider,
model used,
affected user groups,
Types of data processed,
whether the data is personally identifiable,
Risk class under the EU AI Act,
Status of the legal review,
Required human oversight,
Interfaces with other systems,
Date of last review,
planned changes and maintenance cycles.
The registry should cover both in-house AI solutions and purchased services. This also includes features that vendors integrate into existing software products at a later date.
How do you identify undisclosed AI applications within the company?
An empty AI registry doesn’t mean that AI isn’t being used. Often, numerous undocumented tools already exist. This so-called “shadow AI” arises when employees use AI without formal approval.
An assessment can combine several methods:
Survey of business units
Analysis of existing software contracts
Review of cloud and SaaS services
Evaluation of approved browser extensions
Workshops with IT, procurement, and data protection
Investigation of existing automation processes
Technical monitoring of data traffic within legally permissible limits
Communication is crucial here. If employees fear sanctions, they may not report applications. Therefore, explain that the AI registry is intended to enable safe use, not to prevent it across the board.
What Responsibilities Are Required for AI Governance?
Unclear responsibilities lead to delays and gaps in oversight. A governance model should therefore clearly define who is responsible for providing information, who is involved, and who has decision-making authority.
Executive Management
Senior management defines the AI strategy, risk appetite, and fundamental guidelines. It allocates resources and bears overall responsibility for ensuring appropriate organizational structure.
AI Governance Board
An AI Governance Board is a cross-functional decision-making body. It may include representatives from IT, legal, data protection, information security, compliance, risk management, human resources, and business units.
The board decides, for example, on:
particularly high-risk AI use cases,
exceptions to guidelines,
group-wide standards,
escalations and serious incidents,
priorities for governance measures,
AI Owners in the Business Unit
A business owner should be designated for each use case. This person is responsible for the purpose, business quality, and intended use of the application.
IT and AI Development
Technical teams implement requirements related to architecture, security, logging, testing, and maintenance. They document models and monitor technical performance metrics.
Data Protection, Legal, and Compliance
These functions assess legal and contractual requirements. They should be involved early on and in a risk-based manner.
Users
Users also bear responsibility. They must be aware of the systems’ limitations, be able to appropriately verify results, and report incidents.
What does a sensible approval process look like?
Not every AI application requires the same level of scrutiny. A translation tool for public texts has a different risk profile than a system that pre-screens job applicants.
A tiered approval process might look like this:
Submit a use case: The department describes the purpose, data, and users.
Conduct a preliminary review: A short questionnaire identifies initial risks.
Determine the risk class: The company evaluates legal and internal criteria.
Initiate specialized reviews: Data protection, security, legal, or employee representative departments review as needed.
Define controls: Responsible parties establish tests, approvals, and human oversight.
Document the decision: An authorized body approves, restricts, or prohibits the use.
Monitor operations: The team monitors performance, risks, and changes.
Re-evaluate the application: Significant changes trigger a new review.
Standardized end-to-end processes reduce the need for follow-up questions. At the same time, they prevent each team from developing its own governance practices.
How do you assess the risks of AI systems?
Risk management doesn’t just consider the probability of an error. It also assesses its potential impact on people, businesses, and the environment.
Relevant risk dimensions include:
legal and regulatory risks,
data protection risks,
information security,
discrimination and fairness,
erroneous or misleading results,
lack of explainability,
financial implications,
Reputational damage,
dependence on providers,
adverse effects on employees or customers,
energy and resource consumption.
A simple scoring system can combine the probability of occurrence and the severity of the impact. High-risk use cases require an in-depth assessment, documented measures, and closer monitoring.
The context of use is also important. The same model may pose a low risk when summarizing a public document but could have significant consequences when used for medical recommendations.
How do you ensure fairness and non-discrimination?
AI models learn from data. If this data contains historical biases, the model may adopt or reinforce them. This is particularly relevant when making decisions regarding employment, loans, insurance, or access to services.
Appropriate measures include:
Checking training and test data for representativeness,
Evaluating relevant groups separately,
Establishing fairness metrics,
having results reviewed by experts,
examining characteristics that may indirectly discriminate,
allow for complaints and corrections,
monitor model performance after deployment.
Fairness cannot be addressed through technical means alone. Different fairness criteria may contradict one another. Therefore, subject matter experts, data experts, legal counsel, and affected stakeholders must work together to determine what is considered appropriate in each specific context.
Why is human oversight still necessary?
Human oversight does not mean that a person mechanically confirms every AI result. Mere confirmation without genuine review does not constitute effective oversight.
Oversight only works if the person in charge:
understands how the system works and its limitations,
receives sufficient information to make a decision,
can actually question the results,
has time to review the results,
is allowed to reject or correct a recommendation,
and can escalate an incident.
A real-world example: An AI system prioritizes incoming damage reports. The case handler should be able to determine why a case was assigned a low priority. They must be able to change the classification if important information is missing or the result is implausible.
What AI policies do companies need?
A core AI policy outlines the basic rules for using AI. It should be written in a way that is easy to understand and action-oriented.
Typical content includes:
permitted and prohibited uses,
handling of confidential data,
rules for generative AI,
labeling of AI-generated content,
Requirements for human oversight,
Approval and procurement processes,
Documentation requirements,
Security and data protection requirements,
Reporting channels for errors and incidents,
Consequences for violations.
In addition, specific standards for development, model validation, prompt engineering, vendor vetting, or the use of generative AI may be appropriate.
Guidelines alone, however, are not enough. They must be translated into concrete processes, technical configurations, and training programs.
How do you manage generative AI?
Generative AI creates new content such as text, images, program code, or audio. Its use carries specific risks. These include hallucinations, unclear copyright issues, prompt injection, and the unintentional disclosure of confidential information. A governance framework for generative AI should specify, among other things:
which tools are approved,
what data may be entered,
when results must be reviewed,
how sources are verified,
whether AI-generated content is labeled,
how code is tested before being implemented,
whether providers are allowed to use user input for their training,
which plug-ins and interfaces are permitted.
For simple text drafts, minimal checks may suffice. However, if results are published or used for relevant decisions, a mandatory expert review is required.
How do you evaluate external AI providers?
Many companies do not develop AI in-house but instead source models or services from third parties. This does not absolve them of responsibility. Before making a purchase, you should conduct a structured evaluation of the provider. Important questions to ask include:
Where is data stored and processed?
Does the provider use input data for model training?
Which subcontractors are involved?
What security certifications are in place?
How does the provider report vulnerabilities and incidents?
What documentation does the provider make available for the model?
How are changes to the model announced?
What options are available for logging and deletion?
What are the roles of the provider and the customer under the AI Act?
Can data and processes be migrated at the end of the contract?
Regular review is necessary even after the contract is signed. Cloud-based AI models can change even if the company itself does not install a new version.
How do you monitor AI during operation?
Deployment is not the end of the governance process. Models can degrade in quality over time. This phenomenon is known as model drift. It occurs when real-world data or relationships change compared to the development phase.
Depending on the use case, monitoring should track:
accuracy and error rates,
frequency of human corrections,
performance differences between groups,
unusual inputs and outputs,
data protection and security incidents,
user complaints,
Changes to the model or provider’s service,
availability and response times,
Use outside the approved purpose.
Define thresholds for each metric. If a value is exceeded, it must be clear who will investigate and what actions will follow. These can range from an additional check to a temporary shutdown.
What Does AI Incident Management Entail?
An AI incident can be a data breach, a discriminatory decision, a systematic error, or model manipulation. Existing processes for IT and data protection incidents provide a good foundation but must be supplemented with AI-specific aspects.
A complete process includes:
Detecting and reporting the incident
Mitigating the impact
Identifying affected systems and data
Analyzing technical and business causes
Reviewing internal and legal reporting requirements
Inform those affected appropriately
Correct errors
Adjust controls and guidelines
Document findings
Employees need an easily accessible reporting channel. If it is unclear whether a suspicious AI output constitutes an incident, it should still be possible to report it.
What AI skills do employees need?
The EU AI Act requires providers and operators to implement measures that ensure a sufficient level of AI competence among the individuals involved. Specific training should be tailored to the individual’s role, knowledge, context of use, and risks.
A general introduction can cover the following topics:
the basic functioning of artificial intelligence,
limitations and common errors,
data protection and information security,
permissible AI tools,
review of generated content,
internal reporting and approval processes.
Developers also need knowledge of data quality, robustness, and model testing. Managers must understand risks, responsibilities, and regulatory implications. Individuals who monitor high-risk systems need application-specific training. A one-time e-learning course is rarely sufficient. AI technologies, laws, and internal applications are constantly evolving. To ensure your employees are confident in working with AI
What metrics can you use to measure AI governance?
Governance can only be effectively managed once the company establishes appropriate metrics. Possible indicators include:
Percentage of registered AI systems,
Percentage of use cases that have been fully evaluated,
Average duration of an approval process,
Number of open high-risk measures,
Percentage of trained employees,
Number of reported AI incidents,
Frequency of human corrections,
Number of unapproved AI tools,
Percentage of applications reviewed on time,
Time to resolve critical findings.
Key performance indicators must not create false incentives. For example, a low number of reported incidents could also mean that employees are failing to recognize or report problems.
What common mistakes should you avoid?
In our AI consulting work, we frequently encounter situations where companies have already attempted to implement AI but hit a wall when it comes to governance. In some cases, clients have reached out to us after they’ve already had to pay hefty fines. We see these mistakes time and time again:
Mistake #1: Viewing governance solely as a legal project
The use of AI involves technology, data, processes, and people. A purely legal perspective is therefore insufficient.
Mistake #2: All applications go through the same process
An overly complex process slows down low-risk use cases and encourages “shadow AI.” Instead, use tiered requirements.
Mistake #3: Responsibilities remain abstract
A committee without clear decision-making authority does not solve problems. Define specific roles and escalation paths for each process.
Mistake #4: The AI registry is not maintained
An outdated registry only provides the appearance of transparency. Link updates to procurement, changes, and regular reviews.
Mistake #5: Documentation Is Created Only After the Fact
Retrospective documentation is error-prone and time-consuming. Integrate it directly into development and approval processes.
Mistake #6: Human oversight exists only on paper
A person who cannot understand or change decisions does not provide genuine oversight.
What best practices have proven effective?
Successful AI governance is guided by a few consistently applied principles:
Take a risk-based approach: The greater the potential impact, the stricter the controls.
Leverage existing structures: Avoid duplicating efforts in data protection, IT security, and procurement.
Assess early: Incorporate governance right from the concept stage, not just before go-live.
Clearly assign responsibility: Every use case requires a subject-matter owner.
Establish central transparency: Record all AI systems in an AI registry.
Automate controls: Integrate checks into development and procurement processes.
Involve users: Systematically evaluate feedback and complaints.
Update regularly: Models, risks, requirements, and laws change.
Start pragmatically: A minimally viable model is better than a perfect framework that is never implemented.
Case Study: AI Governance in Human Resources
A company wants to use generative AI to draft job postings and summarize application materials.
First, it distinguishes between the different use cases:
Creating an initial draft of a job posting is relatively low-risk, provided that a specialist reviews the text. The automated evaluation or ranking of applicants, on the other hand, may fall under the high-risk provisions of the AI Act and raises sensitive issues of fairness and data protection.
The company therefore stipulates:
Applicant data may only be processed in approved systems.
The model may not make a final hiring decision.
Criteria and results are documented.
HR staff review every recommendation.
The system is reviewed for potential bias.
Applicants receive the necessary information about the use of AI.
Changes to the model trigger a re-evaluation.
This example shows that technology alone does not determine the risk. The purpose, data, impact, and degree of human oversight are decisive factors.
How can a company remain capable of taking action despite AI governance?
Governance often fails due to too many manual approvals. The goal should therefore be “governance by design.” In this approach, requirements are directly integrated into technical and organizational processes.
Here’s an example: When ordering a new software service, the procurement workflow automatically checks whether the product contains AI features. If the answer is yes, an entry is created in the AI registry and the risk-based review begins. The business unit doesn’t have to search for a separate process.
Similarly, controls can be integrated into development platforms. Model maps, test results, and approvals can become part of the continuous integration pipeline. In this way, governance becomes part of everyday work rather than being perceived as an additional task performed after the fact.
AI Governance Establishes Reliable Guidelines
AI governance ensures the safe, ethical, and legally compliant use of artificial intelligence. It encompasses far more than a single policy. Companies need a coordinated system of responsibilities, risk classification, an AI registry, approval processes, technical controls, and ongoing monitoring.
The EU AI Act increases the pressure to act. At the same time, governance should not be viewed solely as a compliance task. Clear guidelines accelerate responsible AI initiatives because teams are aware of requirements and decision-making processes from the very beginning.
Start by taking stock, inventorying your AI systems, and prioritizing use cases with high impact. Then, continue to develop your AI governance framework step by step. This way, your company remains capable of taking action without losing sight of risks, data protection, or human responsibility.
Are you unsure how and where to get started with AI? Reach out to us, and we’ll put our experts at your disposal! With our experience from numerous AI consulting projects, we’ll ensure that you implement AI in compliance with regulations!
FAQ: Frequently Asked Questions About AI Governance
AI governance encompasses all the rules, roles, and controls an organization uses to manage artificial intelligence. Among other things, it defines which systems may be used, who is responsible for them, and how risks are monitored.
There is no general requirement to implement a system called “AI governance.” However, the EU AI Act and other laws mandate numerous organizational and technical measures. A governance framework helps ensure these requirements are implemented in a structured manner.
The AI Act may apply to providers, operators, importers, and distributors of AI systems. It also has extraterritorial effect. Under certain conditions, therefore, companies outside the EU may also be affected.
An AI registry is a central directory of all AI systems and AI use cases within a company. Among other things, it documents the purpose, responsible parties, data, providers, risk class, and audit status.
Overall responsibility lies with senior management. Operational implementation is typically divided among business units, IT, AI development, data protection, legal, compliance, information security, and risk management. Each use case should have a clearly designated owner.
Not necessarily. A small company can consolidate responsibilities within an existing committee. Larger or highly regulated organizations often benefit from a cross-functional AI governance board with clear decision-making authority.
AI compliance focuses on adherence to legal, contractual, and internal requirements. AI governance is broader; it also encompasses strategy, responsibilities, risk management, technical oversight, and ongoing monitoring.
The interval depends on the risk. High-risk or frequently modified systems require more frequent audits. In addition, a new audit should be conducted if there are significant changes to the model, provider, data, purpose, or affected user groups.
That depends on the tool, the contract, and the type of data. Confidential or personal information should only be entered into systems that have been expressly approved. Before doing so, you should review data protection, security, storage location, and the potential use of the data for model training.
Shadow AI refers to AI applications that employees use without official approval or the knowledge of the relevant departments. It can lead to data leaks, compliance violations, and uncontrolled dependencies on vendors.
ISO/IEC 42001 for AI management systems, ISO/IEC 23894 for AI risk management, and the NIST AI Risk Management Framework provide important guidance. Companies should adapt these approaches to their specific organizational context and legal requirements.
Start by taking stock of the current situation. Determine which AI applications are already in use or planned, who is responsible for them, and what data they process. Based on this information, you can prioritize risks and establish appropriate governance structures.