AI Governance Built on Owners, Inventory, Cadence
AI governance is named owners, written policy, risk-tiered approvals, a living inventory, and a review cadence that continues after go-live.

AI governance is named owners, written policy, risk-tiered approvals, a living inventory, and a review cadence that continues after go-live.

AI governance is named owners, written policy, risk-tiered approvals, a living inventory, and a review cadence that continues after go-live. The NIST AI RMF treats inventory as a Govern control, and ISO/IEC 42001 is a certifiable management system that does not replace law. Flexera reports that only 31% of organizations see the AI software already in use.
This page is an operating guide for product, engineering, and strategy teams. It is not legal advice and not a GRC catalog.
GovAI is a frontier-research nonprofit. An IAPP AIGP credential is not an operating system.
The job is turning principles into work you can staff: who is accountable, which uses are allowed, which systems may ship, what you can prove later, and how often you re-open those decisions. IEEE puts the split cleanly.
Ethics asks what you should do. Governance asks how you make sure it gets done: roles, audit trails, monitoring, incident response, compliance.
The work sits on seven primitives. You name an owner who stays accountable through decommission. You write policy that matches evidence you actually collect.
You run risk-tiered approvals that do not stop at go-live. You keep a living inventory of built, bought, embedded, and agent systems. You attach controls and monitoring, then you meet on a cadence you chose, with artifacts a board or auditor can read.
Responsible AI is the principle layer. The enterprise system that enforces it is governance. Data governance (quality, lineage, stewardship) is a prerequisite, not a synonym.
AI security is the cluster sibling that watches runtime behavior. Keep those four labels in separate registers.
Untracked tools are already inside the company. Flexera defines shadow AI as any AI tool, model, or agent used for work without IT, security, or compliance review.
That is an inventory failure, not a culture essay.
Boards are putting AI on the agenda without putting money or disruption analysis behind it. In NACD’s 2025 board survey, more than 62% of director respondents (n=211) set aside agenda time for AI. Only 23% had assessed how AI disruption might happen.
Agenda time is not a budget. ROI uncertainty was the top adoption roadblock for 32% of directors, and an annual AI budget had been approved by 11%.
The legal stack moved in 2025 and 2026 while glossary pages still describe 2023. NIST is revising AI RMF 1.0 under the White House AI Action Plan.
OMB replaced M-24-10 with M-25-21 (use and governance) and M-25-22 (acquisition). The EU AI Act phases in through 2 August 2028.
If you are standing up AI solutions without an owner and an inventory, you are scaling a system you cannot pause.
AI ethics and responsible AI are value statements and design principles. They do not name the person who signs decommission, the fields in the inventory, or the evidence pack for a quarterly review.
UNESCO’s Recommendation (November 2021) is an ethics instrument. It is not a cadence.
Data governance owns definitions, lineage, and stewardship of the data models consume. Put a new model into production and you find the datasets that still have no owner.
That work is required. It is not the same register as “which agents can send email.”
Runtime security and LLM observability answer whether a call was permitted, whether a trace looks healthy, and whether cost or quality drifted. The remaining questions sit with the program: whether the action should have happened, who owns the alert, and which policy the exception sits under.
Glossary pages stay at definitions. The job is seven primitives you can staff, write down, and run.
RACI allows many Responsible people. Accountable is one named person from approval through decommission.
CDO Magazine (Rehan Kausar, updated 29 May 2026) treats “the AI governance committee owns this” as a control gap under examination. Committees coordinate. They do not own.
Keep both layers. The board or executive sponsor sets risk appetite. A CAIO or delegate runs the program.
A model owner owns a specific system’s lifecycle. Legal, security, and product sit in the review path. NIST GOVERN 2.1-2.3 asks for documented roles and for executive leadership to take responsibility.
A CAIO is one owner pattern, not the whole program. Public-sector analogue: M-25-21 required a CAIO within 60 days and, for CFO Act agencies, governance boards within 90 days.
Private-sector example: Joe Atkinson, PwC Global Chief AI Officer.
On r/sysadmin, ownership still bounces: security owns data exposure, legal owns vendor terms, engineering owns the IDE. The recurring correction is that IT enforces a business policy. IT does not invent the policy in a vacuum.
Policy is a stack, not a PDF. Microsoft CAF is a usable skeleton: model select and onboard, third-party tools and data, maintain/monitor/retrain frequency by risk, regional compliance, and user conduct (acceptable use).
ISO 42001 puts an AI-policy clause inside a certifiable AI management system. Torys treats data governance as a prerequisite. Boards approve policy and risk appetite; they do not draft prompt rules.
Write what you can prove. Scope, allowed and forbidden uses, data classes, human-in-the-loop, vendor AI, the exception path, and the evidence you already collect.
A policy that claims every AI use is logged becomes an audit finding the moment logging does not exist. Narrow the PDF to evidenced scope. Put the rest on a dated plan.
Employee use is still confused with product SKUs. A personal ChatGPT Plus seat is not a business tenant. OpenAI says it does not train on ChatGPT Enterprise, Business, or Edu workspace data by default.
Finance approval of a card spend is not IT approval of a processing agreement. Pair the written AUP with one official tenant that can take a no-training contract, then train people the way you train phishing awareness.
Intake is risk-tiered: what can ship with no ticket, what needs a privacy or security review, what needs the committee. That is the start of the control, not the end.
NIST GOVERN 1.5 requires ongoing monitoring and periodic review, including that you determine the frequency. It does not prescribe monthly versus quarterly.
M-25-21 requires an AI impact assessment before deploying high-impact AI, then updates throughout the lifecycle. Agencies must discontinue non-compliant high-impact AI until they meet the minimum practices, and cease it when proper risk mitigation is not possible.
COSO (23 February 2026) maps the Internal Control Integrated Framework onto generative AI. EY (25 June 2026) is blunt: evidence the decision path (inputs, model output, human review, exceptions), not only the recorded outcome.
Microsoft now treats agents as needing identities, tool permissions, and monitoring of actions, not just model metrics. Register at creation. Bind an owner and a use case, and keep the approval in force while the agent runs.
NIST GOVERN 1.6 is the official inventory control: mechanisms to inventory AI systems, resourced to organizational risk priorities. The register is a living system of record.
It covers trained models, bought tools, embedded SaaS AI, browser extensions, and agents. It is not a list of what the ML team trained last year.
Starting fields, drawn from the UK Enzai catalogue pattern and related glossaries:
Field | Why it exists |
|---|---|
Named owner | Accountable through decommission |
Purpose / use case | Risk-proportional approval |
Data sources and sensitivity | Training terms and leakage path |
Risk classification | Intake path and review depth |
Production status | Catch “deprecated” systems still serving |
Regulatory mapping | EU tier, high-impact, AIMS clause |
Last review date | The frequency you set under GOVERN 1.5 |
Known limitations | Model-card facts, not slideware |
Approval records | Decision-path evidence |
Agent tool-reach | Every tool, database, and outbound channel |
Program-level work is not the same as model governance. The production question is how many systems are running, not how many notebooks got tagged.
Owner defaults to whoever built it until that person leaves. Model cards are a documentation control inside the inventory, not a second article.
Agents change the unit of risk. MCP connections, servers, and tool-calling loops mean you can know the model and still miss the agent.
If you cannot list every tool, database, and email an agent can reach, you know the model’s risk. You do not know the agent’s. That gap shows up fast once agentic workflows leave a demo and start calling tools.
Controls are operational: access, evals, logging, drift, human override, vendor-AI usage, red team, incident loop. The genAI surface is prompts, outputs, retrieval data, third-party providers, and agent decisions.
An HTTP 200 is not health for a non-deterministic multi-step agent. Put traces and quality scores in LLM observability.
On LinkedIn, GRC practitioners keep the split: observability answers whether a call was permitted. Governance answers whether it should have happened, and who owns the alert.
Cadence is two clocks. Decision rights, accountability, and policy enforcement are the governance clock. The operating model is how you organize the work (CAIO, committee, center of excellence, model owners).
Those choices live inside the same program.
NIST does not prescribe monthly versus quarterly in 1.0. You set the frequency.
Public artifacts you can copy without inventing a vendor calendar: the FTC board charter (signed 30 July 2025) meets at minimum once per quarter. Inventory and material risks sit on an annual board cycle.
Model owners review faster than the committee. The committee reviews faster than the board.
Stanford CodeX’s 2026 note is the honest constraint: operators must reconcile instruments that do not talk to each other. Treat OECD, UNESCO, NIST RMF, ISO 42001, and IEEE 7000 as complementary stacks, not competing titles.
Use four as the operating map. Leave IEEE 7000 off the spine.
Instrument | What it is | Operating hook |
|---|---|---|
Voluntary risk framework, being revised | GOVERN 1.5 review frequency; GOVERN 1.6 inventory | |
Certifiable AI management system | Overlay AIMS; does not replace law | |
Binding risk-tier law | Extra-territorial hook is Article 2; dates through 2028 | |
Intergovernmental principles (2019, updated 2024) | Policy inputs, not a meeting cadence | |
U.S. federal use and governance memo (April 2025) | CAIO, boards, high-impact inventories; replaced M-24-10 |
NIST.AI.100-1 shipped 26 January 2023. Four functions: GOVERN, MAP, MEASURE, MANAGE. GOVERN is cross-cutting.
The GenAI profile NIST.AI.600-1 followed on 26 July 2024. As of 2026, NIST states that RMF 1.0 is being revised as part of the White House AI Action Plan. The 1.0 publication already scheduled a formal community review no later than 2028.
Elham Tabassi led the RMF work at NIST (Chief AI Advisor through March 2025) and is now at Brookings. Private-sector teams are not required to adopt the RMF. It is voluntary.
NIST still publishes an official RMF-42001 crosswalk.
ISO/IEC 42001:2023 (Edition 1, December 2023) is the first AI management-system standard. You can certify the management system. ISO’s own explainer says the standard does not replace laws or regulations.
Related documents (22989 terminology, 23053 ML, 23894 AI risk) sit around it. Overlay 42001 on NIST.
The EU AI Act is Regulation (EU) 2024/1689. Four risk levels: unacceptable, high, limited, minimal. Provider versus deployer.
Extra-territorial application is Article 2 (placing on the market, putting into service, or use in the Union).
The European AI Office enforces general-purpose AI. Member State authorities cover the rest.
Article 99 requires Member States to lay down effective, proportionate, dissuasive penalties and sets upper limits in paragraphs 3-5. Use the official article, not vendor paraphrases of euro caps.
Use the Service Desk timeline, not folklore that treats August 2026 as the high-risk cliff.
Date | What applies |
|---|---|
1 August 2024 | Entry into force |
2 February 2025 | General provisions, prohibitions, AI literacy |
2 August 2025 | GPAI rules, national competent authorities, penalty laws, EU-level governance |
2 August 2026 | Majority of rules and enforcement, including Article 50 transparency |
2 December 2026 | New prohibitions and Article 50(2) transition |
2 December 2027 | Annex III high-risk |
2 August 2028 | Annex I product-embedded high-risk |
OECD AI Principles (LEGAL/0449) were adopted 22 May 2019 and updated in 2024: five values-based principles plus five policy recommendations. The February 2026 guidance maps six MNE responsible-business-conduct steps.
By May 2023, governments had reported 1,000+ policy initiatives across 70+ jurisdictions in OECD.AI. That is OECD-stated scale, not a census of enforcement.
U.S. federal practice is the operating example, not your private-sector statute. Executive Order 14179 (23 January 2025) directed OMB to revise Biden-era memos.
M-25-21 and M-25-22 issued in April 2025. M-25-21 rescinded M-24-10; M-25-22 rescinded M-24-18. Load-bearing pieces include a CAIO within 60 days.
CFO Act agencies stand up governance boards in 90 days and a barrier-removal strategy in 180 days. High-impact AI folds the former rights-impacting and safety-impacting categories.
Agencies had 365 days from issuance to document minimum practices for high-impact AI. They must cease it when proper risk mitigation is not possible. Waivers require public disclosure.
The new memos do not mention NIST. Private-sector teams can still use the RMF as a voluntary backbone.
GSA publishes a three-body sketch (CAIO, Governance Board, Oversight Committee) if you need a public org chart to steal from.
Shadow AI is any AI tool, model, or agent used for work without review. Flexera lists personal ChatGPT, Claude, Copilot, or Gemini seats, plus AI features toggled inside already-licensed SaaS.
The same inventory also covers browser extensions, personal coding assistants on company repos, personal API keys, meeting notetakers, uncleared service accounts, and MCP agents with real permissions.
Versus classic shadow IT, there is often no new spend, no new domain, and no new DNS name to block.
On r/sysadmin, the recurring failure is a Chrome wrapper users install with no admin rights, then a cloud model trains on meeting recordings. Copilot-only shops push the real work onto personal phones, which destroys the visibility the block was supposed to create.
The rollout order that holds is inventory first, policy second, block third, with a request path. A block with no intake teaches people to hide.
Literacy sits next to shadow AI as the other high-volume people problem. The EU Act’s 2 February 2025 duties already include AI literacy.
Inside a company, literacy is an enablement sandwich. Pair an enterprise tenant (no-training DPA and SSO) with DLP or CASB on the way out. Train people the way you train phishing awareness, not as an ethics seminar.
Platforms exist that automate inventory and evidence. Gartner published an inaugural Magic Quadrant for AI Governance Platforms in June 2026.
Use a platform to run the register if you need one. The operating system stays the seven primitives.
You do not need a vendor case study to see the seven primitives in one document.
The FTC board charter (signed 30 July 2025 by Mark Gray, citing M-25-22) names a board, points at a federal memo, and meets at least quarterly. That is cadence with an artifact.
M-25-21 names a CAIO on a 60-day clock and a board on a 90-day clock for CFO Act agencies. It also expands inventories and sets a 365-day clock to document minimum practices for high-impact AI.
Non-compliant high-impact AI must be discontinued until it meets those practices, and ceased when mitigation is not possible. Approvals are not a one-time gate: complete an impact assessment before deploying high-impact AI, then update it throughout the lifecycle.
Steal the shape, not the statute. Private-sector teams still need a named owner per system, a written policy whose claims match logs, an inventory that includes agents, and a quarterly pack that shows reviews, exceptions, and nil returns.
The federal memos stopped pointing at NIST. Your charter does not have to.
A steering committee that “owns AI” lets every function say the decision was not theirs. Put Accountable on one named person per system, from approval through decommission, and let the committee coordinate.
If you cannot name the human who would sign the shutdown, you do not have an owner.
“All AI use is logged” is an audit finding when logging does not exist. Write the PDF to the controls you run today.
Put the rest on a dated build plan. Over-claiming in the policy is worse than a small evidenced scope.
The register that lists three fine-tunes and misses Copilot, a meeting notetaker, and an MCP agent with mailbox access is a decorative spreadsheet. GOVERN 1.6 is resourced inventory of AI systems.
Agents need tool-reach, not just a model name.
Intake is necessary. It is not sufficient.
NIST GOVERN 1.5 requires you to set periodic-review frequency. COSO and EY want the decision path (inputs, output, human review, exceptions, changes), not a screenshot of the approval ticket.
A Copilot-only allowlist with no intake teaches directors to tell staff to use personal Claude. Inventory, then policy, then block, with a fast request form.
The slightly worse official tool that people actually use beats a perfect unused standard.

Run enterprise AI as a Fund, Defer, or Kill portfolio. Covers operating models, platform layers, shadow AI, and conflicting ROI numbers.

Prompt engineering is how you spec, evaluate, and version LLM behavior in production. Covers CoT caveats, prompt injection, and when RAG or fine-tuning wins.

88% of organizations use AI, but only 12% of CEOs report real ROI. A function-by-function implementation guide covering tools, frameworks, and company-size play