According to a McKinsey study (“The State of AI in 2025”), 88% of organizations worldwide had integrated AI into their operations by 2025, up from 78% a year earlier. ChatGPT, Copilot, AI agents connected to business tools, self-hosted models: AI has spread throughout the enterprise faster than the mechanisms intended to govern it. For a CISO or CIO, the question is no longer “Should we govern AI?” but “Where do we start, and what should our priorities be?”
This guide sets out a comprehensive framework for AI governance in the enterprise, centered on four interrelated dimensions:
- The organization (who makes decisions, who is responsible)
- Risk management (what could happen, and how to mitigate it);
- Regulatory compliance (what the law requires)
- Technical Inspections (How the Rules Are Applied in Practice)
To learn more, check out our other blog posts.
Important clarification regarding the regulatory timeline: Many articles published between January and May 2026 cite August 2, 2026, as the deadline for all “high-risk” obligations under the EU AI Act. This deadline has been changed: the Digital Omnibus, which was definitively adopted in late June 2026, postpones the high-risk obligations in Annex III to December 2, 2027. Details are provided in the compliance section below and in our article dedicated to the EU AI Act.
What is AI governance in business?
AI governance refers to the set of rules, roles, processes, and tools that enable an organization to make decisions about, oversee, track, and control the use of artificial intelligence—whether it involves consumer-grade tools used by employees (ChatGPT, Copilot, Gemini), business solutions that incorporate AI (CRM, HR, scoring), or internally developed systems (AI agents, RAG, fine-tuned models).
It differs from traditional IT governance in three ways:
- Speed of Adoption: An employee can set up an AI tool (personal ChatGPT account, browser extension, no-code agent) without going through the IT department, unlike with traditional business software.
- The probabilistic nature of risk: An LLM can hallucinate, be manipulated through prompt injection, or disclose data through channels not anticipated during its design—risks that have no direct equivalent in traditional application governance.
- Regulatory Convergence: A single AI system may be subject simultaneously to the GDPR (if it processes personal data), the EU AI Act (depending on its risk level), NIS2 (if the company is an operator of essential services), and sector-specific standards.
In practical terms, governing AI in a business involves answering four fundamental questions, which form the four pillars detailed in this guide: Who makes decisions and who is responsible (organization), what risks exist and how to address them (risk management), what legal obligations apply (compliance), and how the rules are actually applied on a day-to-day basis (technical controls).
Pillar 1 – Organizational Framework: Who Makes Decisions, Who Is Responsible
The first building block of any AI governance framework is not technical—it is organizational. Without clear roles and responsibilities, no AI policy will survive the first ambiguous use case.
Establish an AI Governance Committee
Most mature companies structure their governance around a multidisciplinary committee that brings together the CIO, the CISO, the DPO, the legal department, and business representatives. This committee has three main responsibilities: approving new AI use cases prior to deployment, ruling on exceptions, and maintaining an up-to-date registry of the AI systems used within the company (often referred to as the “AI inventory” or “AI registry”).
Clarify Responsibilities Using a RACI Matrix
Every deployed AI system should have an identified business owner (Accountable), a technical team responsible for its maintenance (Responsible), a security function consulted on risks (Consulted), and senior management informed of its uses (Informed). This clarification avoids the most common pitfall observed in companies: AI tools deployed without a clearly identified owner, and therefore without anyone to ensure their security over the long term.
Drafting an AI Usage Policy
The usage policy formalizes what is permitted, restricted, or prohibited: which consumer-grade AI tools may be used, what data must never be entered into a prompt, and what approvals are required before deploying an AI agent connected to internal systems. This is the reference document that is binding on employees, and it is often the first deliverable produced during an AI governance consulting project.
Pillar 2 – Risk Management: Map Risks Before They Strike
Effective AI governance begins with an honest assessment of actual uses, not just stated uses.
The Problem with Shadow AI
Shadow AI—the use of artificial intelligence tools by employees outside of any framework approved by the IT department—is currently the biggest blind spot in AI governance. An employee who pastes an excerpt from a customer contract into ChatGPT to summarize it, or who connects a no-code agent to their work email, creates an invisible risk for the CISO as long as no detection tools are in place. Mapping Shadow AI is therefore generally the operational starting point for a governance initiative: it allows organizations to measure the gap between stated policy and actual usage.
Structuring the Risk Analysis
Once use cases have been mapped, risk analysis can draw on proven methodologies: EBIOS RM for French organizations, supplemented by AI-specific frameworks such as MITRE ATLAS to model attack techniques against AI systems, orthe OWASP LLM Top 10 for application vulnerabilities in LLMs (prompt injection, data leakage via model outputs, RAG knowledge base poisoning). These frameworks are complementary: EBIOS RM structures the risk management approach at the organizational level, while OWASP and MITRE ATLAS document technical attack scenarios specific to AI.
Prioritize based on business impact
Not all AI applications carry the same level of risk. An internal FAQ chatbot does not require the same level of oversight as an autonomous AI agent connected to the CRM and capable of sending emails on behalf of the company. Risk prioritization should be based on the system’s level of autonomy and access to data, not solely on its popularity among users.
→ For more information: see our articles on Shadow AI and on managing AI-related risks.
Pillar 3 – Regulatory Compliance: What the Law Actually Requires in 2026
This is currently the most volatile area, and the one where unintentional misinformation spreads the fastest—much of the content published in the first half of 2026 became obsolete in just a few weeks.
EU AI Act: What Will Actually Change on August 2, 2026
The European Regulation on Artificial Intelligence entered into force on August 1, 2024, and is being implemented gradually. Two deadlines have long defined the timeline for 2026 in the specialized literature: February 2, 2025, for prohibited practices and the requirement for staff to be proficient in AI (already in effect), and August 2, 2026, for most of the obligations related to high-risk systems.
This second deadline was amended by the Digital Omnibus on AI, a legislative package proposed by the European Commission on November 19, 2025, to adjust the implementation schedule in light of delays in the publication of technical standards and guidelines. After several trilogue meetings, a political agreement was reached on May 7, 2026, endorsed by the European Parliament on June 16, 2026, and then finally adopted by the Council of the EU on June 29, 2026.
One point is worth noting for teams following this issue closely: negotiators initially struggled to define the exact scope of the exclusions (particularly machinery already covered by sector-specific regulations and medical devices), which explains why several trilogue meetings were necessary between November 2025 and May 2026 before a compromise was reached. The final text excludes safety components that are already CE-certified under other European regulations, in response to a strong request from several industrial sectors.
→ The article onthe EU AI Act details the classification of systems by risk level, the specific obligations for each profile (provider or deployer), and a preparation checklist.
ISO/IEC 42001: The AI Management System
ISO 42001 is the leading international standard for establishing an artificial intelligence management system (AIMS), following the same principle as ISO 27001 for information security. It is increasingly cited as evidence of maturity by clients and auditors, as a complement to—and not a replacement for—the legal requirements of the EU AI Act.
A company that is already ISO 27001-certified has a governance framework that can be largely reused to structure its ISO 42001 approach: Both standards share the same framework of continuous improvement cycles (PDCA), management reviews, and internal audits, which reduces the implementation burden for an organization that is already mature in information security.
Unlike the EU AI Act, ISO 42001 is a voluntary initiative: there are no penalties for non-compliance. Its value lies elsewhere: it is an internationally recognized common language for demonstrating to a client, partner, or investor that AI is governed in a structured manner, with auditable evidence rather than mere statements of intent.
GDPR and AI: Complementary, Not Redundant
The GDPR continues to apply in full whenever an AI system processes personal data, which is the case for the majority of enterprise deployments (HR, CRM, customer support). The EU AI Act does not replace the GDPR: the two regulations apply simultaneously and complement each other, with the former governing personal data and the latter governing the AI system itself.
NIS2: An Often-Overlooked Perspective
For organizations falling within the scope of NIS2 (operators of essential or important services), business-critical AI systems must be included in the scope of cybersecurity risk management required by the directive, along with the associated incident reporting obligations.
→ See our articles on ISO 42001, the GDPR, and AI, as well as NIS2 and AI, for details on each standard.
Pillar 4 – Technical Controls: Ensuring the Policy Is Implemented on a Daily Basis
A governance policy without accompanying technical controls remains merely a declarative document. Three categories of controls make AI governance operational:
- AI-Ready DLP: Data loss prevention (DLP) solutions must be expanded to cover AI-specific data flows: data entry into chat interfaces, outbound API calls to model providers, and document uploads to RAG tools. A DLP system designed for email and file storage does not natively cover these new vectors.
- API Key and Identity Management: Every connector, agent, or AI integration relies on API keys or machine identities that must be managed with the same rigor as privileged accounts: regular rotation, minimal scope, and prompt revocation in the event of an employee leaving or a change in scope. This is an often-overlooked control, yet it is one of the most well-documented vectors for data exfiltration in recent incidents involving AI agents.
- Logging and Traceability: Logging interactions with AI systems (prompts sent, responses generated, actions triggered by an agent) is essential both for investigating incidents and for meeting the traceability requirements of the EU AI Act and ISO 42001. This logging must be considered from the design phase, as it is very costly to add retroactively to a system that has already been deployed.
Roadmap: Where to Start in Practical Terms
For a company just beginning its AI governance initiative, the following order helps minimize blind spots:
- Map out actual uses, including Shadow AI, before drafting any policies.
- Form the governance committee and designate one owner per identified AI system.
- Assess andprioritize risks based on each system’s level of autonomy and access to data, not on its popularity.
- Assess the level of regulatory risk for each system under the EU AI Act (the 2027 deadline allows time to do this thoroughly rather than in a rush).
- Draft and distribute the user guidelines, along with related training for the teams.
- Deploy technical controls (DLP, IAM, logging) as a priority on the systems identified in Step 3 as posing the highest risk
- Document and audit regularly, as AI governance is an ongoing process rather than a one-time project.
An initial AI governance audit—often conducted over the course of a few days of consulting—typically helps define the first six steps before committing resources to more extensive technical controls.
Frequently Asked Questions About AI Governance in the Workplace
Is AI governance required by law?
There is no general requirement for “AI governance” as such, but rather a set of converging requirements: the EU AI Act requires a risk management system for high-risk systems, the GDPR requires governance of personal data processing, and NIS2 requires cybersecurity risk management for the entities concerned. In practice, establishing cross-functional AI governance is the most effective way to meet these obligations without addressing them in silos.
Do we have to wait until 2027 to prepare for the EU AI Act?
No. The extension of the deadline for high-risk bonds to December 2, 2027, provides an opportunity to develop a robust approach—not a reason to delay it. The transparency requirements under Article 50 take effect in August 2026, and properly mapping out at-risk systems takes several months to complete.
What is the difference between AI governance and AI security?
AI governance is the overarching framework (determining who makes decisions, what rules apply, and what compliance requirements exist); AI security—in the technical sense, including protection against prompt injection, jailbreaking, or data exfiltration—is one of the controls implemented through this governance. It is not possible to secure an AI system in the long term without upfront governance to define its acceptable level of risk.
Where should you start on a limited budget?
Mapping usage patterns (including Shadow AI) and drafting a usage policy are the two actions that deliver the greatest impact at the lowest cost. They do not require complex technical tools and lay the foundation for everything else.
Structuring Your GovernanceAI Governance
Our experts assist CISOs and CIOs in implementing a comprehensive AI governance framework: mapping use cases, assessing risks, and providing guidance on related technical controls. Learn more about our AI risk assessment services and our support for AI risk management.

