Knowledge Centre
AI GovernanceTrust & Compliance··4 min read

What is AI Governance?

Most organisations can produce their AI policy on demand. Far fewer can produce, with the same confidence, a list of the AI systems they actually run, the name of the person answerable for each one, and the date each was last reviewed. The gap between those two abilities is the gap between having AI governance and having a document about it.

What AI governance actually is

AI governance is the operating discipline by which an organisation stays in charge of the AI it uses. Stripped of ceremony, it has four working parts. An inventory: a live register of every AI system in use, including the ones that arrived embedded inside other products and the ones a team adopted without asking. Named ownership: one accountable person per system, not a committee, who can answer for what it does and decide what happens to it next. Risk classification: an honest sorting of each use by the harm it could do, so that a meeting-notes summariser and a candidate-screening model are not governed with the same energy, or the same neglect. And a review cadence: a recurring, diarised act of looking again, because models drift, uses spread, and the system you classified in spring is not the system running in autumn.

Everything else that travels under the governance banner (principles, ethics boards, policy documents) matters only insofar as it feeds those four parts. A principle that no inventory enforces is a hope.

Decisions about AI, not documents about AI

The defining test of governance is whether it produces decisions. Which uses are permitted here, and which are not. Which risk tier this system sits in, and on what grounds. Who may override its output, and how. When it will be reviewed next, and what would cause it to be retired. AI governance is a stream of recorded decisions about AI, made by named people on a known cadence. It is not a library of documents about AI. Documents describe intentions; decisions allocate accountability. When something goes wrong, the question asked will not be whether a policy existed. It will be who decided this use was acceptable, when, and on what evidence. An organisation with real governance answers in minutes.

What the EU AI Act changes

The EU AI Act turns much of this from good practice into legal obligation. The Act is risk-based: it prohibits a small set of uses outright, imposes substantial duties on high-risk AI systems (a category defined largely by a list of uses in Annex III), and asks much less of everything else. Employment and worker management sit on that list: tools that screen or filter applications, evaluate candidates, or inform decisions on promotion, task allocation and performance monitoring. For people businesses (recruitment, staffing, outsourcing) that is not an exotic edge case; it is the day job. High-risk status pulls in obligations that are, in essence, mandated governance: risk management, data governance, logging, human oversight, and documentation that proves all of it. The obligations phase in over several years and their detail is still being interpreted, so treat this entry as educational context, not legal advice. The practical direction, though, is settled: the four working parts above stop being optional for the systems that matter.

One concrete example

Clearly illustrative, with no customer implied. A staffing firm of a few hundred people runs its first AI inventory and finds roughly three times the systems it expected. Among them is a CV-screening feature a regional team switched on inside their existing recruitment tool two years ago. Nobody owns it; nobody has reviewed it; it quietly filters every application in that region. Governance, in this moment, is not writing a policy. It is a sequence of decisions: the operations director is named owner by Friday; the use is classified as high risk because it evaluates candidates; a human review gate is placed in front of its rejections; a quarterly review is diarised; and each of those decisions is recorded with who made it and why. When a client, a regulator or a rejected candidate later asks how the tool is governed, the firm has an answer that is not a shrug.

AI governance and decision intelligence

Seen this way, AI governance is a special case of a more general discipline. Classifying a system, permitting a use, overriding an output: these are consequential decisions, and they deserve what any consequential decision deserves. The evidence attached with its quality. The decision-maker named. The reasoning kept. The outcome revisited. That is the ground covered by decision provenance and a decision audit trail, and it is the stance ONX takes with its own AI: candidate matching in Hiring is treated as high risk under the strict reading of Annex III, with human review gates, and every AI conclusion is kept explainable and challengeable so the person at the gate has something real to review. Governance of AI and decision intelligence converge on the same sentence: know what you decided, who decided it, and on what evidence.

Common questions

What is AI governance?

AI governance is the operating discipline by which an organisation stays in charge of the AI it uses. In practice it has four working parts: a live inventory of every AI system in use, a named owner accountable for each one, an honest classification of each use by the harm it could do, and a recurring review cadence, because models drift and uses spread. Its output is recorded decisions about AI, not documents about AI.

How is AI governance different from an AI policy?

A policy states intentions; governance produces decisions. An organisation can hold an excellent policy and still be unable to say what AI it runs, who owns each system, or when each was last reviewed. Governance is the machinery that turns principles into named ownership, risk classification and scheduled review, and records each decision so it can be inspected later.

What belongs in an AI inventory?

Every AI system the organisation actually uses, including features embedded inside other products and tools adopted by individual teams without central approval. For each entry: what the system does, where its output lands, who owns it, which risk class it sits in, and when it was last reviewed. An inventory that only lists the officially procured systems misses the uses most likely to cause trouble.

Does the EU AI Act require AI governance?

In substance, yes, for the uses it treats as high risk. The Act is risk-based: a small set of practices is prohibited, high-risk uses (including many employment and worker-management uses listed in Annex III) carry obligations such as risk management, data governance, logging and human oversight, and lighter duties apply elsewhere. Those obligations amount to mandated governance for the systems that matter most. This is educational context, not legal advice.

Part of the pillarEnterprise Decision Intelligence, the complete philosophy in one essay

Related reading