AI Governance

AI Governance

The governance layer that now sits over every AI system — the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, translated into inventories, model classification, risk tiering, human oversight and AI impact assessment.

Articles

3 articles in this section.

Assessment
AI Impact Assessments in Practice

How to run an AI impact assessment that changes a deployment decision — screening, the sections that matter, and integrating with the DPIA you already run.

1 Jul 2025 · 2 min read

Read →
Regulation
EU AI Act Readiness

The EU AI Act risk tiers, who carries which obligation, and how to build a readiness program that fits alongside an existing GDPR compliance program.

10 Jun 2025 · 2 min read

Read →
Framework
Building an AI Governance Framework with ISO/IEC 42001

AI inventories, model classification, risk tiering and human oversight — building an AI management system under ISO/IEC 42001 on top of an existing data privacy program.

20 May 2025 · 2 min read

Read →

AI governance, built on the data privacy program you already have

Most organizations do not need a second governance function for AI. They need the existing data privacy program extended — the same inventory discipline, the same impact assessment habit, the same evidence trail, applied to models instead of processing activities.