Skip to main content
v2026.11,858 entries · CC-BY 4.0

What Is AI Governance? A Complete Guide to Principles, Roles, and Compliance

AI governance is the policies, roles, and processes that keep AI systems safe, legal, and accountable. This guide defines the core principles, the roles involved, the major regulatory frameworks (EU AI Act, NIST AI RMF, ISO/IEC 42001, US state laws), and where compliance work actually happens.

Written and maintained by CASRAI Editorial Board

Last updated

What AI governance means

AI governance is the set of policies, roles, and processes an organization puts in place to keep the AI systems it builds or uses safe, legal, and accountable. It is not a single document or a single team — it is the combination of written policy (what the organization has decided is and isn’t acceptable), assigned roles (who has the authority to make and approve AI-related decisions), and operational process (how risks actually get identified, reviewed, and tracked over time). People search for this idea under several different names — AI governance framework, responsible AI governance, AI compliance, AI oversight, AI risk governance, algorithmic governance, enterprise AI governance — and while each term carries a slightly different emphasis, they all describe the same underlying discipline: making sure an AI system’s behavior, and the decisions made about it, can be explained and defended after the fact.

AI governance is distinct from AI safety and AI ethics, though the three overlap. AI safety is mostly a technical discipline — testing, evaluation, and engineering work aimed at preventing an AI system from causing unintended harm. AI ethics is a normative discipline — reasoning about what an AI system should do. AI governance is the organizational layer that sits on top of both: it is how a company or agency turns safety findings and ethical commitments into an enforceable, auditable structure — who decided what, when, and on what basis.

Why AI governance has become a compliance requirement, not just a best practice

Until recently, “AI governance” mostly meant voluntary best practice: an internal ethics committee, a published set of principles, a self-assessment checklist. That has changed. Binding law now requires it in specific, testable ways — the EU AI Act imposes documented risk management and human oversight duties on high-risk systems, and a growing list of US states (California, Colorado, Texas, New York among them) now require frontier AI developers to maintain a written safety framework, assess risk before deployment, and report certain incidents on a deadline. Governance work that used to be optional internal hygiene is now, in a specific and growing set of jurisdictions, a legal obligation with named requirements and named consequences for skipping it.

The core principles of AI governance

Different frameworks word it differently, but most converge on the same four ideas. The OECD’s AI Principles — the most widely referenced values-based framework, adopted in 2019 and updated in 2024 — describe them as human rights and fairness, transparency and explainability, robustness and safety, and accountability. In practice, organizations building an AI governance program tend to operationalize the same four ideas as follows.

Fairness

An AI system should not produce systematically worse outcomes for one group of people than another without a defensible reason. In governance terms, this means testing a system’s outputs across relevant subgroups before deployment, not just overall accuracy, and having a documented process for what happens when a disparity is found.

Transparency

People affected by an AI system’s output should be able to find out that AI was involved, and organizations deploying it should be able to explain, at least at a policy level, what the system does and how decisions about it get made. Transparency is also what makes every other principle checkable from outside the organization — a regulator, an auditor, or a customer can only assess accountability or fairness claims that were actually written down.

Accountability

Accountability means a specific, named role — not just “the company” in the abstract — is responsible for approving a given AI risk, deployment, or framework decision, and can be identified after the fact. California’s SB 53 is a concrete example of regulators pushing toward this: it requires internal governance practices around deployment decisions without ever naming a specific “accountable decision-maker” role in the statute itself, leaving organizations to build that structure on their own (see CASRAI’s SB 53 accountable decision-maker guide for what the law actually requires versus what is emerging practice). CASRAI’s own NIKOLAI project catalogs this concept as a distinct governance element — Accountable Decision-Maker and Sign-Off, in its Commitments and Governance track — as one input into how different organizations structure this role, tracked independently rather than as an endorsed standard.

Human oversight

Human oversight means a person, not just the AI system itself, retains the ability to review, override, or halt an AI-driven decision. The EU AI Act makes this an explicit legal requirement for high-risk systems: Article 14 requires providers to design their high-risk AI system so that a human deployer can actually exercise oversight over it, not just be nominally in the loop. This is closely related to, but broader than, accountability — accountability asks who signed off on a decision; oversight asks whether anyone is positioned to catch a problem while it is still happening. CASRAI tracks the broader governance layer this sits inside — commitments, sign-offs, and update protocols — in NIKOLAI’s Commitments and Governance track (N9).

Who does AI governance: the roles involved

AI governance is organizational work, and most programs converge on a similar cast of roles even when the titles differ. A governance committee (sometimes an AI governance board, sometimes folded into an existing ethics or audit committee) sets policy and reviews the highest-risk decisions; day-to-day risk classification and sign-off usually sits with a designated accountable decision-maker rather than the full committee. CASRAI’s AI Governance Board vs. Ethics Committee vs. Audit Committee comparison works through how these bodies actually differ and where each one’s authority stops, and the AI Governance Framework Template lays out one concrete structure — committee, risk tiers, and escalation paths — that an organization can start from rather than design from scratch.

The regulatory frameworks AI governance has to satisfy

An organization rarely gets to choose one framework in isolation — most governance programs are built to satisfy several at once. Three are worth knowing as the baseline vocabulary, since AI Overview results and most enterprise guidance point back to the same three:

The EU AI Act regulates by risk category rather than by company size or by which country a developer is based in: unacceptable-risk systems are banned outright, high-risk systems face binding documentation, risk-management, and human-oversight duties, and lower-risk systems face lighter transparency rules or none at all. This kind of risk tiering — sorting a system or a model into a category that determines which safeguards apply — is the same underlying mechanic frontier-AI safety frameworks use when they set a capability threshold: the specific, testable point at which a model is judged to have crossed into a risk tier that requires new safeguards before it can be released. CASRAI tracks that concept independently as NIKOLAI’s Capability Threshold element. CASRAI’s EU AI Act high-risk compliance checklist covers the current deadlines in detail, including the 2026 AI Omnibus amendments.

NIST’s AI Risk Management Framework is the most widely referenced US framework, organized around four functions — Govern, Map, Measure, and Manage — that most enterprise AI governance programs use as a structural checklist even when they aren’t formally certifying against it. CASRAI’s guide to building a program on Govern-Map-Measure-Manage walks through each function.

ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System (AIMS): it certifies an organization’s governance process around AI — policies, risk assessments, role definitions, and monitoring — not any specific model or product. See CASRAI’s ISO/IEC 42001 certification guide for what the certification actually covers and doesn’t.

Below the federal and international layer, a fast-growing set of US state laws add their own binding requirements for frontier AI specifically: California’s SB 53, Colorado’s AI Act, Texas’s TRAIGA, and New York’s RAISE Act each take a different regulatory approach (risk-tier disclosure, use-case-based duties, frontier-model-specific transparency) and each has its own effective date and scope. CASRAI’s jurisdiction map is the fastest way to see which of these actually applies to a given organization before going deep on any one of them.

Where AI governance compliance work actually happens

Principles and org charts only matter if they produce ongoing, checkable work. Three activities are where most of that work actually lives:

Risk assessment is the process of identifying, upfront, what could go wrong with a given AI use case and how likely and severe that is — and a risk register is what turns that from a one-time exercise into a maintained, ongoing record. CASRAI’s AI risk assessment framework and risk register guide covers the mechanics of both.

Audits check, on a defined schedule, whether an organization’s AI governance commitments are actually being met in practice — internally, through a dedicated internal audit function, or externally, through third-party AI auditing against a named regulation or standard. CASRAI covers both angles: building an internal audit function and what third-party AI auditing actually involves.

Incident reporting is the deadline-driven duty to notify a regulator, and often the public, when something has already gone wrong — a distinct discipline from audits, which check for problems before they happen. CASRAI’s guide to SB 53’s critical safety incident reporting requirements covers one binding example in detail, and the guide to building an internal AI safety incident response program covers the operational side of being ready to report.

CASRAI’s NIKOLAI dictionary: defining these terms precisely

Every governance term surveyed on this page — accountability, oversight, risk thresholds, sign-off — gets defined and used slightly differently by different labs, regulators, and standards bodies, which is exactly the kind of ambiguity that makes cross-framework compliance work harder than it needs to be. CASRAI’s own NIKOLAI project is an independent reference dictionary, unendorsed by any lab, evaluator, or regulator, that defines 64 such elements across ten tracks and crosswalks how major frontier AI developers and frameworks each use them — explicitly labeling every crosswalk row a “shadow mapping” unless the organization in question has separately, formally declared how it uses that term through NIKOLAI’s own Mapping Declarations system. It exists to make definitional drift visible, not to declare a winner among competing usages.

Every governance term in this explainer is defined precisely, and cross-referenced across frameworks, in NIKOLAI — CASRAI’s own frontier-AI-safety dictionary. Start at casrai.org/nikolai.

Frequently asked questions

What is AI governance in simple terms?

AI governance is the policies, assigned roles, and ongoing processes an organization uses to make sure its AI systems are safe, legal, and accountable — and to make sure those decisions can be explained and checked after the fact.

Is AI governance the same as AI ethics?

No. AI ethics is a normative discipline asking what an AI system should do. AI governance is the organizational structure — policy, roles, process — that turns ethical commitments (and safety findings) into something enforceable and auditable.

Is AI governance the same as AI compliance?

They overlap but aren’t identical. AI compliance specifically means meeting binding legal or regulatory requirements (like the EU AI Act or SB 53). AI governance is broader: it includes compliance, but also voluntary internal policy and process that goes beyond what any law currently requires.

Who is responsible for AI governance inside an organization?

It’s rarely one person. Most programs split the work between a governance committee or board that sets policy and reviews the highest-risk decisions, and one or more accountable decision-makers who handle day-to-day risk classification and sign-off. See CASRAI’s comparison of governance boards, ethics committees, and audit committees for how the split typically works.

What are the main AI governance frameworks?

The three most widely referenced are the EU AI Act (binding law, risk-tier based), NIST’s AI Risk Management Framework (US, voluntary, Govern-Map-Measure-Manage), and ISO/IEC 42001 (an internationally certifiable AI management system standard). A growing set of US state laws add binding requirements specifically for frontier AI developers.

What’s the difference between an AI governance framework and an AI governance policy?

A policy is the written statement of what’s allowed and what isn’t. A framework is the fuller structure around it — roles, risk tiers, escalation paths, and review cadence — that makes the policy actually operational. CASRAI’s AI governance framework template shows what that structure looks like in practice.

Does “AI governance” only apply to companies building frontier AI models?

No. The core principles and roles described here apply to any organization deploying or building AI systems. Frontier AI developers face additional, more specific binding requirements (like SB 53’s incident-reporting duty) because of the scale and novelty of the models they build, but enterprise AI governance as a discipline is broader than that one audience.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about What Is AI Governance? A Complete Guide to Principles, Roles, and Compliance

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →