AI Governance and Compliance
AI governance is the set of policies, processes, and controls that organizations use to manage AI risks and ensure compliance with regulations. It covers frameworks like the EU AI Act and NIST AI RMF, which classify AI systems by risk level and require documentation, testing, human oversight, and monitoring throughout the AI lifecycle.
itArtificial intelligence and machine learning | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — AI Governance and Compliance
Sooner or later somebody asks what an AI system does, who decided it was allowed to do that, and what evidence exists that it behaves as claimed. Governance is the apparatus that makes those answers available in an afternoon rather than through a fortnight of archaeology.
Compliance is its narrower relative: meeting the legal, regulatory and contractual obligations that genuinely apply in a given jurisdiction and sector. A policy nobody enforces is set dressing, and controls with no governing structure behind them hold until the first situation nobody anticipated.
The operating loop is short: classify a system by risk, fit controls to that risk rather than to enthusiasm, document evidence that the controls work, and demonstrate it to whoever is entitled to ask. Then monitor, and respond when conditions move.
Two frameworks supply most of the vocabulary, and they do different jobs.
The EU AI Act is law, and it sorts systems into four bands. Unacceptable risk is prohibited outright — subliminal manipulation, social scoring. High risk carries the full regime, spelled out in Articles 9 to 15: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy with robustness and security. Limited risk mostly means disclosing that a machine is involved. Minimal risk covers spam filters and game AI, and carries no specific EU requirement.
NIST's AI Risk Management Framework is voluntary guidance rather than law. It splits the work into four functions — governing the programme, mapping where a system sits and whom it touches, measuring how it behaves, managing what to do about that — and it reaches jurisdictions the Act never will.
Now the part every framework skips. Classifying systems by risk quietly assumes somebody holds a list of the systems, and in most organisations nobody does. Models arrive inside purchased software nobody procured as AI, in an analyst's notebook, in a vendor's next release. So the first real programme is enumeration, and it never finishes, because new systems appear faster than any inventory is updated. A register with a completion date on it is describing a fiction.
The second thing worth knowing is where this actually fails, which is not in weak controls. It fails in a well-written and entirely defensible paragraph explaining why the comprehensive regime does not apply here, written by the team whose budget the answer decides. It survives review because it is not wrong, merely convenient. The remedy is to route borderline classifications to somebody who does not own the delivery budget, and to record the reasoning rather than only the conclusion.
One diagnostic beats any dashboard: ask when a control last caught something. An all-green register where nothing has ever fired is not evidence of safety, it is evidence that nothing is being tested — and it reads very badly from outside after an incident.
When a risk band or an Article number is needed, the Cheatsheet has them; the Slides give the shape in a single pass. Then read Field Notes for the dates, which have moved — not all of them, and not in the same direction.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://europa.eu/ai-act
Supports
- Risk classification framework
- High-risk AI system requirements
- https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
Supports
- Govern, Map, Measure, Manage function framework
- Trustworthy AI characteristics
