Michael Aim
Founder & CEO
In a few years, artificial intelligence has moved from minimally-regulated innovation to a regulated domain. The symbol is the European AI Act, the world's first horizontal frame: it classifies systems by risk level, bans certain uses, and imposes graduated obligations, from transparency for general-purpose models up to the heavy requirements of high-risk systems, with an application calendar spread over several years.
For an organisation deploying AI, including as a mere user of off-the-shelf tools, the consequence is concrete: AI governance becomes an arrangement in its own right, with its roles, controls, documentation and evidence. An arrangement which, like any other, can be mature or embryonic.
Beyond the AI Act: pressure comes from everywhere
Reducing the subject to Brussels would be a scoping error. Sector regulators are declining their own expectations: financial supervisors on decision models, health authorities on medical devices, data protection authorities on algorithmic processing. Other jurisdictions are advancing with frames of their own, which complicates life for any exporter.
And the fastest pressure is not even regulatory, it is commercial: large buyers are adding AI clauses to their contracts, insurers are starting to ask questions, public tenders demand guarantees. The supplier questionnaire that yesterday asked for your security policy asks today for your AI governance.
What a mature AI governance contains
Concretely, an arrangement worthy of the name covers a few invariants: an inventory of AI systems and uses, including those that sneak in through SaaS tools; a risk qualification per use; named roles and responsibilities; proportionate controls, from human review to drift monitoring; and documentation that lets you prove all of it to an auditor, a client or a regulator.
None of this is exotic: these are the classic gestures of compliance, applied to a new and moving object. The difficulty is not conceptual, it is executional: knowing where you stand, on every entity, and holding the trajectory over time.
The inventory, first stone and first shock
Every serious approach starts in the same place: the inventory of systems and uses. And it is almost always a shock: between AI modules embedded in SaaS tools, teams' unofficial uses of generative assistants and forgotten pilot projects, the real scope far exceeds the scope known to management.
Governing a fictional scope protects from nothing. An honest inventory allows sorting: which uses are benign, which touch decisions about people, which will fall into high risk. That sorting sizes the effort, and it changes everything for the budget.
From obligation to measurable arrangement
The experience of previous regulations, from data protection to cybersecurity, teaches one thing: the organisations that fare well are those that turn the requirement into a measured arrangement early, rather than improvising at the deadline. Those who lived through the GDPR's entry into application know exactly what this means.
The approach holds in four gestures: mapping your AI uses, assessing your governance's maturity against a structured framework, identifying the gaps against the obligations that genuinely concern you, and rolling out a dated action plan, re-assessed each cycle. Our catalogue holds 19 data and AI frameworks to equip that gesture, from generic governance frames to specific regulatory requirements.