AI governance: how to run it in an organisation
As of 11 October 2026
AI governance is the set of decisions and checks that settle which AI your organisation uses, for what purpose, with which data, and who answers for the result. In practice it is a short programme of seven steps: know what is in use, write a policy people can follow, give them an approved tool, enforce the important rules technically, keep useful records, cap spending and review everything on a fixed date. Frameworks such as ISO/IEC 42001 and the NIST AI RMF describe the management side. The EU AI Act and data protection law set the legal minimum.
Shadow AI is where most programmes start
Shadow AI is the use of AI tools the organisation has not approved, usually personal accounts with public chatbots. It is common. In the 2024 Work Trend Index by Microsoft and LinkedIn, 78% of AI users said they were bringing their own AI tools to work.
A ban rarely ends it. People who find a tool useful keep using it on a private phone, where you see nothing at all. Programmes work better when they first ask what people use AI for and then offer an approved route that is at least as convenient. Blocking known chatbot domains can follow once that route exists.
Seven steps of a working programme
1. Take an inventory
List every AI use you can find: licensed tools, AI features inside software you already run, API keys held by developers, and the private accounts people admit to in a short anonymous survey. For each entry, note the purpose, the data involved, the provider and the operator. Under the AI Act, the list also tells you where your organisation is a deployer and whether a use might fall into an Annex III high-risk area such as employment or access to essential services.
2. Write an AI usage policy
A usable policy fits on two pages. It names the approved tools and the data that must never go into a given tool, says who may approve a new use, and explains what happens after a mistake. Name concrete data classes, for example customer records, personnel files, unpublished financial figures and source code. If you need a starting point, adapt our AI policy template.
3. Offer approved tools
Pick one general workspace for everyday work and a small number of specialist tools. Approval should cover the contract and the data processing agreement, the locations where data is stored and processed, the models that may be used, and the export you get at the end of the contract.
4. Control access and models
Connect every approved tool to your identity provider so that people who leave lose access on their last day. Then decide per use case which models are allowed. A project with personnel data may need models operated in your own jurisdiction only, while a marketing team can use any approved model. Put these rules into the server-side configuration of the tool. A rule that lives only in a PDF depends on everyone having read it.
5. Keep records you can actually use
Decide what you log and for how long. Usage records with user, model, tokens and cost support budgets and incident response. Prompts in logs often contain personal data, so store them only where you need them and set retention periods. Keep a separate record of administrative changes, so you can show who changed a rule and when.
6. Set budgets
Costs grow with use. An agent stuck in a loop can spend a month's budget in an afternoon. Set spending caps per team or application, with an alert before a cap is reached.
7. Review on a fixed date
Look at the inventory, the policy and the incidents at least twice a year, and whenever a new rule starts to apply. The AI Act alone gives you dates. The transparency duties in Art. 50 apply from 2 August 2026, and high-risk duties for Annex III systems from 2 December 2027. Since Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026, Art. 4 asks providers and deployers to “take measures to support the development of AI literacy” of their staff. A short training record per team is a reasonable way to show that you did.
Which framework covers what
| Framework | What it is | Status in October 2026 | Use it for |
|---|---|---|---|
| ISO/IEC 42001:2023 | International standard for an AI management system (AIMS) | First edition, published December 2023; certifiable | An auditable management system, especially next to ISO 27001 |
| NIST AI RMF 1.0 | Voluntary framework with the functions Govern, Map, Measure, Manage | Released 26 January 2023; Generative AI Profile (NIST AI 600-1) since July 2024; under revision | Shared risk vocabulary and a catalogue of actions |
| EU AI Act | Regulation (EU) 2024/1689, amended by Regulation (EU) 2026/1744 | In force; Annex III high-risk duties from 2 December 2027, Annex I from 2 August 2028 | Legal duties as provider or deployer |
| UK approach | Five cross-sectoral principles applied by existing regulators | Government response of 6 February 2024; Information Commission (formerly ICO) guidance on AI and data protection | Sector rules, UK GDPR duties, DPIAs |
ISO describes ISO/IEC 42001 as a standard that “specifies requirements for establishing, implementing, maintaining, and continually improving” an AI management system within organisations. Certification applies to your management system. No software product makes you conformant, and buying from a certified vendor does not certify your own use.
NIST says its AI RMF is “intended for voluntary use”, and its website notes that version 1.0 is being revised as part of the White House AI Action Plan. Many teams take the four NIST functions as working vocabulary and use ISO/IEC 42001 as the frame for audits.
The UK has taken a principles-based route. The government's response to its AI regulation white paper set five cross-sectoral principles “for existing regulators to interpret and apply within their remits”. For personal data, the Information Commission writes that “in the vast majority of cases” AI use will trigger the legal requirement for a DPIA. Public bodies also have the AI Playbook for the UK Government, published on 10 February 2025, with 10 principles for civil servants.
Where a gateway or workspace helps
Steps 3 to 6 are where software does real work. An AI gateway sits between users or applications and the model providers, which makes it the natural place to enforce model rules, masking, budgets and logs. Products sold as an “AI governance platform” cover different parts of the programme: some keep inventories and risk registers, others sit in the request path. Ask which of the seven steps a product enforces.
In Myra AI Workspace, which is built around such a gateway, the controls look like this:
- Access: single sign-on via OIDC or SAML, SCIM provisioning, system roles such as “AI Manager” and “Finance”, and custom roles.
- Model rules: projects with the access tier “Local only”, “PII protection required” or “User configurable”; administrators can switch off individual models per gateway, and EU routing can be enforced (it is off by default).
- Data protection: PII masking in every plan, as pseudonymisation that restores the original values in the answer, plus an organisation policy that is added to every chat and agent interaction.
- Budgets: hard spending caps per access token, per gateway and per tenant, with in-app alerts as a cap approaches.
- Oversight: four-eyes approval for changes to the prompt library and agents, human approval steps in workflows, and the label “AI-generated” on answers.
Records work in two layers. Request logs show provider, tokens, cost and latency per request, and on request Myra can switch request logging off for a tenant. Admin changes and security events go into a separate audit log, which can be made tamper-evident with a hash chain on request. Customer administrators have no view of that audit log in the interface.
Governance templates map AI Act and GDPR obligations onto three controls today: EU routing, the provider allowlist and enforced masking. You see a preview of the change before you apply it, and a template can never lower the residency floor. Templates you create yourself are marked non-authoritative, and the documentation is clear that they do not confirm legal compliance. Monthly compliance reports as CSV or PDF can be switched on per tenant by Myra.
What software will not do for you
A gateway only sees the traffic that passes through it. AI features inside other SaaS products and private accounts on personal phones stay invisible, so the inventory and the survey remain manual work. Software also cannot set your risk appetite, write your DPIA or train your staff.
Be careful with certificates as well. Myra Security operates an ISMS certified to ISO 27001 on the basis of IT-Grundschutz and holds a BSI C5 Type 2 attestation for the infrastructure that AI Workspace runs on. Neither is a certificate for an AI management system. If data location and jurisdiction are your main concern, read the guide on sovereign AI.
Frequently asked questions
What is the difference between ISO/IEC 42001 and the NIST AI RMF?
ISO/IEC 42001 is an international standard with requirements for an AI management system, and organisations can have their management system certified against it. The NIST AI RMF is a free, voluntary framework from the US National Institute of Standards and Technology. It organises risk work into four functions called Govern, Map, Measure and Manage. Many organisations use the NIST functions for day-to-day risk work and ISO/IEC 42001 when they need a certificate.
What should an AI usage policy contain?
The approved tools, the data classes that may go into each tool, who approves new tools and use cases, how people check an output before they use it, and whom to contact after a mistake. Keep it short enough to be read. Enforce the critical rules in the tool's configuration as well, because a rule that exists only on paper depends on everyone remembering it.
How do you find shadow AI?
Combine an anonymous survey about what people use and why with web proxy or DNS logs for known AI services and with expense claims for AI subscriptions. The survey usually reveals more than the logs, because many people use AI on private devices. Then offer an approved tool for the most common tasks before you block anything.
Does the EU AI Act apply to UK or US companies?
It can. Under Art. 2(1)(c), the AI Act applies to providers and deployers established in third countries where the output produced by the AI system is used in the Union. A UK or US company with customers or staff in the EU should check which of its AI uses fall under that rule, with its own counsel.
Sources
- ISO: ISO/IEC 42001:2023, AI management systems, retrieved 11 October 2026
- NIST: AI Risk Management Framework, retrieved 11 October 2026
- NIST AI 100-1: Artificial Intelligence Risk Management Framework (AI RMF 1.0), PDF, retrieved 11 October 2026
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex, retrieved 11 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, retrieved 11 October 2026
- UK Government: A pro-innovation approach to AI regulation, government response (6 February 2024), retrieved 11 October 2026
- Information Commission (formerly ICO): Guidance on AI and data protection, accountability and governance, retrieved 11 October 2026
- UK Government: AI Playbook for the UK Government (10 February 2025), retrieved 11 October 2026
- Microsoft and LinkedIn: 2024 Work Trend Index (8 May 2024), retrieved 11 October 2026
- Myra AI Workspace documentation, retrieved 11 October 2026