Perspective
AI Governance Requires More Than Policies
2 August 2026 · Author: Lisbeth Loft
Governance also requires an understanding of models, use and organisational consequences.
AI governance is often translated into policies, principles and guidelines.
That is necessary. But it is not sufficient.
An organisation can have an AI policy and an approval process and still lack a real picture of how AI is actually used, which models lie behind it, where the risks arise, and who is accountable.
Good AI governance therefore requires more than documentation. It requires an understanding of the models, the use and the organisation around them.
AI Rarely Exists in One Place
AI is not only introduced through large strategic projects. It also arrives through existing systems, suppliers, analytics tools and employees’ own use of generative AI solutions.
This means the organisation may well be using more AI than it has a consolidated overview of.
If governance takes as its starting point only the systems formally approved as AI systems, a significant part of the actual use may therefore fall outside it.
From AI Policy to Actual Use
A policy can describe how AI should be used.
But governance begins in earnest when the organisation knows how AI is actually being used.
That requires, among other things, an overview of which systems and models are used, what purposes they serve, which data is involved, who makes decisions based on the output, and who owns the risk.
Only there can the organisation assess whether the formal frameworks fit the actual use.
The AI Act Makes Governance More Concrete
With the AI Act, AI governance is no longer purely a matter of voluntary principles.
The rules are built on a risk-based approach, and several central requirements are already in force, including requirements for AI literacy. Other requirements are being phased in gradually.
That does not mean every organisation must build a large AI compliance function. But it increases the need to be able to answer some basic questions: which AI the organisation uses, what it is used for, which risks follow with it, who is accountable, and how we know whether the solutions work as expected.
The Risk Does Not Lie in the Model Alone
Two AI solutions can be technically similar and at the same time have very different risk profiles.
That depends not only on the model, but also on how it is used.
An AI system that helps draft an internal text is something quite different from a system that plays a part in assessing people, recruitment or decisions with significant consequences.
The same technology can therefore require very different governance depending on the context.
That is an important point, because otherwise organisations risk assessing risk based on the product’s name or the supplier’s description rather than the actual use.
Bias Is Also an Organisational Issue
Bias is often treated as something to be found in data or in the model.
But bias can also arise in the way AI is implemented and used.
A system can work technically as designed and still produce inappropriate outcomes, if the output takes on a different meaning in the organisation than intended, or if a recommendation is in practice treated as a decision.
Governance should therefore cover both the model and the organisational use.
AI Literacy Is More Than a Course
The AI Act contains requirements for AI literacy.
This is easily translated into a matter of training. But real AI literacy is also about different roles having the knowledge they need to use and govern AI responsibly.
An employee may need to understand the limitations of an AI output. A manager needs to understand accountability and risk. A procurement function needs to ask the right questions of a supplier.
That is not necessarily the same knowledge.
It therefore often makes more sense to offer tailored programmes for different roles and functions than one general AI course for the whole organisation. A session for management might, for example, focus on accountability and governance, while a programme for employees might deal more with concrete use, risks and good practice.
From Policy to Actual Governance
Perhaps the most important difference is this:
A policy describes what the organisation wants to happen.
Governance must help the organisation understand what is actually happening – and what that means.
That requires an eye for rules and compliance, but also for models, data, bias, people, workflows and organisational consequences.
Only when those perspectives are brought together does AI governance become real governance.