AI governance for boards: ask for evidence, not assurances.

For the people who set strategy, approve risk appetite and answer for outcomes: the decisions that are yours, the few numbers to ask for, and what a working governance function can show you.

Who this is for.

You do not need the mechanics. You need to know which decisions only you can take, what to ask for in the board pack, and how to tell a governance function that runs from one that only reports. This route is short on purpose: the argument, the decisions, the oversight.

  • Board members
  • Chief executives and executive committees
  • Chief AI, data and technology officers
  • Audit and risk committees

On the learning path, start at What the discipline is or Maturity self-assessment.

New to the field? Read AI governance explained: the definition, the frameworks and where engineering fits.

Three questions you bring.

Each one answered in brief here, and in full in the Body of Knowledge.

  1. Which decisions are ours to take?

    Whether to use AI for a purpose at all, how much risk the organisation will accept, and what it will not do. A committee takes the exceptions and the risk acceptances against that appetite; the gates in the pipeline enforce everything else.

  2. What should we see in the board pack?

    One page generated by a query, not assembled by hand: registry coverage, gate coverage, open exceptions by age, incidents and time to contain, and realised risk reduction, with anything outside appetite flagged for a decision.

  3. What does the law already expect of us?

    In the EU, the AI literacy provision (Art. 4) and the prohibited practices (Art. 5) already apply, with two new prohibitions from 2 Dec 2026; the Annex III high-risk obligations apply from 2 Dec 2027 12. Data protection, consumer, equality and product-liability law apply to AI today.

Start this week.

  1. Ask for the inventory: every AI system in use, with an owner. If it cannot be produced, that is the first finding. AI system register entry
  2. Name one accountable executive and charter the committee that takes exceptions. Committee charter template
  3. Approve a risk-appetite statement that can be compiled into gate thresholds. Risk appetite, compiled into gates
  4. Put six to eight indicators, generated from live systems, on the next board agenda. KPIs and KRIs for the board
  5. Ask which of the next three EU AI Act dates touch your products and services. What applies now

The obligations that matter most.

The duties that land on the organisation as a whole: literacy, prohibitions, classification, the quality management system, deployer duties, and the policy and accountability controls of the management-system standards.

Obligations for this route (Executives and boards), with status, date and evidence
Obligation Applies Evidence
EU AI Act Art. 4 AI literacy AIGE-OBL-EUAIA-ART4 In force · Literacy programme as code; role-based training records; onboarding gates
EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) AIGE-OBL-EUAIA-ART5 In force · Policy-as-code blocklist; input/output guardrails; refusal and abuse detection
EU AI Act Art. 6 classification of high-risk AI systems (incl. the Annex III route) AIGE-OBL-EUAIA-ART6 Deferred · Risk-tiering as code; high-risk classification decision record; register entry flagging Annex III status
EU AI Act Art. 17 quality management system AIGE-OBL-EUAIA-ART17 Deferred · QMS-as-code; versioned policies; pipeline controls and change management
EU AI Act Art. 26 deployer obligations for high-risk systems AIGE-OBL-EUAIA-ART26 Deferred · Deployment registry; monitoring hooks; assigned oversight and logging retention
ISO 42001 · A.2 Policies related to AI AIGE-OBL-ISO42001-A2 Voluntary Policy-as-code library; versioned policy repository
ISO 42001 · A.3 Internal organization AIGE-OBL-ISO42001-A3 Voluntary Operating model; RACI; ownership in the registry
NIST AI RMF · GOVERN AIGE-OBL-NISTRMF-GOVERN Voluntary Policy-as-code; operating model; registry ownership

Every obligation in the register

Sources

  1. [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 (Art. 4 AI literacy, Art. 5 prohibited practices, Art. 113 application dates). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
  2. [2] Regulation (EU) 2026/1744 (Digital Omnibus on AI) (Art. 5(1)(ba) and (bb) prohibitions from 2 December 2026; Annex III high-risk obligations from 2 December 2027). Publications Office of the EU (EUR-Lex). 2026-07-24. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified: primary)

Start at the top of the route.

Step 01 is The Thesis. Each step after it builds on the one before.