---
title: "AI governance"
description: "The set of rules, roles, controls and evidence that keeps AI systems within the limits an organisation or a state has chosen."
canonical: https://aigovernanceengineer.com/glossary/ai-governance
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-26
---

# AI governance

The set of rules, roles, controls and evidence that keeps AI systems within the limits an organisation or a state has chosen. It decides which systems may run and what they may do, and draws on law such as the AI Act [1], management-system standards [2], risk frameworks [3] and principle sets [4].

- Developed in: [What is AI governance?](https://aigovernanceengineer.com/ai-governance); [ch. 12, The organisation as an object of governance](https://aigovernanceengineer.com/bok/governance-program#the-organisation-as-an-object-of-governance)
- Chapters: [ch. 01, Definition](https://aigovernanceengineer.com/bok/definition) · [ch. 12, Governance Program](https://aigovernanceengineer.com/bok/governance-program) · [ch. 22, Principles & Standards](https://aigovernanceengineer.com/bok/principles-and-standards)
- Contrast with: [AI governance engineering](https://aigovernanceengineer.com/glossary/ai-governance-engineering)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-ai-governance

## Sources

[1] Regulation (EU) 2024/1689 (AI Act), consolidated text as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 Jul 2026; definitions in Art. 3, incl. 3(1), 3(3) to 3(14), 3(14b), 3(20), 3(22), 3(23), 3(29) to 3(32), 3(49), 3(55) to 3(57), 3(60), 3(61), 3(63), 3(68); Arts. 4, 5, 6 (incl. 6(3) third subparagraph, profiling), 9, 10, 11, 13, 14, 15, 17, 22 to 27 (incl. 26(11)), 40, 41, 43, 47, 48, 50, 53 (incl. 53(1)(c)), 55, 57, 60, 72, 73, 86; Annexes I, III, IV). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
[2] ISO/IEC 42001:2023, AI management systems (referenced by identifier only; requirements for an AI management system; clause 10.2 nonconformity and corrective action). ISO/IEC. 2023. https://www.iso.org/standard/81230.html (verified: secondary)
[3] Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (risk tolerance and residual risk; seven trustworthy characteristics; transparency answers "what happened", explainability "how", interpretability "why"; MAP 1.1 intended purposes; MANAGE 1.1 go/no-go determination; profiles). NIST. 2023-01-26. https://doi.org/10.6028/NIST.AI.100-1 (verified: primary)
[4] Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449 (adopted 22 May 2019; AI-system definition revised 8 Nov 2023; revised 3 May 2024; five principles and five recommendations; 1.3 enables people adversely affected to challenge an output; definitions of AI system, lifecycle and AI actors). OECD. 2024-05-03. https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449 (verified: primary)
