# What is AI Governance?

> AI governance is the organizational framework of policies, roles, and processes that decides how AI may be selected, built, deployed, and monitored — before models reach production or users.

- Canonical URL: https://yellowcube.eu/glossary/ai-governance/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It answers who may approve AI use cases, which models and data are permitted, what testing and human oversight are required, how shadow AI is handled, and how incidents are escalated. Frameworks such as the NIST AI Risk Management Framework structure it as govern-map-measure-manage; laws such as the EU AI Act increasingly turn parts of it into legal duty.

### Key points

- **Inventory and policy first:** Know which AI systems and features are in use — including embedded AI in vendors’ tools — and set acceptable-use rules before risk assessment begins.
- **Named system owners:** Each deployed model needs a named owner for its risk, performance, data, and retirement — not diffuse committee accountability.
- **Important limitation:** Governance is the scaffolding, not the protection. An approved-model list and a policy page do not secure a model; the value comes from the controls, testing, and monitoring the framework demands and from the enforcement behind it.

### Related terms

[AI risk management](<https://yellowcube.eu/glossary/ai-risk-management/>) · [AI security](<https://yellowcube.eu/glossary/ai-security/>) · [Shadow AI](<https://yellowcube.eu/glossary/shadow-ai/>) · [Artificial Intelligence Act (AI Act)](<https://yellowcube.eu/glossary/artificial-intelligence-act/>) · [AI security posture management (AI-SPM)](<https://yellowcube.eu/glossary/ai-security-posture-management/>)

### Sources

[NIST, AI Risk Management Framework 1.0](https://www.nist.gov/itl/ai-risk-management-framework) · [EUR-Lex, Regulation (EU) 2024/1689 (Artificial Intelligence Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

