Governance has to work in practice.
AI governance gets complicated very quickly inside a large organization. Different teams own different parts of the technology, the risk and the decision.
My focus is on how those pieces actually work together. Who can approve an AI use case? What requires additional review? What evidence is needed? Who owns an issue after deployment? And when something changes, who needs to know?
A new AI use case can involve technology, security, privacy, legal, risk, business teams and sometimes several other groups. Someone still has to know who makes the decision, what needs to be reviewed, what level of risk is acceptable and who is responsible once the technology is in use.
These sound like simple questions. In a large organization, they rarely are.
The Practical Side of AI Governance
Once organizations start using AI, some very basic questions need clear answers.
Who approves a new use case? What needs additional review? Who can restrict or stop the use of a system? When does a change require another review? And who is responsible for following the system once it is in use?
In a large organization, these decisions can cross technology, business, legal, security, privacy and risk teams. Clear ownership is key.
Where AI Governance Gets Complicated
AI governance can involve a lot of people and a lot of decisions. Who can approve an AI system? Who can decide that it needs additional review or should not be used? What happens when a model changes after it has already been approved?
There also needs to be clarity after deployment. If the system starts performing differently, the use case changes or a new risk appears, someone needs to know who should review it and who has the authority to act.
These are some of the practical governance questions organizations need to work through.

