Most organisations already use AI through approved platforms, embedded software and unsanctioned employee tools. The first governance task is therefore to understand what exists, what decisions it influences and who owns the risk.

1. Build an AI inventory

Record the system, supplier, purpose, users, data, outputs and business owner. Include pilots and shadow AI, not only production systems.

2. Classify the role and risk

Separate low-impact productivity tools from systems that influence people, access, safety, employment or essential services. Classification determines the depth of documentation and oversight.

3. Assign accountability

Each use case needs a business owner, a technical owner and clear escalation paths. Legal, security, procurement and HR should support decisions rather than own every system.

4. Establish literacy and minimum controls

Teams need role-based AI literacy, acceptable-use rules, data-handling expectations, human review requirements and a process for reporting failures.

A useful first output: one inventory, one accountability map, one minimum-control baseline and a prioritised 90-day roadmap.

5. Create evidence as work happens

Document decisions, testing, supplier reviews, incidents and changes continuously. Governance becomes sustainable when evidence is part of the workflow.

This article is general information and not legal advice. Organisations should assess the Act against their specific role, systems and jurisdictions.
← All insights