Most organisations already use AI through approved platforms, embedded software and unsanctioned employee tools. The first governance task is therefore to understand what exists, what decisions it influences and who owns the risk.
1. Build an AI inventory
Record the system, supplier, purpose, users, data, outputs and business owner. Include pilots and shadow AI, not only production systems.
2. Classify the role and risk
Separate low-impact productivity tools from systems that influence people, access, safety, employment or essential services. Classification determines the depth of documentation and oversight.
3. Assign accountability
Each use case needs a business owner, a technical owner and clear escalation paths. Legal, security, procurement and HR should support decisions rather than own every system.
4. Establish literacy and minimum controls
Teams need role-based AI literacy, acceptable-use rules, data-handling expectations, human review requirements and a process for reporting failures.
5. Create evidence as work happens
Document decisions, testing, supplier reviews, incidents and changes continuously. Governance becomes sustainable when evidence is part of the workflow.