Your employees are already using AI. Right now, at this very moment, someone is pasting a client document into ChatGPT for help drafting an email. Someone else has switched on an AI assistant to take notes in a meeting where sensitive information about your organization is being discussed. Neither of them is doing anything wrong on purpose. They’re simply trying to do their jobs better and more efficiently.
The question isn’t WHETHER AI is being used in your organization. The question is whether you have a grip on HOW it’s being used, and what information those AI tools have access to.
That is exactly what AI Governance is about: having a grip on it. And it’s why we at AddComply are starting this article series, to give you a practical, concrete route there.
What is AI Governance?
AI Governance is how your organization directs, controls and takes responsibility for its use of AI. Not as a theoretical policy document sitting in a folder no one opens, but as a living system in which strategy, rules, mapping, legal compliance, training and accountability all connect.
The field is growing fast. New roles such as Head of AI and AI Strategist appear on LinkedIn every week. That’s a sign that organizations are seriously starting to recognize that AI use needs the same kind of governance that other areas such as finance, security and HR already have.
And the risks of not having AI Governance in place are clear. A single AI-related mistake, whether a data leak, a discriminatory decision, or a system that breaks the law, can damage your reputation in ways that take a long time to repair. At the same time, if you get it right you’ll extract considerably more value from your investment in AI, because then your people will actually dare to use it.
So how do you build AI Governance in practice? We’ve broken it down into seven concrete steps.
The 7 steps of AI Governance: a practical guide:
Step 1: Set the direction with an AI strategy
It all starts with a simple question: where do we want our AI initiative to take us?
An AI strategy is about connecting AI to your actual business goals. Which organizational objectives can you reach faster, more cheaply or more effectively with AI? Without a clear direction, AI use becomes scattered. Every department trials its own tool, and nobody knows what the purpose is or what they’re actually trying to achieve.
We see it again and again: organizations that develop a clear AI strategy get a completely different level of internal buy-in. It suddenly becomes clear why AI matters, not just that it’s fashionable.
That said, it’s important that the AI strategy doesn’t become a technical side project for the IT department or a single Head of AI. The board and the executive team must own the question, because AI is business-critical and affects everything from competitiveness and risk exposure to brand and employee trust. When leadership drives the issue actively and the board asks for follow-up, it signals that the question matters, and the result is usually real action and real change. Without that ownership, buy-in and follow-up, even the best-conceived strategy risks becoming a document gathering dust.
Step 2: Give people clear rules in an AI policy
The next step is turning strategy into concrete rules. An AI policy should give employees clear, practical guidance: what may you do, what may you not do, and who do you go to with questions?
Without a clear policy, employees either become passive and don’t dare experiment with AI (and you miss out on the value), or they guess and use AI without considering the consequences (and you carry the risk). Neither option is good. Having a clear, practical AI policy that lets employees feel confident in how they use AI is now simply table stakes for any organization.
Step 3: Map the systems that contain AI functionality
This is the step most people underestimate. Where do you begin? By making a list.
Go through all the software you use, both on-premise and cloud services, and find out which ones actually contain AI functionality. It’s more of them than you think. Many systems have had AI features added without anyone internally making a decision about it.
Look for shadow AI too: the AI tools employees use on their own initiative, without approval or even the knowledge of management.
Once the list is complete, work through the terms of use for each system. How is the data you and your colleagues enter being used? Is the vendor training its own model on your data? Where is your data stored? These are questions you need answered before it’s too late.
Step 4: Get legally secure with compliance under the AI Act
Once you know which AI systems you actually have, it’s time to become compliant with the EU AI Act.
First you need to establish whether you are the provider or the deployer of each AI system. That determines which obligations apply to you. Then you classify each AI system according to the regulation’s risk levels and make sure the requirements for each level are met.
For high-risk systems, in HR or critical infrastructure for example, that often means a substantial set of requirements, including a risk management system, a quality management system, technical documentation and registration in the EU database. Here it’s essential to find out by what date you must be compliant, and to start in good time.
At the same time, check that none of your systems fall under the prohibited practices in Article 5. Those have been banned since 2 February 2025.
Step 5: Classify your data so you know what may be shared
Before employees enter information into an AI system, you need to decide: which information may be used where?
Classify your data by type and sensitivity, and map it to each AI system. Without that link, it’s left to each individual employee to guess what’s acceptable to share, which isn’t good enough for an organization that wants to use AI responsibly.
Step 6: Train your people, because knowledge is your best risk management
A policy document nobody has read does no good. AI literacy is the key to responsible AI use, and it’s regulated in Article 4 of the AI Act. Training needs to happen at several levels:
- General training on AI, AI law and the risks of AI, with concrete do’s and don’ts.
- System-specific training tailored to the particular tool and the employee’s level of use.
The goal is for employees to be able to make informed decisions in their day-to-day work without feeling uncertain every time. Only then can you get the full benefit of your AI use.
Step 7: Build an AI team with a mandate to act
Last but not least: someone needs to own AI Governance. An AI team, large or small depending on your size, should be responsible for:
- Approving new AI tools and reviewing contract terms
- Regularly reviewing the terms of use for existing AI systems, since vendors change their terms over time and what was acceptable at approval may no longer be
- Ensuring ongoing regulatory compliance
- Training employees and owning the training programme
- Receiving and handling incident reports
- Having the mandate to pause the use of an AI system when necessary
- Following up on the AI strategy and keeping the AI policy up to date
AI use affects both the organization as a whole and the individual employee, as new roles emerge, others disappear, and new skills need to be built. That makes every question this article touches on deserving of clear ownership in the form of an AI team where different competencies such as IT, leadership, HR, legal and the business can work together for the best possible outcome.
Seven steps, one tool for AI Governance
Doing all of this manually in Word documents, spreadsheets and email threads is entirely possible. But without a clear overall picture and a smooth workflow, it risks petering out.
That’s why we at AddComply built AI Governance Starter: to bring strategy, policy, system mapping, risk classification and training together in one place, making it easy to get started and stay on top of things. Click here to read more about our AI Governance Starter.
In the next article in the series we go deeper into Step 1: how you actually formulate an AI strategy that your board and executive team own. Keep an eye out.
Key takeaways:
- Set the direction with an AI strategy.
- Give people clear rules in an AI policy.
- Map the systems that contain AI functionality.
- Get legally secure with compliance under the AI Act.
- Classify your data so you know what may be shared.
- Train your people, because knowledge is your best risk management.
- Build an AI team with a mandate to act.



