What AI governance is, and why it matters
AI governance is the set of rules, roles and processes an organisation uses to keep its AI systems useful, lawful, safe and accountable. It covers each system from the first idea to the day it is switched off.
AI brings risks that ordinary IT governance does not fully cover:
- Errors at scale: a flawed model can repeat the same wrong decision thousands of times before anyone spots it.
- Unfair outcomes: models learn from past data, including its biases, and can treat groups of people differently. A credit model trained on old lending records may, for example, score some regions or groups lower for reasons unrelated to repayment.
- Opacity: it can be hard to explain why a model reached a result. That matters when a customer, auditor or regulator asks.
- New security risks, such as prompt injection (hidden instructions in content the AI reads) and leaks of the data a model was given.
- Systems that act: AI agents can move money, change records and send messages, not only give advice.
Governance does not exist to slow AI down. It lets an organisation use AI with confidence, because it knows what it is running, who is responsible and how problems will be caught.
The principles behind it
Most AI governance rests on a shared set of principles. Two international statements are widely cited:
- The OECD AI Principles, adopted by the OECD in May 2019 and updated in May 2024. All OECD members and a number of other countries, as well as the European Union, have signed up to them.
- The UNESCO Recommendation on the Ethics of Artificial Intelligence, adopted by all 193 UNESCO member states in November 2021.
The wording differs from document to document, but the same ideas keep appearing:
- Human oversight: people stay in control of decisions that matter and can step in.
- Fairness: systems should not discriminate unlawfully or unjustly.
- Transparency and explainability: people should know when AI is being used and be able to get a meaningful explanation of a result.
- Safety, security and robustness: systems should work reliably and resist misuse.
- Privacy: personal data is used lawfully and only as much as needed.
- Accountability: a named person or organisation answers for each system and its results.
Principles alone change little. Governance is the work of turning them into specific rules, checks and responsibilities.
Frameworks and standards
Frameworks and standards turn principles into practice. Three are widely used:
- The NIST AI Risk Management Framework (AI RMF 1.0, January 2023), from the US National Institute of Standards and Technology. It is voluntary and free to use. It groups the work into four functions: Govern (culture, policies and roles), Map (understand each system's context and risks), Measure (assess and track those risks) and Manage (act on them). NIST added a Generative AI Profile in 2024 and has said it is revising the framework, so check for the latest version.
- ISO/IEC 42001:2023, the international standard for an AI management system. Like ISO/IEC 27001 for information security, it sets requirements an organisation can be independently certified against.
- ISO/IEC 23894:2023, guidance on managing AI risk. It adapts the general risk-management standard, ISO 31000, to AI.
These fit together. An organisation might use the NIST framework to organise its thinking, ISO/IEC 23894 as its risk method, and ISO/IEC 42001 as the management system that holds everything together, with evidence an auditor can check.
You do not need to adopt everything at once. A small organisation can start with a policy, an inventory and a risk review for each system, and build from there.
The laws that apply
AI is regulated by AI-specific laws and, more often, by laws that already exist.
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. It sorts AI systems by risk:
- Unacceptable risk: a short list of banned practices, such as certain kinds of social scoring.
- High risk: systems used in sensitive areas, such as some uses in employment, education, credit scoring and access to essential services. These must meet requirements on risk management, data quality, documentation, human oversight and accuracy.
- Transparency duties: for example, people must be told when they are dealing with an AI system, and some AI-generated content must be marked.
- Minimal risk: most other systems, with no specific new duties.
It also sets duties for providers of general-purpose AI models. The duties apply in stages. The bans and the AI literacy duties applied from 2 February 2025, and the rules for general-purpose AI models from 2 August 2025. Most other rules, including the transparency duties, applied from 2 August 2026. An amending law adopted in July 2026, Regulation (EU) 2026/1744, moved the high-risk rules to 2 December 2027, and to 2 August 2028 for AI built into products such as machinery. The Act can reach organisations outside the EU, for example when they offer AI systems in the EU or their AI's output is used there.
In Kenya, Article 31 of the Constitution protects privacy, and the main law today is the Data Protection Act, 2019, supervised by the Office of the Data Protection Commissioner. Section 35 gives people a right not to be subject to a decision based solely on automated processing, including profiling, that has legal effects on them or significantly affects them. Exceptions exist, for example where the decision is needed for a contract, is authorised by law, or the person has consented. Even then, the person must be told in writing and can ask for the decision to be reconsidered, or taken again with human involvement.
Kenya launched a National Artificial Intelligence Strategy 2025–2030 in March 2025. It is a policy, not a law. An Artificial Intelligence Bill, 2026 was before the Senate in 2026 but had not become law by September 2026. Sector rules, such as those for banks and insurers, and consumer and employment law also apply to decisions made with AI. This area is changing quickly, so check the current position and take legal advice for specific cases.
Who does what
Governance works when responsibilities are clear. A common structure:
- The board sets how much AI risk the organisation will accept and receives regular reports on AI use and incidents.
- An AI governance group, usually drawn from technology, risk, compliance, legal, data protection and the business, sets policy, reviews higher-risk systems and decides on exceptions.
- A business owner for each AI system answers for its purpose, its results and its risks.
- Technical teams build, test, document and monitor systems to the agreed standards.
- Risk, compliance and data protection teams check that controls exist and work, including data protection impact assessments where the law requires them.
- Internal audit gives independent assurance that the whole arrangement works in practice.
Other staff have a part too: using only approved AI tools, keeping confidential and personal data out of unapproved ones, and reporting anything that looks wrong. Basic AI training for all staff makes this realistic.
Start simple: a policy, an inventory of AI systems, a named owner for each and a review before anything high-risk goes live. Then improve it as your use of AI grows.
Ten questions
Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.
Your answers
Your certificate of completion
Enter your name as you want it to appear, then save the certificate as a PDF. In the print window, choose Save as PDF. A certificate is issued once per completion of the course.
Saolix does not record who takes this course, so it cannot verify these certificates. The certificate confirms completion of a free self-paced course and is not an accredited qualification.
Sources
The official documents this course relies on. Laws and guidance change, so check the current version.
- OECD AI Principles · OECD
- Recommendation on the Ethics of Artificial Intelligence · UNESCO
- AI Risk Management Framework · US National Institute of Standards and Technology
- ISO/IEC 42001:2023 AI management systems · ISO
- ISO/IEC 23894:2023 Guidance on risk management · ISO
- AI Act (overview and application timeline) · European Commission
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) · EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) · EUR-Lex
- Data Protection Act, 2019 (section 35) · Kenya Law
- Kenya Artificial Intelligence Strategy 2025–2030 · Ministry of Information, Communications and the Digital Economy
- Bill Digest: The Artificial Intelligence Bill, 2026 (Senate Bills No. 4 of 2026) · Parliament of Kenya