{"id":6011,"date":"2026-07-20T03:01:25","date_gmt":"2026-07-20T07:01:25","guid":{"rendered":"https:\/\/workai.tv\/news\/2026\/07\/ai-security\/4-steps-for-businesses-to-establish-an-ai-governance-policy\/"},"modified":"2026-07-20T03:01:25","modified_gmt":"2026-07-20T07:01:25","slug":"4-steps-for-businesses-to-establish-an-ai-governance-policy","status":"publish","type":"post","link":"https:\/\/workai.tv\/news\/2026\/07\/ai-security\/4-steps-for-businesses-to-establish-an-ai-governance-policy\/","title":{"rendered":"4 steps for businesses to establish an AI governance policy"},"content":{"rendered":"<h2>Share with your CISO<\/h2>\n<p>AI governance has moved from best practice to board-level obligation, and <a href=\"https:\/\/www.fm-magazine.com\/issues\/2026\/jun\/4-steps-for-businesses-to-establish-an-ai-governance-policy\/\" target=\"_blank\" rel=\"noopener nofollow\">a detailed framework walkthrough in FM Magazine<\/a> maps the practical path forward. The piece draws on Deloitte, Oxford&#8217;s Sa\u00efd Business School, and Mirae Asset Securities to synthesize three dominant governance models: ISO\/IEC 42001 certification, the EU AI Act&#8217;s risk-tier regime with fines up to 7% of global revenue, and NIST&#8217;s voluntary AI Risk Management Framework. A four-step implementation sequence covers structure, risk mapping, controls, and complexity budgeting.<\/p>\n<h2>What this means for your business<\/h2>\n<p>The governing condition here is that most enterprises already have an AI exposure problem before they have a governance program. Employees are using generative tools now, today, at a speed that outpaces any approval workflow. The question isn&#8217;t whether your organization needs a framework; it&#8217;s whether the absence of one is already creating liability you haven&#8217;t priced. Companies with meaningful EU revenue face a hard deadline, not a planning exercise. Everyone else is choosing between getting ahead of the audit or reacting to the incident.<\/p>\n<p>The article&#8217;s most underappreciated argument is the &#8220;complexity budget&#8221; framing from Oxford&#8217;s Felipe Thomaz. The idea is simple and sobering: every organization has a finite capacity to understand and supervise what its AI systems are doing. When autonomous agents make consequential decisions at machine speed, the instinct is to add more AI tooling to monitor the first layer of AI. That path tends to compound the opacity rather than reduce it. The companies that will manage AI risk well are the ones that size their deployment to what their human and technical oversight can actually track, not to what sounds strategically ambitious in a board deck.<\/p>\n<p>The governance structure debate, centralised versus federated versus hub-and-spoke, is real but often resolved too early in the wrong direction. Centralised control protects against the worst outcomes but creates a bottleneck that slows every business unit trying to ship. The advice here to start centralized and migrate toward hub-and-spoke once foundations exist is correct, but it undersells the political difficulty. The CISO or Chief AI Officer who can&#8217;t hold the center against business unit pressure during the migration window is the one who ends up with federated chaos dressed as agile governance. The governance structure is only as durable as the executive will behind it.<\/p>\n<p>The falsification condition for this framework is straightforward: if your organization has no current AI inventory, meaning no documented list of which models are running, where, and for what decisions, none of the downstream steps matter. Risk-tiering, controls design, and monitoring are all downstream of knowing what you&#8217;re governing. The inventory isn&#8217;t a technical task; it&#8217;s an organizational one, and the CISO who doesn&#8217;t own that list by end of quarter is building governance on assumptions rather than facts.<\/p>\n<h2>Concept deep-dive: Risk-tiered AI classification<\/h2>\n<p>The EU AI Act sorts every AI use into four risk tiers, from outright banned applications down to minimal-risk tools requiring almost no oversight. Think of it like a building code that treats a hospital differently from a garden shed. The practical value isn&#8217;t EU compliance alone; the tier logic gives any organization a defensible vocabulary for prioritizing governance effort, directing the heaviest controls to AI touching credit decisions, hiring, or safety, and lighter oversight to tools generating meeting summaries.<\/p>\n<p><em>Based on reporting from <a href=\"https:\/\/www.fm-magazine.com\/issues\/2026\/jun\/4-steps-for-businesses-to-establish-an-ai-governance-policy\/\" target=\"_blank\" rel=\"noopener nofollow\">4 steps for businesses to establish an AI governance policy<\/a>, originally published 2026-06-05 03:00:00.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Share with your CISO AI governance has moved from best practice to board-level obligation, and a detailed framework walkthrough in FM Magazine maps the practical path forward. The piece draws on Deloitte, Oxford&#8217;s Sa\u00efd Business School, and Mirae Asset Securities to synthesize three dominant governance models: ISO\/IEC 42001 certification, the EU AI Act&#8217;s risk-tier regime [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":6012,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[238],"tmauthors":[],"class_list":["post-6011","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai-security","tag-ciso"],"_links":{"self":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts\/6011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/comments?post=6011"}],"version-history":[{"count":0,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts\/6011\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/media\/6012"}],"wp:attachment":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/media?parent=6011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/categories?post=6011"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/tags?post=6011"},{"taxonomy":"tmauthors","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/tmauthors?post=6011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}