Cortexa AI Glossary · Your data, rights, and the rules
What is AI governance?
From Cortexa Learn, by Cortexa Consulting. Last checked .
Your workplace has a rule about who can approve an expense. This is that rule, for the artificial intelligence tools you use at work.
Who can sign the check
Most workplaces have a rule about who can approve an expense or sign a check. Nobody finds it exciting. But everyone knows it's there, and it stops a lot of problems before they start. Artificial intelligence (AI) governance is the same kind of rule, written for the AI tools people use at work.
Three questions
Most of it comes down to three questions.
- Which AI tools can people use?
- What can they use them for?
- Who answers for it when something goes wrong?
The policies, the roles, and the checks all exist to answer those clearly, so people can use AI with confidence instead of guessing.2
A written policy
The first piece is usually a written policy. It says which tools are approved, what kinds of information must never go into them, and where to ask when you're unsure. Topic 36, "Is it safe to paste work information into AI?", is the everyday side of that. A good policy is short enough that people read it.
A name next to each tool
The second piece is people. Good governance puts a named owner next to each tool and each important use. That person decides who gets access and keeps an eye on how it's going. They're also the one to call when something looks wrong. Without a name, a problem can sit for weeks, because everyone assumes someone else has it. In a small team, one person might own several tools, and that's fine.
A shared framework
Organizations don't have to invent this from scratch. The National Institute of Standards and Technology (NIST), a United States government agency, publishes a free AI Risk Management Framework. It's built around govern, map, measure, and manage. Govern is the one that runs through the rest: it sets the policies, the roles, and the culture the others depend on. NIST later added a companion for generative AI, with suggested actions for tools that write text and make images.13
Checking after launch
Governance doesn't stop when a tool is approved. Tools change. A tool that worked well in January can drift by June. The vendor updates the model. People start using it for new jobs, or the data changes. So organizations review their tools on a schedule, and some run audits that check whether a system still works as intended and hasn't picked up errors or bias.2
Agents raise the stakes
The stakes go up with AI agents, tools that can take actions like sending an email or changing a record. A chatbot that writes a draft needs one kind of rule. An agent that can act needs clearer limits: what it can touch, what it has to ask about first, and a record of what it did. Topic 32, "What is agentic AI?", looks at that label more closely.4
Small teams count too
None of this needs a big company. For a small team, governance can fit on one page: the approved tools, what never goes into them, and who to ask. If your workplace has a page like that, find out where it lives. And if it doesn't, you could ask who would be the right person to write one.