What is AI Governance?

August 21, 2026Download

Consider what AI safety, security and governance looks like for your own use of AI tools and what it might look like to develop policies and frameworks for your organization.

The Principles of AI Governance

Before you begin, think about what kind of support you need. Each workflow is designed to help with a different kind of task.

You might need help getting started when your ideas are still scattered, making complex information easier to understand, writing something that connects with community, or moving a process forward. Use the categories below to find the workflow that fits your task.

AI safety

Making sure the model does what it's supposed to do.

Safety is about preventing harm and increasing reliability and predictability.

AI security

Protecting the model, the data moving through it, and the people using it.

Security is about making sure the model is safe from attack, and that data is going and being used as it should.

AI governance

These are the rules for using AI.

Governance looks like privacy policies, AI disclosures, data access controls, vendor reviews, and acceptable use policies. It also includes the regulatory landscape.

Governance actions, safety and security.

As AI becomes more common in everyday work, one thing is clear: trust matters. People are more likely to use and support AI when they understand how it works and feel confident that it is being used responsibly.

At its core, AI governance is about asking:

  1. Who is responsible for how AI is used?

  2. How do we ensure decisions remain fair and transparent?

  3. When and how should humans stay involved?

These questions help organizations and Nations use AI as a tool while staying grounded in their own values, responsibilities, and ways of knowing.

When applying data governance within an organization, these core pillars are important to consider:

Accountability

Clear responsibility for AI use and outputs.

Transparency

Understanding how AI tools function and produce results.

Fairness

Identifying and reducing bias and discrimination when AI tools are used.

Security

Protecting your digital systems and data from misuse, breaches, or manipulation.

Here’s a framework you may find useful in your own governance thinking and work by asking:

  1. “Can we?”—what is technically possible
  2. “Should we?”—what aligns with your laws, values, and relational responsibilities
  3. “Who decides?”—whose authority is upheld, whose voices are centred, and who benefits from the choices being made.

These questions help ensure that decisions about data, digital systems, and AI remain grounded in your values and responsibilities to community.

These questions help ensure that decisions about data, digital systems, and AI remain grounded in your values and responsibilities to community.

As AI becomes more common in everyday work, one thing is clear: trust matters. People are more likely to use and support AI when they understand how it works and feel confident that it is being used responsibly.

At its core, AI governance is about asking:

  • Who is responsible for how AI is used?
  • How do we ensure decisions remain fair and transparent?
  • When and how should humans stay involved?

Tools for Developing AI Governance

Understanding the principles of AI governance is one thing. Having documents you can actually use, share, and enforce is another. None of these needs to be long or complicated. They do need to be grounded in your community's values, governance structures, and understanding of the AI tools you're using or considering.

How These Tools Work Together

Data governance framework

Sets your values and decision-making principles. The foundation on which everything else rests.

Privacy policy

Tells people what data is collected, how it is used, and what their rights are. Learn how to develop your own privacy policy here.

AI disclosure statement

  1. Tells people when and how AI has been used in your work. Learn how to develop an AI disclosure statement here.

Acceptable use policy

Sets the rules for how staff, volunteers, and partners can use AI tools in your organization. Learn how to develop an AI acceptable use policy here.

Developing these policies and frameworks takes time and capacity. If you're starting out, you can work through these steps at a pace that works for you:

  1. Review existing policies if they haven't been reviewed recently

  2. Develop an AI Acceptable Use Policy as it's the most immediately protective

  3. Build the AI Disclosure Statement into your workflows

  4. Develop a Data Governance Framework when you have the capacity to do it properly, or draw on existing frameworks