Topic
AI Governance
Institutions, instruments and practices that steer AI toward public-interest outcomes—without treating every document as law.
Last reviewed 2026-08-22
Overview
AI governance is the organizing idea of this directory. It includes binding law, treaties, voluntary frameworks, standards, procurement, and civic oversight. The pages clustered here help distinguish who has authority, what is optional, and where to read primary sources. Start with the glossary term, then move to organizations and instruments rather than relying on secondary commentary.
What is AI governance, in practice?
AI governance is often defined as the institutions, rules, processes and practices used to steer AI toward public-interest outcomes—accurate, but abstract until it is tied to who actually holds which kind of authority. In practice, four kinds of actor exercise governance authority over the same AI system at once, and they rarely have identical mandates: a legislature or regulator that can create binding legal duties (the EU AI Act is the clearest current example); a standards body like ISO or a technical agency like NIST that publishes voluntary frameworks organizations can choose to adopt; the organization deploying the system, which sets internal policy, assigns owners and decides what "responsible AI" means in its own context; and civil society, researchers and affected communities, who can document harms, demand transparency and push for stronger law even without formal authority over any of the above. Treating a voluntary framework as if it were law, or an internal company policy as if it bound anyone outside the company, is the single most common error in AI governance discussion. This directory keeps regulations and frameworks in separate collections for exactly this reason: knowing which layer a document belongs to is usually more useful than knowing its content in isolation.
NIST AI Risk Management Framework: Govern, Map, Measure, Manage
One of the most widely referenced voluntary frameworks structures its guidance around four functions, and understanding what each one covers is more useful than treating the NIST AI RMF as a single undifferentiated document. Govern establishes the organizational culture and accountability structure for managing AI risk—policies, roles, and how risk tolerance gets decided before any system is built. Map identifies the context a specific AI system operates in: its intended purpose, the people it affects, and the risks specific to that use case, since a Map exercise for a hiring tool looks nothing like one for a medical device. Measure applies quantitative and qualitative methods to assess the risks identified in Map—testing, metrics and evaluation against the system's own stated purpose. Manage uses that measurement to actually prioritize and respond to risk: accepting some, mitigating others, and deciding when a system's risk is unacceptable regardless of its benefits. Companion resources extend this core structure to specific contexts, including a profile addressing generative AI's distinct risks. None of this is regulation: an organization can follow all four functions rigorously and still have unresolved legal obligations elsewhere, or can be fully compliant with binding law in its jurisdiction without ever adopting this structure. The four functions are best used as a checklist for whether a governance program has a gap, not as a certification or a legal safe harbor.
How organizations operationalize AI governance
Search interest in AI governance tools has grown as organizations move from writing policy documents to implementing them, but "tools" covers several distinct kinds of work worth separating. Model and system documentation—records of what a system does, what data trained it, and its known limitations—is the foundation most other governance activity depends on; without it, audits and impact assessments have nothing concrete to examine. Risk registers and impact-assessment processes translate the Map and Measure functions above into a repeatable internal workflow, typically owned by a named team rather than left to individual engineers. Human-oversight workflows define specifically where and how a person can review, override or halt an automated decision, a stated requirement in several regulatory regimes and not merely good practice. Audit logging and monitoring provide the ongoing record that makes AI audit and AI assurance possible after deployment, not only at launch. This directory does not endorse or rank specific commercial products in any of these categories (see the disclaimer), but the categories map directly onto the glossary terms above—AI audit, AI assurance, algorithmic impact assessment—and a governance program missing one of them has an identifiable, specific gap rather than a vague deficiency.