AI governance & risk

Use AI with
clear responsibility.

Establish clear oversight of AI: who makes decisions, how risks are managed, and when people need to intervene.

A competent human in the loopA competent human in the loopReviewers need relevant expertise, enough context, and the authority to approve, change, or stop an AI-assisted action.ExpertiseContextAuthorityAIoutputActionReview & decideApprove · Change · Stop
Reviewers need relevant expertise, enough context, and the authority to approve, change, or stop an AI-assisted action.

What is AI governance?

AI governance sets out who is responsible for AI, how it should be used, and how the organization checks that it is working as intended. It gives leaders a clear view of performance, risk, and the effects of AI on customers, employees, and others.

RPA2AI’s work connects enterprise adoption with AI ethics, risk, and governance. Kashyap Kompella’s writing examines organizational accountability, privacy, and the institutions that oversee automated decisions.

Put governance into practice

Ownership

Who is responsible for an AI system? Who can authorize its use, change its purpose, or stop it? These responsibilities need to be clear in everyday practice as well as in policy.

Evidence

What does a reviewer need to know about how an AI system is used? Consider its purpose, affected people, evaluation results, limitations, and dependencies on data or external suppliers.

Oversight

When should a person review a result? How will problems be found, reported, and resolved? Human involvement should have a defined purpose and the authority to act.

Coordination

Business, data, security, and legal teams each see a different part of the picture. RPA2AI’s published analysis explores why governance needs to cross these organizational boundaries.

A body of work on governance

A Short & Happy Guide to AI Governance and Regulation, co-authored with James M. Cooper, examines the landscape of AI policy, laws, and standards.

Other work includes a 2025 SMU Science and Technology Law Review essay on algorithmic decisions in public governance, and 2026 TechTarget articles on cross-functional data governance and AI and privacy.

Questions about AI governance.

Who should be accountable for AI decisions?

Name business and technical owners, with executive oversight. Accountability belongs to the organization deploying AI and cannot be assigned to the model itself.

Responsibility should remain identifiable when a project moves from development into everyday use. A business owner needs a way to act on failures, supported by technical ownership and executive oversight. Kashyap’s accountability article explains how clear roles and correction mechanisms connect governance to business value. Read more about building accountability into AI.

What makes human oversight effective for AI agents?

People need the expertise, information and authority to intervene. Define approval boundaries, escalation routes and fallback arrangements before granting agents autonomy.

A reviewer who cannot challenge an output or stop an action provides little protection. Set permissions and escalation rules before deployment, and make intervention part of the workflow. Kashyap’s work on managing agentic teams describes the management practices required when people supervise systems capable of taking actions. Read more about managing human and AI teams.

How does AI governance relate to data privacy?

AI governance and privacy should be coordinated. What data a system accesses, why it uses that data and who can authorize access are central to both disciplines.

The connection becomes especially important when AI accesses information across multiple systems. Oversight must consider the purpose of access, permissions and the consequences of reuse, rather than treating privacy as a separate document. Kashyap’s article with Tom Walat explains the need to integrate these responsibilities. Read more about AI governance and privacy.

Can an AI governance tool make an organization responsible?

A tool can support monitoring and records, but responsibility requires people and processes. Integrate controls into existing AI workflows rather than treating a new platform as the solution.

Start by identifying the decisions and controls the organization needs to support. A platform is useful when it helps people carry out that work and preserve an appropriate record. Kashyap’s review of governance tools places their capabilities in the context of the organization’s broader oversight needs. Read more about selecting AI governance tools.

What should an organization do before deploying generative AI?

Inventory proposed uses, define acceptable data and actions, assess risk and assign owners. Establish monitoring and a way to respond when behavior or vendor terms change.

An initial assessment should be followed by operational checks. A system’s behavior, information sources and use can change, so review cannot end at approval. Kashyap’s risk-management article sets out the need for monitoring, defined remediation ownership and attention to changing third-party services. Read more about managing language-model risks.

A good place to start

What is your next AI decision?

Talk to us about your business priorities, an investment, or your team’s learning needs.

Start a conversation