AI Governance: The 10 Essentials, QL's Security-Led Starter Framework

QL Security
ai-governance ai-governance-programme ai-governance-checklist eu-ai-act ai-security

AI governance is the set of ownership, controls and evidence that lets an organisation show its AI is used safely, lawfully and on purpose. It has become a board-level question, and in 2026 the timeline shifted underneath it. The EU’s Digital Omnibus simplification package, endorsed by the European Parliament and Council in June 2026, deferred the AI Act’s high-risk obligations: standalone Annex III systems now fall due on 2 December 2027, and AI embedded in regulated products under Annex I on 2 August 2028. The headline deadline moved. The reason to govern your AI did not.

Procurement teams and insurers are already asking organisations to evidence how their AI is governed, and the Act’s prohibitions and general-purpose AI rules are already in force. A later high-risk deadline is not less work. It is more time to build controls that actually operate, and the organisations that use it that way will be the ones that can prove their governance when a customer, an insurer or a regulator asks.

Most beginner guides to AI governance are written by lawyers, and they frame it as a decision and policy exercise. That framing under-weights the part that actually breaks: the security of the AI systems themselves, and the work of turning a policy into controls that demonstrably operate. What follows is the version a security team would write. It runs the way we deliver, from assessing where you stand, through implementing controls, to assuring that they work: Assess, Implement, Assure.

The 10 essentials

1. Know what you are running

You cannot govern what you cannot see. The first essential is an AI inventory that captures not just the tools you procured but shadow AI adopted by staff and the AI features quietly embedded in software you already licence. Most organisations underestimate their real footprint by a wide margin. Start by combining a light technical discovery with a structured staff disclosure, then keep the inventory live rather than treating it as a one-off audit.

2. Set your redlines, then wire them into controls

Decide what your organisation will not do with AI, then make that decision enforceable rather than aspirational. A redline that lives only in a policy document is a preference, not a control. Use the EU AI Act’s prohibited practices as a starting conversation about where your own limits sit, then implement the technical and process controls that stop a redline being crossed by accident.

3. Name one accountable owner

If everyone owns AI risk, no one does. Governance needs a single named owner with the authority to make decisions and the accountability when they go wrong, supported by the functions that carry the work. Assign that ownership explicitly at board or executive level, and make the reporting line to it as clear as the one you already run for information security or data protection.

4. Treat your supply chain as your attack surface

Most organisations consume AI through vendors rather than building it, which means most of your AI risk is inherited. Demand transparency from suppliers about the AI in their products, and secure the contractual right to verify those claims rather than taking them on trust. A vendor’s AI feature that touches your data is part of your attack surface whether or not it appears on your own systems.

5. Test for bias and for failure

A fairness sign-off is not the same as a security test, and a governed AI programme needs both. Test for bias and discriminatory outcomes, and separately run adversarial, red-team testing of the AI system itself to see how it behaves under pressure and attack. The question is not only whether the model is fair on a good day, but how it fails on a bad one.

6. Keep a human in the loop where it counts

Automated decisions that affect people carry both regulatory and reputational weight, and the higher the stakes, the more human oversight the decision needs. Identify the high-risk and solely automated decisions in your estate, including the position under UK GDPR on automated decision-making, and build in meaningful human review at those points rather than a rubber stamp after the fact.

7. Govern the data, not just the model

AI risk is often data risk wearing a new coat. Govern the data that flows into and out of your AI systems: training-data provenance, data protection impact assessments, sensitive-data flows, and the trade secrets and intellectual property that can leak through a prompt. A well-governed model fed ungoverned data is still an exposure.

8. Secure the AI itself

This is the essential the generic guides skip, and it is the one that breaks. AI systems face a live and evolving attack surface: prompt injection, data poisoning, model abuse, and AI-enabled deepfakes and voice phishing. Treat these as security threats to be tested and controlled, not abstract risks to be noted in a policy. Securing the AI is where an AI governance programme stops being paperwork and starts being protection.

9. Make evidence a by-product of working controls

Governance you can only describe is worth less than governance you can prove. The goal is continuous assurance that satisfies boards, procurement and regulators, produced as a by-product of controls that actually operate rather than assembled by hand the week before an audit. Build your controls so that evidence falls out of them automatically. That is the Assure in Assess, Implement, Assure.

10. Make AI literacy a habit

Governance holds only if the people using AI understand it. Build AI literacy as an ongoing habit rather than a one-off training module, so that every user can recognise a manipulated or unreliable model output and knows how to escalate it. Culture is a control. It is the one that decides whether the other nine survive contact with daily work.

From checklist to evidence

These ten essentials share a single thread: the obligation now lands on evidence, not intention. A policy tells a regulator what you meant to do. Working controls, tested and secured, tell them what you actually did, and they produce the proof as they run.

That is the difference between AI governance as a document and AI governance as a discipline. Where advisers and law firms produce recommendations and policies, we implement the controls and produce the evidence as a by-product of working protection. It is the same principle we apply across AI governance and EU AI Act readiness: assess where you stand, implement what is missing, then assure that it works.

Where to start

Not sure how many of these ten you have actually covered? An AI Security Gap Analysis gives you a clear, evidenced answer: where your AI exposure sits, which of the ten essentials you can prove today, and what to prioritise first. For the regulatory picture and the deferred high-risk timeline, see our AI Act Preparedness work and our breakdown of EU AI Act Article 6 high-risk classification; for board-level responsible-AI support, our AI Advisory service.

This article is for general information and does not constitute legal or regulatory advice. Regulatory dates reflect the Digital Omnibus position as of mid-2026 and are subject to formal publication in the EU Official Journal.

Common questions on AI governance

What are the essentials of an AI governance programme?

A security-led AI governance programme rests on ten essentials: an AI inventory including shadow and vendor-embedded AI, enforceable redlines, a single accountable owner, supply-chain transparency with a right to verify, bias and adversarial testing, human oversight of high-risk decisions, data governance, security of the AI systems themselves, evidence produced by working controls, and ongoing AI literacy. The distinguishing move is treating AI security as core to governance, not an afterthought.

Has the EU AI Act high-risk deadline changed?

Yes. The Digital Omnibus simplification package, endorsed by the European Parliament and Council in June 2026, deferred the high-risk obligations. Standalone Annex III high-risk systems now apply from 2 December 2027, and product-embedded Annex I systems from 2 August 2028, subject to formal publication. The prohibitions in force since February 2025 and the general-purpose AI rules from August 2025 are unaffected.

How do you prove AI governance to a board or regulator?

You prove it with evidence produced by controls that operate, not with a policy document. Continuous assurance means each control generates its own record as it runs, so an inventory, a risk assessment, a test result or an oversight log is available on demand rather than assembled before an audit. Evidence as a by-product is what turns a governance claim into a defensible position.

Prepare for what is coming

The high-risk deadline moved to 2027 and 2028. That is more time to build controls that operate, not less work to do. Our AI Act Preparedness work turns the deferral into a plan you can evidence.