06 · AI Governance
AI governance and AI literacy
Most businesses already use AI. Rarely following a decision, usually because individuals have started using tools that work. That gives gains quickly, and a risk no one has an overview of.
AI governance is about knowing where AI is used, what the models actually do, which data they get to see, and who answers for the result. It is a leadership question before it is a technical question.
I do not build models. I work on the specification, the governance and the compliance around them.
When is this the right service?
This area is particularly relevant when:
- AI has been taken into use without anyone having the full overview
- a system is to profile, recommend or prioritise on behalf of users
- the business delivers into the EU and is covered by the EU AI Act
- management must be able to answer what the models do and why
- employees use AI tools without shared ground rules
The requirements of the EU AI Act are being introduced in stages. The AI literacy requirement already applies to organisations in the EU, and Norwegian implementation is expected. Those who map their use now avoid having to do it under time pressure.
How I work
I begin by mapping where AI is actually used, not where it has been decided to use it. Then I work with:
- specifying what the models are to do, and what they are not to do
- assessing the data basis, the legal basis for processing and the duty to inform
- roles and ownership: who answers for the outcome
- ground rules and AI literacy measures for employees
- documentation of the assessments that have been made
The work is concrete. The aim is documented choices, not a policy document no one reads.
What the organisation is left with
The result is often:
- an overview of where AI is used and what it is used for
- clear ownership of the models and the results
- documented assessments that withstand external review
- ground rules employees can actually follow
- a basis for taking a position on new AI initiatives
The point is not to slow things down. It is to be able to say yes without having to guess.
Experience base
I work with this in practice myself:
- In Spotz Global I hold strategic ownership of AI-driven models that assess user needs and recommend services. I do not build the models. I specify what they are to do, and I answer for the consequences.
- In PRiME I designed the data handling regime for a clinical project in neonatal intensive care, where no data left the hospital and the patient could not be identified from the data set.
I have made these assessments on my own products before offering them to others.
My role
In this kind of work I come in as:
- adviser on AI governance and compliance
- responsible for specification in AI projects
- sounding board for management and the board in assessments of AI initiatives
I am neither a lawyer nor a model developer. I take responsibility for making sure the choices are made deliberately, documented and properly anchored.
A good starting point
Many start with a simple question: do we actually use AI, and where? That is a good place to begin. The first step is usually a mapping.
Next service
Strategy & Direction
