Part VII: Organizational AI governance

An organization needs to know which AI systems it uses, who can make decisions about them, and which risks justify further security work.

A control can be effective in one application while other AI uses remain unknown. Chapter 20 connects approved and unapproved uses to accounts, connectors, data, suppliers, and review dates. Chapter 21 assigns decision authority and examines duties that depend on the organization and its setting. Chapter 22 compares exposure, expected outcomes, uncertainty, and cost to support security investment. These decisions depend on the technical evidence established in the earlier Parts.

A titled technical map shows organization, supplier, affected-person, and external-oversight boundaries beside Chapter 20 AI use inventory, Chapter 21 responsibility, and Chapter 22 security investment. The flow ends in an executive decision record. Lower strips list governance measurements, risks, and record categories. In the responsibility panel, provider offers the service, deployer implements and configures it, and operator runs and monitors it. These are generic operational labels, separate from the EU AI Act role definitions.
Figure 1: Organizational decisions begin with visible AI uses. Chapter 20 records approved services, unapproved use, embedded AI, accounts, connectors, suppliers, owners, and changes. Chapter 21 assigns roles and evidence across internal and external parties. Chapter 22 connects coverage, outcomes, uncertainty, value, cost, staff, money, time, and unresolved risk to a funded action, owner, due date, and review trigger. The diagram uses provider, deployer, and operator as generic operational functions. These labels do not define the EU AI Act roles discussed in Chapter 21.

Chapters in this part

  • Shadow AI and unmanaged use: An organization-wide adoption process connects visible AI uses to acceptable-use rules, account and connector controls, and employee support.
  • Responsibility and legal duties: A responsibility map assigns decisions and evidence across developers, providers, deployers, data owners, purchasers, and affected people.
  • Prioritizing security investment: An investment decision connects measures, evidence, responsible owners, review dates, and remaining risk to staff, money, and time.