Getting started with AI governance: 5 steps every organisation should take

Your organisation is already using AI. Here's what to do next. 

Artificial intelligence is quickly becoming part of everyday work. 

Employees are using AI to draft content, summarise meetings, analyse information and automate tasks. New AI-powered tools and agents are appearing across organisations at an unprecedented pace, often without formal governance structures in place. 

While AI presents significant opportunities, it also raises important questions around visibility, security, data protection and organisational risk. 

For many organisations, the challenge isn't whether to adopt AI - it's how to adopt it responsibly. 

This is particularly important as organisations look to align with existing obligations around data protection and prepare for emerging AI regulation across Europe. The European Union's AI Act introduces a risk based approach to AI governance while GDPR continues to apply wherever personal data is processed. 

The good news is that getting started with AI governance doesn't need to be overwhelming. Taking a few practical first steps can help establish the foundations needed to support AI adoption as it grows across the business. 


Step 1: Understand how AI is already being used

Before creating policies or implementing controls, it's important to understand your current AI landscape. 

Many organisations discover that employees are already using AI tools independently, often without IT or security teams having full visibility.

Start by asking:

  • What AI tools are currently being used?
  • Which departments are using them?
  • What type of information is being shared with AI systems?
  • Are AI agents already being deployed?
Building visibility is often the first step toward effective governance.

Step 2: Define clear AI usage guardrails

One of the most effective early governance measures is creating simple and practical guidance for employees.

This doesn't need to be a lengthy policy documment. Instead, organisations should establish clear guardrails around:

  • Approved AI tools

  • Acceptable business use cases
  • Handling sensitive information
  • User responsibilities
  • Escalation and review processes

The European Data Protection Board (EDPB) has highlighted the importance of protecting personal data throughout the development and use of AI technologies, reinforcing the need for clear organisational controls around AI usage. 



Step 3: Review data access and security controls

One of the most important aspects of AI governance is understanding what information AI systems can access. 

AI tools often reflect existing permissions and data access structures. If permissions are overly broad, AI can surface information that employees may not otherwise have discovered easily. 

This makes governance and security closely connected. 

Organisations should review:

  • Access permissions

  • Sensitive data locations
  • Data classification policies
  • Security controls
  • Identity and access management processes

Good AI governance often starts with good information governance.


Step 4: Create a simple AI risk assessment process

Not every AI tool presents the same level of risk. 

Having a structured approach to evaluating new AI solutions can help organisations make informed decisions before deployment.

The EU AI Act introduces a risk based framework for AI systems, recognising that different use cases present different levels of risk. Certain applications face strict requirements, while others may have minimal obligations. 

Even before considering formal regulatory requirements, organisations can benefit from introducing a simple AI risk assessment process.

Questions might include:

  • What data will the tool process?

  • Does it involve personal information?
  • Where is data stored and processed?
  • What business problem is it solving?
  • What measures are available for monitoring and control?

A basic risk assessment process allows organisations to scale governance as adoption increases. 

Step 5: Establish accountability

AI governance should not sit entirely with IT. 

Successful organisations typically involve stakeholders from across multiple functions, including; IT, security, risk, data protection, legal and business leadership. 

Defining ownership helps ensure governance becomes an ongoing organisational capability rather than a one-off project.


Don't wait for regulation to force action

AI regulation is evolving quickly. 

The EU AI Act was introduced to create the world's first comprehensive legal framework for artificial intelligence, using a risk based approach to protect safety, fundamental rights and transparency while supporting innovation. 

At the same time, GDPR remains applicable whenever personal data is processed by AI systems. 

Organisations don't need to have every answer today. However, establishing governance foundations now can make future AI adoption significantly easier, safer and more sustainable. 


Governance should enable innovation, not slow it down. 

One of the biggest misconceptions about AI governance is that it creates barriers to innovation. 

In reality, effective governance does the opposite. 

When organisations have the right controls, policies and visibility in place, employees can adopt AI with greater confidence. Leaders gain assurance that risks are being managed, and the business is better positioned to take advantage of emerging technologies. 

AI governance isn't about restricting innovation. 

It's about creating the foundations that allow innovation to scale safely. 


Looking at how to govern AI within Microsoft 365?

Codec helps organisations understand the governance, security and operational considerations that support responsible AI adoption across Microsoft environments. 

Talk to our Microsoft AI specialists.


Back to all blogs