
Researchers at Springer Nature note that global databases currently document more than 3,000 recorded AI incidents in which systems have failed or caused harm. This figure underscores an urgent need for structured control. To succeed with AI governance, leadership must establish a framework of policies, processes, and technical standards. This framework ensures that artificial intelligence creates business value without breaching legislation or ethical boundaries. Many organisations struggle to translate complex legal requirements into practical IT architecture. We often see projects stall because the foundation is missing. Through professional advisory support, companies can bridge the gap between business strategy and technical execution.
Many companies blend these concepts together in their strategy documents. Academic literature, however, distinguishes them clearly, and this distinction is essential for precise implementation. Ethical AI concerns the moral principles behind the technology. It covers discussions of fairness, human dignity, and societal impact, the overarching values an organisation wants to promote. Responsible AI, by contrast, is the operational discipline focused on risk minimisation. It is about building systems that are transparent, secure, and free of bias. While ethical AI defines the goal, responsible AI delivers the concrete tools to get there. An effective AI governance strategy requires an organisation to master both. Focus on ethics alone, and you end up with declarations of intent lacking technical substance. Focus on responsibility alone, and you risk building secure systems that solve the wrong problems.
The Partnership on AI defines a three-layer model called the AI Governance Stack. This model bridges the gap between lofty declarations and the code that developers write. It allows leadership to delegate responsibility precisely across the organisation.
The top layer consists of global values and multilateral agreements. Here we find initiatives such as UNESCO's Recommendation on the Ethics of Artificial Intelligence, adopted by 193 countries in 2021. The OECD Working Party on Artificial Intelligence (AIGO) also operates at this level, setting the direction for international policy. The middle layer covers legislation and national priorities. This layer translates global values into binding rules for companies and citizens. In Europe, this layer is primarily defined by new EU regulations and national data protection law. The bottom layer consists of technical standards and industry practice. Technical AI Governance (TAIG) forms the foundation here, covering the concrete test protocols, data quality checks, and security measures that engineers carry out daily. Without this layer, legislation remains theoretical.
On 13 June 2024, Regulation (EU) 2024/1689 was formally adopted. This legislation sets harmonised rules for artificial intelligence across the EU. The law divides AI systems into four risk categories. Systems with unacceptable risk are banned outright. High-risk systems are subject to strict requirements for documentation, monitoring, and human oversight. Limited-risk systems primarily require transparency, while minimal-risk systems can be used freely. A key detail is the law's extraterritorial effect. Like the GDPR, the EU AI Act does not only affect European companies. If a US or Asian company delivers an AI system that produces output used in the EU, it must comply with the regulation. This makes the law a de facto global standard. Companies therefore need to map their systems now to avoid massive fines. The legislation is also constantly evolving, requiring a proactive approach from leadership.
Technology evolves faster than legislation. The OECD therefore recommends a strategy based on anticipatory governance. This approach is about handling future AI developments proactively rather than reacting once the damage is done or the law is broken. Companies applying anticipatory governance set up internal councils and monitor initiatives such as the Global Dialogue on AI Governance. They build flexibility into their systems so they can adapt quickly to new rules. This requires a culture where employees are encouraged to report potential risks early in the development phase. A lack of anticipatory governance is often a primary reason why IT projects fail.
To establish effective control, leadership needs data on the organisation's current state. UNESCO has developed the Readiness Assessment Methodology (RAM), which helps governments and large organisations assess their readiness. The method systematically maps legal, social, and technical gaps. In the business world, similar assessments serve as the foundation for investment decisions. At We Lead Projects, we conduct dedicated AI-EA assessments lasting four to eight weeks. These engagements map a company's existing AI assets, identify gaps in data quality, and establish frameworks for compliance with the EU AI Act and GDPR. A thorough assessment ensures a company does not invest in technology its infrastructure cannot support. Our team has more than 125 years of combined experience delivering these analyses.
Successful implementation requires that artificial intelligence is not treated as an isolated IT project. It must be deeply integrated into the company's existing architecture. We use the TOGAF framework to ensure that business goals, data, applications, and technology align. A business-first approach means the technology must solve a concrete problem. We always start by defining the business value. We then ensure the data foundation is valid and legal to use. Only at the end do we select the specific algorithm or platform. This method minimises the risk of failed investments. The choice of project model is also critical to success, different organisations require different approaches.
Responsibility typically lies with a combination of the legal department, IT leadership, and business units. A cross-functional steering committee ensures every aspect of the technology is covered. It is leadership's job to distribute this responsibility clearly.
The rules depend solely on the system's risk level, not the size of the company. SMEs that develop or use high-risk systems must document their processes as thoroughly as large corporations. Certain exceptions do exist for research and development.
The first step is a complete inventory of all AI systems currently used or under development within the organisation. This includes third-party solutions and shadow IT.
AI governance work never ends. It is a continuous process that requires adaptation as technology and legislation evolve. Start by mapping your current systems and assessing them against the requirements of the EU AI Act. Then establish clear guidelines for how employees may use artificial intelligence in their daily work. Make sure to integrate these guidelines into your enterprise architecture so they become a natural part of IT operations. If you lack the internal resources to drive this change, external project management can ensure the initiatives are properly anchored in the business.

Brian P.N. Tofft
Managing Partner, We Lead Projects
Brian has more than 30 years of experience in project management and IT transformations across industries.
Get in touch and find out how we can help with your next project.
Contact us