AI governance within a company determines whether an AI project continues after the pilot phase or gets stuck in a gray area because no one wants to take responsibility for approving it. Without clear guidelines, each department decides for itself what risks to take, often without management’s knowledge.
An AI policy covers roles, risk classification, data protection, approval processes and ongoing monitoring in a single document. It is built in four steps: Inventory of the systems in use, classification into the four risk categories, definition of roles, and finally, training and monitoring. Two to four pages per topic area are sufficient.
What an AI policy covers—and what it doesn't replace
The directive implements two legal frameworks simultaneously: the European AI Regulation 2024/1689 and the General Data Protection Regulation (caralegal, 02/2026). It translates abstract obligations into concrete procedures within the company. It specifies who is authorized to test a new AI tool, who verifies whether personal data is being fed into a language model, and who decides whether a use case should be classified as high risk.
In industry and retail, the need usually shows up first in purchasing or sales. One employee tests an AI tool for preparing quotes, another uses a different tool to translate supplier contracts. Without an overarching policy, this produces several parallel isolated solutions, each carrying its own risk.
A policy is no substitute for training or technical inspections. It provides the framework within which both take place. Companies that merely adopt a document without actually filling the roles described in it end up with a piece of paper that has no effect.
Four Steps to Establishing AI Governance in Your Company
- Taking Stock. Which AI applications are already in use—either officially or unofficially by individual employees? This list is often longer than expected because many employees have long been using free AI tools without the IT department’s knowledge.
- Risk Classification. Each identified application is classified into one of four levels (caralegal, 02/2026). This classification determines the scope of further work.
- Define roles. Approval of new use cases, monitoring of operational systems, and serving as the point of contact in the event of incidents. For high-risk applications, a human remains central to the decision-making process; this “human-in-the-loop” principle cannot be replaced by automated controls.
- Training and Monitoring. To ensure that new use cases do not slip under the radar of governance again.
| Class | A typical example | What is required |
|---|---|---|
| Prohibited | Social scoring, biometric categorization based on sensitive characteristics | Use Prohibited |
| High | Pre-screening of job applications, credit decisions | Documentation, human-in-the-loop, ongoing monitoring |
| Limited | Chatbots in Customer Service, AI-Generated Content | Disclosure Requirements, Labeling |
| Minimal | Internal text summary, spell check | No specific obligations; observe data protection regulations |
These four steps can be completed one after another, but they do not all have to be finished before the first project begins. A lean first draft of the policy that addresses only the most urgent issues is better than waiting months for the perfect document. Governance evolves as the first use cases are implemented.
Does every company need its own AI governance role?
Not every company needs to create a new full-time position for this. In smaller companies, the IT manager or a member of the data protection team often takes on this additional responsibility. What matters is not so much the title as it is clear accountability. AI governance that exists only on paper but is not specifically assigned to anyone is, in practice, no governance at all.
A valid counterargument is that additional approval processes slow down projects and rob them of the very agility that makes AI applications attractive. This concern is not unfounded if governance is interpreted as an additional hurdle for every little thing. An effective policy therefore distinguishes between low-risk applications, which can be launched without a lengthy approval process, and high-risk cases, where careful review is indeed necessary. Failing to make this distinction unnecessarily slows down even non-critical projects.
We have outlined the timeframes specified in the AI Regulation—which a directive should be based on—in our article on the EU AI Act Compliance Roadmap compiled. By planning governance and deadline management together, you can avoid duplicating work when it comes to documentation.
Assessment in a Single AppointmentWe'll work with you to identify which AI applications are already in use at your company and categorize them into the four classes. After that, we'll draft the first version of the policy.
Frequently Asked Questions
Does a company with 50 employees already need AI governance?
Yes, as soon as AI systems are in use, regardless of the size of the business. The scope of the policy may be narrower than that of a corporate group. At a minimum, there must be a risk classification and a designated approval authority, even if that person fulfills multiple roles at the same time.
Who should take on the governance role within the company?
Often, this role is filled by the head of IT in collaboration with the data protection officer. It is important that this person both understands the technical systems and has a say in legal and organizational decisions. Without this dual access, the role remains ineffective. In larger companies, it is also worthwhile to establish a small committee comprising representatives from the business unit, IT, and legal departments to evaluate new use cases.
How often should the AI policy be reviewed?
An annual review is a reasonable minimum frequency; in addition, every new AI application should undergo a review against the guidelines before it goes live. Given the ongoing changes to the EU AI Act, it’s also worth reviewing the guidelines as soon as a new deadline takes effect. A fixed trigger can be helpful—such as the annual financial closing or a recurring IT security audit.
The Next Step
torck builds AI systems for industry and retail and therefore knows the organisational side of governance from its own projects. With teams in Maxhütte-Haidhof, Vienna and Rabat, we implement the approval processes a policy describes. In an initial consultation we look at the AI applications already running in your own operation. Schedule an Initial Consultation.
This article refers to laws and regulations to put technical decisions in context. It is not legal advice. Whether and how a rule applies to your company is a question for your legal department or a law firm.