AI Governance in the Enterprise: Guidelines, Roles, and Approvals


Cover Image: AI Governance in the Enterprise – Roles, Risk Categories, Approvals

AI governance within a company determines whether an AI project continues after the pilot phase or gets stuck in a gray area because no one wants to take responsibility for approving it. Without clear guidelines, each department decides for itself what risks to take, often without management’s knowledge.

In a nutshell

An AI policy covers roles, risk classification, data protection, approval processes and ongoing monitoring in a single document. It is built in four steps: Inventory of the systems in use, classification into the four risk categories, definition of roles, and finally, training and monitoring. Two to four pages per topic area are sufficient.

What an AI policy covers—and what it doesn't replace

The directive implements two legal frameworks simultaneously: the European AI Regulation 2024/1689 and the General Data Protection Regulation (caralegal, 02/2026). It translates abstract obligations into concrete procedures within the company. It specifies who is authorized to test a new AI tool, who verifies whether personal data is being fed into a language model, and who decides whether a use case should be classified as high risk.

In industry and retail, the need usually shows up first in purchasing or sales. One employee tests an AI tool for preparing quotes, another uses a different tool to translate supplier contracts. Without an overarching policy, this produces several parallel isolated solutions, each carrying its own risk.

A policy is no substitute for training or technical inspections. It provides the framework within which both take place. Companies that merely adopt a document without actually filling the roles described in it end up with a piece of paper that has no effect.

The Test for a Good PolicyEmployees should consult it before trying out a new tool, not only after a problem has arisen. This means it must be written in a concise, easy-to-understand manner, without legal jargon. A twenty-page document that no one reads is as good as no policy at all.

Four Steps to Establishing AI Governance in Your Company

  1. Taking Stock. Which AI applications are already in use—either officially or unofficially by individual employees? This list is often longer than expected because many employees have long been using free AI tools without the IT department’s knowledge.
  2. Risk Classification. Each identified application is classified into one of four levels (caralegal, 02/2026). This classification determines the scope of further work.
  3. Define roles. Approval of new use cases, monitoring of operational systems, and serving as the point of contact in the event of incidents. For high-risk applications, a human remains central to the decision-making process; this “human-in-the-loop” principle cannot be replaced by automated controls.
  4. Training and Monitoring. To ensure that new use cases do not slip under the radar of governance again.
The four risk classes and the effort they require, after caralegal 02/2026
Class A typical example What is required
Prohibited Social scoring, biometric categorization based on sensitive characteristics Use Prohibited
High Pre-screening of job applications, credit decisions Documentation, human-in-the-loop, ongoing monitoring
Limited Chatbots in Customer Service, AI-Generated Content Disclosure Requirements, Labeling
Minimal Internal text summary, spell check No specific obligations; observe data protection regulations

These four steps can be completed one after another, but they do not all have to be finished before the first project begins. A lean first draft of the policy that addresses only the most urgent issues is better than waiting months for the perfect document. Governance evolves as the first use cases are implemented.

Does every company need its own AI governance role?

Not every company needs to create a new full-time position for this. In smaller companies, the IT manager or a member of the data protection team often takes on this additional responsibility. What matters is not so much the title as it is clear accountability. AI governance that exists only on paper but is not specifically assigned to anyone is, in practice, no governance at all.

A valid counterargument is that additional approval processes slow down projects and rob them of the very agility that makes AI applications attractive. This concern is not unfounded if governance is interpreted as an additional hurdle for every little thing. An effective policy therefore distinguishes between low-risk applications, which can be launched without a lengthy approval process, and high-risk cases, where careful review is indeed necessary. Failing to make this distinction unnecessarily slows down even non-critical projects.

We have outlined the timeframes specified in the AI Regulation—which a directive should be based on—in our article on the EU AI Act Compliance Roadmap compiled. By planning governance and deadline management together, you can avoid duplicating work when it comes to documentation.

Assessment in a Single AppointmentWe'll work with you to identify which AI applications are already in use at your company and categorize them into the four classes. After that, we'll draft the first version of the policy.

Request an Appointment

Frequently Asked Questions

Does a company with 50 employees already need AI governance?

Yes, as soon as AI systems are in use, regardless of the size of the business. The scope of the policy may be narrower than that of a corporate group. At a minimum, there must be a risk classification and a designated approval authority, even if that person fulfills multiple roles at the same time.

Who should take on the governance role within the company?

Often, this role is filled by the head of IT in collaboration with the data protection officer. It is important that this person both understands the technical systems and has a say in legal and organizational decisions. Without this dual access, the role remains ineffective. In larger companies, it is also worthwhile to establish a small committee comprising representatives from the business unit, IT, and legal departments to evaluate new use cases.

How often should the AI policy be reviewed?

An annual review is a reasonable minimum frequency; in addition, every new AI application should undergo a review against the guidelines before it goes live. Given the ongoing changes to the EU AI Act, it’s also worth reviewing the guidelines as soon as a new deadline takes effect. A fixed trigger can be helpful—such as the annual financial closing or a recurring IT security audit.

The Next Step

torck builds AI systems for industry and retail and therefore knows the organisational side of governance from its own projects. With teams in Maxhütte-Haidhof, Vienna and Rabat, we implement the approval processes a policy describes. In an initial consultation we look at the AI applications already running in your own operation. Schedule an Initial Consultation.

Legal note
This article refers to laws and regulations to put technical decisions in context. It is not legal advice. Whether and how a rule applies to your company is a question for your legal department or a law firm.

Questions about this post?

Just a couple of sentences about your situation will suffice. The person responding builds these kinds of systems himself.

We'll respond within one business day.torck · code with torque
Florian Blischke
Managing Director of torck GmbH · Over 20 years of software development experience
Florian Blischke is the managing director of torck GmbH and has been working in software development for over 20 years. He is responsible for custom software solutions for industry and retail, ranging from the integration of physical processes and IoT to cloud architecture and data- and AI-driven systems. At torck, he oversees, among other projects, the Jouvoli energy platform and the KVM Fleet fleet management product. torck develops software at its locations in Maxhütte-Haidhof, Vienna, and Rabat, and places a strong emphasis on software that actually works in real-world operations.

Are you facing the same question?

We’ve been building software for industry and retail since 2017, based in Maxhütte-Haidhof, with teams in Vienna and Rabat. An initial consultation lasts 30 minutes and is free of charge. Afterward, you’ll know whether the project is worth pursuing—even if the answer is no.

More Articles

AI Funding Programs in Germany and Austria in 2026

AI Funding Programs in 2026 in Germany and Austria

Germany and Austria will fund AI projects in 2026 through several programs with varying funding rates and maximum grant amounts. This article categorizes the Research Grant, ZIM, KMU-innovativ, FFG, and aws programs and outlines the technical requirements for submitting an application.

Read more »