AI governance: why existing IT frameworks fall short.

AI governance is the set of agreements, roles, and processes that determines how an organization deploys, manages, and controls AI systems. Large organizations are already using AI, but only 31% have established a formal AI governance framework. This is shown by research from Deloitte Netherlands from 2025.

The consequences are concrete. Employees use AI tools without IT's knowledge. Decisions are made based on AI output that no one fully understands. And the EU AI Act turns this into a compliance issue with serious financial risks starting in 2026. 

In this article, we explain why existing IT governance is not sufficient for AI, what goes wrong if you don't manage it, what the EU AI Act concretely requires of you, and how to set up AI governance alongside the structures you already have.

What is AI governance?

AI governance determines who within an organization makes decisions about the deployment of AI, how those decisions are accounted for, and how risks are managed. It is about roles, policy, oversight, and processes that together ensure that AI is used safely, transparently, and controllably.

It differs fundamentally from IT governance. IT governance regulates decision-making about systems, infrastructure, and investments. AI governance goes a layer deeper: it regulates what happens when a system supports or makes decisions itself. Who is responsible if an AI system makes a mistake? How do you know if the output is reliable? And how do you ensure that employees know when they can trust AI output and when they cannot?

These questions are not technical in nature. They touch on strategy, legal liability, and organizational culture at the same time.

Why existing IT governance is not sufficient for AI

Many large organizations have established IT governance. There are decision-making structures, frameworks like COBIT or ITIL, and governing bodies that determine which systems are purchased and how they are managed. That works well for traditional IT. But AI behaves differently.

A traditional IT system does what it is programmed to do. The output is predictable and controllable. An AI system learns from data, adapts, and produces output that no one has fully determined beforehand. This means that standard control mechanisms are not sufficient. You cannot audit an AI system the way you audit an ERP system.

In addition, AI is entering the organization at a rapid pace, often bypassing IT. Marketing uses ChatGPT for texts. HR screens job applications with AI tools. Finance uses AI for forecasting. No one has registered this centrally, let alone assessed it for risk. We call this shadow AI: AI use without policy, oversight, or control.

Existing IT governance is designed for systems that IT manages. Shadow AI, by definition, falls outside of that. And even the AI systems that IT does manage require different governance than traditional software: who monitors the quality of the training data? Who decides when a model is updated? And who is responsible if the model makes a mistake that impacts customers or employees?

Read more about how IT governance works and how to set it up properly in our article What is IT governance and how to set it up properly.


What goes wrong if you don't manage AI governance

The risks are concrete and already visible in organizations that have deployed AI without frameworks.

Decisions without control

AI systems that support HR, finance, or operations produce output that employees rely on. If no one has determined how that output should be checked, decisions are made based on results that no one fully understands or can account for. That is a liability issue, not just a technical problem.

Shadow AI undermines your security

Employees using AI tools without supervision regularly enter confidential company information into public AI systems. Customer data, strategic plans, financial details: once that information ends up in an external AI system, you have lost control over it. Research by DTEX and Ponemon shows that shadow AI is now the leading cause of negligent insider incidents, with an average annual cost of 19.5 million dollars per organization.

Legal and reputational risks

The EU AI Act obliges organizations to be transparent about their AI use. If you don't know which AI systems are being used in your organization, you cannot provide that transparency. This leads to compliance risks, but also to reputational damage if things go wrong.

You lose control over your own processes

Organizations that deploy AI without governance notice over time that AI systems have become embedded in critical processes without anyone knowing exactly how. 63% of organizations can no longer enforce target limits for AI agents and 60% cannot terminate an AI agent if necessary. These are no longer theoretical risks.

What the EU AI Act requires of you

The EU AI Act has entered into force in phases since August 2024. For large organizations, the key obligations are already in effect or are coming soon.

AI literacy is already mandatory

Since February 2, 2025, all organizations using AI are required to ensure adequate AI literacy among employees who work with AI systems. That doesn't mean everyone has to take an AI course, but you must be able to demonstrate that employees understand how the systems they use work, what the limitations are, and what risks are associated with them. Enforcement by the Dutch Data Protection Authority starts on August 2, 2026.

Transparency obligations apply from August 2026

As of August 2, 2026, the general transparency obligation of Article 50 enters into force. Organizations must be able to demonstrate which AI systems they use and how human oversight is organized. For the strictest requirements around high-risk AI systems, such as risk assessment, technical documentation, and registration in the EU database, a new deadline of December 2, 2027, applies due to the Digital Omnibus package.

Fines are real

In case of violation of the ban on unacceptable AI practices, fines can reach up to 35 million euros or 7% of the global annual turnover. For other violations, fines up to 15 million euros or 3% of the turnover apply. The Dutch Data Protection Authority has announced that it will conduct targeted audits in the second half of 2026.

An AI register is the first step

Map out which AI systems your organization uses, including shadow AI. For each system, record the purpose, the supplier, what data it processes, and which risk category it falls into. Without that overview, compliance is impossible.

Read what the EU AI Act concretely requires of you and how to take the first step in our article EU AI Act: what do you need to arrange now and how do you take the first step.

How to set up AI governance alongside existing IT governance

AI governance does not need to be built from scratch. Large organizations already have structures, roles, and processes that serve as a foundation. The trick is expanding, not replacing.

Map out your AI use

Start with an AI inventory. What AI systems does your organization use, both formally and informally? Which departments use which tools? What data is being processed? Without this overview, governance is impossible. An AI register, even if it is a simple spreadsheet, is the first concrete step.

Determine who is responsible

Existing IT governance has roles for decision-making about systems and investments. AI requires additional roles. Who monitors the quality of AI output? Who decides if an AI system falls into a high-risk category? Who is responsible if an AI system makes a mistake? Record this before things go wrong.

Link AI governance to existing consultation structures

You do not need to establish a new governance body. Add AI as a standing agenda item to existing IT meetings. Ensure that HR, Legal, and Finance are at the table, because AI governance is not just an IT issue. It touches on liability, privacy legislation, and organizational culture at the same time.

Draft an AI policy

An AI policy does not need to be extensive. It determines what employees can and cannot do with AI tools, how shadow AI is reported, and how new AI applications are assessed before they are put into use. That policy is also the foundation for your AI literacy obligations under the EU AI Act.

Ensure human oversight

AI governance is not a one-time project. It requires continuous monitoring of how AI systems are deployed and what they deliver. Establish for which decisions AI output must always be checked by a human. That is not only wise, but also legally expected.

How we approach this

AI governance affects the entire organization, but also requires people who can translate between technology, legislation, and organizational issues. That is exactly where our consultants step in.

We start with an inventory of current AI use within your organization. What systems are there, who uses them, and what risks are associated with them? Next, we map out where the current IT governance structure falls short and what needs to be supplemented.

Then, we help you assign the right roles and responsibilities, draft an AI policy that fits the scale and complexity of your organization, and integrate AI governance into existing consultation structures. We ensure the right people are at the table and that decision-making about AI does not just land on IT.

Our consultants take responsibility for the outcome. They not only work on the governance structure but also ensure your team can actually work with it. This way, you build something that keeps working, even when we are no longer there.

Curious how your organization approaches AI governance?

Is your organization already working with AI but the frameworks are not yet in order? Contact Maarten.

Anything to amaze you.


Frequently asked questions about AI Governance

What is the difference between AI governance and IT governance?

IT governance regulates decision-making regarding systems, infrastructure, and IT investments. AI governance goes a layer deeper: it regulates what happens when a system itself supports or makes decisions. Who is responsible when an AI system makes a mistake? How do you control output that no one has fully determined? Those questions fall outside the scope of traditional IT governance.

What is shadow AI and why is it a risk?

Shadow AI is the use of AI tools by employees without the knowledge or approval of IT or management. For example, an employee entering confidential customer data into ChatGPT to write a report. This way, the data leaves the organization without any control. Shadow AI has now become the leading cause of negligent internal data breaches at organizations.

How do I know if my AI systems fall under the high-risk category?

The EU AI Act classifies AI systems based on risk. High-risk systems are those that have an impact on areas such as recruitment, creditworthiness, critical infrastructure, or law enforcement. If you use AI in HR, finance, or operations, there is a significant chance that your systems fall into this category. A risk assessment per system is the only way to know this for sure.

What is an AI register and am I required to maintain one?

An AI register is an overview of all AI systems used by your organization, specifying the purpose, the supplier, the processed data, and the risk category for each system. A formal register is mandatory for high-risk systems. For other systems, it is not legally required, but it is the foundation for any form of AI governance and compliance.

Where do you start if you want to set up AI governance but already have an existing IT governance structure?

Start with an AI inventory: map out which AI systems are already in use, including informal ones. Next, look at where your existing governance structure falls short and what needs to be added. You don't need to establish a new body. Add AI as a regular agenda item in existing consultation structures and ensure HR, Legal, and Finance are involved. The governance structure you already have is an advantage, not an obstacle.

B. Amsterdam (B.2)

John M. Keynesplein 12-46

1066 EP Amsterdam

Follow us on LinkedIn for updates

© 2022 - 2026 Koodin

|

|

B. Amsterdam (B.2)

John M. Keynesplein 12-46

1066 EP Amsterdam

Follow us on LinkedIn for updates

© 2022 - 2026 Koodin

|

|

B. Amsterdam (B.2)

John M. Keynesplein 12-46

1066 EP Amsterdam

Follow us on LinkedIn for updates

© 2022 - 2026 Koodin

|

|