Skip to content

AI Governance — plain language, current weekly

AI governance is the set of decisions and habits that keep a company in control of the AI it uses — instead of the other way around. It is what the board, the regulator, the customer, and the curious new hire all want to understand the moment they hear "we're using AI."

This site is the plain-language version. No jargon, no legal Latin, no pretending you should have already read 500 pages of legislation. Twelve clear steps, in everyday words, that take you from "we use AI" to "we govern AI" — with the actual laws, standards, and real-world examples linked alongside.

What is AI governance, really?

Imagine your company starts using AI: a chatbot for customers, an internal tool that summarises meeting notes, a model that helps decide which insurance claims look suspicious. Each one of those is a powerful piece of machinery — and like any powerful machinery, it can save you a fortune or cause real harm depending on how you build it, who you let near it, and what you do when it misbehaves.

AI governance is the practical answer to three simple questions:

  1. What are we allowed to do with AI here? The rules your company has set, and the laws that apply to you.
  2. How do we know the AI is doing what we said it would? The testing, the documentation, the named people on the hook.
  3. What do we do when something goes wrong? Because eventually it will — incidents, drift, surprises, complaints.

The good news: this is not new ground. Aviation, medicine, banking, food safety, electrical work — every powerful industry built its own playbook over decades. AI is doing the same, in years rather than decades, and this site walks you through that playbook one stage at a time.

How to use this site

There are three ways in. Pick whichever feels right.

  1. Read the journey in order. Start with Stage 1 — AI Policy and click through to stage 12. Each page takes about 8 minutes. The whole journey is roughly an afternoon's reading and gives you a complete mental model.
  2. Jump to what you need. Use the sidebar (left, or hamburger menu on mobile) or click any stage in the diagram below. Each stage page stands on its own — no need to read the earlier ones first.
  3. Try the wizard. Five quick questions and you get a personalised checklist of governance topics to take to your lawyer. No personal data leaves your browser.

Every stage page opens with an "In plain English" section that explains the topic the way you'd explain it to a friend over coffee. Below that you'll find three lenses — Executive, Engineer, and Compliance — so each reader can jump to the angle that speaks to them. A recurring cast of fictional companies (a Berlin hospital, a London insurer, a Tokyo logistics firm, a US robotics maker) threads real scenarios through the narrative so concepts always come back to something you can picture.

The 12-stage AI governance journey

Read the map below like a journey: four phases, twelve stages. Every box is a click. Below the diagram you'll find a plain-language summary of each phase so you can spot which one applies to your situation.

What each phase actually means

Phase 1

Set the rules

Decide what your company will — and won't — do with AI.

Before you build, buy, or deploy a single AI feature, your company needs to agree (in writing) on the basics: which uses of AI are welcome, which are off-limits, and who decides when something falls in the grey zone. Without this, every team will quietly make up their own rules — and a year later nobody can explain why one team's chatbot is fine and another's was shut down.

  • 1 · AI Policy — the short written document that says "here's what we'll do, here's what we won't, here's who owns each call."
  • 2 · Risk Tiering — rating each AI system before you build it: is it banned, high-risk, moderate, or routine? The rating decides how much paperwork follows.
  • 3 · Risk Check — rechecking each system as things change. New data, new users, new regulators — the rating from day one rarely stays true.
Phase 2

Make it legal & safe

Meet the laws. Vet your suppliers. Protect your data.

Powerful machinery is regulated for a reason. The EU AI Act, GDPR, sector rules in finance and healthcare, US state laws — all of them apply to what your AI does, not what it's called. Phase 2 is the unglamorous but unavoidable work of producing the evidence that you're inside the lines. It also covers the AI you didn't build yourself (most of it, in practice) and the data running through all of it.

  • 4 · Compliance — the folder of evidence that proves your AI meets the laws and standards that apply where you operate.
  • 5 · Third-party AI Risk — governing the models, APIs, and SaaS tools you bought. Your name is over the door even when someone else built the model inside.
  • 6 · Data Controls — knowing where every piece of data came from, who can see it, and how long you keep it. AI is mostly data; ungoverned data means ungoverned AI.
Phase 3

Prove it works

Stress-test the AI. Document everything. Name who's on the hook.

Once your AI runs in production, regulators, customers, and your own board will want to see proof — not promises — that it works as claimed, that it's been deliberately tested for ways to break it, and that there is a clear human on the line if something goes wrong. Phase 3 is where the evidence file gets built. Skip it and you'll spend the rest of your AI's life reconstructing it under deadline pressure.

  • 7 · Continuous Red-teaming — deliberately trying to fool, jailbreak, or trip up your AI — over and over, forever — so that you find the failure modes before a real user does.
  • 8 · Documentation — writing down what the AI is, how it was built, what it's good at, what it's bad at, who tested it, and who signed it off — in language a non-engineer can read.
  • 9 · Accountability — naming the role (not the person) responsible at every decision: build, launch, run, stop, explain.
Phase 4

Run and watch

Supervise live AI. Handle incidents. Keep an eye on it forever.

Launching the AI is the beginning, not the end. The world changes, the data changes, the rules change, users get more creative. Phase 4 is the ongoing work of keeping a live AI system honest — special care for AI that acts (not just answers), a rehearsed playbook for the day something breaks, and continuous monitoring so you spot drift before a customer complains on social media.

  • 10 · Agentic AI Oversight — special governance for AI that does things on its own (sends emails, spends money, writes code), not just AI that answers questions.
  • 11 · Incident Response — the rehearsed playbook for when the AI goes wrong: detect, contain, notify, fix, learn. The deadlines for regulator notifications are short and unforgiving.
  • 12 · Monitoring — the dashboards, alerts, and quiet daily eyes-on-it that keep the AI from quietly degrading. Findings here loop you back to Phase 1.

Where to start

If you only have ten minutes, open Stage 1 — AI Policy and read the In plain English section. It is the most important page on the site. Almost everything that goes wrong in AI governance starts with the organisation not having written down what it will and won't do.

If you want to know what's changed in the world of AI regulation recently, open What's new. Once the tracking pipeline is fully live (Phase 3), this page lists every detected change with a link to the dated snapshot.

Where this site is right now: All twelve stage explainers are live in plain language. The weekly "what changed in AI regulation" tracker is being wired up next.


This site explains AI governance in plain language. It is not legal advice. Talk to a qualified lawyer before acting on anything you read here.