AI governance and law: build controls around real uses, not slogans
A practical evidence guide to AI governance, legal duties and organisational controls, including literacy, accountability, data protection, security and why a policy document is not the same thing as working governance.
Last reviewed 2026-07-25
What does practical AI governance look like?
Practical AI governance connects each real system to an owner, purpose, data boundary, risk level, approval process, monitoring plan and route for stopping or escalating use. It should be visible in procurement, access control, staff guidance and incident handling, not just a policy PDF. The aim is to make responsibility legible when an AI system influences work, customers or regulated decisions.
Which legal issues should organisations consider?
The answer depends on jurisdiction and use case, but recurring areas include data protection, discrimination, consumer protection, intellectual property, sector regulation, employment duties, record keeping and contractual responsibility. The EU AI Act adds system-specific obligations for activities within its scope, while UK organisations must still apply existing law and regulator guidance. A single “AI policy” cannot replace that legal mapping.
Why are AI literacy and governance connected?
Governance fails if the people operating a system cannot recognise when its output is unreliable or outside scope. The European Commission’s AI literacy guidance explicitly links understanding to the context, risk and purpose of systems. That does not mean every employee needs technical depth. It means controls have to be understandable enough for the people expected to apply them during ordinary work.
What is the most common governance trap?
The trap is governing the vendor description instead of the actual use. A low-risk writing assistant can become high-risk when staff paste sensitive data into it, and a powerful system can be tightly constrained to a harmless task. Inventory the use case, data, permissions and decision impact. Then revisit it when the tool changes, because cloud AI products can evolve without asking your policy document for permission.
What does the current evidence say?
- The European Commission says AI literacy measures under Article 4 should reflect technical knowledge, context, purpose and system risk, and that high-risk deployers retain specific staff-training obligations for human oversight. Source
- The Bank of England/FCA 2024 survey found 84% of responding firms had an individual accountable for their AI approach, while 34% reported a complete understanding of the AI they used. Source
Limitations
There is no single AI governance framework that automatically proves compliance across jurisdictions or sectors. Obligations change with the system, data, affected people and legal context, and this guide is an evidence map rather than legal advice.
A counterpoint worth keeping
A bigger governance committee can make control worse if ownership becomes diffuse. For many organisations, a smaller set of named decision owners, clear thresholds and auditable records beats a grand board that meets quarterly and owns nothing between meetings.
Sources and provenance
- European Commission, AI Office · AI Literacy - Questions & Answers · 2025-11-19 · Primary source
- Bank of England and Financial Conduct Authority · Artificial intelligence in UK financial services - 2024 · 2024-11-21 · Primary source
- Information Commissioner’s Office · Guidance on AI and data protection · 2025-06-19 · Primary source
- UK Government · Code of Practice for the Cyber Security of AI · 2025-01-31 · Primary source