What it actually is, the vocabulary it runs on, and how organizations put it into practice — three ways into the same body of knowledge, for three different starting points.
Every page in this section is grounded in the IAPP AIGP Body of Knowledge (v2.1, effective February 2026) — nothing here is invented or paraphrased loosely from memory.
AI governance is the set of principles, roles, policies and controls an organization puts in place so that its AI systems are built and used responsibly — fair, transparent, safe, accountable to a real person, and compliant with the laws that already apply, plus the newer laws written specifically for AI. It sits at the intersection of law, risk management and engineering practice, which is why it's usually its own discipline rather than something bolted onto an existing legal or IT function.
The field is organized around four domains — think of them as the map this whole section follows, from "what is this and why does it need rules" through to "how do you actually keep a live system safe once it's deployed."
What AI governance is, the shared vocabulary, why AI carries novel risk, and how an organization stands up a program with clear roles, policies and lifecycle controls.
Existing law that already binds AI — privacy, IP, non-discrimination — plus AI-specific law and frameworks: above all the EU AI Act, alongside OECD, NIST and ISO.
The build half of the lifecycle — scoping a use case, assessing impact, governing the data, training and testing rigorously, then releasing and monitoring responsibly.
The deploy half — choosing and assessing a system (built or bought), contracting with vendors, then operating, monitoring and eventually retiring it.
Pick the page that matches where you're starting from — they all draw on the same source material, just at different altitudes.
Every page in this section refers back to the same four frameworks. They are not interchangeable — one is a voluntary pledge, one is a certification, one is a risk checklist, and one is an actual law with fines attached.