What is AI governance?
Deciding what your AI may do, who answers for it, and being able to show how you decided. The law that binds you, any standard you follow and your own rules all meet here.
Where this usually starts
Almost nobody sets out to do AI governance. People arrive at it through a narrower question: whether a law reaches them, whether a standard is worth certifying to, or whether the policy someone wrote last year still describes what staff are actually doing.
Those turn out to be the same question asked from different ends, and the answers have to agree with each other. A policy that contradicts a duty you are under is worse than no policy, because it tells people the wrong thing with authority. That is the job a framework does. It is the structure that keeps the separate answers consistent, and it is built from decisions and records rather than bought.
If you are starting from nothing and want the short version first, where to start with AI governance sets out the first few moves without the detail.
Four things get called AI governance, and they are not interchangeable
The EU AI Act is law. Where it reaches you it binds you, and whether it reaches you at all is settled by Article 2 rather than by where you are registered.
ISO/IEC 42001 is a voluntary management system standard, and the one instrument here an accredited body can certify you against (ISO/IEC 42001:2023). Choosing it is a decision about how you want to run and evidence your AI governance, not a way of discharging a legal duty.
EN 18286 is the European standard written around the quality management system the Act requires. CEN-CENELEC ratified it on 12 July 2026 and BSI has issued it in the UK as BS EN 18286:2026 (CEN-CENELEC on the publication of EN 18286). It has not been cited in the Official Journal yet, so nobody can claim a presumption of conformity from it so far.
The NIST AI Risk Management Framework is voluntary too, and has no certification machinery behind it at all (the NIST AI Risk Management Framework (NIST AI 100-1)). It is a way of thinking about AI risk that many organisations run inside a management system built to the standard.
The distinction that matters most across all four: conformity with a standard is not compliance with a law. The standard-versus-Act guide works through where the two meet and where they do not.
If you are in the UK
The EU AI Act can still reach a UK organisation. It works on what your AI touches rather than where your office is, which is why the scope test in Article 2 is the first thing worth settling. Plenty of UK organisations are caught through outputs used in the EU without having any EU presence at all.
Whether the Act applies to you works through that test properly.
The rest of the site
Checked against Regulation (EU) 2024/1689, the Artificial Intelligence Act as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI
Primary sources
Start with what binds you
The EU AI Act check works through the scope rules and tells you which duties reach the systems you named, and when each one applies.