AI Governance Frameworks: A Tiered Model Using NIST, ISO 42001, and the EU AI Act
How to build AI governance that scales with risk: inventory, risk tiers, controls per tier, and EU AI Act dates after the 2026 Digital Omnibus.

AI governance fails in two opposite ways. Some companies write principles, form a committee, and never connect either to the systems actually being built. Others apply the same heavy review to every use of AI, so a meeting-notes tool waits three months behind the same process as a credit model, and people route around the process entirely.
What works is governance proportional to risk: light rules for low-risk uses, real controls for high-risk ones, and a reliable way to know which is which. This guide lays out that model, maps it to the main frameworks, and gives the current EU AI Act dates after the 2026 Digital Omnibus.
The frameworks, briefly
You do not need to invent a framework. Three references cover most needs:
- NIST AI Risk Management Framework (AI RMF 1.0, January 2023). Four functions: Govern (policies, roles, culture), Map (context and risks of each system), Measure (testing and metrics), and Manage (acting on risks). The Generative AI Profile (NIST AI 600-1, July 2024) adds risks specific to generative models, such as confabulation and information integrity. Free, flexible, and widely used in the US.
- ISO/IEC 42001:2023. An AI management system standard, structured like ISO 27001 for security. It is certifiable, which matters when enterprise customers want third-party assurance rather than your word.
- OWASP Top 10 for LLM Applications. A practical security list: prompt injection, sensitive information disclosure, excessive agency, and others. Useful for engineering teams building on language models.
Use NIST to design controls, ISO 42001 if you need certification, OWASP for the security of LLM features, and map all of it to the laws that apply to you.
EU AI Act dates after the Digital Omnibus
The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026 and changed several dates and duties.
| Obligation | Applies from |
|---|---|
| Prohibited practices (Art. 5) | 2 February 2025 |
| AI literacy (Art. 4), now phrased as a duty to take supporting measures | 2 February 2025 |
| General-purpose AI model obligations | 2 August 2025 |
| Transparency duties (Art. 50): disclosing AI interactions, labeling certain content | 2 August 2026 |
| New prohibitions on non-consensual intimate imagery and AI-generated CSAM | 2 December 2026 |
| High-risk systems in Annex III (hiring, credit scoring, education, essential services) | 2 December 2027 |
| High-risk AI in products under Annex I (machinery, medical devices) | 2 August 2028 |
Fines reach €35 million or 7% of global turnover for prohibited practices and €15 million or 3% for most other breaches. SMEs and small mid-caps now face the lower of the two amounts.
In the US there is no federal AI law, but state rules are arriving: California's CCPA regulations on automated decision-making and Colorado's revised AI law both take effect on 1 January 2027. Our AI and SaaS data privacy guide covers those.
Step 1: Know what you have
Governance starts with an inventory, and most companies find more AI than they expected. Include:
- Models your teams built or fine-tuned
- AI features inside vendor products you use (CRM scoring, HR screening, support chatbots)
- Direct use of AI APIs in scripts and internal tools
- Employee use of AI assistants
For each, record the owner, purpose, data used, who is affected by its outputs, and whether a person reviews those outputs. A spreadsheet is fine to start.
Step 2: Tier by risk
Assign each use a tier based on what happens when it is wrong. A simple three-tier model:
| Tier | Examples | What makes it this tier |
|---|---|---|
| 1: Low | Drafting internal documents, meeting summaries, code suggestions a developer reviews | A person reviews every output; errors are cheap and internal |
| 2: Medium | Customer-facing chatbots, marketing content, sales lead scoring, internal forecasting | Outputs reach customers or drive business decisions; errors cost money or reputation |
| 3: High | Hiring and promotion, credit and insurance decisions, medical or safety uses, anything in EU AI Act Annex III | Outputs affect people's rights or safety; regulated |
Any use that falls under a specific law goes to Tier 3 by default.
Step 3: Controls per tier
| Control | Tier 1 | Tier 2 | Tier 3 |
|---|---|---|---|
| Registered in inventory with owner | Yes | Yes | Yes |
| Approved tool with enterprise data terms | Yes | Yes | Yes |
| Documented purpose and data sources | Brief | Yes | Detailed |
| Pre-launch testing | Not required | Accuracy and safety tests on representative cases | Accuracy, bias across groups, robustness, security |
| Independent review before launch | No | Peer review | Separate validation team or external |
| Human oversight in use | User reviews output | Sampling and escalation path | Defined human review; ability to override |
| Monitoring in production | No | Error and complaint tracking | Drift, outcome, and fairness monitoring |
| Explanation for affected people | No | On request | Required, in plain language |
| Incident process | General IT | Named owner | Formal, with regulatory notification where needed |
The point of the table is speed for Tier 1. A developer using an approved coding assistant should need no approval at all. A team launching a customer chatbot should get through review in days. Only Tier 3 should take the full process.

Agents need their own rules
AI agents that call tools, send emails, change records, or spend money add a risk the tiers above do not fully capture: excessive agency, in OWASP's terms. A few rules help:
- Least privilege. Give each agent only the tools and data it needs, with scoped credentials rather than a person's full access.
- Approval for irreversible actions. Payments, deletions, external communications, and changes to access rights need a human confirmation step.
- Treat inputs as untrusted. Agents that read emails, web pages, or documents can be manipulated by instructions hidden in them (prompt injection).
- Log everything. Every tool call, with inputs and outputs, so actions can be reconstructed.
Shadow AI
Verizon's 2026 Data Breach Investigations Report found 45% of employees using AI tools regularly, two-thirds through personal accounts, with source code the most common data pasted in. IBM's 2026 breach study found that 92% of organizations that had an AI-related breach had no access controls on their AI systems.
Blocking consumer AI tools outright usually pushes use onto personal devices. More effective:
- Provide approved tools with enterprise terms that exclude your data from training.
- Publish a one-page policy: which data classifications may go into which tools.
- Make adding a new tool a quick, lightweight request.
- Monitor for large uploads to unapproved AI services, as you would for file-sharing sites.
Who owns governance
A small cross-functional group, typically legal, security, data, and a business representative, owns the policy, the tiering rules, and Tier 3 reviews. Each AI system has a named business owner accountable for its results. Engineering builds the controls (logging, testing, monitoring) into the platform so teams do not reinvent them. Training for the AI literacy duty can be short and role-specific; what matters is keeping a record of it.

A first quarter
- Weeks 1 to 4. Build the inventory and assign tiers.
- Weeks 4 to 6. Publish the acceptable use policy and the approved tool list.
- Weeks 6 to 10. Apply the control matrix to all Tier 3 and Tier 2 systems, starting with any that fall under the December 2027 EU deadline.
- Weeks 10 to 13. Build shared tooling for logging, testing, and monitoring, and decide whether ISO 42001 certification is worth pursuing for your customers.
For the data side, see generative AI data governance. For model monitoring, see MLOps best practices. For regulated financial models, AI financial risk management covers SR 11-7 and model validation.
This guide is for informational purposes only and is not legal advice. AI regulations are changing quickly; confirm current obligations with qualified counsel.



