Putting AI Governance Into Practice

Ian Hopkins, Head of Sales & Commercial Ops- EMEA, Axonis
September 8, 2026

Every conference this year has had governance somewhere on the agenda — on a panel, on a booth, in a keynote. But it took a lunchtime conversation at Ai4 to make me stop and think about what the word actually means in day-to-day operations. Below is where that question led me, and the five things I'd focus on if you're moving AI from pilot into production.

What Does AI Governance Actually Mean?

Having attended many conferences over the last year, one topic has come up again and again during conversations, and plastered across every booth marketing campaign: Governance. It's a fundamental building block to successfully operationalising AI at scale.

But what do we actually mean by it, as that single word has such a broad scope?

That question came into sharper focus for me during a chance conversation over lunch at Ai4 2026, when someone flipped the question and asked me, “What does governance mean to you?”

It’s a simple enough question, but when a term is used by so many people, it’s bound to mean different things to different individuals and organisations. In my work with organisations putting AI into practice, I see just how important it is to move beyond talking about governance in principle, to establishing what it actually means in practice.

At its core, governance is about how rules, responsibilities and actions are structured, sustained and enforced. It touches policies, frameworks, access and controls, providing the guardrails organisations need to operate with trust and accountability.

So, when it comes to AI, how does this apply, and why is it so important?

The Cost of Weak AI Governance

I’m sure you’ve heard about the very large tech company that built an AI recruiting tool to help score job applicants by learning patterns from past CVs. At first, it appeared efficient, but its training data reflected the company’s historically male-dominated technical workforce. The model consequently learned to penalise CVs containing signals associated with women, for example, references to women’s colleges or women’s sports, because it treated those terms as negative predictors of hiring success.

The system was eventually abandoned. The key governance failure was not that the model “decided” to discriminate on its own; it was that the organisation did not adequately govern the full lifecycle:

  • Historical data was accepted as a proxy for merit without sufficient bias testing.
  • The team had no robust, pre-defined fairness thresholds for automated candidate scoring.
  • Human oversight and auditability were insufficient for a high-impact employment decision.
  • Detecting individual biased features did not prove the wider model was fair.

Without the correct guardrails and controls in place before deployment, AI can often go off track quietly. It can optimise exactly what it has been trained to do while violating an organisation’s actual values, legal obligations and intended policy.

Data provenance, impact assessment, independent testing, clear accountability, monitoring and a credible route to stop or override the system are all important. Yet having a human in the loop to attest to a decision still isn’t part of the process for many organisations.



5 Ways to Put AI Governance Into Practice

So, what does putting those principles into practice actually look like? Here are my top 5 suggestions for putting AI Governance into practice:

  1. Define decision rights before deployment
    Before go-live, name the individual accountable for AI outcomes and define the escalation path when the model is wrong. Operationalising AI at scale requires accountability to be personal and specific, not just documented in a policy framework.
  2. Require human attestation on high-stakes decisions
    The right person must review the evidence behind an AI recommendation, not just the output, and formally attest to the decision. This is what keeping humans accountable for the decisions that follow looks like in practice.
  3. Log non-decisions as well as decisions
    When AI assesses a situation and chooses not to act, that is still a consequential decision. Logging it with full context and data provenance builds the evidence and auditability needed to meet regulatory requirements, including the EU AI Act.
  4. Test for fairness before accuracy
    Define fairness thresholds across demographic and contextual slices before deployment. Overall accuracy is not the same as equitable outcomes, and the guardrails need to be in place before go-live, not retrofitted after a regulatory challenge.
  5. Give compliance a read-only window into AI reasoning
    Build role-based access into your audit trail from the start. The operational team sees the recommendation; compliance sees the full evidence chain; regulators receive a time-stamped record of every decision and its provenance. This is governance as architecture, not an afterthought.

As organisations move AI from pilot to deployment, the challenge is making these principles part of how AI actually operates. Governance can’t simply sit alongside an AI strategy; it needs to be built into the architecture and into how AI-informed decisions are made and governed.

Building Governance Into AI Operations

That’s a challenge we help organisations address at Axonis. Our approach to Decision Intelligence is designed to enable organisations to operationalise AI at scale while maintaining control over their data, establishing clear governance and keeping humans accountable for the decisions that follow. It also helps organisations build the evidence, oversight and auditability needed to support compliance with evolving regulatory requirements, including the EU AI Act.

Meet Me at HumanX Amsterdam

I’ll be at HumanX Amsterdam with Axonis, meeting with organisations navigating this transition. If AI governance, sovereignty, EU AI Act compliance, and scaling trusted AI are priorities for your organisation, I’d welcome the opportunity to meet and discuss how you’re approaching them.


Book a Meeting with Ian: https://bookings.cloud.microsoft/book/AxonisHumanXDiary@axonis.ai/?ismsaljsauthenabled 

Frequently Asked Questions

What is AI governance?

AI governance is the framework of policies, controls, responsibilities and oversight that determines how AI is developed, deployed and used within an organisation. Effective governance extends beyond written policies to include how data is accessed, how AI outputs are used, who has authority to act on them and who is ultimately accountable for the decisions that follow.

Why is AI governance important?

As AI becomes embedded in operational and business decisions, organisations need to know that those decisions are based on trusted data, made within established guardrails and subject to appropriate human oversight. Without effective governance, organisations can introduce regulatory, security, bias and accountability risks that may not become apparent until after AI is deployed.

How do organisations move AI governance from policy into practice?

Operationalising AI governance means building controls into the way AI actually works. This can include data provenance, role-based access, defined decision rights, human review and attestation, audit trails, monitoring and mechanisms to stop or override AI when necessary. Governance should be part of the architecture and decision process rather than something applied after deployment.

What role should humans play in AI governance?

For decisions requiring human accountability, having a human in the loop means more than simply reviewing an AI recommendation. The appropriate person needs access to the evidence behind the recommendation, the authority to question or override it and the ability to attest to the decision. This creates a clear line of accountability between AI-generated intelligence and human action.

What is the relationship between AI governance and data sovereignty?

They address different but increasingly interconnected requirements. Data sovereignty focuses on where data resides, who controls it and which legal or organisational requirements apply to it. AI governance focuses on how AI and AI-informed decisions are controlled and overseen. Organisations operating across jurisdictions, business units or sensitive environments often need to address both simultaneously.

How does Axonis support AI governance?

Axonis brings AI to distributed data rather than requiring organisations to centralise sensitive information before they can use it. Its Decision Intelligence approach is designed to preserve control and provenance while enabling organisations to apply governance, access controls, evidence and human accountability to AI-informed decisions across cloud, on-premises and edge environments.