Skip to content
AI Literacy
Lektion 8 von 170/17 abgeschlossen
Datenschutz, Haftung & Governance

AI Governance in the Enterprise

BoardAI OfficeDSBAuditPolicyDPIAReviewGovernance-Struktur

🖱️ Interaktiv: Ziehen zum Drehen · Lektion 8

Learning objectives

After this lesson you will be able to:

  • Build an AI governance structure for your organization
  • Define roles and responsibilities for AI topics
  • Implement approval processes for new AI tools
  • Run compliance monitoring and internal audits

What is AI governance?

AI governance covers the structures, processes and policies that ensure AI systems are used responsibly, legally and with low risk in an organization.

The goal is not to prevent AI, but to steer its use so that opportunities are seized and risks minimized.

The AI policy

An AI policy is the central document of AI governance. It regulates:

  1. Scope: who does the policy apply to? (All employees, contractors)
  2. Approved AI tools: whitelist of approved AI systems
  3. Prohibited use: what is not allowed? (Personal data, critical decisions)
  4. Data protection requirements: which data may be entered into AI tools?
  5. Quality assurance: how is AI output reviewed?
  6. Labeling obligations: when must AI use be communicated?
  7. Training obligation: which training is required?
  8. Incident reporting: how are incidents reported?
  9. Responsibilities: who is accountable for what?
  10. Sanctions: what happens in case of violations?

💡 The AI policy is not a one-time document

A good AI policy is alive: it is updated regularly (at least annually), adapted to new AI developments and communicated to all employees. Best kept as a wiki page, not a dusty PDF.

Roles and responsibilities

AI officer

Responsible for the strategic steering of AI use. Accountable for policies, training, audits and communication with authorities. This role can be taken on by an existing position (data protection officer, compliance).

AI committee

An interdisciplinary body from IT, legal, data protection, compliance and business departments. Decides on approvals of new AI tools and handles escalations.

Department representatives

Each department (HR, marketing, sales) names a contact person for AI topics. This person knows the AI tools in their area and is the point of contact for questions.

📝 Schnellprüfung

Which role is responsible for the strategic steering of AI use?

The approval process for AI tools

Before an AI tool may be used in the company, it goes through an approval process:

Stages of the approval process

  1. Request: the business department reports a need
  2. Initial review: IT checks technical requirements (interfaces, security)
  3. Data protection review: data protection checks GDPR compliance (DPA, server location, data categories)
  4. Risk assessment: classification by EU AI Act risk classes
  5. Legal review: compliance checks the legal framework
  6. Decision: the AI committee or AI officer approves or rejects
  7. Integration: IT sets up the tool (with security configuration)
  8. Training: employees are trained
  9. Monitoring: regular review of usage

🏢 Praxis-Szenario: Approving a new AI tool

The marketing department wants to introduce an AI tool for automatic social media planning. The tool promises to create posts automatically and publish them at the optimal time. It would access customer data. How do you proceed?

Compliance monitoring

Regular reviews

IntervalMeasure
MonthlyReview usage statistics, record new AI tools
QuarterlyUpdate the AI inventory, check training progress
Semi-annuallyUpdate risk assessments, review policies
AnnuallyFull AI audit, policy update, refresher training

What is audited?

  • Completeness of the AI inventory: are all AI systems recorded?
  • GDPR compliance: are DPAs in place? Are data rights respected?
  • Art. 4 compliance: have all employees been trained?
  • Policy compliance: do employees follow the AI policy?
  • Incident history: have incidents been documented and resolved?

The emergency plan for AI incidents

An organization needs an emergency plan for AI incidents:

  1. Detection: how is an AI incident detected? (Monitoring, employee reports)
  2. Assessment: is it a reportable incident?
  3. Escalation: who is informed? (AI officer, management, data protection)
  4. Response: what measures are taken? (Stop the system, contain damage)
  5. Documentation: what happened? What was done?
  6. Follow-up: how is the incident resolved? What measures prevent recurrence?

💡 AI governance is a competitive advantage

Companies with good AI governance are not just compliant — they can introduce AI faster and more safely than competitors. Governance builds trust with customers, employees and supervisory authorities.

Summary: the AI governance roadmap

  1. Create and publish the AI policy
  2. Record the AI inventory (all AI systems)
  3. Conduct Art. 4 training (AI literacy)
  4. Name the AI officer
  5. Establish the approval process for new AI tools
  6. Set up compliance monitoring
  7. Plan the annual refresher

✅ Wichtige Erkenntnisse

Haken setzen, um deinen Lernfortschritt zu markieren:

→ Go deeper: AI tools at work — concrete usage policies for tools · Liability & compliance — incident reporting and fines

Weiterführende Inhalte

Governance-Checkliste im Guide

Relevante Rechtsgrundlagen: Art. 9 · Art. 17 · Art. 26

Im Modul "Datenschutz, Haftung & Governance" — weiter lernen