AI security

What is AI Governance?

A plain-language guide to AI governance in cybersecurity, covering the risks, the EU and Swedish rules and the controls that keep AI lawful, secure and accountable.

Key takeaways
  • AI governance is the policies, roles and controls that decide how an organisation adopts, uses and oversees AI so it stays lawful, secure and accountable.
  • It is broader than AI security and is owned at board level.
  • Most AI risk comes from buying and using third-party tools, including shadow AI, so using AI is a form of deploying it.
  • The World Economic Forum found only 37 percent of organisations assessed AI tool security before deployment in 2025, rising to 64 percent in 2026, still leaving about a third with no check.
  • The EU AI Act applies in phases, with general rules from 2 August 2026 and high-risk duties from 2 December 2027. Fines reach 35 million euros or 7 percent of global turnover.
  • Three frameworks anchor a programme: the NIST AI Risk Management Framework (Govern, Map, Measure and Manage), the certifiable ISO/IEC 42001 and the EU AI Act.
  • OWASP ranks prompt injection the top risk for AI applications, where hidden text becomes a command the model obeys.
  • Sweden’s Cybersäkerhetslagen makes the board responsible for security measures, with personal accountability for its members.
  • Air Canada was held liable in 2024 for wrong advice its chatbot gave a customer, so a deployed AI speaks for the business.
  • Start with an inventory of every AI tool in use, then a policy, a named owner and human oversight of consequential decisions.

AI Governance Defined in Plain Terms

AI governance is the set of policies, roles and controls an organisation uses to decide how it adopts, uses and oversees artificial intelligence so that every AI system stays lawful, secure and accountable to a named person. It covers the whole life of a tool, from the decision to buy it through to the day it is retired.

In cybersecurity terms, governance is the layer that sits above the tools. Security asks whether an AI system can be attacked. Governance asks the wider question of whether the organisation should be using the system at all, who signed it off, what data it may touch and who answers for it when it goes wrong.

That matters because most AI risk today is not exotic. It is the ordinary result of useful tools being adopted faster than anyone put rules around them. Governance is how a business keeps the value of AI without quietly inheriting a liability it never reviewed.

Why AI Governance Became Urgent

AI governance is not a new idea. It became urgent because adoption outran oversight. Generative AI tools reached almost every desk in about two years and staff began using them to write code, summarise documents and draft customer replies long before most employers had any policy.

Why AI Governance Became Urgent

The World Economic Forum caught the gap plainly. Its Global Cybersecurity Outlook 2025 found that 66 percent of organisations expected AI to have the most significant impact on cybersecurity in the year ahead, yet only 37 percent had a process to assess the security of an AI tool before deploying it.

By the 2026 edition that second figure had nearly doubled to 64 percent. That is real progress, though it still leaves about a third of organisations deploying AI with no security check at all.

There is a technical reason AI is hard to govern too. A large language model reads instructions and data through the same channel so text hidden in a document or a web page can be treated as a command. That is why governance has to reach into how AI is actually used day to day. It cannot stop at the contract you signed to buy the tool.

The Risks AI Governance Has to Manage

Good governance starts by naming what can go wrong. AI risk falls into a few clear groups and a programme has to hold all of them at once.

  • Security: AI systems are a new attack surface. The OWASP Top 10 for LLM Applications puts prompt injection at the top where hidden instructions in a document or web page hijack the model alongside data leakage, poisoned training data and over-permissioned agents.
  • Data and privacy: Staff paste confidential or personal data into public tools and that data can leave the organisation for good. Personal data used to train or feed an AI still falls under GDPR.
  • Model risk: Models can be confidently wrong, a behaviour often called hallucination and they inherit bias from the data they learned on. An unchecked model can reach a decision no person would defend.
  • Third party and supply chain: Most organisations buy AI rather than build it so the risk sits inside a vendor model, a plug-in or an API you do not control.
  • Autonomy: Agentic tools that act on their own, sending emails or changing records, widen the blast radius when something goes wrong so they need tighter limits.

The Business Impact of Weak AI Governance

When AI governance is missing, the costs are not abstract. They arrive as fines, lawsuits, lost data and lost trust.

The regulatory exposure is now large. Under the EU AI Act, penalties reach 35 million euros or 7 percent of worldwide annual turnover for banned uses above the ceiling under GDPR. A data-protection failure involving AI can trigger a GDPR case on top of that.

There is direct legal liability too. As the Air Canada case shows, a court can hold a company responsible for what its AI tells a customer, even when the company argues the tool acted on its own.

Then there is the quiet cost. Confidential code or customer records fed into a public tool cannot be pulled back and a biased automated decision can harm real people and end up in the press.

Under Sweden’s Cybersäkerhetslagen and the wider NIS2 regime the board is not a bystander in any of this. Article 20 makes the management body responsible for approving and overseeing security measures and supervisors can hold its members personally accountable.

Real-World Cases

Three failures show the pattern from different angles. A chatbot the company tried to disown, a leak nobody meant to cause and an automated decision that harmed thousands.

Real-World Cases

Air Canada Was Held Liable for Its Chatbot

In Moffatt v. Air Canada, decided by the British Columbia Civil Resolution Tribunal on 14 February 2024, a customer relied on the airline’s website chatbot which told him he could claim a bereavement fare after travelling. The airline’s real policy required the request beforehand, so it refused the refund.

Air Canada argued that its chatbot was a separate entity responsible for its own answers. The tribunal rejected that. It found the airline owed customers a duty of care and had not taken reasonable care to keep the chatbot accurate, then ordered it to pay the fare difference, about 650 Canadian dollars.

The money was trivial. The precedent was not. A deployed AI speaks for the business so its answers need testing, monitoring and a named owner, the same as any other official channel.

Samsung Lost Source Code to a Public AI Tool

In 2023, within about three weeks of allowing ChatGPT in its semiconductor division, Samsung engineers pasted confidential material into the tool on three separate occasions including internal source code and a recording of a private meeting turned into notes.

Under the tool’s default terms at the time, anything submitted could be used to improve the model and none of it could be recalled. Samsung then banned generative AI tools on company devices, as Bloomberg reported.

A ban alone tends to send people back to their phones. The governing move is an acceptable-use policy with one clear data rule. Never paste confidential or personal data into a public tool. Pair that with an enterprise option that keeps the data inside the organisation.

An Automated System Wrongly Accused Thousands in the Netherlands

The Dutch childcare benefits scandal, known locally as the toeslagenaffaire, is the hardest lesson. The Dutch tax authority used a self-learning risk-scoring system to flag benefit claims as possibly fraudulent with nationality among the factors it weighed.

It wrongly labelled tens of thousands of families as fraudsters, hitting people with dual nationality and non-Dutch surnames hardest and forced repayments that ruined households. The Dutch Data Protection Authority found the processing unlawful and discriminatory and Amnesty International called it racial profiling. The fallout helped bring down the Dutch government in January 2021.

High-impact decisions about people cannot be handed to a model unsupervised. They need a lawful basis for the data, testing for bias, a person who reviews adverse outcomes and a way for those affected to challenge them.

AI Governance and Compliance

AI governance is where several regimes now meet. Four matter most for Swedish organisations and each turns governance from good practice into a legal duty.

The EU AI Act, Regulation 2024/1689, is the first comprehensive AI law. It entered into force in 2024 and applies in phases with the first obligations from 2025. It sorts AI into risk tiers from banned uses through to high-risk systems that must meet strict duties on risk management, data quality, logging and human oversight.

General obligations and transparency rules apply from 2 August 2026 and the main high-risk tier from 2 December 2027 after the Digital Omnibus moved the date with high-risk AI built into regulated products following on 2 August 2028 . The Act binds deployers and non-EU providers whose output is used in the EU, not only the companies that build AI.

NIS2, transposed into Swedish law as Cybersäkerhetslagen (SFS 2025:1506, in force 15 January 2026), makes cyber risk governance a board duty. Article 20 puts the management body in charge of approving and overseeing security measures with personal accountability for its members and Article 21 requires supply-chain security and staff awareness training both of which now reach AI. See our guide to NIS2 in Sweden.

GDPR still applies whenever AI touches personal data. Any personal data used to train or prompt a model needs a lawful basis and a breach involving an AI system carries the same 72-hour notification duty to IMY under Article 33. More in our guide to GDPR compliance.

For financial entities, DORA adds ICT risk and incident-management duties supervised by Finansinspektionen and an AI tool counts as ICT. See our guide to DORA compliance.

None of these frameworks is satisfied by a document. They expect AI to sit inside a working management system which is where certification such as ISO 27001 for information security and continuous monitoring such as AI detection and response earn their place.

Signs Your AI Governance Is Failing

You can usually tell whether AI is governed by asking a few blunt questions. If the answers are vague so is the governance.

Signs Your AI Governance Is Failing
  • You cannot produce a list of the AI tools and features in use across the business.
  • Staff are using free AI tools for real work with no policy telling them what is allowed.
  • No single person owns AI risk so it falls between IT, legal and the business.
  • AI helps make decisions about people or money with no human reviewing the output.
  • There is no rule about what data can go into a tool and no way to tell if it already has.
  • If an AI system failed or leaked tomorrow, no incident plan mentions it.

One warning is worth stating plainly. A written AI policy is not governance. Governance is the inventory, the oversight and the monitoring actually running and a policy nobody enforces offers the comfort of control without the substance.

How to Build AI Governance

Building AI governance is less about a grand framework and more about a few durable habits run consistently. People, process and technology each carry part of the load.

Three reference points anchor most programmes. The NIST AI Risk Management Framework organises the work into four functions, Govern, Map, Measure and Manage. ISO/IEC 42001 turns that into a certifiable management system you can be audited against. The EU AI Act sets the legal floor. They overlap by design so using them together avoids duplicated effort.

  • Inventory every AI system: List the tools, features and vendors in use including the ones staff added quietly and keep the list current.
  • Write an acceptable-use policy: Say which tools are approved, what data is off limits and where to find an approved alternative.
  • Assign an owner: Give one accountable person or group the job of AI risk, reporting to the board that Cybersäkerhetslagen already holds responsible.
  • Tier your AI by risk: Map each use to a framework such as the NIST AI Risk Management Framework or ISO/IEC 42001 and treat high-impact uses with the most care.
  • Keep a human in the loop: Require human review of any AI decision that affects people, money or safety.
  • Build security in from the start: Follow the UK NCSC and US CISA Guidelines for Secure AI System Development across design, development, deployment and operation.
  • Check your suppliers: Ask AI vendors how they handle your data, where it is processed and how they secure their models.
  • Monitor and rehearse: Watch AI systems in use and fold them into incident response so a failure is caught and handled early.

Start with the inventory. You cannot govern, secure or report on AI systems you have never written down and everything else on this list depends on knowing what you actually run.

Myths & Facts

Myth

AI governance is an IT or legal problem.

If we do not build AI, we do not need to govern it.

A written AI policy means we are governed.

The EU AI Act only applies to companies that build AI.

Banning tools like ChatGPT solves shadow AI.

AI decisions are objective and neutral.

Fact

It is a board-level accountability issue. Sweden’s Cybersäkerhetslagen makes the management body responsible for security measures, with personal accountability for its members.

Most exposure comes from buying and using AI, including tools staff adopt on their own. Using AI is a form of deploying it, and the duties apply either way.

Governance is an inventory, active oversight and monitoring in practice. A policy nobody enforces changes nothing.

It also binds deployers and non-EU providers whose AI output is used in the EU. Running an AI system brings obligations too.

Bans tend to push use onto personal devices. Governed access with a clear data rule and a private alternative works better, as Samsung’s 2023 leak showed.

Models inherit bias from their training data. An ungoverned automated system wrongly accused tens of thousands of Dutch families of fraud, helping bring down a government.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. An employee wants to paste a confidential customer contract into a free public AI chatbot to summarise it quickly.

    What is the right call?

    • Allow it, summaries save time
    • Point them to an approved enterprise tool that keeps the data in-tenant
    • Ban all AI tools across the company
  2. Your customer-service chatbot has started giving answers that do not match your published policies.

    What should governance require?

    • Nothing, the chatbot is a separate system
    • Test and monitor its answers, and give it a named owner
    • Add a disclaimer that the bot may be wrong
  3. A team wants an AI model to automatically approve or reject benefit or loan applications.

    What must be in place first?

    • A human who reviews adverse decisions and a lawful basis for the data
    • Nothing, automation removes human bias
    • A faster server so decisions are quicker
  4. Leadership asks who is accountable for AI risk across the company.

    What does good governance answer?

    • It sits with IT alone
    • The board is accountable, with a named owner for day-to-day risk
    • The AI vendor is responsible

Knowledge Test

  1. What does AI governance mainly decide?

    • How fast an AI model runs
    • How an organisation adopts, uses and oversees AI safely and lawfully
    • Which AI vendor is cheapest
    • How to market AI features

    Governance is the policies, roles and controls around AI, broader than security alone.

  2. In the 2026 World Economic Forum survey, what share of organisations assessed AI tool security before deployment?

    • 37 percent
    • 64 percent
    • 10 percent
    • 90 percent

    It rose from 37 percent in 2025 to 64 percent in 2026, still leaving about a third with no check.

  3. Under the EU AI Act, what is the maximum fine for banned AI uses?

    • 20 million euros or 4 percent of turnover
    • 35 million euros or 7 percent of worldwide turnover
    • 10 million euros or 2 percent of turnover
    • There are no fines

    Prohibited practices carry fines up to 35 million euros or 7 percent of global annual turnover, higher than GDPR.

  4. Which risk does OWASP rank at the top for AI applications?

    • Slow response times
    • Prompt injection
    • High electricity use
    • Small context windows

    Prompt injection lets hidden text act as a command the model obeys.

  5. Why is banning public AI tools often not enough on its own?

    • It is too expensive
    • It pushes staff to use the tools on personal devices
    • It breaks the internet
    • It is illegal

    Bans tend to drive shadow AI underground. Governed access with a data rule works better.

  6. Who is ultimately accountable for AI and cyber risk under Sweden’s Cybersäkerhetslagen?

    • The IT helpdesk
    • The management body or board
    • The AI vendor
    • No one

    Article 20 makes the management body responsible, with personal accountability for its members.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Most AI risk begins with people. Staff reach for whatever tool saves time, usually meaning no harm, which is exactly how confidential data ends up in a public model. Governance only holds if the people using AI every day know the rules.

That is why security awareness training belongs inside AI governance rather than beside it. Teach staff which tools are approved, what data must never be pasted into them and how to spot an AI-driven scam such as a deepfake or a phishing message written by a model. eBuilder Security helps Swedish organisations turn AI governance from policy into daily practice, through advisory, monitoring and training.

Frequently Asked Questions

What is AI governance in cybersecurity?

AI governance is the set of policies, roles and controls an organisation uses to adopt, use and oversee AI safely and lawfully. In cybersecurity it sits above the tools, deciding which AI is allowed, what data it can touch, who signs it off and who is accountable when it fails.

Why does AI governance matter for my business?

AI governance matters because ungoverned AI creates real, costly risk. It can leak confidential data, produce decisions no one reviewed and breach the law. The EU AI Act, GDPR and Sweden’s Cybersäkerhetslagen now attach fines and personal board accountability to how organisations manage and secure AI.

Is AI governance a legal requirement in the EU and Sweden?

In effect, yes. The EU AI Act sets binding duties by risk tier, GDPR governs any personal data AI touches, and Sweden’s Cybersäkerhetslagen makes the board responsible for cyber risk. None names a single governance document, but together they require the controls that governance provides.

What frameworks are used for AI governance?

Three frameworks anchor most programmes. The NIST AI Risk Management Framework organises the work into Govern, Map, Measure and Manage. ISO/IEC 42001 is a certifiable AI management system standard. The EU AI Act is binding law. Teams use NIST and ISO to meet the Act’s requirements efficiently.

What is shadow AI and why is it a governance risk?

Shadow AI is any AI tool staff use for work without approval or oversight. It is a governance risk because sensitive data can leave the organisation through tools no one is monitoring, and once data reaches a public model it usually cannot be recalled, as Samsung found in 2023.

Who is responsible for AI governance in an organisation?

Accountability sits with the board, with day-to-day ownership assigned to a named person or group. Under Sweden’s Cybersäkerhetslagen and NIS2, the management body must approve and oversee security measures and can be held personally accountable, so AI risk cannot float between IT, legal and the business.

What is the difference between AI governance and AI security?

AI security protects AI systems from attack and misuse. AI governance is broader. It decides whether a system should be used at all, sets the rules and controls around it and assigns accountability. Security is one part of governance, and the two work best when planned together.

How do we start building AI governance?

Start by inventorying every AI tool and feature in use, including shadow AI. Then write an acceptable-use policy, assign a clear owner, require human review of decisions that affect people or money and fold AI into your incident response. You cannot govern what you have not written down.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.