An AI governance framework is the set of rules that decides who can use which AI, for what, and how you check the results are safe and worth having. The word ‘governance’ makes people picture committees and sign-off queues. Good governance is the opposite. It is the clarity that lets people move quickly inside limits they already understand, instead of stopping to ask permission for every small decision.
That clarity is worth real money. In aibl’s State of UK AI Adoption Survey 2026 (755 UK mid-market leaders), governance was the single biggest predictor of whether AI paid off. Firms with no governance reported measurable returns 22.2 per cent of the time. Firms with mature, embedded governance reported them 85.3 per cent of the time, on much the same tools. Only 21 per cent of the mid-market has reached that mature stage, so the gap is wide open.
One warning before you start writing policies. A document is not governance. In the survey, HR teams whose policy was written but applied inconsistently reported 16 per cent measurable ROI, below the 33 per cent managed by HR teams with no policy at all. A framework sitting on the intranet creates false confidence: it feels like the job is done, so no one funds the work of following it, and the return comes in below doing nothing.
What a framework actually does
The practical job of governance is to give people a fast, safe default route so they don’t invent their own. When the approved path is slow or unclear, people reach for whatever gets the job done, often a personal ChatGPT account with company data pasted into it. The survey calls this shadow AI, and it tracks governance closely: unapproved tool use is common in 75 per cent of ungoverned firms, falling to 35 per cent among the most mature. In the most governed firms, the official route is quick enough that people take it rather than working around it.
The NIST AI Risk Management Framework
The US National Institute of Standards and Technology publishes a free, voluntary framework that most sensible AI governance borrows from. It comes down to four things you do, again and again.
Map. Find out where AI is being used across the business, what each system touches, and who it affects. You can’t govern what you can’t see.
Measure. Check how each system actually performs, its accuracy, bias and failures, using numbers rather than gut feel.
Manage. Act on what you found. Fix the weak systems, put limits on the risky ones, switch off the ones that aren’t worth it, and aim your effort where the risk is highest.
Govern. The one that holds the other three together: clear ownership, policies people follow, and treating AI risk as a normal part of running the business rather than a special project.
The EU AI Act risk tiers
The EU AI Act sorts AI into four tiers by how much harm it could do. It applies if you sell into or operate in the EU, and even if you don’t, the tiers are a clean way to classify your own risk. Take a mid-market business services firm running three AI tools.
Prohibited. Banned outright, such as social scoring or covertly reading staff emotions to manage performance. Most firms never go near this, but it helps to know the line is there.
High-risk. Allowed, but tightly controlled. The firm’s CV-screening tool sits here, because AI in hiring can affect people’s livelihoods. It needs human oversight, bias testing and a proper audit trail.
Limited-risk. Mainly a transparency duty. The firm’s customer chatbot has to tell people they’re talking to a machine, not a person.
Minimal-risk. Almost everything else, including the firm’s demand-forecasting tool and the AI baked into its everyday software. No special obligations. This is where most mid-market AI lands.
Building one: six steps
You don’t need a consultant or a new department to start. Six steps get a mid-market business to a working framework.
Map your AI use cases. List every place AI is being used, approved or not. Most firms are surprised how many turn up.
Classify by risk. Put each use case in a tier. The EU Act’s four levels are a good default. A demand forecast and a CV screener are not the same kind of risk and shouldn’t be handled as though they were.
Design controls by risk level. Match the effort to the risk. Minimal-risk tools need almost nothing. High-risk ones need human sign-off, testing and records. Wrapping a spam filter in the same red tape as a hiring tool is exactly how governance becomes the bureaucracy people route around.
Assign accountability, one owner per system. Every system gets a single named owner responsible for it working and staying safe. One person, not a committee, because shared ownership usually means no ownership.
Measure and review quarterly. Check each system against how it’s actually performing every quarter. Some will have drifted, some will be worth expanding, some you’ll retire.
Document simply, one page per system. What it does, who owns it, which tier, what controls it has, when you last reviewed it. One page. Anything longer goes unread, and an unread folder is the policy trap all over again.
Start with the map. You can’t classify, control or assign owners for systems you haven’t found yet, and finding them is the step most firms skip.
Read the full research
A framework only pays once it’s enforced. Measurable ROI climbs from 22% with no governance to 85% where governance is mature and embedded. It’s one finding from State of UK AI Adoption 2026, aibl’s benchmark of 755 UK mid-market leaders, in partnership with Executive Summary.
Read the full State of UK AI Adoption 2026 report →
Frequently asked questions
NIST or ISO 42001, which do we need?
They do different jobs. The NIST framework is voluntary, free and practical, good for building the habit. ISO 42001 is a certifiable international standard you can be formally audited against, which matters when a customer or regulator wants proof. Most mid-market firms start with NIST and move to ISO 42001 when they need to demonstrate it to someone else. You don’t need both to begin.
How long does it take to build?
A first working version takes weeks, not months: map, classify, name owners, one page each. Reaching the mature, embedded stage takes longer, because governance is a habit rather than a document, and it’s the stage most of the mid-market still hasn’t reached.
Do we need a separate AI governance team?
No. Most mid-market firms don’t have the headcount and don’t need it. What you need is one accountable owner per system and someone senior, usually the CIO, COO or CFO, holding the whole thing together. A dedicated team is a later choice, not a starting requirement.
What happens without governance?
Two things, and the survey shows both. Returns stay stuck near the bottom of the range, well below what the same tools deliver in governed firms. And people go around you: unapproved AI use is far more common where there’s no governance than where it’s mature. Ungoverned isn’t faster. It’s usually slower and riskier.