Skip to content
Advise · Module 02

AI Governance

Regulators assign obligations to organisations and accountability to those who govern them. Antropic helps boards and committees turn the regulatory picture into a system of governance: clear roles, policies fit for resolution, both regimes watched.

The context

Two regimes, one boardroom.

The United Kingdom has no horizontal AI statute. Its approach is principles-based and sector-led: existing regulators — the ICO on data protection, the FCA in financial services — apply their expectations to AI within their remits, with policy led by DSIT.

Across the Channel, the EU AI Act sets a statutory, risk-based regime — and it does not stop at the border. UK organisations serving the European market fall within its reach, alongside their duties under UK GDPR.

A board governs well when it distinguishes what is owed under each regime from what is merely feared. The institute keeps that distinction current and turns it into an agenda.

Who it serves

Boards of directors

The direction and oversight function answers for AI choices before shareholders, regulators and the market.

Audit and risk committees

Risk oversight extends to the AI systems the organisation adopts, integrates or procures.

Executive management and legal functions

Those who translate regulatory duties into roles, policies and operating processes across the organisation.

Workstreams

From perimeter to board resolution.

The work follows the institute's method and produces documents in resolvable form, built for the board agenda.

It opens with a framing session with senior leadership and the functions involved: legal, risk, technology. Cycles of work follow, with interim reviews, through to the final documents.

The engagement runs behind closed doors. The framework remains the property of the organisation, with a handover session for the functions that will have to live with it.

01

Perimeter and accountability

A map of the AI systems in use and on the way, of the regulatory roles assumed, and of the responsibilities that follow for the top.

02

Governance framework

Roles, delegations, internal policies and escalation paths: who decides what, on what information, at which risk thresholds.

03

AI literacy at the top

AI literacy programmes for boards and senior executives, aligned with the EU AI Act's literacy duty where it applies and with the expectations of UK regulators.

04

Watching both regimes

A board agenda aligned with the obligations that actually apply — under UK law and, for organisations serving the EU, under the European framework — and updated as either moves.

Frequently asked questions

Isn't AI governance a matter for the IT function?

No. Regulators on both sides of the Channel assign obligations to the organisation and accountability to those who govern it. The IT function manages the systems; the board answers for the choices, the controls and the delegations. That is why AI governance belongs on the board agenda.

There is no UK AI act. Why build a governance framework now?

Because the United Kingdom's approach is principles-based and sector-led: existing regulators — the ICO on data protection, the FCA in financial services, among others — already apply their expectations to AI. Accountability sits with the board today, statute or no statute. A framework turns that exposure into a system of governance.

Does the EU AI Act concern a UK organisation at all?

It can. The Regulation reaches providers and deployers established outside the Union when their systems are placed on the EU market or their output is used there. UK organisations serving the European market fall within the EU AI Act's reach; mapping that exposure is part of the perimeter work.

The organisation buys AI from external vendors: do the obligations stay with the vendors?

Only in part. Whoever uses AI systems in its own activity takes on duties of its own: use consistent with the instructions, human oversight, staff literacy, and — under UK GDPR — accountability for personal data. Buying does not transfer the responsibility of governance.

Does a governance framework slow AI adoption?

A well-designed framework accelerates it: it clarifies who may decide what, removes uncertain hand-offs and separates the cases that need the board from those that do not. Slowness comes from ambiguity, not from rules.

What does the engagement actually produce?

A map of systems and responsibilities, a framework of roles and policies fit for board approval, a literacy programme for the top, and an agenda for watching the regulatory picture on both sides of the Channel. All in resolvable form, not in scenario slides.

AI Governance

The regulatory picture becomes a system of governance.