
August 18, 2026 • 13 min read
AI governance definitions: The complete glossary for GRC teams

Natalie Dytrych
AI governance definitions now vary by vendor, regulator, and internal stakeholder, and the gap costs real time in scoping, control design, and audit. This glossary defines the terms GRC teams encounter most, grouped in the way the work actually breaks down.
The stakes changed twice this year. In June 2026, Gartner published its first Magic Quadrant for AI Governance Platforms, treating AI governance as a software category with a budget line of its own. Weeks later, on August 2, 2026, the transparency obligations in Article 50 of the EU AI Act became applicable, while the obligations for high-risk systems moved to December 2027 and August 2028 under the Digital Omnibus on AI.
What is AI governance, and how is it different from AI risk management?
AI governance
AI governance is the system of accountability an organization applies to its AI: who decides what gets built or bought, what rules those systems operate under, and how the organization proves those rules were followed. It spans policy, ownership, controls, documentation, and oversight from intake through retirement.
The overlap with AI risk management causes most of the confusion. Governance is the broader structure, answering who holds authority and what the standard is. Risk management is one function operating inside that structure, concerned with identifying and reducing specific harms. An organization can conduct competent risk assessments and still lack governance because nobody owns the decision to deploy. Here’s what AI governance is and why it matters.
- AI governance framework: the structured set of policies, controls, and oversight mechanisms an organization uses to operationalize AI governance.
- AI risk: the potential for harm, non-compliance, or business disruption arising from AI system development or use.
- AI risk management: the practice of identifying, assessing, and mitigating AI risk. It is a discipline within AI governance rather than a synonym for it.
- AI governance platform: a dedicated software category for centrally defining, approving, and enforcing responsible AI policy across an organization’s AI use cases, applications, and agents. Common capabilities include AI discovery and inventory, policy management and enforcement, risk scoring, evidence collection, approval workflows, and an audit trail.
What frameworks and standards define AI governance today?
No single framework governs AI. Most programs anchor to one voluntary framework for structure, then map binding regulation on top of it so a single control set answers to several regimes.
NIST AI Risk Management Framework
The NIST AI Risk Management Framework (AI RMF) is a voluntary framework published by the National Institute of Standards and Technology in January 2023 to help organizations build trustworthiness into the design, development, deployment, and use of AI systems. It is technology-neutral and use-case agnostic, which is why it has become the default backbone for U.S. programs.
Adoption tends to stall in the same place: translating framework language into working controls and evidence. Optro’s Checklist: NIST AI risk management framework walks through that translation function by function.
- NIST AI RMF core functions: Govern, Map, Measure, and Manage, the four functions that structure the framework, with Govern at the center of the other three.
- ISO/IEC 42001: the international standard for an AI management system (AIMS).
- ISO/IEC 23894: the international standard specifically for AI risk management guidance.
- EU AI Act: the EU’s binding, risk-tiered AI regulation. Article 50 transparency obligations became applicable on August 2, 2026. Following the Digital Omnibus on AI, obligations for standalone high-risk systems under Annex III apply from December 2, 2027, and for AI embedded in regulated products under Annex I from August 2, 2028.
- Trustworthy AI framework: a set of principles, including fairness, reliability, transparency, and accountability, used to guide responsible AI design.
U.S. state AI laws
State law is where most U.S. organizations first meet binding AI obligations. Requirements attach based on where consumers, applicants, or employees are located rather than where a company is headquartered, so multi-state operations are routinely in scope for statutes they never tracked. Dates in this cluster moved repeatedly through 2026, so confirm the current status before scoping work.
- Colorado SB 26-189 (Automated Decision-Making Technology Act): Signed May 14, 2026, repealing and replacing Colorado SB 24-205, the state’s original AI Act, which never took effect. It regulates automated decision-making technology that materially influences a consequential decision, and applies from January 1, 2027.
- Texas TRAIGA (HB 149): The Texas Responsible Artificial Intelligence Governance Act, effective January 1, 2026, prohibits specified AI uses such as intentional harm, unlawful discrimination, and social scoring, and sets disclosure duties for government AI use.
- Utah AI Policy Act (SB 149): Effective May 1, 2024, and amended in 2025, requiring disclosure when a consumer is interacting with generative AI, with stricter duties in regulated professions.
- Illinois HB 3773: Effective January 1, 2026, amending the Illinois Human Rights Act so that discriminatory use of AI in employment decisions is treated as a civil rights violation.
- California SB 53 and AB 2013: Both effective January 1, 2026, these laws cover frontier model transparency and training-data disclosure. California’s separate AI Transparency Act requirements became operative in August 2026.
What is the difference between AI governance, model risk management, and model governance?
Model risk management (MRM)
Model risk management is the discipline of identifying, measuring, and controlling the risk that a model produces incorrect output or is used for something it was never validated to do. It predates AI governance by more than a decade in banking, where SR 11-7 established the expectation that models be independently validated, documented, and monitored.
For banking and financial services teams, that history changes the question. The task is rarely building AI governance from nothing. It is deciding which AI systems fall inside the existing MRM perimeter, which fall outside it, and where the two programs should share evidence rather than produce it twice.
- Model governance: The policies and oversight structure specifically for how models, including AI and machine learning models, are approved, used, and retired.
- SR 11-7:The Federal Reserve and OCC supervisory guidance that established modern model risk management practice in banking.
- Model validation: Independent testing and review confirming a model performs as intended before and during deployment.
- Model card: A standardized document summarizing a model’s intended use, performance, limitations, and risks.
- AI model risk: Risk specific to AI and machine learning models, including accuracy, bias, drift, and explainability, assessed under an MRM program.
What terms do I need to know for AI compliance and audit readiness?
AI compliance
AI compliance is the work of meeting the legal, regulatory, and contractual obligations that apply to how an organization builds, buys, and uses AI. The difficulty is rarely any single requirement. One AI system can sit under the EU AI Act, a state statute, sector regulation such as SR 11-7, and a customer contract at once, each carrying its own definitions, thresholds, and evidence expectations.
Auditors respond to that overlap in a predictable sequence. They ask what AI you have, who owns each system, what standard it was assessed against, and what evidence supports the assessment.
- AI audit: A formal review assessing whether AI systems and governance practices meet internal policy and external regulatory requirements.
- AI audit readiness: The state of having documentation, controls, and evidence in place to pass an AI audit without scrambling.
- AI conformity assessment: The EU AI Act’s required process for verifying a high-risk AI system meets legal requirements before market entry.
- AI impact assessment (also algorithmic impact assessment): A structured evaluation of how an AI system affects individuals and groups, covering intended use, affected populations, potential harms such as bias or wrongful denial of service, and the mitigations in place. Several regimes require or presume one for higher-risk systems, which makes it a primary evidence artifact in an AI audit.
- High-risk AI system: An AI system classified under the EU AI Act, or a comparable regulation, as posing a significant risk to health, safety, or fundamental rights, triggering stricter obligations.
- AI third-party risk management: Assessing and monitoring risk introduced by vendor-supplied or partner-supplied AI systems and models.
- AI inventory: A maintained record of every AI system and use case in an organization, and the foundational artifact for governance and audit.
- Shadow AI: AI tools or models in use across an organization without governance, security, or IT visibility.
How does agentic AI change AI governance definitions?
Agentic AI governance
Agentic AI governance is the extension of AI governance to systems that plan and execute multi-step actions with limited human involvement at each step. Traditional model governance assumes a person initiates the request, reviews the output, and decides what to do with it. Remove that person and several standard controls quietly stop working. Review-before-use becomes review-after-action, and the governed object shifts from an inaccurate output to an unauthorized action already taken.
That shift is why agent controls end up resembling access management and change control more than model validation. What an agent is permitted to touch, what it must escalate, and what stops it are governance decisions before they are technical ones.
- AI agent: an AI system that can autonomously plan and take multi-step actions toward a goal, often with tool or system access.
- AI agent oversight: the human review and control mechanisms applied to monitor and constrain autonomous agent actions.
- AI agent policy: organizational rules defining what actions, systems, and data AI agents are permitted to access or act on.
Build the program behind the vocabulary
Shared definitions are the inexpensive part. Turning them into a program that holds up under audit takes an inventory you trust, controls mapped to the frameworks that apply, and evidence generated as work happens rather than assembled the week before fieldwork.
See our ebook, Checklist: NIST AI risk management framework, to work through the four core functions as a step-by-step implementation plan.
About the authors

Natalie Dytrych is a Senior Product Marketing Manager for Regulatory Compliance at Optro. She has 8 years of experience helping financial institutions navigate complex regulatory compliance and risk challenges, most recently as a Senior Manager at PwC.
You may also like to read


Agentic AI governance: 6 questions GRC teams keep asking

NIST AI RMF guide: A practical roadmap to implementing the AI Risk Management Framework

AI procurement policy: A practical guide for enterprises

Agentic AI governance: 6 questions GRC teams keep asking

NIST AI RMF guide: A practical roadmap to implementing the AI Risk Management Framework
Discover why industry leaders choose Optro
SCHEDULE A DEMO
