En este modulo

  1. Why governance: it is not bureaucracy, it is protection
  2. The AI committee: composition and operations
  3. The CAIO: do you need one?
  4. AI risk framework for executives
  5. 3 policies you need (and how to draft them)
  6. AI systems registry
  7. What the board must approve
  8. Practical exercise
  9. Puntos clave

Why governance: it is not bureaucracy, it is protection

AI governance is not another document in a drawer. It is the structure that protects your company from 3 concrete risks:

  1. Regulatory risk: the AI Act imposes fines of up to EUR 35M. Without governance, you have no evidence of compliance.
  2. Reputational risk: algorithmic bias in hiring or a chatbot generating inappropriate content can destroy years of reputation in a single day.
  3. Operational risk: shadow AI (uncontrolled usage) means client data flows to external services without your knowledge.

Well-designed governance does not slow down innovation. It enables it. When the team knows what they can and cannot do, they move faster, not slower.

Data point

1 in 4 companies already has a Chief AI Officer (IBM 2025). Those with formal governance adopt AI 2x faster than those without, because they eliminate the paralysis of "are we allowed to do this?".

The AI committee: composition and operations

The AI committee is the body that makes AI decisions within the organization. It does not need to meet every week. It needs to exist and have authority.

Recommended composition

Operations

What the committee decides

The CAIO: do you need one?

The Chief AI Officer (CAIO) is the executive role responsible for AI strategy. In 2026, 1 in 4 large companies has one. But not all need one.

You need a CAIO if

You do NOT need a CAIO (yet) if

Alternative: part-time "AI Lead"

For SMEs and mid-sized companies: designate a person (typically with a combined technical and business profile) who dedicates 20-30% of their time to coordinating AI strategy. A formal title is not necessary. Authority and dedicated time are.

AI risk framework for executives

As an executive, you need to evaluate 5 risk categories before approving any AI initiative:

1. Data risk

What data does the system process? Is it personal? Sensitive? Where is it stored? Who has access?

Mitigation: data policy, anonymization, enterprise plans, encryption.

2. Regulatory risk

Is the system high-risk under the AI Act? Does it affect decisions about people? Are there sector-specific requirements?

Mitigation: risk classification, impact assessment, registration, documentation.

3. Bias risk

Does the system make or influence decisions that affect people? Could it discriminate by gender, age or origin?

Mitigation: bias audit, diverse training data, human oversight.

4. Operational risk

What happens if the system fails? Is there a plan B? How dependent is the business on this system?

Mitigation: redundancy, human oversight, circuit breakers, contingency plan.

5. Reputational risk

What would happen if a journalist published "Company X uses AI for [what you do]"? Would it be positive or negative?

Mitigation: transparency, proactive communication, ethics by design.

The executive's question

Before approving any AI project, ask these 3 questions: 1) What data does it use? 2) Does it affect decisions about people? 3) What happens if it fails? If any answer concerns you, you need further analysis.

3 policies you need (and how to draft them)

1. AI usage policy

Which tools are approved, what data can be shared, what is prohibited. 2-3 pages. The coverage in module B09 serves as a baseline.

2. Data policy for AI

An extension of your existing data policy: how data is handled when processed by AI. Data classification (public, internal, confidential, sensitive) and which AI tier each level may use.

3. AI Act compliance policy

AI systems inventory, risk classification, responsible parties, compliance timeline. Mandatory for high-risk systems before August 2026.

Tip: do not write policies from scratch. Use AI (Claude or ChatGPT Team) to generate the first draft. Prompt: "Draft an AI usage policy for a [industry] company with [N] employees. Include: approved tools [list], data restrictions, responsibilities. Format: 2-3 pages, plain language."

AI systems registry

The AI Act requires registering high-risk AI systems in the EU database. But even for lower-risk systems, an internal registry is good practice:

Registry template

AI SYSTEMS REGISTRY - [COMPANY]

| # | System | Provider | Department | Data processed | AI Act risk | Owner | Start date |
|---|--------|----------|------------|----------------|-------------|-------|------------|
| 1 | ChatGPT Team | OpenAI | All | Internal, no PII | Minimal | IT Lead | 2026-01 |
| 2 | Claude Team | Anthropic | Legal, Executive | Contracts, reports | Minimal | IT Lead | 2026-03 |
| 3 | HubSpot AI Scoring | HubSpot | Sales | B2B client data | Limited | Sales Dir. | 2026-02 |
| 4 | CV Screener AI | [Vendor] | HR | Candidate CVs | HIGH RISK | HR Dir. | 2026-04 |

This registry gives you instant visibility into what AI your company uses, with what data, and which systems need regulatory attention.

What the board must approve

Not everything goes to the board. But these decisions do:

  1. AI strategy: vision, annual budget, ambition (optimize vs transform)
  2. High-risk systems: any AI that makes or influences decisions about people
  3. Budget above [threshold]: define your threshold (e.g., >EUR 10,000)
  4. Serious incidents: data leak via AI, detected bias, failure with client impact
  5. AI policy: initial approval and annual reviews

Practical exercise

Ejercicio CX02: Set up your AI governance
  1. Define the composition of your AI committee (real names from your organization)
  2. Decide: do you need a CAIO or a part-time AI Lead? Justify your choice
  3. Create the AI systems registry for your company (use the template)
  4. Classify each system by AI Act risk (unacceptable, high, limited, minimal)
  5. Identify which of the 3 policies you need first. Generate a draft using AI
  6. Define which decisions go to the committee vs which are delegated

Puntos clave

Puntos clave from CX02

  1. Governance does not slow down innovation, it enables it. Teams with clear rules move faster.
  2. AI committee: executive sponsor + AI lead + legal + HR + IT + business. Monthly, 60 min.
  3. CAIO for companies with 500+ employees or AI as core business. For SMEs: AI Lead at 20-30%.
  4. 5 risks: data, regulatory, bias, operational, reputational. Evaluate before approving.
  5. 3 minimum policies: AI usage, data for AI, AI Act compliance.
  6. AI systems registry: instant visibility into what your company uses.
  7. The board approves: strategy, high-risk, budget, serious incidents, policy.
Guia de estudio — Conceptos clave de CX02

Por que governance: no es burocracia, es proteccion

  • Riesgo regulatorio:el AI Act impone sanciones de hasta 35M EUR. Sin governance, no tienes evidencia de cumplimiento.
  • Riesgo reputacional:un sesgo algoritmico en seleccion de personal o un chatbot que genera contenido inapropiado puede destruir anos de reputacion en un dia.
  • Riesgo operativo:shadow AI (uso no controlado) significa que datos de clientes fluyen a servicios externos sin tu conocimiento.
  • Dato: 1 de cada 4 empresas ya tiene un Chief AI Officer (IBM 2025). Las que tienen governance formal adoptan IA 2x mas rapido que las que no la tienen, porque eliminan la paralisis del "podemos hacer esto?".

El comite de IA: composicion y funcionamiento

  • Sponsor ejecutivo(CEO o director general): da legitimidad y autoridad. No necesita asistir a todas las reuniones, pero debe aprobar las decisiones clave.
  • Responsable de IA(CAIO, CTO, o director de innovacion): lidera el comite, propone iniciativas, reporta progreso.
  • Legal/Compliance:valida que las iniciativas cumplen AI Act, RGPD, normativa sectorial.
  • RRHH:gestion del cambio, formacion, impacto en puestos de trabajo.
  • IT/Seguridad:infraestructura, seguridad de datos, integraciones.
  • 1-2 directores de negocio(rotativo): aseguran que la IA resuelve problemas reales de negocio.

El CAIO: necesitas uno?

  • Mas de 500 empleados
  • IA es parte core del modelo de negocio
  • Multiples proyectos de IA simultaneos
  • Sector altamente regulado (finanzas, salud, legal)
  • Menos de 200 empleados
  • IA es herramienta de productividad, no core business

Framework de riesgos IA para directivos

  • Mitigacion: politica de datos, anonimizacion, planes empresariales, cifrado.
  • Mitigacion: clasificacion de riesgos, evaluacion de impacto, registro, documentacion.
  • Mitigacion: auditoria de sesgo, datos de entrenamiento diversos, supervision humana.
  • Mitigacion: redundancia, supervision humana, circuit breakers, plan de contingencia.
  • Mitigacion: transparencia, comunicacion proactiva, etica por diseno.
  • Pregunta del directivo: Antes de aprobar cualquier proyecto de IA, haz estas 3 preguntas: 1) Que datos usa? 2) Afecta a decisiones sobre personas? 3) Que pasa si falla? Si alguna respuesta te preocupa, necesitas analisis adicional.

3 politicas que necesitas (y como redactarlas)

  • Tip: no escribas las politicas desde cero. Usa la IA (Claude o ChatGPT Team) para generar el primer borrador. Prompt: "Redacta una politica de uso de IA para una empresa de [sector] con [N] empleados. Incluye: herramientas aprobadas [lista], restricciones de datos, responsabilidades. Formato: 2-3 paginas, lenguaje claro."
no escribas las politicas desde cero. Usa la IA (Claude o ChatGPT Team) para generar el primer borrador. Prompt: "Redacta una politica de uso de IA para una empresa de [sector] con [N] empleados. Incluye: herramientas aprobadas [lista], restricciones de datos, responsabilidades. Formato: 2-3 paginas, lenguaje claro."

Que debe aprobar el consejo

  • Estrategia de IA:vision, presupuesto anual, ambicion (optimizar vs transformar)
  • Sistemas de alto riesgo:cualquier IA que tome o influya en decisiones sobre personas
  • Presupuesto superior a [umbral]:define tu umbral (ej: >10.000 EUR)
  • Incidentes graves:filtracion de datos via IA, sesgo detectado, fallo con impacto en clientes
  • Politica de IA:aprobacion inicial y revisiones anuales

Siguiente: CX03 - Business Case and AI ROI

You have governance. Now you need the numbers: how to calculate, present and defend AI investment to the board.

Ir al modulo CX03