En este modulo
Why governance: it is not bureaucracy, it is protection
AI governance is not another document in a drawer. It is the structure that protects your company from 3 concrete risks:
- Regulatory risk: the AI Act imposes fines of up to EUR 35M. Without governance, you have no evidence of compliance.
- Reputational risk: algorithmic bias in hiring or a chatbot generating inappropriate content can destroy years of reputation in a single day.
- Operational risk: shadow AI (uncontrolled usage) means client data flows to external services without your knowledge.
Well-designed governance does not slow down innovation. It enables it. When the team knows what they can and cannot do, they move faster, not slower.
Data point
1 in 4 companies already has a Chief AI Officer (IBM 2025). Those with formal governance adopt AI 2x faster than those without, because they eliminate the paralysis of "are we allowed to do this?".
The AI committee: composition and operations
The AI committee is the body that makes AI decisions within the organization. It does not need to meet every week. It needs to exist and have authority.
Recommended composition
- Executive sponsor (CEO or General Manager): provides legitimacy and authority. Does not need to attend every meeting, but must approve key decisions.
- AI lead (CAIO, CTO, or Head of Innovation): chairs the committee, proposes initiatives, reports progress.
- Legal/Compliance: validates that initiatives comply with the AI Act, GDPR and industry regulation.
- HR: change management, training, impact on job roles.
- IT/Security: infrastructure, data security, integrations.
- 1-2 business directors (rotating): ensure AI solves real business problems.
Operations
- Frequency: monthly (biweekly during the launch phase)
- Duration: 60 minutes maximum
- Typical agenda: metrics review (10 min) → new AI requests (20 min) → risks/incidents (15 min) → decisions (15 min)
- Output: minutes with decisions, owners, deadlines. Published internally.
What the committee decides
- Approve new AI tools
- Classify systems by risk level (AI Act)
- Approve AI usage in processes affecting people (HR, credit, healthcare)
- Review AI incidents (hallucinations, bias, data leaks)
- Prioritize AI investments
The CAIO: do you need one?
The Chief AI Officer (CAIO) is the executive role responsible for AI strategy. In 2026, 1 in 4 large companies has one. But not all need one.
You need a CAIO if
- More than 500 employees
- AI is a core part of the business model
- Multiple simultaneous AI projects
- Highly regulated industry (finance, healthcare, legal)
You do NOT need a CAIO (yet) if
- Fewer than 200 employees
- AI is a productivity tool, not core business
- 1-3 active AI projects
- The CTO or Head of Innovation can assume the role part-time
Alternative: part-time "AI Lead"
For SMEs and mid-sized companies: designate a person (typically with a combined technical and business profile) who dedicates 20-30% of their time to coordinating AI strategy. A formal title is not necessary. Authority and dedicated time are.
AI risk framework for executives
As an executive, you need to evaluate 5 risk categories before approving any AI initiative:
1. Data risk
What data does the system process? Is it personal? Sensitive? Where is it stored? Who has access?
Mitigation: data policy, anonymization, enterprise plans, encryption.
2. Regulatory risk
Is the system high-risk under the AI Act? Does it affect decisions about people? Are there sector-specific requirements?
Mitigation: risk classification, impact assessment, registration, documentation.
3. Bias risk
Does the system make or influence decisions that affect people? Could it discriminate by gender, age or origin?
Mitigation: bias audit, diverse training data, human oversight.
4. Operational risk
What happens if the system fails? Is there a plan B? How dependent is the business on this system?
Mitigation: redundancy, human oversight, circuit breakers, contingency plan.
5. Reputational risk
What would happen if a journalist published "Company X uses AI for [what you do]"? Would it be positive or negative?
Mitigation: transparency, proactive communication, ethics by design.
The executive's question
Before approving any AI project, ask these 3 questions: 1) What data does it use? 2) Does it affect decisions about people? 3) What happens if it fails? If any answer concerns you, you need further analysis.
3 policies you need (and how to draft them)
1. AI usage policy
Which tools are approved, what data can be shared, what is prohibited. 2-3 pages. The coverage in module B09 serves as a baseline.
2. Data policy for AI
An extension of your existing data policy: how data is handled when processed by AI. Data classification (public, internal, confidential, sensitive) and which AI tier each level may use.
3. AI Act compliance policy
AI systems inventory, risk classification, responsible parties, compliance timeline. Mandatory for high-risk systems before August 2026.
AI systems registry
The AI Act requires registering high-risk AI systems in the EU database. But even for lower-risk systems, an internal registry is good practice:
Registry template
AI SYSTEMS REGISTRY - [COMPANY]
| # | System | Provider | Department | Data processed | AI Act risk | Owner | Start date |
|---|--------|----------|------------|----------------|-------------|-------|------------|
| 1 | ChatGPT Team | OpenAI | All | Internal, no PII | Minimal | IT Lead | 2026-01 |
| 2 | Claude Team | Anthropic | Legal, Executive | Contracts, reports | Minimal | IT Lead | 2026-03 |
| 3 | HubSpot AI Scoring | HubSpot | Sales | B2B client data | Limited | Sales Dir. | 2026-02 |
| 4 | CV Screener AI | [Vendor] | HR | Candidate CVs | HIGH RISK | HR Dir. | 2026-04 |
This registry gives you instant visibility into what AI your company uses, with what data, and which systems need regulatory attention.
What the board must approve
Not everything goes to the board. But these decisions do:
- AI strategy: vision, annual budget, ambition (optimize vs transform)
- High-risk systems: any AI that makes or influences decisions about people
- Budget above [threshold]: define your threshold (e.g., >EUR 10,000)
- Serious incidents: data leak via AI, detected bias, failure with client impact
- AI policy: initial approval and annual reviews
Practical exercise
- Define the composition of your AI committee (real names from your organization)
- Decide: do you need a CAIO or a part-time AI Lead? Justify your choice
- Create the AI systems registry for your company (use the template)
- Classify each system by AI Act risk (unacceptable, high, limited, minimal)
- Identify which of the 3 policies you need first. Generate a draft using AI
- Define which decisions go to the committee vs which are delegated
Puntos clave
Puntos clave from CX02
- Governance does not slow down innovation, it enables it. Teams with clear rules move faster.
- AI committee: executive sponsor + AI lead + legal + HR + IT + business. Monthly, 60 min.
- CAIO for companies with 500+ employees or AI as core business. For SMEs: AI Lead at 20-30%.
- 5 risks: data, regulatory, bias, operational, reputational. Evaluate before approving.
- 3 minimum policies: AI usage, data for AI, AI Act compliance.
- AI systems registry: instant visibility into what your company uses.
- The board approves: strategy, high-risk, budget, serious incidents, policy.
Guia de estudio — Conceptos clave de CX02
Por que governance: no es burocracia, es proteccion
- Riesgo regulatorio:el AI Act impone sanciones de hasta 35M EUR. Sin governance, no tienes evidencia de cumplimiento.
- Riesgo reputacional:un sesgo algoritmico en seleccion de personal o un chatbot que genera contenido inapropiado puede destruir anos de reputacion en un dia.
- Riesgo operativo:shadow AI (uso no controlado) significa que datos de clientes fluyen a servicios externos sin tu conocimiento.
- Dato: 1 de cada 4 empresas ya tiene un Chief AI Officer (IBM 2025). Las que tienen governance formal adoptan IA 2x mas rapido que las que no la tienen, porque eliminan la paralisis del "podemos hacer esto?".
El comite de IA: composicion y funcionamiento
- Sponsor ejecutivo(CEO o director general): da legitimidad y autoridad. No necesita asistir a todas las reuniones, pero debe aprobar las decisiones clave.
- Responsable de IA(CAIO, CTO, o director de innovacion): lidera el comite, propone iniciativas, reporta progreso.
- Legal/Compliance:valida que las iniciativas cumplen AI Act, RGPD, normativa sectorial.
- RRHH:gestion del cambio, formacion, impacto en puestos de trabajo.
- IT/Seguridad:infraestructura, seguridad de datos, integraciones.
- 1-2 directores de negocio(rotativo): aseguran que la IA resuelve problemas reales de negocio.
El CAIO: necesitas uno?
- Mas de 500 empleados
- IA es parte core del modelo de negocio
- Multiples proyectos de IA simultaneos
- Sector altamente regulado (finanzas, salud, legal)
- Menos de 200 empleados
- IA es herramienta de productividad, no core business
Framework de riesgos IA para directivos
- Mitigacion: politica de datos, anonimizacion, planes empresariales, cifrado.
- Mitigacion: clasificacion de riesgos, evaluacion de impacto, registro, documentacion.
- Mitigacion: auditoria de sesgo, datos de entrenamiento diversos, supervision humana.
- Mitigacion: redundancia, supervision humana, circuit breakers, plan de contingencia.
- Mitigacion: transparencia, comunicacion proactiva, etica por diseno.
- Pregunta del directivo: Antes de aprobar cualquier proyecto de IA, haz estas 3 preguntas: 1) Que datos usa? 2) Afecta a decisiones sobre personas? 3) Que pasa si falla? Si alguna respuesta te preocupa, necesitas analisis adicional.
3 politicas que necesitas (y como redactarlas)
- Tip: no escribas las politicas desde cero. Usa la IA (Claude o ChatGPT Team) para generar el primer borrador. Prompt: "Redacta una politica de uso de IA para una empresa de [sector] con [N] empleados. Incluye: herramientas aprobadas [lista], restricciones de datos, responsabilidades. Formato: 2-3 paginas, lenguaje claro."
Que debe aprobar el consejo
- Estrategia de IA:vision, presupuesto anual, ambicion (optimizar vs transformar)
- Sistemas de alto riesgo:cualquier IA que tome o influya en decisiones sobre personas
- Presupuesto superior a [umbral]:define tu umbral (ej: >10.000 EUR)
- Incidentes graves:filtracion de datos via IA, sesgo detectado, fallo con impacto en clientes
- Politica de IA:aprobacion inicial y revisiones anuales
Siguiente: CX03 - Business Case and AI ROI
You have governance. Now you need the numbers: how to calculate, present and defend AI investment to the board.
Ir al modulo CX03