Two words that are not synonyms
Governance is structure. Who decides, who approves, who can stop a thing, what is written down, how often it is reviewed. It is observable, auditable, and it produces artefacts — a policy, a register, a committee, a Statement of Applicability.
Safety is an outcome. It is the claim that the AI operating in your organisation does not harm the people it touches, and that if it started to, you would find out. It produces no artefacts of its own. You can only infer it from evidence.
The relationship between them is one-directional and imperfect. Good governance makes safety more likely. It does not deliver it, and the assumption that it does is the single most expensive mistake we see in this work.
How an organisation ends up governed and unsafe
None of what follows is hypothetical or unusual. Each is a pattern that turns up repeatedly, in organisations that would describe themselves as having AI governance in place.
Approved, dated, published on the intranet. Ask five people who use AI daily what it permits and you get five answers, three of them wrong. The artefact exists; the behaviour it was meant to produce does not.
There is a process for approving an AI system. It takes six weeks. A department needed something in two days, so they used a free tool with a personal account, and it now touches customer data. The gate is real. So is the shadow estate beside it.
A maintained AI system inventory, last genuinely reconciled eleven months ago. Every vendor in your stack has shipped AI features since. Nobody added them because nobody procured them — they arrived in a release note.
A human reviews every output before it takes effect. That human reviews four hundred a day and agrees with the system ninety-eight percent of the time. That is not oversight; it is a rubber stamp with a job title, and an auditor will say so.
Someone was refused something eight months ago. They have complained. The model has been updated twice, the prompt three times, and no record ties the decision to the version that made it. You cannot investigate your own decision.
In every one of those cases the governance artefacts would pass inspection. In every one, the question a board is actually being asked has no good answer.
The six questions
These are the ones worth putting to your own executives. They are deliberately about evidence and behaviour rather than documents, and none of them can be answered by producing a policy.
- Which AI systems make or materially influence decisions about people? Customers, patients, applicants, employees. Not a count of tools — a list of the ones where a person is on the receiving end.
- For each of those, what happens when it is wrong? Who is affected, how badly, and how quickly would anyone know.
- Who can stop one, today, without asking permission? A name. If the answer is a committee, the answer is nobody.
- When did a human last disagree with one of these systems and win? If never, the oversight is nominal and you have just found that out cheaply.
- Could we reconstruct a specific AI-assisted decision from six months ago? The inputs, the version, the reviewer, the outcome.
- What has gone wrong, and what changed because of it? An organisation with no recorded AI incidents is not a careful one. It is one that is not looking.
An executive team that can answer all six with evidence has something worth calling safety. One that answers all six by describing a process has governance, and a gap.
Why this lands on the board specifically
Oversight is a duty that cannot be delegated. A director can delegate the work of AI governance; they cannot delegate the responsibility for being satisfied it is working. That distinction is familiar from financial controls and health and safety, and it applies here in the same way.
The regulatory direction reinforces it. The EU AI Act places obligations on providers and deployers of high-risk systems — risk management, data governance, human oversight, logging, transparency — and applies on the basis of where the output is used, so a UK organisation whose AI output reaches people in the EU can be in scope. Stand-alone high-risk obligations apply from 2 December 2027 and product-embedded ones from 2 August 2028; those dates are fixed rather than conditional on standards being ready. In the UK the approach is regulator-led rather than statutory — ICO, MHRA, FCA, CQC, GDC — which means no single deadline and no single exemption either.
What to do about it
Build the governance. It is necessary, and there is no route to safety that skips it. Then do the part that is usually skipped: test whether the structure produced the outcome. Take the six questions to your executives and ask for evidence, not process descriptions.
And start by finding out where you actually are, which costs nothing and takes a quarter of an hour.
This article is general information, not legal advice. Certification against ISO/IEC 42001 is issued only by a certification body accredited under ISO/IEC 42006. VisionXY7 Ltd prepares organisations for certification audits and reviews their systems independently; it does not perform them.