Know what’s on your site before a plaintiff’s firm does
A free privacy audit shows which cookies, pixels and trackers are running — and which ones commonly appear in privacy claims.
Companies have spent the last two years creating AI committees, appointing “responsible AI” leads, adding artificial intelligence to privacy programs and asking legal departments to review new tools before employees start using them.
The structure has often been improvised.
One company puts AI governance under privacy.
Another gives it to legal.
Another puts cybersecurity in charge.
A fourth creates an AI council containing 15 executives but gives nobody responsibility for maintaining the AI inventory, performing assessments or verifying whether controls actually work.
The International Association of Privacy Professionals is now attempting to bring some order to that ambiguity.
In September 2026, the IAPP released its AI Governance Skills Framework, an effort to define the people, responsibilities and professional skills that make up an AI governance program.
The most useful conclusion may also be the simplest:
AI governance is not one job.
The IAPP divides the work into eight categories: policy, governance, technical, product, ethics, risk, legal and assurance. The framework separately identifies executive functions responsible for oversight and ultimate accountability.
That structure offers companies a practical way to think about a problem that has become increasingly difficult to avoid.
Someone has to decide what AI the company is permitted to use.
Someone has to understand the law.
Someone has to inventory the systems.
Someone has to evaluate the risks.
Someone has to translate the controls into software.
Someone has to test whether those controls work.
And someone ultimately has to own the consequences when they do not.
Those may be different people.
Privacy teams became the accidental AI governance department
The emergence of AI governance has followed a familiar pattern.
Generative AI entered organizations quickly.
Employees started using ChatGPT, Microsoft Copilot, Google Gemini and specialized AI systems before most companies had formal approval processes.
Legal and privacy teams were among the first groups asked questions such as:
- Can employees upload customer data?
- Can we use this model in hiring?
- Does the vendor train on our information?
- Is a DPIA required?
- Is this subject to the EU AI Act?
- Can the AI make this decision automatically?
That naturally pulled AI governance into privacy and legal organizations.
The IAPP’s 2025 AI Governance Profession Report found that privacy and legal/compliance were the two most common primary owners of AI governance, at 22% each. IT followed at 17%. The report also found that half of AI governance professionals were situated within ethics, compliance, privacy or legal teams.
That makes sense.
Privacy professionals already know how to build inventories, conduct assessments, interpret regulation, handle data subject rights and manage vendors.
But an AI governance program cannot stop there.
A lawyer can determine that an AI system needs human oversight.
Someone still needs to build it.
A privacy professional can identify prohibited sensitive-data use.
Someone has to configure the application to prevent it.
A risk officer can identify model drift.
Someone has to implement monitoring capable of detecting that drift.
That is why AI governance becomes cross-functional almost immediately.
The IAPP framework identifies eight different kinds of work
The IAPP’s new framework is based on annual survey responses from 2023 through 2026, public AI governance job postings collected during 2026 and research from organizations including the U.K. government, TechUK, the Ada Lovelace Institute, the Center for Democracy and Technology and Partnership on AI.
The resulting eight categories are useful because they describe actual work rather than forcing everything under a vague “AI officer” title.
Governance
Governance is the operational machinery.
The IAPP describes these roles as responsible for things such as AI committees, inventories, risk registers, system cards, accountability matrices, readiness reviews and governance documentation.
This is the team that answers:
What AI do we have?
Who approved it?
Who owns it?
What assessment was performed?
When does it need to be reviewed again?
Without this function, companies often have policies but no reliable execution.
Policy
Policy teams monitor the external regulatory environment and translate it into internal rules.
That includes new legislation, regulatory guidance, standards and industry expectations.
The IAPP specifically distinguishes policy from internal governance: policy looks outward at changing requirements, while governance turns those requirements into internal processes.
That distinction is particularly important now.
A multinational company may simultaneously be tracking:
EU AI Act
state AI laws
employment AI rules
sector regulations
NIST AI RMF
ISO standards
privacy laws
consumer protection enforcement
Someone needs to determine which requirements actually apply.
Technical
The technical function may be where many current AI governance programs are weakest.
IAPP’s framework places model versioning, evaluation gates, monitoring, drift detection, compliance dashboards, explainability, fairness testing, robustness and security assessments within the technical governance function.
This is where a policy statement becomes a control.
Suppose company policy says:
AI systems cannot expose restricted employee information to unauthorized users.
The technical team needs to determine whether connector permissions, retrieval systems and access controls actually enforce that rule.
Or suppose policy requires human review before a model rejects an applicant.
Someone needs to ensure the workflow cannot bypass that review.
AI governance becomes meaningful only when legal and policy requirements can be translated into measurable technical behavior.
Product
Product governance becomes important because companies are increasingly embedding AI directly into products rather than merely buying standalone models.
The IAPP describes AI governance product roles as responsible for integrating governance into product roadmaps, use-case intake and life-cycle management.
That means governance should appear before launch rather than after engineering completes the product.
A healthy process might look like:
Use case proposed
↓
Risk classification
↓
Legal/privacy review
↓
Technical requirements
↓
Product design
↓
Testing
↓
Approval
↓
Deployment
↓
Monitoring
The unhealthy version is familiar:
Product launches
↓
Legal discovers it
↓
Governance begins
Risk
Risk teams provide independent challenge.
The IAPP’s framework describes AI risk roles as identifying, tracking and escalating risks while maintaining risk registers, dashboards and incident-management processes.
The distinction between the team using AI and the team independently assessing its risk is important.
A business unit deploying an AI sales system has an incentive to get it into production.
The risk function asks different questions.
What happens if it hallucinates?
What happens if the vendor changes models?
What happens if protected characteristics influence the output?
What happens if employees rely on it too heavily?
What happens if an AI agent gets access to a system it was never supposed to reach?
Risk governance provides a second line of defense rather than asking the product owner to grade its own work.
Legal
Legal teams remain central.
They determine how the growing collection of AI laws, contractual obligations and regulatory requirements apply to a system.
But legal should not become the entire governance program.
A legal opinion that says an EU AI Act requirement applies does not satisfy the requirement.
The organization still needs operational controls, technical implementation, documentation and testing.
AI governance fails when legal teams become the place where every AI question goes to die.
Ethics
The ethics category addresses issues that may extend beyond minimum legal compliance.
The IAPP describes these roles as evaluating fairness, transparency, human impacts, misuse and effects on vulnerable populations.
That function may become increasingly important as companies confront decisions for which the law provides an incomplete answer.
A practice can be legal but still create reputational or human consequences the company does not want.
Should an employer use AI to infer employee disengagement?
Should an insurer use behavioral data to predict risk?
Should a customer service agent be allowed to infer a customer’s emotional state?
Law provides one boundary.
Corporate risk appetite may provide another.
Assurance
The final layer is assurance.
This is the function that asks whether the governance program actually works.
That could involve internal audit, independent evaluations, control testing or external assurance.
The distinction is similar to cybersecurity.
Writing a security policy does not prove the network is secure.
Writing an AI governance policy does not prove an AI system is operating within it.
Organizations increasingly need evidence.
That means:
testing
monitoring
evaluation results
audit trails
approvals
incident records
remediation evidence
AI assurance is likely to become a substantial profession of its own.
Executive accountability cannot disappear into a committee
The IAPP framework also separates operational roles from executive accountability.
Its executive framework identifies strategic leaders, domain leaders and horizontal leaders, emphasizing that executives do not need to participate in every AI decision but do need defined responsibility where AI intersects with their areas of authority.
The IAPP specifically identifies the CEO as responsible for strategic alignment and setting the organizational tone around AI, while the COO is responsible for embedding governance into operating processes.
That addresses one of the biggest weaknesses in AI committees.
Committees can distribute expertise.
They can also distribute accountability so broadly that nobody owns the outcome.
An organization should be able to answer:
Who has authority to stop deployment?
Who accepts residual AI risk?
Who owns an AI incident?
Who reports material AI risks to the board?
Who determines whether the organization is operating within its AI risk appetite?
If the answer is simply “the AI committee,” the governance structure may still be incomplete.
Small organizations do not need eight new employees
The framework should not be interpreted as suggesting every company needs a policy officer, governance officer, AI engineer, product lead, ethics officer, risk officer, lawyer and assurance team.
The IAPP explicitly notes that most organizations are unlikely to assign a separate individual to every profile. Responsibilities will overlap, particularly in smaller organizations.
A mid-sized company might instead build a structure such as:
Chief Privacy / Legal Officer
→ Legal + policy
AI Governance Lead
→ Governance + assessments
CTO / Engineering
→ Technical controls
Product Leaders
→ Use-case ownership
Enterprise Risk
→ Independent challenge
Internal Audit
→ Assurance
The important point is not the titles.
It is coverage.
Every governance function needs an owner.
The AI inventory becomes the foundation
Before organizations worry about organizational charts, they need to know what they are governing.
That begins with an AI inventory.
For every system, the organization should know:
System name
Provider
Model
Business owner
Purpose
Users
Data sources
Connectors
Affected individuals
Decision type
Risk classification
Jurisdictions
Assessment status
Human oversight
Approval status
Monitoring requirements
That inventory becomes the operating layer connecting legal, privacy, security, engineering and risk.
When regulations change, the company can determine which systems are affected.
When a model changes, it can trigger reassessment.
When an incident occurs, the organization knows who owns the system.
Without an inventory, AI governance becomes largely theoretical.
Assessments should route the work
The same is true of AI assessments.
A good assessment should not merely generate a report.
It should determine what happens next.
For example:
AI USE CASE SUBMITTED
↓
LOW RISK
↓
Basic approval
OR
HIGH RISK
↓
Legal review
Privacy assessment
Security review
Technical evaluation
Human oversight requirement
Executive approval
Continuous monitoring
Certain deployments may also trigger a DPIA, Fundamental Rights Impact Assessment, bias evaluation or sector-specific review.
The governance system should identify those requirements automatically rather than expecting every employee proposing an AI tool to understand the EU AI Act.
AI governance is becoming an operating system for enterprise AI
The IAPP framework is important because it suggests the profession is beginning to mature.
The organization collected public job profiles across industries and regions during 2026 and found enough consistency to classify AI governance work into recognizable categories.
That does not mean the organizational structure is settled.
The IAPP itself expects the framework to evolve as the market matures and acknowledges that AI developers and organizations merely deploying AI may ultimately need different governance models.
But the direction is becoming clearer.
AI governance is moving beyond:
Write an AI policy.
Toward:
Discover AI
↓
Classify it
↓
Assign ownership
↓
Assess risk
↓
Establish controls
↓
Approve deployment
↓
Monitor behavior
↓
Record incidents
↓
Reassess when something changes
That is an operational system.
The companies that solve ownership first will have an advantage
The central question for most organizations is therefore no longer whether they need AI governance.
It is how to make governance function without preventing the company from using AI.
Too little governance produces uncontrolled deployment, unknown systems and regulatory risk.
Too much friction encourages employees to bypass the process.
The goal is a structure in which legitimate AI use can move quickly while higher-risk applications receive deeper scrutiny.
The IAPP’s framework provides a useful vocabulary for building that structure.
Companies do not necessarily need eight departments.
They need to make sure the eight kinds of work actually happen.
Someone must interpret the rules.
Someone must maintain the inventory.
Someone must assess the risk.
Someone must build the controls.
Someone must test them.
And an executive must ultimately be accountable for the outcome.
That is what turns an AI policy into AI governance.
Put this into practice
Turn privacy guidance into working controls.
Captain Compliance helps teams discover tracking technologies, enforce consent, manage privacy requests and document the evidence behind every decision.