Lesson 11 of 11 · Running the program · 2 min read

Who owns AI governance? Splitting the work across legal, security and product

In brief

AI governance works when each step of the chain has an owner: legal and compliance own policy and reports, security and trust and safety own controls and testing, product and engineering own the systems. Platform choice often follows whichever team holds the budget.

By The Charter Desk, Agentic Governance Compare · Published 2026-09-14 · Vendor pages read 14 September 2026 · Editorial assessment

Why does ownership decide so much?

AI governance touches law, security, product design and engineering. When no one owns a step, it does not happen: the policy is written but no control enforces it, or the guardrail runs but no one maps its logs to a framework. A simple ownership model prevents that.

What is a workable split?

  • Legal, privacy and compliance: write the policies, classify systems under the EU AI Act, own the framework mapping and the reports, run third-party AI assessments.
  • Security and trust and safety: turn policies into controls, run red teaming before and after launch, watch the logs, respond to incidents.
  • Product and engineering: register each system, fix findings, keep documentation current, decide release readiness with the other two.
  • A governance lead or committee: approve policies, accept residual risk and run the management review that ISO/IEC 42001 asks for.

How do platforms map to owners?

Inventory-first platforms are usually bought by legal, risk and compliance teams: Credo AI's regulatory intelligence and forward-deployed experts and Holistic AI's discovery and framework evidence fit that buyer. Enforcement-first platforms are usually bought by security or trust and safety teams: Pillar Security, SPLX and Lasso describe red teaming and runtime controls; Alice's WonderSuite describes testing before launch, runtime guardrails and retesting for customer-facing AI, with framework mapping on top.

If both groups buy separately, make sure the two tools share identifiers for each system, so that the register entry, the control and the evidence point to one another.

Where should you start?

Start with the team that will be asked the first hard question. The readiness score on this site re-weights the ranking for your situation: number of systems, regulated sector, frameworks, need for runtime enforcement, languages and vendor AI.

What should a governance committee review each quarter?

A short, fixed agenda keeps the chain intact:

  • New AI systems added to the register, and any without an owner.
  • Policies changed, and whether controls were updated to match.
  • Red teaming findings opened and closed, by severity.
  • Control decisions: volumes of blocks and escalations, and reviewed false positives.
  • Third-party AI assessments due or overdue.
  • Framework changes that affect the control library.