Startege Logo
Guide

AI governance principles

AI governance principles are the standing commitments an organisation makes about how it will build and use AI: who answers for outcomes, what people are told, how fairness is tested, and where a human can intervene. Most published frameworks converge on the same seven. They are not themselves law, but they are the vocabulary regulation is written in, which is why the wording recurs across the OECD AI Principles, the NIST AI Risk Management Framework, the EU AI Act and ISO/IEC 42001.

The useful question is not which list to adopt. It is which decisions each principle would actually change. A principle you cannot point to in a decision someone made is a statement, not a control.

The seven principles

A named person answers for the system's outcomes. Not a committee, not a function: a person.

In practice: Someone can say who approved deployment, on what evidence, and who would stop it.

Affected people know an AI system was involved, and internal reviewers can reconstruct what it did.

In practice: Disclosure to users, plus logs an investigator could actually follow months later.

03

Fairness

The system does not produce unjustified differences in outcome across protected groups.

In practice: Tested, not asserted. Fairness claims without test evidence are the most common gap in an audit.

A person can review, override and stop the system, and is positioned to do so meaningfully.

In practice: Reviewers have the time, information and authority to disagree. A rubber stamp is not oversight.

05

Safety and robustness

The system behaves predictably under conditions it was not designed for, and fails safely.

In practice: Known limits, monitored drift, and a defined response when performance degrades.

Personal data is lawfully obtained, minimised to purpose, and retained no longer than needed.

In practice: Under the GDPR this stops being a principle and becomes a legal obligation with a named lawful basis.

07

Contestability

A person affected by a decision can challenge it and reach someone empowered to change it.

In practice: A route to a human, a defined response time, and a record of what happened as a result.

Where they come from

The OECD AI Principles (2019, updated 2024) are the most widely adopted intergovernmental statement and shaped most of what followed, including the G20 AI Principles. The NIST AI Risk Management Framework reorganises similar ground into four functions, Govern, Map, Measure and Manage, which makes it easier to operationalise than a list. The EU AI Act converts several principles into binding obligations scaled to risk tier. ISO/IEC 42001 wraps them in a certifiable management system.

The practical consequence: principles are portable across jurisdictions, obligations are not. Use the principles to structure how you think, and the regulation that applies to you to decide what you must evidence. For how the frameworks differ in scope, see the frameworks guide.

Principles, policies and the gap between them

Principles state intent. Policies state what people must do. Most organisations that struggle here have published the first and skipped the second, which is why their principles are not observable in any decision anyone made. The distinction is worth reading properly: principle-based versus rule-based AI policies covers when each is appropriate, and designing governance from first principles covers what to do when no existing framework fits.

Common mistakes

Applying them to a real use case

Principles become useful at the point a specific system is proposed. "We are considering an AI tool to shortlist CVs" engages accountability, fairness, human oversight, privacy and contestability at once, and the order in which you address them matters more than the list.

Describe what you are doing with AI and Startege will tell you which of these principles apply to it, the risks that follow, and what to do about them. Free, no account.

Assess your use case

Common questions

What are the core AI governance principles?
Most frameworks converge on seven: accountability, transparency, fairness, human oversight, safety and robustness, privacy and data governance, and contestability. The wording differs between the OECD AI Principles, the NIST AI Risk Management Framework, the EU AI Act and ISO/IEC 42001, but the underlying obligations overlap heavily.
Are AI governance principles legally binding?
The principles themselves are not. They become binding when a regulation adopts them: the EU AI Act turns human oversight and transparency into enforceable obligations for high-risk systems, and the GDPR makes accountability and data minimisation legal duties wherever personal data is processed. Treat principles as the shared vocabulary, and the regulation that applies to you as the actual requirement.
What is the difference between AI principles and an AI policy?
A principle states what you are trying to achieve. A policy states what people must do. Principles survive changes in technology and regulation; policies have to be specific enough to follow, which means they date faster. Organisations that publish principles without translating them into policies tend to find the principles are not observable in any decision anyone made.
How many AI governance principles should an organisation adopt?
Fewer than most adopt. A principle earns its place only if you can name a decision it would change. Long lists tend to be aspirational rather than operational, and every principle you cannot evidence is one a regulator or auditor can ask about.
Where do AI governance principles come from?
The OECD AI Principles (2019, updated 2024) are the most widely adopted intergovernmental statement and shaped much of what followed, including the G20 AI Principles. The NIST AI Risk Management Framework organises similar ground into four functions: Govern, Map, Measure and Manage. The EU AI Act converts several principles into obligations tied to risk tier, and ISO/IEC 42001 provides a certifiable management system.

Related concepts