Before addressing risks, audits, or regulatory requirements, it is essential to master the principles that structure AI governance.
AI governance refers to the set of frameworks, practices, processes, and responsibilities established across an organisation to guide the design, deployment, use, and oversight of AI systems.
It aims to ensure responsible and ethical development, to manage associated risks, and to ensure compliance with applicable legal, regulatory, and internal requirements.
An obligation for developers, deployers, and distributors of an AI system to ensure that it operates ethically, equitably, transparently, and in compliance with applicable rules.
Accountability implies that the actions, decisions, and results of an AI system can be documented, explained, and, where necessary, traced back to the relevant actors or entities.
In the field of data protection, it also involves the implementation of appropriate technical and organisational measures to demonstrate compliance with current regulations, notably the GDPR.
Transparency
Principle according to which the operation, purposes, limitations, and conditions of use of an AI system must be understandable and accessible to the relevant stakeholders.
Transparency can cover the information available about the system, its technical and non-technical documentation, the data used, the criteria influencing its results, and also the accessibility of the source code in an open-source context.
In the context of data protection, it involves providing data subjects with clear, concise, intelligible, and easily accessible information about the processing of their data.
Principle according to which an AI system must produce fair, consistent, and non-discriminatory results for the individuals or groups concerned.
Fairness involves identifying, measuring, and mitigating biases that may lead to unfavourable treatment based on sensitive or protected characteristics, such as origin, gender, age, religion, health status, or any other situation that could result in discrimination.
In the context of data protection, this concept is close to the principle of lawful processing in the GDPR, which requires that processing be carried out fairly, transparently, and in a manner that is understandable to the data subjects.
The ability of an AI system to provide understandable explanations for the results, decisions, or recommendations it produces.
Explainability aims to allow users, business teams, auditors or authorities to understand the main factors that influenced the outcome of an AI system, without necessarily exposing all of its technical complexity.
It is particularly important when decisions made by AI can have an impact on people's rights, opportunities, safety or well-being.
Ability to understand the inner workings of an AI model and the key factors that influence its outcomes.
Unlike explainability, which often aims to provide an explanation after a decision, interpretability relies on models or methods whose structure directly facilitates human understanding.
It is particularly important in sensitive contexts, when the results of an AI system need to be able to be analysed, verified, or justified by experts.
An approach to AI development, deployment and governance aimed at ensuring AI systems are safe, robust, transparent, explainable, accountable, privacy-preserving and non-discriminatory.
Trustworthy AI is based on a combination of technical, ethical, organisational, and legal principles that limit risks, protect those affected, and promote responsible AI use.
This concept is close to those of responsible AI and ethical AI, but it particularly emphasizes the reliability, safety, conformity, and trust that stakeholders can place in the system.
A design, development, and deployment approach for AI that places human well-being, autonomy, rights, values, and needs at the heart of the system.
The aim is to develop AI systems that support, enhance or augment human capabilities, rather than completely replacing human judgement, responsibility or intervention.
This approach involves particular attention to the safety, accessibility, human oversight, protection of fundamental rights, and social impacts of AI systems.
Autonomy
The ability of an AI system to operate, make decisions, or perform certain actions with a limited degree of direct human intervention.
Autonomy can vary depending on the system: some simply assist humans with a task, while others can act more independently within a predefined framework.
From a governance perspective, autonomy must be framed by mechanisms of supervision, control, traceability, and, where necessary, human intervention.
AI governance involves identifying risks from the system's design phase and then monitoring them throughout its lifecycle.
Systematic bias that can lead an AI system to produce unfair, inaccurate, or discriminatory results.
A bias can originate from the training data, the model's assumptions, design choices, or even cognitive and societal biases present in the data used.
These biases can affect the rights of the data subjects, reinforce existing inequalities, and constitute a major ethical, operational, and regulatory risk, particularly within the framework of the European AI Regulation.
Hallucinations refer to situations in which a generative AI model produces results that are seemingly plausible, but factually incorrect, made-up, or unverified.
This phenomenon, sometimes called confabulation, is particularly critical in contexts where the reliability of information is essential, especially in the medical, legal, financial, or regulatory sectors.
From a governance perspective, hallucinations must be anticipated through verification mechanisms, human supervision, documentation of system limitations, and control of risky uses.
An adversarial attack is a technique used to manipulate an AI model's input data in order to cause an error, bypass, or incorrect behaviour.
For example, it may involve subtly altering an image, text, signal, or data used by the system, in order to mislead the model.
These attacks represent a significant security risk, particularly for AI systems used in sensitive contexts such as autonomous vehicles, cybersecurity, healthcare, finance, or access control.
From a governance perspective, they must be anticipated by robustness tests, continuous performance monitoring, detection mechanisms, and appropriate security measures.
AI accountability refers to the obligation to identify the actors responsible for the design, deployment, use, and oversight of an AI system.
It implies that the decisions, actions and outcomes produced by an AI system can be documented, explained and, when necessary, traced back to the relevant individuals, teams or organisations.
From a governance perspective, accountability clarifies who is answerable for risks, errors, biases, potential harms, and compliance with ethical, regulatory and organisational requirements.
Data poisoning is an attack that aims to introduce false, biased, or manipulated data into datasets used to train, fine-tune, or update an AI model.
The objective is to corrupt the learning process in order to influence the model's behaviour and produce incorrect, misleading, discriminatory, or dangerous results.
From a governance perspective, this risk must be anticipated through data quality controls, source traceability, validation mechanisms, and continuous monitoring of model performance.
Data drift occurs when the data used as input to an AI system evolves over time to the point where it no longer statistically matches the data on which the model was trained.
This phenomenon can lead to degraded performance, less reliable results, or erroneous decisions.
From a governance perspective, data drift must be monitored throughout the system's lifecycle to detect significant changes, re-evaluate model performance and, where necessary, make adjustments or retrain it.
Deepfakes are AI-altered or AI-generated audio, video, or visual content, often very realistically.
They can be used to create fake speeches, fake images, fake videos, or fake evidence, with a significant risk of manipulation, reputational damage, fraud, or the spread of misinformation.
Misinformation refers to the intentional spread of false or misleading content. Conversely, misinformation refers to the spread of inaccurate or misleading content without deliberate intent to harm.
From a governance perspective, these risks must be anticipated through mechanisms for verification, traceability, detection of AI-generated content, and user awareness.
Governance tools allow for the documentation, control, and improvement of AI systems before and after they go into production.
An AI audit is a systematic evaluation of an AI system, or a portfolio of AI systems, aimed at verifying its functioning, performance, compliance, and risk management.
It allows for examination of whether the system operates as intended, complies with applicable laws, regulations, standards, and internal policies, and has sufficient documentation to be understood, controlled, and supervised.
AI auditing can also identify risks that were not detected during the design or development phases, particularly in terms of bias, security, transparency, robustness, or impact on individuals' rights.
AI Assurance refers to the set of frameworks, policies, processes, and controls for assessing, demonstrating, and strengthening the safety, reliability, and compliance of AI systems.
It aims to provide a reasonable level of assurance that an AI system operates as intended, that its risks are managed, and that it complies with applicable requirements.
AI assurance devices can include compliance assessments, impact assessments, audits, certifications, robustness testing, documentary checks, and continuous monitoring mechanisms.
AI impact assessment is a process of analysis aimed at identifying, understanding, evaluating, and mitigating the potential effects of an AI system on individuals, organisations, and society.
It can cover the ethical, legal, economic, social, organisational and operational implications of the system, particularly concerning fundamental rights, security, non-discrimination, transparency and data protection.
It distinguishes itself from risk assessment, which focuses more on the identification, probability, severity, and control measures of risks associated with the system.
Conformity assessment is an analysis to determine whether an AI system complies with applicable requirements before it is placed on the market, deployed or used.
It can be carried out by the organisation itself or, in some cases, by an independent entity, depending on the risk level of the system and the applicable regulatory requirements.
This assessment may cover, but is not limited to, the risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, robustness, cybersecurity and post-deployment monitoring.
A model card is a concise document that describes the main characteristics of an AI model, including its intended use, training data, performance, limitations, terms of use, and known risks.
It can also present performance metrics and evaluation results according to different contexts, populations or groups concerned, in order to identify potential variations in reliability, accuracy or fairness.
From a governance perspective, the template sheet facilitates transparency, documentation, auditability, and risk assessment related to the model.
A system card is a concise document that describes the overall functioning of an AI system, going beyond just the model used.
It notably presents the system's purpose, its components, the integrated models, the data used, the users concerned, the conditions of use, the known limitations, the controls in place and the associated risks.
From a governance perspective, the system sheet facilitates transparency, explainability, auditability, and oversight of the AI system as a whole.
Human-in-the-loop refers to a design approach where human oversight, intervention, or validation is integrated into the functioning of an AI system.
This mechanism allows a person to control, correct, confirm or interrupt certain decisions or actions produced by the system, particularly when these may have a significant impact.
From a governance perspective, human-in-the-loop contributes to strengthening accountability, safety, risk management, and trust in AI systems.
A fail-safe is a mechanism put in place to be activated when an AI system behaves unexpectedly, malfunctions, or dangerously.
It can forecast temporary system shutdowns, switching to manual procedures, the use of an alternative system, or the activation of technical redundancy mechanisms.
From a governance perspective, the contingency plan helps to strengthen the security, robustness, business continuity, and risk management of AI systems.
Understanding AI governance also requires a grasp of certain basic technical concepts.
A set of technologies that enable computer systems to perform tasks that usually require human capabilities, such as analysis, prediction, classification, or content generation.
Concept of an AI capable of executing a wide variety of intellectual tasks with a level of adaptability comparable to or greater than that of a human.
Method enabling a system to improve its performance from data, without being explicitly programmed for each decision rule.
Deep learning is a subfield of artificial intelligence and machine learning that uses artificial neural networks composed of multiple layers.
These layers allow the model to progressively identify complex patterns in large volumes of data.
Deep learning is particularly used for processing unstructured data, such as images, natural language, voice, or video.
A neural network is a type of AI model that is a simplified imitation of how biological neurons function.
It is made up of layers of interconnected nodes that process data and allow complex, including non-linear, relationships to be identified.
Neural networks are widely used in deep learning, for example in image recognition, natural language processing, speech recognition, or certain medical applications.
An algorithm is a set of instructions, rules, or steps that allow a computer system to perform a task, solve a problem, or produce a result from data.
In the field of AI, algorithms can be used to analyse data, detect patterns, make predictions, or train a machine learning model.
Computational power refers to the hardware resources used to train, run, or deploy an AI system, including central processing units, graphics processing units, and other specialised accelerators.
It influences a model’s capability to process large volumes of data, perform complex calculations, and produce results during training or inference.
From a governance perspective, computational power can have implications for costs, performance, energy consumption, security, and access to the capabilities needed to develop or use certain AI systems.
Understanding the various learning methods is essential for assessing the risks of bias, data requirements and supervision requirements.
Supervised learning
Model trained on labelled data with known outputs.
Traceability and quality of essential training data.
Unsupervised learning
Model trained on unlabelled data to detect structures.
Risks of biases or problematic groupings that are more difficult to detect.
Semi-supervised learning
Model trained with a combination of labelled and unlabelled data.
Provenance, quality and documentation of data to be checked.
By reinforcement learning
Model trained by trial, error, rewards and penalties.
Possible unforeseen behaviours if objectives are poorly defined.
Federated
Distributed learning without centralisation of raw data.
Strengthens privacy protection but requires robust technical governance.
Active
The model selects the most useful data to improve its learning.
Human supervision required in data selection and validation.
By transfer
Knowledge gained from one task reused for another.
Risk of inherited biases, limitations or errors from the source model.
The AI governance is based on structured frameworks that cover the technical, ethical, organisational and regulatory dimensions of AI systems.
We use cookies to improve your experience. Some features may not work without them. Manage your preferences.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper functioning of the website.
You will find more information in our...Cookie Policy and Terms & Conditions of Sale.
Notifications