AI Governance
Most organisations are deploying AI faster than they are governing it. The EU AI Act is now in force. The NDPC is watching. The gap between deployment and governance is where the risk sits.
Who this is for: Organisations deploying AI systems, or rolling out generative AI tools, with no governance framework around them.
The problem: Most organisations cannot say what AI systems they use, what decisions those systems influence, or what happens when one gets it wrong.
The outcome: An AI inventory, risk classification, and governance framework aligned to the EU AI Act and NIST AI RMF.
The problem
Boards approve AI initiatives. Procurement buys AI tools. Development teams deploy models. And in most organisations, nobody has catalogued what AI systems are in use, what decisions they influence, or what happens when they produce a wrong or biased output.
The EU AI Act entered into force in August 2024. It applies to any organisation placing AI systems on the EU market or deploying AI that affects people in the EU, including UK and Nigerian organisations with EU operations or customers. High-risk AI systems face mandatory conformity assessments, technical documentation requirements, human oversight obligations, and registration in the EU database. The obligations are real and the enforcement timeline is running.
Beyond regulation, AI systems that make consequential decisions such as credit scoring, hiring, fraud detection, or medical triage create liability when they go wrong. Most organisations have no process for identifying when an AI system has produced a harmful or discriminatory output, let alone responding to it.
Generative AI tools add a fast-moving, less visible layer of risk. Staff paste confidential information into public chatbots without realising where that data goes. Teams adopt AI coding assistants and writing tools without any policy governing what can be shared with them. Shadow AI usage grows faster than most organisations can track it.
Nigeria does not yet have AI-specific legislation equivalent to the EU AI Act, but that does not mean the space is unregulated. Existing obligations under NDPA 2023 already apply to AI systems that process personal data, and the NDPC’s position on AI governance continues to develop. Organisations that wait for dedicated AI legislation before building any governance are already behind their existing data protection obligations.
What we do
FortressPoint builds AI governance programmes for enterprises across UK and Nigerian markets. We start with an AI inventory, cataloguing every AI system in use or development, who owns it, what decisions it influences, and what data it processes.
From the inventory we classify each system under the EU AI Act risk tiers. Prohibited systems. High-risk systems. General purpose AI. The classification determines the compliance obligations and the governance controls required. We implement the NIST AI Risk Management Framework as the operational structure. Its Govern, Map, Measure, and Manage functions give you a repeatable process for ongoing AI risk management.
We work with both technical and non-technical stakeholders. AI governance requires the board to understand risk, legal to understand obligations, and engineering to implement controls. We bridge that gap.
For organisations with Nigerian operations, we map AI-related data processing against NDPA 2023 obligations directly, because that is the enforceable framework already in place. We build the programme so it can absorb dedicated AI-specific regulation as it develops, rather than starting again when it arrives.
We build practical usage policies for generative AI tools, covering what can and cannot be shared with public AI services, which approved tools staff should use instead, and how to bring shadow AI usage under visibility without treating every use of AI as a violation to be punished.
Who this is for
What you get
Why FortressPoint
AI governance is not separate from cybersecurity and GRC. It sits inside them. The controls that govern AI systems overlap substantially with information security controls, data governance obligations, and risk management frameworks. We bring those disciplines together so you are not building a separate AI compliance programme alongside your existing ones.
We understand the EU AI Act in operational terms. We know which obligations apply to which system types, what the conformity assessment process looks like for high-risk systems, and what NDPA 2023 already requires of AI systems processing personal data in Nigeria. We do not summarise the regulation and leave you to work out the implications.
We work at board level and at engineering level. A governance framework that the board endorses but the engineering team ignores does not reduce risk.
We build for a regulatory environment that is still moving. The framework we put in place is designed to extend as EU AI Act guidance matures and as Nigeria’s own AI governance position develops, rather than needing to be rebuilt each time the regulatory picture changes.
Common questions
An AI governance consultant catalogues the AI systems your organisation uses or builds, classifies the risk each one carries, assesses your obligations under applicable regulation such as the EU AI Act, and builds the policies and controls needed to manage that risk. It combines regulatory knowledge with practical technical understanding of how AI systems actually work.
It can. The EU AI Act applies to any organisation that places AI systems on the EU market or whose AI systems affect people located in the EU, regardless of where the organisation itself is based. If you sell AI-enabled products or services to EU customers, or your AI systems process data about people in the EU, an assessment of your obligations is worth doing early.
Nigeria does not yet have AI-specific legislation equivalent to the EU AI Act. AI systems that process personal data are already covered by NDPA 2023, and the NDPC’s position on AI governance continues to develop. We build Nigerian AI governance programmes around these existing, enforceable obligations rather than waiting for dedicated legislation.
High-risk categories include AI used in areas such as employment decisions, credit scoring, access to essential services, and certain biometric or law enforcement applications. High-risk systems carry the most demanding obligations, including conformity assessments, technical documentation, and human oversight requirements. Classification depends on the specific use case, not just the underlying technology.
This needs an acceptable use policy that specifies which tools are approved, what categories of information must never be shared with public AI services, and how approved alternatives are provided so staff are not tempted to use unapproved tools to get their work done. Policy alone rarely works without a genuinely usable approved alternative in place.
If your organisation is deploying AI systems and has no governance framework around them, contact us.