Skip to main content
Arif Mughal

An AI Governance Board That Doesn't Slow Everything Down: Intake Tiers, Risk Classes and a Fast Path

Most AI governance boards fail in one of two ways: they review everything and become a queue, or they review nothing and become a rubber stamp. This article proposes an operating model built on intake tiers, clear decision rights and a fast path for low-risk AI use, grounded in the NIST AI RMF, ISO/IEC 42001, the EU AI Act as amended by the 2026 AI Omnibus, Microsoft's Responsible AI Impact Assessment and OMB M-25-21.

Arif Mughal10 min readAI Governance

Published 26 September 2026. Every regulatory date and standards claim below was checked against the European Commission's, NIST's, ISO's, Microsoft's or the US Office of Management and Budget's own documentation on 19 September 2026. Where sources disagree, I say so rather than pick one. The operating model itself is my own proposal, and it is labelled as such throughout.

Most AI governance boards I encounter fail in one of two ways. Some review everything, so the queue grows until teams stop asking and use AI without telling anyone. Others review nothing of substance, so the board exists on an organization chart and nowhere else. Both end in the same place: AI in use that nobody has assessed.

In architecture governance in large technology programs I argued that governance works when decision rights are explicit. This article applies that idea to AI, and builds on building secure and governed enterprise AI services.

The one idea that organizes the model

Review effort should follow risk, not arrival order. Most AI use should be registered, not reviewed.

This is not a new principle. The NIST AI RMF says it plainly in GOVERN 1.3: organizations should determine "the needed level of risk management activities based on the organization's risk tolerance." A board that gives a meeting-summary tool the same review as a hiring model has not applied that principle.

What the frameworks require, and what they leave to you

None of the main references prescribes a board design. Each one supplies a piece.

ReferenceWhat it gives youWhat it leaves to you
NIST AI RMF 1.0 (GOVERN function)Risk-proportionate effort (1.3), an AI inventory (1.6), clear roles (2.1), executive accountability (2.3)Tier definitions, thresholds, meeting design
ISO/IEC 42001:2023A certifiable AI management system; ISO states it makes impact assessment "a consistent and required part of AI governance"How to scale assessment depth; ISO/IEC 42005:2025 gives assessment guidance
EU AI Act, as amended by the AI OmnibusFour legal risk levels: prohibited, high-risk, transparency, minimalYour internal tiers, which must also reflect data, autonomy and business impact
Microsoft Responsible AI Impact Assessment (public template, June 2022)Intake-ready questions on intended uses, restricted uses, known limitations, and three Sensitive Use triggersRouting and decision rights
OMB M-25-21 (US federal agencies, April 2025)A board model with named membership and a "high-impact AI" definitionAnything outside US federal agencies is voluntary adoption

NIST also notes that AI RMF 1.0 "is being revised as part of the White House AI Action Plan." No revised version was published when I checked, so this article uses 1.0.

Where the EU AI Act dates stand in September 2026

Timelines in older material are now wrong. The AI Omnibus entered into force on 27 July 2026, and the European Commission's current timeline reads as follows.

ObligationApplies from
Prohibited practices and AI literacy2 February 2025
Governance rules and general-purpose AI model obligations2 August 2025
Enforcement by the AI Office and Member State authorities; new transparency requirements2 August 2026
High-risk systems in areas such as biometrics, critical infrastructure, education, employment, migration, asylum and border control2 December 2027
High-risk AI integrated into regulated products2 August 2028

Source: European Commission, AI Act policy page and AI Omnibus news item, checked 19 September 2026.

Two cautions. Secondary summaries describe transition details for transparency labelling that the Commission's own omnibus announcement does not mention, so I have left them out; read the legal text before relying on any grace period. And the deferral moves the deadline, not the obligation. A hiring or credit model your board approves today will still be in service in December 2027.

Who sits on the board

The US federal model is a useful reference even outside government. Under OMB M-25-21, an agency AI Governance Board is chaired at Deputy Secretary level or equivalent, with the Chief AI Officer as vice-chair, and includes IT, cybersecurity, data, budget, legal, privacy, civil rights and civil liberties.

My proposal for a private-sector organization is a smaller standing core: an executive chair who can accept risk, the accountable AI lead, security, privacy, legal, and a data or architecture lead. Business owners attend for their own cases. The rule that matters is that every standing member can approve on behalf of their function. A board whose members must take decisions back to someone else adds a second queue.

One intake, short enough to finish

Every AI use enters through the same form, including the ones that will take the fast path. The inventory NIST GOVERN 1.6 asks for is a by-product of the intake, not a separate project. The fields below are my proposal, drawn partly from Microsoft's public Impact Assessment template.

FieldWhy it is there
Business owner and purposeAccountability, and Microsoft's "intended uses"
Tool or platform, and whether it is already approvedDecides fast-path eligibility
Highest data classification usedData risk
Does output affect a decision about a person?Sensitive Use and high-risk screening
Can it take actions in other systems?Autonomy risk
Who sees the output: staff, customers, public?Transparency obligations
Restricted or unsupported usesScope the approval
Markets and jurisdictionsEU AI Act applicability

Four tiers and a hard stop

This is the part to take into a standard. Every threshold, reviewer and decision time in it is my proposal, not a framework requirement.

Author-proposed intake-to-decision flow. Every AI use starts with one intake form and passes through triage questions. A use that matches a prohibited practice stops. A use that runs on an approved tool, handles only low-classification data and takes no actions goes on the fast path: it is registered in the inventory and starts. Other uses route to Tier 1 standard review by delegated reviewers, Tier 2 elevated review by the board, or Tier 3 high-impact review by the board with executive sign-off. All decisions, including fast-path registrations, feed one AI inventory with a review date, and any material change sends the use back to intake.
Figure 1: One front door, four routes and a hard stop. The fast path is still a decision: it is recorded in the inventory.

The fast path (Tier 0) applies only when all of these are true: the tool is already approved; no data above the agreed classification is used; the output does not decide anything about a person; the AI takes no actions in other systems; and nothing in the output reaches customers or the public unreviewed. Meeting all five means registration, not review.

Escalation triggers move a case up regardless of how it was submitted. Any one of Microsoft's three Sensitive Use triggers (consequential impact on legal position or life opportunities, risk of physical or psychological injury, threat to human rights), any EU AI Act high-risk area, or anything meeting the OMB definition of high-impact AI goes to Tier 3.

Author-proposed tier matrix. Tier 0, fast path: approved tool, low data classification, no decisions about people, no actions and no unreviewed public output; decided by registration with no meeting; evidence is the intake form; target same day. Tier 1, standard: new tool or internal data, no decisions about people, no actions in other systems; decided by delegated security and data reviewers; evidence is the intake form plus a data and security check; target 5 business days. Tier 2, elevated: confidential data, customer-facing output, or agents that act in other systems; decided by the board; evidence is an impact assessment plus test results; target the next board meeting. Tier 3, high-impact: decisions about people, an EU AI Act high-risk area, or a Sensitive Use trigger; decided by the board plus executive sign-off; evidence is a full impact assessment, legal review and a monitoring plan; target date agreed at intake. For Tiers 2 and 3, any one criterion is enough. Prohibited: an EU AI Act prohibited practice or an internal red line; stopped at intake; evidence is the intake record.
Figure 2: Decision rights, evidence and target times rise together. The target times are proposals to calibrate against your own baseline.

Two design choices matter more than the tier boundaries. First, every approval carries a review date, and any material change (new data, new users, new actions) sends the case back to intake. Microsoft's Responsible AI Standard takes the same line on its own assessments, requiring review "at least annually, when new intended uses are added, and before advancing to a new release stage." Second, the board publishes its decisions as reusable patterns. Once one retrieval assistant over a given document library is approved, the next one that looks the same can take the fast path.

How to measure the board without inventing numbers

I will not quote an industry benchmark for review times, because I have not found one I can trace to a primary source. Measure your own instead:

MeasureWhat it tells you
Cycle time from complete intake to decision, per tierWhether the target times are real
Share of intakes returned for missing informationWhether the form is too long or unclear
Share of cases that move tiers after triageWhether the criteria are clear
AI uses discovered outside the inventoryWhether teams trust the process
Decisions later reversed or incidents in approved usesWhether the fast path is too loose

Run a quarter, set targets from that baseline, and publish the results to the people who submit cases. The fourth measure is the one I would give the executive chair, because it shows whether the board is being bypassed.

What I would actually do

Start with the inventory and the intake form, not the board charter. Register what is already in use before debating tiers, because the tiers should be designed around the real mix of use cases rather than an imagined one.

Then launch the fast path on day one. A board that opens with only a full-review route will spend its first six months proving the complaint that governance slows everything down.

Keep Tier 3 small and serious. Hiring, credit, health and safety cases deserve a full impact assessment and legal review, and the EU dates in 2027 and 2028 are close enough that a model approved now will still be running when they apply.

If you are setting up an AI governance board, or already have one that has become a queue, that is work Avalon does: intake and tiering design, AI inventory set-up, impact assessment templates mapped to the NIST AI RMF and ISO/IEC 42001, and EU AI Act applicability screening. It is part of my enterprise AI and security practice, and the contact page is the best way to start a conversation.

Sources

All checked on 19 September 2026.

EU AI Act — AI Act policy page and timeline, European Commission (opens in a new tab) · AI Omnibus enters into force, European Commission (opens in a new tab) · AI Omnibus legal text, Official Journal (opens in a new tab)

NIST — AI Risk Management Framework (opens in a new tab) · AI RMF Core: GOVERN function (opens in a new tab)

ISO — ISO/IEC 42001:2023 (opens in a new tab) · ISO/IEC 42005:2025 (opens in a new tab) · ISO responsible AI governance and impact package (opens in a new tab)

Microsoft — Microsoft's framework for building AI systems responsibly (opens in a new tab) · Responsible AI Standard v2, general requirements (opens in a new tab) · Responsible AI Impact Assessment template (opens in a new tab)

US federal — OMB M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust (opens in a new tab)


Published 26 September 2026; sources checked on 19 September 2026. EU AI Act dates changed in July 2026 and may change again, so check the Commission's timeline before relying on them. The board composition, intake fields, tiers, target decision times and measures are an operating model I propose, not a requirement of any framework cited. No client, employer or engagement is named in this article, and any scenario described is an illustrative composite rather than a description of specific customer work.

AI Governance

NIST AI RMF and ISO/IEC 42001 in Practice: A One-Page Map to Microsoft Controls

NIST's AI Risk Management Framework is voluntary and ISO/IEC 42001 is certifiable, but they describe the same management cycle. This guide lines the two up, maps each theme to the Microsoft controls that produce evidence for it (Purview, Entra Agent ID, Agent 365, Defender for Cloud and Foundry), and is clear about what no tool can do for you. Checked against NIST, ISO and Microsoft documentation in September 2026.

10 min read

AI Governance

Agent Sprawl: An Inventory and Lifecycle Model for Enterprise AI Agents

Most organizations can now build AI agents faster than they can say who owns them. This article proposes a twelve-field inventory record and a seven-stage lifecycle from proposal to retirement, and maps each stage to what the Microsoft 365 Agent Registry, Microsoft Agent 365, Entra Agent ID and Power Platform inventory actually do as of September 2026, including where the tooling stops.

10 min read

AI Governance

Building Secure and Governed Enterprise AI Services

AI services are entering organizations through every door at once. Treating them as enterprise platforms — with identity, data boundaries, logging, and governance — is the difference between adoption and exposure.

3 min read