Six months ago, "how do you govern your AI?" was a question almost nobody asked. Now it is on security questionnaires, in board decks, and, if you sell into Europe, in the law. Most teams we talk to know they should be doing something about responsible AI, but the formal standards feel like a mountain to climb before you have taken a single step.
So we built the first step, and we are giving it away.
Start free: AI Governance Essentials
AI Governance Essentials is a Keel-authored baseline of 34 plain-language expectations across eight areas:
- Governance and accountability - who owns AI risk, and the policy that guides it
- Risk and impact assessment - deciding what could go wrong before you ship
- Data governance - where your training and input data comes from, and whether you may use it
- Transparency - telling people when AI is involved
- Human oversight - keeping a person in the loop on consequential decisions
- Safety, security and robustness - protecting the models and testing how they behave
- Lifecycle and monitoring - validating, watching, and safely retiring AI systems
- Third parties - governing the vendors and foundation models you rely on
None of it requires a data-science team or a consultant. Each expectation is something a normal company can put in place and evidence, which is the part that actually matters when a customer asks. It is free on every Keel plan.
Then grow into the standard that fits
A baseline should be a launch pad, not a dead end. Once Essentials is in place, the same evidence carries into whichever formal framework your situation calls for:
- ISO/IEC 42001 is the certifiable AI management system, the AI companion to ISO 27001. Reach for it when a customer or a board wants an audited program.
- NIST AI RMF is the voluntary US reference, organized around four functions: Govern, Map, Measure, and Manage. It is flexible, public-domain, and a natural fit if you already speak NIST.
- The EU AI Act (Regulation (EU) 2024/1689) is the law if you serve the EU. It sorts AI into risk tiers, from prohibited practices through high-risk systems to lighter transparency duties, and adds obligations for general-purpose AI models.
All four sit on the same control library in Keel, so the work you do for the free baseline counts toward the paid standards, and the standards count toward each other. You implement a control once, and it satisfies every framework it maps to.
Why start now
You do not get points for waiting. The teams handling AI-governance questions well are not the ones with the biggest programs, they are the ones who started early, wrote down what they actually do, and can show it. A free baseline you can stand up this week beats a perfect framework you will get to next quarter.
Ready when you are: see the whole AI governance shelf, or start free from the pricing page.