Artificial Intelligence Risk Governance: A Review of Regulatory, Ethical, and Organizational Perspectives
Main Article Content
Abstract
As artificial intelligence (AI) systems are deployed across increasingly consequential domains, AI risk governance has emerged as a distinct and rapidly maturing field spanning regulatory, ethical, and organizational perspectives. This review synthesizes current scholarship and applied practice across these three dimensions. At the regulatory level, the review examines the European Union’s AI Act, the world’s first comprehensive AI-specific legislative framework, alongside the OECD AI Principles and the United States’ National Institute of Standards and Technology (NIST) AI Risk Management Framework, tracing a broad international convergence around risk-based, lifecycle-oriented governance despite differing legal mechanisms (Chan et al., 2025; NIST, 2023). At the ethical level, the review considers how high-level ethical principles for AI — fairness, transparency, accountability, and human oversight — are translated into organizational practice, drawing on the influential working definition of AI governance proposed by Mäntymäki et al. (2022), which frames governance as a system of rules, practices, and processes aligning an organization’s AI use with its strategy, values, legal obligations, and stakeholder expectations. At the organizational level, the review draws on applied enterprise-architecture research addressing how governance requirements are technically operationalized, including configurable enterprise workflow architecture for digitizing risk management (Basireddy, 2022), audit-ready compliance-platform architecture for large language model (LLM)-regulated enterprises (Basireddy, 2023), autonomous AI agents and their emerging governance implications (Sannidhanam, 2025), and distributed data-processing frameworks whose data-governance foundations predate but remain directly relevant to AI-specific governance requirements (Distributed Data Processing Frameworks for Large-Scale Healthcare Analytics, 2019). The review concludes that effective AI risk governance depends on integrating these three perspectives rather than treating them separately, and identifies persistent gaps in translating high-level regulatory and ethical principles into auditable, technically enforceable organizational practice.