AI decisions Governance and the EU AI Act
Centralised vs federated AI governance: who should decide what in your organisation?
Centralise what must be identical everywhere: policy, risk classification, approved models and platforms, the AI inventory and the regulatory evidence. Federate what depends on business context: use-case priorities, adoption and day-to-day accountability for results. A purely central model becomes a bottleneck as demand grows and a purely federated one fragments risk and spend, so the model that holds up at scale is a hybrid: a central committee with real authority plus embedded champions in each business line.
The options
Centralised (AI CoE)
A central team or committee sets policy, approves use cases, owns the platform and often builds the solutions itself.
Federated
Business units own their AI use cases and decisions within shared standards, with governance roles embedded in each unit.
Side by side
| Criterion | Centralised (AI CoE) | Federated |
|---|---|---|
| Decision speed | Slows down as demand grows; a queue forms at the centre. | Faster locally, with a risk of inconsistent decisions. |
| Consistency of risk classification | High: one team applies one taxonomy. | Varies unless the taxonomy and review are shared. |
| Regulatory evidence (inventory, roles, documentation) | Easy to assemble in one place. | Scattered unless a central register is mandatory. |
| Business ownership of results | Weak: AI is seen as the centre’s or IT’s project. | Strong: the P&L owner answers for the outcome. |
| Cost and vendor control | Consolidated purchasing and a common platform. | Risk of duplicated tools, contracts and spend. |
| Expertise | Scarce specialists concentrated, sometimes far from operations. | Domain knowledge close to the work; AI expertise thinly spread. |
| Shadow AI | Grows when approval is slow and people route around it. | Grows when there is no common platform and each unit picks its own tools. |
| Fits best | Early stage: few use cases, low maturity, no shared platform yet. | Many use cases, mature standards and a shared platform in place. |
Choose Centralised (AI CoE) when…
- You are early: few use cases, little in-house expertise and no common platform yet.
- You deploy or plan high-risk uses under the EU AI Act, such as credit scoring, insurance pricing or recruitment, where a classification error is expensive.
- AI spend, vendors and tools are fragmented and need consolidating.
- You need a defensible AI inventory and role map quickly.
Choose Federated when…
- Several business units with distinct processes have the maturity to own their decisions.
- Shared standards, a common platform and a central register already exist.
- The central team has become the bottleneck and use cases wait months for approval.
- Accountability for AI outcomes has to sit with P&L owners, not with IT.
When to combine them
The answer is almost always hybrid, and the useful question is which decisions sit where. In the Thinkia AI Compass Framework this is explicit. The AI Nexus is the central, multidisciplinary committee (sponsor, technology lead, legal, FinOps, HR) that aligns, prioritises and mitigates risk. AI Champions are functional experts inside the business lines who land use cases, lead adoption and measure results. Synapse is the technical layer they share. The centre sets the rules and decides the exceptions, the business decides what to do within them, and the platform makes both visible.
Common mistakes
- A committee without authority or budget: governance by meeting minutes.
- Federating before a shared inventory, risk taxonomy and platform exist: you federate the chaos.
- Making the CoE build everything, so it turns into a delivery bottleneck instead of a standard-setter.
- Banning tools while approval takes months: use moves to channels nobody can see.
- Leaving legal and HR out of the central body, so AI Act duties and workforce obligations surface late.
How Thinkia approaches it
We use the Thinkia AI Compass Framework to structure this decision: five dimensions (North Star Engine for value, AI Foundation Layer for technology and data, Efficiency & Sustainability Grid for cost, Trust Fabric for ethics and risk, Human Amplifier for skills) and three enablers that map directly onto the operating model, the AI Nexus at the centre, AI Champions in the business, Synapse as the shared platform.
Our sequence is to start central and federate deliberately. First the inventory, a risk taxonomy aligned with the AI Act and an approved platform; then champions in a few business lines, with decisions moving to them as the standards settle. The test for moving a decision out of the centre is simple: can the business unit make it with the shared standard and leave the evidence in the common register?
In Europe the centre keeps a core that cannot be delegated: the classification of each system and of the organisation’s role as provider or deployer, AI literacy under Article 4, which applies since February 2025, and the evidence the AI Act asks for. Our public AI governance guide and checklist cover those points, and the Shadow AI whitepaper explains why making use visible works better than banning it. Legal counsel sits in the AI Nexus because none of this is legal advice.
Thinkia products involved
- EU AI Act governance guideRisk tiers, timeline, roles and a 20-point checklist. Not legal advice.
- SynapseGoverned agentic platform: agents, models, costs and data in one place.
Related AI solutions
- AI governance, risk & controlAI your board, legal team and regulators can sign off on.
- AI strategy & roadmapFrom ambition to a plan your teams can ship
- AI readiness & maturity auditHonest gaps, risks, and the next 90 days
- AI use-case discoveryEnds with a backlog, not a deck
- Data quality, lineage & governanceGovernance AI actually needs
Frequently asked questions
Who should own AI governance?
Ownership is split by design. A central executive sponsor, often a Chief AI or Chief Data Officer, owns the policy, the standards and the register; the business leader in whose P&L a system runs owns its outcomes. Legal, risk, security and HR take part in the central body rather than reviewing at the end.
Is an AI Centre of Excellence the same as AI governance?
No. A CoE is a capability: expertise, platforms and reusable assets. Governance is the decision system: who can approve what, under which rules, with what evidence. A CoE can host governance, but if it also has to build every use case, governance slows down with it.
How many AI Champions do we need?
There is no universal number. A practical rule is one champion per business line with live or planned use cases, with time formally allocated to the role and a direct line to the central committee. A champion without time or a mandate becomes a title, not a role.
Does the EU AI Act require a particular governance structure?
It does not prescribe one. It does assign obligations by role and by system, requires AI literacy for staff dealing with AI systems and, for high-risk systems, requires deployers to assign human oversight to competent people with the necessary authority. In practice that forces a central register and named responsibilities in the business.
How do we know it is time to federate more?
Common signals: use cases waiting long for central approval, business units buying tools outside the platform, and the central team spending more time reviewing than setting standards. If the standards, the platform and the register are stable, move the routine decisions out and keep the exceptions in.
What role does a platform play?
It makes federation safe. A shared platform with single sign-on, logging, model routing and cost visibility lets business units move on their own while the centre still sees what is used, by whom and at what cost. Without it, federation tends to turn into shadow AI.
Keep exploring
Related decisions
- EU AI Act provider vs deployer: which role are you, and what does each one owe?
- In-house team, AI consultancy or platform: who should build your AI?
- AI pilot vs production: what actually changes when you scale?
- Single AI vendor vs multi-model strategy: should you bet on one provider?
- Build vs buy AI agents: which agents should you own, and which should you rent?
Sectors where this decision comes up
Key terms
Thinkia articles
- AI Governance: The Strategic Engine for Competitive Advantage
- Enterprise AI Strategy: A Guide to the AI-First Operating System
- Why Modular Agent Governance is Key to Enterprise AI Adoption
- Beyond Spreadsheets: Why New AI Governance Tools Are Essential for Compliance
Whitepapers
- Shadow AI. Govern it, don't ban it.Three in four employees already use AI where IT cannot see it. Banning removes the witnesses, not the risk: make visible, govern, and enable.
- AI Ethics & Governance. Beyond compliance.How the EU AI Act turns ethics and governance into business value—the operational lens, Thinkia AI Compass, and a roadmap to scale AI with trust.
- The AI Act already applies.The Digital Omnibus postponed Annex III to December 2027. It did not touch Article 4 or Article 50. Five questions for your next committee meeting.
Sources
Orientation, not legal advice. Confirm obligations and deadlines with qualified counsel and the official EU sources. EU AI Act guide and checklist.