Artificial intelligence (AI) governance is the emerging GRC category that every regulated organisation will need to address in the next 12–24 months. MSPs that build AI governance capability now will be ahead of a demand wave that is only beginning.
Who this is for: Forward-thinking MSPs looking to build the next generation of GRC service offerings.
TL;DR
- The EU AI Act came into force in 2024 with phased compliance obligations through 2026–2027
- Australia’s voluntary AI Ethics Framework is increasingly being supplemented by proposed mandatory guardrails for high-risk AI systems, with the AIIA actively engaged in AI policy and regulatory discussions
- Organisations using AI systems — especially in regulated sectors — now face AI governance and risk management obligations
- 6clicks' Responsible AI solution supports MSPs in delivering AI governance programmes to clients
- MSPs that build AI governance capability now will have a 12–18 month head start on competitors
The rapid adoption of AI across business operations has created a new category of risk that most organisations are not yet managing systematically. AI governance encompasses:
This is GRC for a new category of technology — and it requires the same structured programme approach as any other compliance obligation.
Several AI governance initiatives are taking shape across regions and sectors:
The EU Artificial Intelligence Act creates tiered obligations based on AI risk classification (unacceptable, high, limited, minimal). High-risk AI systems (used in healthcare, employment, credit scoring, and similar domains) face the most extensive obligations, including conformity assessments, technical documentation, and human oversight requirements.
Australia's voluntary AI Ethics Framework has eight core principles. The government is consulting on mandatory guardrails for AI used in high-risk settings, with regulatory requirements expected to crystallise in 2026–2027.
APRA and ASIC have published guidance on AI use in financial services, increasing governance expectations for regulated entities and their suppliers.
6clicks includes a Responsible AI solution specifically designed to help organisations establish AI governance programmes. For MSPs, this means:
The most effective entry point for AI governance conversations depends on the client's sector: