Skip to main content

AI decisions Governance and the EU AI Act

Centralised vs federated AI governance: who should decide what in your organisation?

Short answer

Centralise what must be identical everywhere: policy, risk classification, approved models and platforms, the AI inventory and the regulatory evidence. Federate what depends on business context: use-case priorities, adoption and day-to-day accountability for results. A purely central model becomes a bottleneck as demand grows and a purely federated one fragments risk and spend, so the model that holds up at scale is a hybrid: a central committee with real authority plus embedded champions in each business line.

Updated: · Thinkia

The options

Centralised (AI CoE)

A central team or committee sets policy, approves use cases, owns the platform and often builds the solutions itself.

Federated

Business units own their AI use cases and decisions within shared standards, with governance roles embedded in each unit.

Side by side

Criterion Centralised (AI CoE)Federated
Decision speed Slows down as demand grows; a queue forms at the centre. Faster locally, with a risk of inconsistent decisions.
Consistency of risk classification High: one team applies one taxonomy. Varies unless the taxonomy and review are shared.
Regulatory evidence (inventory, roles, documentation) Easy to assemble in one place. Scattered unless a central register is mandatory.
Business ownership of results Weak: AI is seen as the centre’s or IT’s project. Strong: the P&L owner answers for the outcome.
Cost and vendor control Consolidated purchasing and a common platform. Risk of duplicated tools, contracts and spend.
Expertise Scarce specialists concentrated, sometimes far from operations. Domain knowledge close to the work; AI expertise thinly spread.
Shadow AI Grows when approval is slow and people route around it. Grows when there is no common platform and each unit picks its own tools.
Fits best Early stage: few use cases, low maturity, no shared platform yet. Many use cases, mature standards and a shared platform in place.

Choose Centralised (AI CoE) when…

  • You are early: few use cases, little in-house expertise and no common platform yet.
  • You deploy or plan high-risk uses under the EU AI Act, such as credit scoring, insurance pricing or recruitment, where a classification error is expensive.
  • AI spend, vendors and tools are fragmented and need consolidating.
  • You need a defensible AI inventory and role map quickly.

Choose Federated when…

  • Several business units with distinct processes have the maturity to own their decisions.
  • Shared standards, a common platform and a central register already exist.
  • The central team has become the bottleneck and use cases wait months for approval.
  • Accountability for AI outcomes has to sit with P&L owners, not with IT.

When to combine them

The answer is almost always hybrid, and the useful question is which decisions sit where. In the Thinkia AI Compass Framework this is explicit. The AI Nexus is the central, multidisciplinary committee (sponsor, technology lead, legal, FinOps, HR) that aligns, prioritises and mitigates risk. AI Champions are functional experts inside the business lines who land use cases, lead adoption and measure results. Synapse is the technical layer they share. The centre sets the rules and decides the exceptions, the business decides what to do within them, and the platform makes both visible.

Common mistakes

  • A committee without authority or budget: governance by meeting minutes.
  • Federating before a shared inventory, risk taxonomy and platform exist: you federate the chaos.
  • Making the CoE build everything, so it turns into a delivery bottleneck instead of a standard-setter.
  • Banning tools while approval takes months: use moves to channels nobody can see.
  • Leaving legal and HR out of the central body, so AI Act duties and workforce obligations surface late.

How Thinkia approaches it

We use the Thinkia AI Compass Framework to structure this decision: five dimensions (North Star Engine for value, AI Foundation Layer for technology and data, Efficiency & Sustainability Grid for cost, Trust Fabric for ethics and risk, Human Amplifier for skills) and three enablers that map directly onto the operating model, the AI Nexus at the centre, AI Champions in the business, Synapse as the shared platform.

Our sequence is to start central and federate deliberately. First the inventory, a risk taxonomy aligned with the AI Act and an approved platform; then champions in a few business lines, with decisions moving to them as the standards settle. The test for moving a decision out of the centre is simple: can the business unit make it with the shared standard and leave the evidence in the common register?

In Europe the centre keeps a core that cannot be delegated: the classification of each system and of the organisation’s role as provider or deployer, AI literacy under Article 4, which applies since February 2025, and the evidence the AI Act asks for. Our public AI governance guide and checklist cover those points, and the Shadow AI whitepaper explains why making use visible works better than banning it. Legal counsel sits in the AI Nexus because none of this is legal advice.

Thinkia products involved

Related AI solutions

Frequently asked questions

Who should own AI governance?

Ownership is split by design. A central executive sponsor, often a Chief AI or Chief Data Officer, owns the policy, the standards and the register; the business leader in whose P&L a system runs owns its outcomes. Legal, risk, security and HR take part in the central body rather than reviewing at the end.

Is an AI Centre of Excellence the same as AI governance?

No. A CoE is a capability: expertise, platforms and reusable assets. Governance is the decision system: who can approve what, under which rules, with what evidence. A CoE can host governance, but if it also has to build every use case, governance slows down with it.

How many AI Champions do we need?

There is no universal number. A practical rule is one champion per business line with live or planned use cases, with time formally allocated to the role and a direct line to the central committee. A champion without time or a mandate becomes a title, not a role.

Does the EU AI Act require a particular governance structure?

It does not prescribe one. It does assign obligations by role and by system, requires AI literacy for staff dealing with AI systems and, for high-risk systems, requires deployers to assign human oversight to competent people with the necessary authority. In practice that forces a central register and named responsibilities in the business.

How do we know it is time to federate more?

Common signals: use cases waiting long for central approval, business units buying tools outside the platform, and the central team spending more time reviewing than setting standards. If the standards, the platform and the register are stable, move the routine decisions out and keep the exceptions in.

What role does a platform play?

It makes federation safe. A shared platform with single sign-on, logging, model routing and cost visibility lets business units move on their own while the centre still sees what is used, by whom and at what cost. Without it, federation tends to turn into shadow AI.

Related decisions

Sectors where this decision comes up

Key terms

Thinkia articles

Whitepapers

Sources

Orientation, not legal advice. Confirm obligations and deadlines with qualified counsel and the official EU sources. EU AI Act guide and checklist.

Facing this decision now? Talk it through with us.

Talk to an AI Expert