Starting point
Start with the operational problem—not the tool
An AI initiative should begin with a concrete problem, a defined user and an outcome that can be measured. Starting from a general ambition to “do something with AI” often creates disconnected pilots without ownership, adoption or a decision on continued use.
Leadership does not need to select the model or write technical requirements. It must decide which problems merit investment, what level of risk the organisation accepts, who owns the result and how value will be verified.
1. AI as a leadership responsibility
AI affects working practices, accountability, skills, data and sometimes people’s rights. It cannot be delegated solely to IT or an innovation team. Leadership must set direction, agree principles and review use as it would any other business-critical change.
A useful governance model distinguishes permitted everyday use, controlled experiments and AI systems that influence decisions or core processes. Greater impact requires stronger documentation, risk assessment, human oversight and follow-up.
Leadership checklist
- Agreed ambition and AI policy
- A clear owner for each use case
- An inventory of tools, pilots and AI systems
- Risk classification before deployment
- Regular reporting to leadership
2. Law and compliance
The EU AI Act applies a risk-based model. Obligations depend on the use of the system and whether the organisation acts as provider or deployer. The rules apply in stages, so classification and accountability must be assessed for each use case and kept under review.
GDPR applies when personal data is processed. Purpose, legal basis, roles, information duties, retention and security must be addressed. A data protection impact assessment may be required where risk is high. Copyright, confidentiality, administrative law, employment law and procurement rules may also apply.
This page provides orientation and does not replace legal advice for a specific deployment.
Leadership checklist
- Classify the use case under the AI Act
- Assess personal data and legal basis
- Document human oversight and intervention
- Assess confidentiality, copyright and employment law
- Secure processor terms and international transfers
3. Information security and data
An AI system can expose protected information through prompts, logs, integrations or a supplier’s further use. Information classification and security assessment must therefore precede the use of operational data.
Data quality is also a leadership matter. Incomplete or biased data can produce persuasive but wrong outputs. The organisation must know which data is used, who owns it, how quality is verified and how errors are detected.
Leadership checklist
- Information classification before use
- Approved tools and clear access rights
- Control of logging, retention and model training
- Testing for manipulation, errors and leakage
- Incident response and the ability to disable the solution
4. How to run an AI project
An AI project should be treated as operational development with technology—not as a technical demonstration. It needs an operational owner, a measurable baseline and a clear decision after the pilot.
A pilot succeeds when it establishes whether the solution should be deployed, changed or stopped. Technical function is insufficient; quality, time saved, risk, usability and total cost must be assessed together.
Recommended process
- Define the problem, users and intended outcome
- Map the process, data and current cost
- Complete legal, ethical and security risk assessments
- Select a bounded use case and agree measures
- Build or procure a controlled pilot
- Test quality, human oversight and negative scenarios
- Evaluate value, total cost and organisational impact
- Make an explicit decision: deploy, change or stop
5. Human oversight and leadership accountability
Human oversight is more than requiring someone to click a button. The responsible person must understand the evidence, be able to challenge the output and have the mandate, time and information to choose another action.
Swedish public-sector guidance recommends that generative AI should not make fully autonomous decisions that directly affect people. Decisions need to be explainable and controllable. The same principle is useful elsewhere: the consequence of error should determine the strength of human oversight.
Leadership checklist
- A named accountable person or function
- Clear situations where AI output must not be used
- Skills to detect errors and bias
- Traceability from evidence to decision
- Regular quality review after deployment
6. Procurement and supplier governance
AI services change quickly and often rely on several subcontractors. Contracts should address data use, security, changes, transparency, service levels, cost development, incidents and exit.
The organisation cannot transfer its accountability to a supplier. It needs internal commissioning capability, documented requirements and the ability to verify that the solution continues to work as intended.
Leadership checklist
- Known subcontractors and processing locations
- Rules for customer data and model training
- Rights to information, audit and incident notification
- Control of version changes and performance
- Exit plan, data export and supplier dependency
7. AI in public administration
Municipalities, regions and public authorities must combine innovation with due process, transparency, equal treatment, data protection and democratic accountability. This makes governance more important, not less.
Swedish national guidance recommends an AI policy, preparation for the AI Act, clear human oversight, risk assessment, information security and deliberate procurement. These practices should form part of ordinary governance rather than a separate technology track.
Leadership checklist
- Connection to the authority’s statutory mission
- Due process and equal treatment in impact assessment
- Management of public records and confidentiality
- Collaboration across operations, legal, security and IT
- Transparency for citizens, employees and decision-makers
Authoritative sources
Legal and regulatory information changes. Verify the current requirements in the primary sources before making decisions.
- Swedish national guidelines for generative AI in public administration
- Swedish Authority for Privacy Protection: GDPR and AI
- European Commission: AI Act and implementation
- EUR-Lex: Regulation (EU) 2024/1689
Last editorial review: 26 July 2026. This page is not legal advice.
Need a structured starting point?
Use the assessment to identify governance gaps, or contact Peter to discuss a controlled first step.