Who Who Governs AI in Your Safety System?
Say "AI governance" in a safety meeting and watch what happens. Someone mentions a law in a country you don't operate in, everyone agrees it's important, and nothing gets done.
👋 Hello, Lucas Domingues here and welcome to the 8th edition of Safety 4.0 Insights in 2026. As AI in EHS content floods the internet, true signal is becoming rare. This newsletter is where we keep it real: human, SafetyTech clarity, and practical AI for EHS leaders. Thanks for helping make it a leading publication.
🎓 Now is a great time to learn and upskill in AI, safetytech and digital transformation. Here's how the SafetyTech Academy can help you:
- Discover our learning programmes and start your AI literacy journey today.
- Subscribe to my Newsletter, Youtube Channel and Podcast.
🥳 BIG NEWS 1 - This newsletter is about to hit the 3,000 subscribers mark. THANK YOU 3,000 times! If you're reading it but never subscribed, please do it now. Share this edition in your network so others can join.
🥳 BIG NEWS 2 - SafetyTech Academy has been shortlisted as "Learning and Training Provider of the Year" by IOSH Awards while Lucas Domingues, MSc, CMIOSH is in the "Health & Safety Influencer of the Year". While we win or not, the important thing is that we're proud to support EHS leaders globally and it stays our core mission.
🚀 Let's go...
If AI is helping decide something in your workplace, whether a permit gets signed, whether an incident gets escalated, whether a policy gets drafted, then that decision is owned by whoever is using AI. It always was. Nothing about that depends on where you're reading this from. Here's where that responsibility comes from, why the clock is running faster than most people think, and a simple scorecard you can use on your own team this week.
You're already responsible, and that's good news
Safety law around the world agrees on one thing: the employer is responsible for whether its controls actually work. Guard rail, procedure, competent supervisor, algorithm. It doesn't matter what the control is made of. If it's part of how you manage risk, you own it.
So you don't need to wait for anyone to write an AI rulebook. Your safety management system already asks four questions, and they work perfectly well on AI:
- Competence - Are the people using this thing actually capable of using it well, including knowing when to overrule it?
- Records - Can you find the paperwork when someone asks for it?
- Change - When your supplier quietly updates the software, does anyone treat that as a change to your safety system?
- Review - Are you checking whether it still works, or just assuming it does?
Everyone's asking the same thing
The rules are arriving at different speeds in different places, which makes the picture look messier than it is. Europe has moved fastest and gone furthest, and this is the bit worth paying attention to even if you've never set foot in the EU. Parts of the EU AI Act were delayed this summer. These two were not:

Five things to check (at least)
Most AI governance advice is written for tech teams, assuming a data scientist and a risk register with a column for algorithms. Safety teams have none of that, and are using AI anyway. Here's the version that fits how we actually work.
01 - Visibility (Know what you have) - A simple list of what it is, who owns it, what it's for, what it affects. No list, no governance.
02 - Literacy (What people know) - Can you show what your people were taught, and when? Competence is the oldest ask in safety. AI doesn't get a pass on it.
03 - Governance (Decisions) - Who says yes or no before AI touches a safety decision, and whose name is on it if it gets one wrong? This isn't about blame but ownership and accountability.
04 - Assurance (Testing) - How do you know it still works?
05 - Records (Proof) - If someone asked tomorrow, what could you actually put in front of them by Friday?
The AI Governance Scorecard
I've built the full thing as a free resource on the SafetyTech Academy website. It breaks each of the five down into scored questions with evidence prompts, so you can run it as a proper session with your team rather than just reading about it. It doesn't care which country you're in. It only asks what you can show.
-> Get our FREE AI in EHS Governance Readiness Scorecard
And finally, last month I had the pleasure of sitting down with the brilliand Susan M. Moore, PhD for a podcast episode on ISO 42001 and the top things EHS leaders need to know. It's a full hour of pure knowledge, tips and actionable insights on AI governance. Thanks, Susan!
Nobody got into safety because they love governance. But this is the part that decides whether the AI you've brought in is a control or a liability. Very few teams get caught out by the technology failing. They get caught out by not being able to explain what they bought, who approved it, and what happened next.
Thanks for reading.
Lucas
References
- ISO. ISO 45001:2018, Occupational health and safety management systems. Competence (7.2), documented information (7.5), management of change (8.1.3) and performance evaluation (9.1).
- ISO. ISO/IEC 42001:2023, Artificial intelligence management system. Available at: iso.org
- European Union. Regulation (EU) 2024/1689 (AI Act): Article 4 (AI literacy), Article 5 (prohibited practices) and Article 50 (transparency obligations). Available at: eur-lex.europa.eu
- European Union. Regulation (EU) 2024/1689, Article 99 (penalties): €15m/3% tier for Article 50 breaches, €35m/7% tier for Article 5 breaches. Available at: ai-act-service-desk.ec.europa.eu
- European Union. Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 27 July 2026. Deferred the high-risk deadlines and revised the AI literacy duty. Available at: eur-lex.europa.eu
Transparency note: AI (Claude Opus 5 and Google Gemini) were used whilst curating parts of this edition including image generation. All opinions are my own. This newsletter is editorial commentary for EHS practitioners and is not legal advice; for compliance decisions, consult qualified counsel in your jurisdiction.

Responses