Lesson 16 / 26

AI Policy and Governance Roles

Write a short, usable AI policy and set up a review body with clear authority.

Rules people can follow

An AI policy states what is allowed, what is not, who decides, and what to do in doubt. Keep it short and practical: approved tools and data, prohibited uses, rules for personal and confidential data, human review requirements, disclosure rules, and how to request approval for a new use. Pair it with a governance body (an AI review board or committee with members from product, engineering, legal, privacy, security and risk) that has real authority to approve, require changes or stop a launch, and that decides quickly for low-risk cases.

Policy, people, process, proof

Governance gives AI work clear rules, owners, checkpoints and records.

Four parts: policy, roles, gates, records.
Figure 5.1 — Policy, roles, gates and records.

Policy skeleton

Each heading should fit in a few lines. If the policy cannot be read in ten minutes, staff will not read it.

1 Scope            who and what this covers (staff, vendors, all AI use)
2 Approved tools    list + how to request a new one
3 Data rules        never input: customer personal data, secrets, unreleased financials
4 Prohibited uses   e.g. fully automated decisions about hiring or credit
5 Human review      required for external content and high-tier use cases
6 Disclosure        tell users when AI is involved
7 Approval path     tier -> reviewer -> sign-off timeline
8 Incidents         how to report, within what time
9 Owner and review  named owner; policy reviewed every 6 months

Make the safe path the easy path

If getting approval takes months, people will use unapproved tools in secret. Provide approved tools, a fast route for low-risk uses and clear answers, so following the policy is easier than avoiding it.

Quick check: Why provide approved tools and a fast approval route?

  • Approved tools are always free
  • To make the policy longer
  • Otherwise people use unapproved tools in secret ("shadow AI")
  • It removes the need for any rules
Answer

Otherwise people use unapproved tools in secret ("shadow AI") — Governance that is slow or unclear is bypassed, which creates the risks it was meant to prevent.