Skip to content

Briefing 4 of 8

AI Governance

If your AI policy is a document nobody reads, is it protecting your business, or just decorating a shared drive?

A 15-Minute Executive Read

Prepared by 3rd Element Consulting, Mechanicsburg, Pennsylvania

Executive summary

Most businesses land in one of two places on AI governance: no policy at all, or a policy document somebody wrote once, nobody reads, and nothing actually enforces. Neither one protects the business. The first leaves every decision to whoever tries a new tool first. The second creates the appearance of control without the substance of it, which can be worse, because it feels like the problem is handled.

This briefing lays out what real AI governance looks like for a business your size: a short, specific policy that says what's actually allowed, software that enforces it instead of just stating it, real consequences for not following it, and one person whose job it is to keep both current. None of it requires a governance committee or a hundred-page manual. It requires making a small number of decisions on purpose and writing them down where they'll actually get used.

It also has to apply to everyone who touches company systems, ownership and leadership included. A policy that only governs employees while leaving whoever wrote it exempt isn't governance. It's a rule for other people, and it tends to fall apart the first time anyone notices.

Every risk raised in Briefing 3 gets addressed here, not in the abstract, but as a specific control someone owns.

Get this series delivered weekly instead.

Sign up for the Executive AI Briefing Series

What every executive should know

  1. 1. Governance is a short list of owned decisions, not a document

    The instinct when a topic feels serious is to write a policy about it. A policy is necessary, but it isn't governance by itself. Governance is what happens when someone specific is responsible for a decision, that decision is written down, and something checks that it's actually being followed. A policy with no owner and no enforcement is a paragraph, not a program.

    The fastest way to tell which one you have: ask who is responsible for AI decisions at your company right now, by name. If the honest answer is "nobody, really," you have a document at best, not governance.

  2. 2. What a usable AI policy actually says

    A policy that works fits on a couple of pages and answers the questions employees actually run into, not the questions a lawyer finds interesting:

    • Which AI tools are approved for use, and which account type, personal or business-tier, is required.
    • What information may never be entered into an AI tool, the data types from Briefing 3.
    • Which uses require a human review step before the output reaches a client, a contract, a financial figure, or a public statement.
    • When AI use must be disclosed, particularly for client deliverables.
    • Which decisions can never be handed to AI at all: hiring, discipline, compensation, termination, financial sign-off, legal judgment, and safety-critical calls.
    • Who the policy applies to, which should be everyone with access to company systems and data, not just staff, and what happens when it isn't followed.
  3. 3. Disclosure, consequences, and who the policy covers

    That disclosure requirement is worth pausing on. A policy that requires disclosing significant AI involvement in a deliverable doesn't just set an expectation. It gives you a defensible answer when a client or a regulator asks how something was produced, and it removes the ambiguity that let the behavior happen quietly in the first place.

    The last bullet is worth pausing on too, in both directions. First, consequences: a policy that says what's prohibited without saying what happens if someone does it anyway isn't really a policy, it's a suggestion. The consequence doesn't need to be severe by default. It needs to be defined in advance and scaled to what happened.

    Second, scope: it has to apply to ownership and leadership too, by name, not just to employees. This is easy to get backward. The instinct is to write the policy for the people leadership is worried about, which usually means staff, and leave an unstated assumption that the owner or the executive team is trusted enough not to need it. In practice, ownership and leadership often have the broadest access to the most sensitive information in the business, financials, strategic plans, acquisition talks, so exempting them isn't the low-risk choice. It's frequently the highest-risk one.

  4. 4. What actually enforces the policy

    Here is what a reasonable starting set of software controls looks like in practice:

    • Business-tier or enterprise AI accounts issued to employees, instead of relying on personal accounts nobody tracks.
    • Multifactor authentication on every AI account.
    • Role-based access, so the accounting team's AI tool access looks different from the marketing team's.
    • Network-level controls that restrict which AI tools and websites are reachable from company devices.
    • Logging on approved tools, so there's a record of what was used and when.
    • None of this requires exotic technology. Most of it is a configuration decision inside tools your business likely already has, made deliberately instead of left on the default setting.
  5. 5. Someone has to own it, specifically

    Every one of the following needs a name next to it, not a department: who approves a new AI tool before anyone uses it, who reviews a vendor's terms of service before that tool touches company data, who is told when something goes wrong, and who keeps track of which AI tools are actually in use across the business.

    This does not need to be a full-time role or a committee. In most businesses this size, it's a meaningful slice of one person's existing job, with clear authority to say yes or no, including the authority to hold ownership accountable to the same policy everyone else follows.

  6. 6. Keep a running inventory, not a one-time list

    The fix for shadow AI isn't a one-time audit. It's a living list: which AI tools are in use, which department uses them, what data they touch, what account type they run on, and when their vendor terms were last reviewed. A list you build once and never update is already out of date by the time you need it.

  7. 7. Train people on the specific failure modes, not AI in general

    Governance-relevant training is narrower and more useful than generic AI training: which accounts to use, what data never goes into a prompt, when a human review step is required, and what needs to be disclosed. Fifteen focused minutes on your actual policy beats an hour on AI in general.

  8. 8. Review it on a schedule, not when something breaks

    A policy and a set of controls are a starting point, not a finished project. A short, recurring leadership review, quarterly is enough for most businesses this size, is what keeps governance from quietly going stale six months after it was written.

Real business examples

Composite scenarios, illustrative, not specific to any one company.

The rule that only applied to everyone else

At a family-owned distribution company, staff were required to use an approved, logged, business-tier AI account for anything involving company data. The owner, who had set that policy himself, kept using his personal account for financial modeling and early conversations about a possible sale of the business, reasoning that the rule was really there for employees, not for him. When a buyer's due diligence team later asked how a specific valuation figure had been produced, no one, including the owner, could give a confident answer, because that work had never gone through any documented process at all. The policy already covered exactly this. It just hadn't been written to include the person who wrote it.

The policy nobody enforced

A 50-person firm wrote a thorough AI acceptable-use policy after a scare involving a competitor. It named approved tools and prohibited data types clearly. Eight months later, an internal review found most employees had never read it, personal AI accounts were still in daily use, and nothing on the network would have stopped either. The policy was accurate. It just wasn't governance, because nothing enforced it and no one was checking.

The disclosure that should have been required

A marketing agency delivered a client strategy document that turned out to be almost entirely AI-generated, with the account manager presenting it as original analysis. The client noticed inconsistencies and asked directly how it was produced. The agency had no policy requiring AI-use disclosure on deliverables, so there was no standard answer, and no way to say confidently that this hadn't happened before on other accounts.

The simple version that actually worked

A 35-person firm skipped the big policy project entirely. Leadership picked one business-tier AI tool, wrote a page and a half covering what could and couldn't be entered into it, turned on the admin controls that came with the subscription, and named one partner to approve any new tool request, themselves included. No incidents in the first year, and new tool requests started coming through the front door instead of showing up unannounced in someone's workflow.

Decision framework

Eight questions that reveal whether you have governance or just a document

  • If we have an AI policy, could you name the specific person responsible for enforcing it, by name, right now?
  • Does anything technical actually stop an employee from using an unapproved AI tool or account, or does it rely entirely on them remembering the policy?
  • Does our policy say when AI involvement in a client deliverable must be disclosed, and to whom?
  • Is there a current, accurate list of which AI tools are in use across our business, updated in the last quarter?
  • Has anyone been trained on our specific policy, versus AI in general, in the last six months?
  • Is there a standing date on the calendar for leadership to review AI tools, policy, and incidents, or does review only happen after something goes wrong?
  • Does our policy say what actually happens when someone doesn't follow it, or would we be deciding that for the first time in the middle of an incident?
  • Does the policy apply to ownership and leadership by name, or does it functionally only govern employees?

If you answered "no" or "not sure" to two or more of these questions, you likely have a document, not governance.

Leadership discussion questions

  • If we already have an AI policy, when did anyone last actually read it, and would we know if it were being followed?
  • Whose job is it, specifically, to approve a new AI tool before someone on our team starts using it?
  • Where in our client or vendor relationships would it matter most if AI involvement went undisclosed?
  • Are we relying on employees remembering our rules, or is there something in place that makes the safe choice the default?
  • How would we find out today if a new, unapproved AI tool started being used somewhere in our business?
  • What would it take to put one name and one recurring date on our calendar for AI governance, starting this quarter?
  • If we found out an owner or a senior leader had broken our own AI policy, would we handle it the same way we'd handle it for anyone else?
  • Is there anywhere in our own use, ownership or leadership, where we've quietly assumed the rules don't apply to us?

Action plan

This Week

  • Name one person to own AI governance decisions, even if it's a slice of an existing role rather than a new one. Governance without an owner doesn't happen.
  • Have an honest conversation, just among leadership, about whether ownership has quietly been holding itself to a different standard than everyone else.

This Month

  • Draft or revise your AI policy to fit on two pages and answer the questions in this briefing: approved tools and accounts, prohibited data, required review, disclosure requirements, decisions AI can never make, who it applies to, and what happens if it isn't followed.
  • Turn on the admin controls that already exist in whatever business-tier AI tool you use, or evaluate one if you haven't yet.

Next 90 Days

  • Continue with Briefing 6, Selecting AI Tools, to formalize how new tools get evaluated and approved, and Briefing 8, Your 90-Day AI Plan, to put a date on the calendar for the first leadership review.

This is the fourth in an eight-part series designed to give your leadership team a shared, working understanding of AI, without turning your business into a training exercise.

Get this series delivered weekly instead.

Sign up for the Executive AI Briefing Series

Continue the series

Ready to talk through where your business stands? Schedule an IT Environment Review with 3rd Element Consulting.

Schedule an IT Environment Review

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.