Use Case
What is the employee or business function actually trying to achieve?
AI Governance
Organisations need a consistent way to experiment with and adopt AI without allowing it to become unmanaged Shadow IT.
Assessment
Use Case + Data + Risk + Platform
Rather than creating governance around individual product names, I prefer an approach that can be applied consistently as new AI capabilities appear.
What is the employee or business function actually trying to achieve?
What information will the AI service receive, process or potentially expose?
What could happen if the information, model or output is incorrect, exposed or misused?
What security, privacy, access, enterprise and monitoring controls are available?
Governance Philosophy
The objective of governance should not be to become the department that says no to AI.
It should provide enough structure that the organisation can reach a consistent and informed yes, no or yes-with-controls decision.