AI Governance

The default answer to AI does not need to be no.

Organisations need a consistent way to experiment with and adopt AI without allowing it to become unmanaged Shadow IT.

A simple starting point.

Use Case + Data + Risk + Platform

Rather than creating governance around individual product names, I prefer an approach that can be applied consistently as new AI capabilities appear.

Use Case

What is the employee or business function actually trying to achieve?

Data

What information will the AI service receive, process or potentially expose?

Risk

What could happen if the information, model or output is incorrect, exposed or misused?

Platform

What security, privacy, access, enterprise and monitoring controls are available?

Enable informed decisions.

The objective of governance should not be to become the department that says no to AI.

It should provide enough structure that the organisation can reach a consistent and informed yes, no or yes-with-controls decision.