Milan Bogojevic Blog

What a governance policy for AI should not try to cover

1 min read

A board asks for an AI policy. Someone finds a template. The template has thirty clauses and covers model training, biometric data, and automated decision-making with legal effect.

Your organisation has eleven staff and uses a chatbot to draft newsletter copy.

The policy is now longer than the practice it governs, which means nobody reads it, which means it governs nothing.

Start from what people already do

Before writing anything, ask the team what they are already using. You will find tools nobody approved. That is not a failure of compliance, it is your actual starting point, and it is more accurate than anything you would have guessed.

A policy that describes reality and then draws two or three lines around it gets followed. A policy that describes a hypothetical organisation does not.

The lines worth drawing

What never goes into a tool you do not control. Usually beneficiary data, unpublished financials, and anything under a funder confidentiality clause.

What always gets a human read before it leaves the building.

Who decides when a new tool comes in. One name, not a committee.

That fits on a page, and a page gets read.

Revisit it on a date, not on an incident

Put a review date in the document itself. Policies written in a hurry after something went wrong are always too tight, and they stay too tight for years because nobody wants to be the person who loosened them.

Next in AI Transformation