Artificial Inteligence
Use AI deliberately, not indiscriminately.
AI is already part of how many organisations work. Good governance shouldn't prevent people from using it; it should make sure they can use it safely, responsibly and with a clear understanding of the risks.
AI governance isn't only about what goes into a model and what comes out. It's also about the dependencies, costs and capabilities we create around it.
Start with people, not tools
AI governance is ultimately about people making decisions. Tools, models and suppliers will change quickly, so policies built around a particular product are unlikely to age well.
I prefer to establish principles first: what information can be shared, where human judgement is required, who is accountable for an outcome, and what level of risk is acceptable.
The more consequential the decision, the greater the need for human oversight.
Make AI use visible
You can't govern AI use you don't know about.
Organisations should understand where AI is being used, which tools and models are involved, what information is being shared with them, and whether AI has become part of a critical business or development process.
This doesn't require monitoring every prompt. It means having enough visibility to understand where meaningful dependencies and risks exist.
Don't drive AI underground
Blanket bans can create shadow AI: people continuing to use useful tools through personal accounts, unsanctioned services or processes the organisation can't see.
A better approach is to provide approved routes for experimentation, clear boundaries for sensitive information and a straightforward process for evaluating new tools.
Governance should make the safe thing easy to do.
Shadow AI can become shadow infrastructure
Unsanctioned AI isn't only a privacy or security problem.
If employees use personal subscriptions, credits, models or third-party services to deliver production work, those tools can quietly become part of the organisation's infrastructure.
The organisation should know which AI services materially contribute to delivery, who owns the accounts, how they're paid for, what happens if access disappears, and whether the work remains maintainable without them.
Protect sensitive information
Staff need clear guidance about what can and can't be shared with AI systems.
Client information, personal data, commercially sensitive material, credentials, intellectual property and confidential documents shouldn't be entered into services unless their use has been explicitly assessed and approved.
Different tools have different terms, retention policies and data controls. Approval should be based on those realities rather than treating all AI as the same thing.
Keep humans accountable
AI can help research, analyse, write, design, code and make recommendations. Responsibility for the result still belongs to a person.
AI-generated output should be reviewed in proportion to its potential impact. A rough internal summary doesn't require the same scrutiny as production code, financial advice, public communications or a decision affecting another person.
AI can assist judgement. It shouldn't become a convenient way of avoiding responsibility for it.
Verify what AI produces
AI can be convincing and wrong at the same time.
Factual claims should be checked where accuracy matters. Code should be reviewed and tested. Important recommendations should be challenged. Sources should be inspected rather than assumed to support an answer.
The appropriate level of verification should reflect the consequences of getting something wrong.
AI-generated systems still need human owners
Productivity isn't a substitute for understanding.
If AI materially contributes to a codebase, workflow or operational system, the organisation still needs people capable of understanding, reviewing, operating and maintaining what has been produced.
A system shouldn't become dependent on a particular employee's personal AI workflow, model subscription or undocumented relationship with an agent.
Give autonomous systems boundaries
As AI moves from answering questions to taking actions, governance needs to consider what an agent is actually allowed to do.
Agents may be able to modify code, access systems, call external services, consume paid inference, retry operations or introduce new dependencies. Technical permission doesn't necessarily mean organisational permission.
The greater the autonomy, the clearer the boundaries need to be.
Cost is a governance issue
Agentic systems can make technical decisions with financial consequences.
Metered services should be identified, usage should be observable and meaningful spending limits should be understood. Agents shouldn't be able to introduce significant new costs or paid dependencies without deliberate approval.
The budget is part of the technical constraint, not something to consider after the system has been built.
Understand your dependencies
AI services are external dependencies like any other, but they can change unusually quickly.
Models are updated, deprecated and replaced. Pricing changes. Usage limits change. Suppliers change their terms. Capabilities that a workflow depends on may not remain available indefinitely.
Where AI becomes operationally important, organisations should understand what happens if the model, provider or commercial arrangement changes.
Be proportionate
Not every use of AI needs a committee.
Asking AI to rewrite an internal paragraph isn't equivalent to allowing an autonomous agent to modify production systems or make decisions about customers.
Governance should reflect risk. Low-risk uses should remain easy. Higher-risk uses should introduce stronger controls, review and accountability.
Over-governance creates bureaucracy and encourages people to work around it. Under-governance creates risks the organisation may not even know it has.
Keep governance alive
An AI policy written once and forgotten will become obsolete very quickly.
Governance should be reviewed as the organisation learns, new capabilities appear and AI becomes more deeply embedded in everyday work.
The goal isn't to predict every possible use of AI. It's to establish principles strong enough to make sensible decisions when something new appears.
Responsible doesn't have to mean restrictive
I'm broadly optimistic about AI. I use it, encourage experimentation with it and think organisations that learn how to use it well will have a significant advantage.
But adoption without governance can create hidden dependencies, unexpected costs, security problems and systems nobody fully understands.
Good governance should enable experimentation while keeping humans accountable, important decisions visible and the organisation in control of the technology it depends on.