AI Governance: Where Should Organisations Actually Begin?
Artificial intelligence is entering organisations faster than many governance programmes can keep up.
Employees use generative AI to draft documents, summarise information and analyse data.
Development teams integrate AI services into applications. HR, marketing, customer support and operations increasingly encounter AI-enabled tools.
In many organisations, AI is therefore already being used before anyone formally asks:
What AI systems are we actually using, what data are they processing, and who is responsible for them?
That is a good place for AI governance to begin.
Start by Discovering Where AI Is Already Being Used
An organisation cannot govern AI it does not know about.
The first step does not necessarily need to be a large AI governance framework or a lengthy policy.
Start with discovery.
Which teams are using AI? Which external AI services have been adopted? Which business applications now include AI features? Are employees uploading organisational information into public AI tools?
The result should be a practical inventory of AI use cases rather than merely a list of AI products.
For each use case, understand:
What is the AI being used for? What data goes into it? What does it produce? Who relies on the output? Who owns the business process?
That immediately makes governance more practical.
Not Every AI Use Case Carries the Same Risk
Using AI to improve the wording of an internal presentation is very different from using it to recommend candidates for employment.
Similarly, generating a marketing image does not carry the same implications as analysing customer behaviour or making recommendations that could affect individuals.
Governance should therefore be proportionate to the use case.
Consider the nature of the data, the purpose of the system, the consequences of an incorrect output and whether people could be materially affected by the result.
Higher-impact use cases deserve greater scrutiny.
Understand the Data Going Into AI
AI governance and data governance are closely connected.
Employees may unintentionally provide personal data, confidential information, customer records, intellectual property or internal documents to AI services without understanding what happens to that information afterwards.
Organisations should therefore ask practical questions.
What information may be entered into an AI system? Is personal or confidential information permitted? Is the information retained by the provider? Could it be used for model improvement? Where is it processed? Can it be deleted?
The answers may differ considerably between consumer AI tools, enterprise services and privately deployed AI systems.
Keep Humans Accountable for Outcomes
AI can support decisions without necessarily becoming the decision-maker.
This distinction becomes especially important where outputs affect employees, customers or other individuals.
An AI-generated recommendation should not automatically become a business decision simply because the technology produced it.
Organisations need to define when human review is required, who can override an AI output and who remains accountable for the eventual decision.
Human oversight should be a real operating control—not simply a sentence in an AI policy.
Create Guardrails People Can Actually Follow
A governance programme becomes ineffective if employees cannot understand what it expects from them.
Instead of beginning with dozens of pages of policy, organisations can establish some clear operating rules.
Which AI tools are approved? What information may or may not be uploaded? Which uses require additional review? When must AI-generated information be verified? How should incidents or unexpected behaviour be reported?
Different teams may then require more specific guidance.
A developer integrating an AI model, an HR professional using an AI-enabled recruitment system and an employee using generative AI for research do not necessarily need the same controls.
Governance Must Continue After Approval
AI systems change.
Models are updated. Providers introduce new functionality. Data sources change. Employees find new ways of using existing tools.
An AI system that was acceptable when first reviewed may therefore present different risks later.
Governance should include periodic review, monitoring of material changes, incident handling and a process for reassessing higher-risk use cases.
The objective is not simply to approve AI.
It is to govern AI throughout its operational lifecycle.
From the Consultant's Desk
The temptation with AI governance is to begin by writing an AI policy.
A policy may certainly be necessary.
But before writing it, ask a simpler question:
What AI is already being used inside the organisation today?
The answer is often more revealing than expected.
Once the organisation understands its actual AI use cases, data, risks and ownership, policies and controls can be designed around reality rather than assumptions.
Key Takeaways
Discover before you govern. Build visibility into actual AI use across the organisation.
Assess the use case, not simply the technology. Different applications of the same AI platform can create very different risks.
Understand the data. Know what information enters AI systems and how providers handle it.
Keep accountability with people. Human oversight must work operationally.
Make governance understandable. Employees need practical rules, not merely policy documents.
Keep reviewing. AI governance is a lifecycle, not a one-time approval.

