Governance That Busy Leaders Can Run
Policies, owners, and lightweight operating rhythm
Listen to executive summary
Audio length ~2 min
Full lesson about ~35 min
Executive summary
~8 min to read the written sections · ~2 min to listen to this summary
This week designs governance busy leaders will actually run: tiered review by stakes, response to shadow AI, and a one-page acceptable-use note staff can apply on a Tuesday afternoon.
You will name approved tools, never-do items, exception contacts, and pause authority for high-risk systems — without freezing useful productivity work.
Outcome: a lightweight operating system for AI that scales with the enterprise.
Core concepts
The terms and comparisons you need for this week’s decisions — with examples by function.
Tiered governance
Match review intensity to stakes: light rules for low-risk productivity assist; formal review, documentation, and monitoring for people, money, safety, and external claims.
Why this works: Freeze-everything fails adoption. Ignore-risk fails louder. Tiers keep useful work moving while concentrating control where harm is real.
Why it matters: Publish approved tools and data traffic lights on one page staff will actually use.
Example: Spellcheck-level help: light rules. Hiring or credit decisions: formal review and monitoring.
Policy design
Weak / before: One approval process for all AI.
Strong / after: Tier A: approved tools, no special approval. Tier B: register use + owner. Tier C: risk committee + eval pack.
By function
Legal
Tiered review: light for productivity assist; heavy for rights and external claims.
HR
Manager onboarding includes AI acceptable-use one-pager.
Purchasing
Shadow AI inventory informs approved vendor shortlist.
Marketing
One approved creative AI stack; kill orphan tools after exception window.
Finance
Amnesty inventory of shadow finance chatbots; migrate to approved tools.
Operations
Pause authority named for high-risk automation.
Sales
Approved tools list in enablement; no personal accounts for CRM data.
Risk
NIST RMF vocabulary shared across ELT — Map, Measure, Manage, Govern.
Shadow AI
Staff using unapproved tools because official options are slow, unclear, or missing. It is a friction signal as much as a compliance problem.
Why this works: Punishment without better tools drives secrecy. Inventory with psychological safety first, then migrate.
Why it matters: Publish approved tools and simple data rules; run a short amnesty inventory.
Example: Teams paste client data into free ChatGPT because the approved workspace is hard to get.
30-day response
Weak / before: Ban all AI immediately.
Strong / after: Amnesty inventory → designate 1–2 enterprise tools → migrate → cancel orphans after exception window.
Acceptable use (one-pager)
Clear dos and don’ts for AI tools, data classes, disclosure, and escalation — short enough to apply on a Tuesday afternoon.
Why this works: Forty-page policies do not change behavior under deadline pressure. One page does.
Why it matters: Include: approved tools, three never-do items, exception contact, incident path.
Example: Never paste Red data into consumer AI; always verify numbers; call Privacy for exceptions.
Team publish
Weak / before: Link to corporate AI policy PDF.
Strong / after: Pin one-pager in the team channel; review in staff meeting; update quarterly.
Deep dive lesson
~13 min readDeep dive: Governance that people will actually follow
Learning objective. Design tiered rules (light vs heavy review) and a one-page acceptable-use note your team will use under deadline pressure.
Context. Freeze-everything fails. Ignore-risk fails louder. This lesson is about rules people can follow on a Tuesday afternoon.
1. Tiered governance
Match review intensity to stakes. Low-risk productivity assist can use light rules and approved tools. People, money, safety, and external claims need formal review, documentation, and human oversight. Shadow AI appears when official tools are slow or unclear — treat it as feedback about friction, not only disobedience.
Publish approved tools, data traffic lights, and escalation contacts on one page. Name owners for inventory, exceptions, and incidents. Use frameworks (NIST AI RMF, EU AI Act categories where relevant) as shared vocabulary — not as wallpaper.
2. Inventory without blame theater
If every team bought a different chatbot, start with a short amnesty inventory. Designate 1–2 approved enterprise tools, migrate, then cancel orphans after an exception window. Psychological safety increases honesty; honesty is required for control.
Method: One-page acceptable use
Tools
Name approved tools for Green/Amber work.
Never
Three never-do items (Red data, unsupervised people decisions, inventing external claims).
Exception
Who to call and response time expectation.
Incident
What to do if the wrong data was pasted — no heroics, follow process.
Worked example: Every team bought a different chatbot
Situation
Finance, Sales, and Ops each have separate AI subscriptions. Nobody has an inventory.
How an executive thinks it through
- Shadow sprawl multiplies data risk and cost.
- Need inventory + approved shortlist + exception process.
- Do not punish discovery if you want honesty.
Decision / what to say
30-day amnesty inventory; designate 1–2 approved enterprise tools; migrate; cancel orphans after exception window.
Apply in your function
Risk / Legal
Define tiers and pause authority for high-risk systems.
HR
Include AI tool norms in onboarding for managers.
Ops
Run the amnesty inventory for shadow tools in your area.
All
Post the one-pager where work happens; review quarterly.
Common mistakes
- 40-page policies with no one-pager.
- Same process for spellcheck and hiring tools.
- No pause authority for high-risk systems.
Practice (15 minutes)
- Draft a one-page note: approved tools for Green data; three never-do items; exception contact.
- Walk it with one skeptical teammate; fix unclear lines.
- Post it where work happens (team channel / wiki).
Check your understanding
Key takeaways
- Tiered governance matches control to risk.
- Named owners beat abstract 'the committee.'
- Shadow AI is a signal — channel it, don’t only punish it.
- Incident drills for AI errors are underrated.
Practical applications
Codify prohibited uses (e.g., unsupervised legal advice to clients).
Require disclosure when AI assists hiring decisions.
Include AI in existing control testing cycles.
Publish an approved-tools list that is easy to find.
One approved creative AI stack; kill orphan tools after an exception window.
Library materials for this week
Extend this week’s decisions with briefs, cases, and primary sources that matter for your next meeting.
Tiered AI Governance
A proportional governance model (Tier 0–3) matching review intensity to impact — designed for organizations that need speed and safety.
Acceptable Use Starter Policy
A starter acceptable-use outline covering approved tools, data rules, disclosure expectations, prohibited uses, and escalation — ready to customize.
Optional focus hour
After the core lesson (~35 min), spend about 55 minutes on one long-form source matched to this week’s level.
EU AI Act — Regulation (EU) 2024/1689 (EUR-Lex official text)
European Union — Official Journal
Published 13 June 2024
Why this week
Governance week needs the binding text structure, not only secondary explainers.
What to take away
Risk tiers ; which of your uses may be higher-risk; who owns the gap analysis.
Check your understanding
Week 8 · 3 short questions · no grades shared outside this device
Select an answer for each question.
Hands-on
~15 minYour function’s tier table
Makes abstract policy concrete for your team.
- List five AI uses in your world.
- Assign each Tier 0–3 with a one-line rationale.
- Identify the approver for Tier 2+.
- Note one use currently operating above its approved tier.
Reflection
- If a journalist asked who owns AI decisions in your function, could you answer in one sentence?
- Where is shadow AI already happening on your team?