Week 8Month 2~35 min lesson~2 min listen~8 min read

Governance That Busy Leaders Can Run

Policies, owners, and lightweight operating rhythm

Listen to executive summary

Audio length ~2 min

Full lesson about ~35 min

Executive summary

~8 min to read the written sections · ~2 min to listen to this summary

This week designs governance busy leaders will actually run: tiered review by stakes, response to shadow AI, and a one-page acceptable-use note staff can apply on a Tuesday afternoon.

You will name approved tools, never-do items, exception contacts, and pause authority for high-risk systems — without freezing useful productivity work.

Outcome: a lightweight operating system for AI that scales with the enterprise.

Core concepts

The terms and comparisons you need for this week’s decisions — with examples by function.

Tiered governance

Match review intensity to stakes: light rules for low-risk productivity assist; formal review, documentation, and monitoring for people, money, safety, and external claims.

Why this works: Freeze-everything fails adoption. Ignore-risk fails louder. Tiers keep useful work moving while concentrating control where harm is real.

Why it matters: Publish approved tools and data traffic lights on one page staff will actually use.

Example: Spellcheck-level help: light rules. Hiring or credit decisions: formal review and monitoring.

Policy design

Weak / before: One approval process for all AI.

Strong / after: Tier A: approved tools, no special approval. Tier B: register use + owner. Tier C: risk committee + eval pack.

By function

Legal

Tiered review: light for productivity assist; heavy for rights and external claims.

HR

Manager onboarding includes AI acceptable-use one-pager.

Purchasing

Shadow AI inventory informs approved vendor shortlist.

Marketing

One approved creative AI stack; kill orphan tools after exception window.

Finance

Amnesty inventory of shadow finance chatbots; migrate to approved tools.

Operations

Pause authority named for high-risk automation.

Sales

Approved tools list in enablement; no personal accounts for CRM data.

Risk

NIST RMF vocabulary shared across ELT — Map, Measure, Manage, Govern.

Shadow AI

Staff using unapproved tools because official options are slow, unclear, or missing. It is a friction signal as much as a compliance problem.

Why this works: Punishment without better tools drives secrecy. Inventory with psychological safety first, then migrate.

Why it matters: Publish approved tools and simple data rules; run a short amnesty inventory.

Example: Teams paste client data into free ChatGPT because the approved workspace is hard to get.

30-day response

Weak / before: Ban all AI immediately.

Strong / after: Amnesty inventory → designate 1–2 enterprise tools → migrate → cancel orphans after exception window.

Acceptable use (one-pager)

Clear dos and don’ts for AI tools, data classes, disclosure, and escalation — short enough to apply on a Tuesday afternoon.

Why this works: Forty-page policies do not change behavior under deadline pressure. One page does.

Why it matters: Include: approved tools, three never-do items, exception contact, incident path.

Example: Never paste Red data into consumer AI; always verify numbers; call Privacy for exceptions.

Team publish

Weak / before: Link to corporate AI policy PDF.

Strong / after: Pin one-pager in the team channel; review in staff meeting; update quarterly.

Deep dive lesson

~13 min read

Deep dive: Governance that people will actually follow

Learning objective. Design tiered rules (light vs heavy review) and a one-page acceptable-use note your team will use under deadline pressure.

Context. Freeze-everything fails. Ignore-risk fails louder. This lesson is about rules people can follow on a Tuesday afternoon.

1. Tiered governance

Match review intensity to stakes. Low-risk productivity assist can use light rules and approved tools. People, money, safety, and external claims need formal review, documentation, and human oversight. Shadow AI appears when official tools are slow or unclear — treat it as feedback about friction, not only disobedience.

Publish approved tools, data traffic lights, and escalation contacts on one page. Name owners for inventory, exceptions, and incidents. Use frameworks (NIST AI RMF, EU AI Act categories where relevant) as shared vocabulary — not as wallpaper.

2. Inventory without blame theater

If every team bought a different chatbot, start with a short amnesty inventory. Designate 1–2 approved enterprise tools, migrate, then cancel orphans after an exception window. Psychological safety increases honesty; honesty is required for control.

Method: One-page acceptable use

1

Tools

Name approved tools for Green/Amber work.

2

Never

Three never-do items (Red data, unsupervised people decisions, inventing external claims).

3

Exception

Who to call and response time expectation.

4

Incident

What to do if the wrong data was pasted — no heroics, follow process.

Worked example: Every team bought a different chatbot

Situation

Finance, Sales, and Ops each have separate AI subscriptions. Nobody has an inventory.

How an executive thinks it through

  1. Shadow sprawl multiplies data risk and cost.
  2. Need inventory + approved shortlist + exception process.
  3. Do not punish discovery if you want honesty.

Decision / what to say

30-day amnesty inventory; designate 1–2 approved enterprise tools; migrate; cancel orphans after exception window.

Apply in your function

Risk / Legal

Define tiers and pause authority for high-risk systems.

HR

Include AI tool norms in onboarding for managers.

Ops

Run the amnesty inventory for shadow tools in your area.

All

Post the one-pager where work happens; review quarterly.

Common mistakes

  • 40-page policies with no one-pager.
  • Same process for spellcheck and hiring tools.
  • No pause authority for high-risk systems.

Practice (15 minutes)

  1. Draft a one-page note: approved tools for Green data; three never-do items; exception contact.
  2. Walk it with one skeptical teammate; fix unclear lines.
  3. Post it where work happens (team channel / wiki).

Check your understanding

Key takeaways

  • Tiered governance matches control to risk.
  • Named owners beat abstract 'the committee.'
  • Shadow AI is a signal — channel it, don’t only punish it.
  • Incident drills for AI errors are underrated.

Practical applications

Legal

Codify prohibited uses (e.g., unsupervised legal advice to clients).

HR

Require disclosure when AI assists hiring decisions.

Risk

Include AI in existing control testing cycles.

All

Publish an approved-tools list that is easy to find.

Marketing

One approved creative AI stack; kill orphan tools after an exception window.

Library materials for this week

Extend this week’s decisions with briefs, cases, and primary sources that matter for your next meeting.

1~11 min read

Tiered AI Governance

A proportional governance model (Tier 0–3) matching review intensity to impact — designed for organizations that need speed and safety.

2~10 min read

Acceptable Use Starter Policy

A starter acceptable-use outline covering approved tools, data rules, disclosure expectations, prohibited uses, and escalation — ready to customize.

Optional focus hour

After the core lesson (~35 min), spend about 55 minutes on one long-form source matched to this week’s level.

Optional focus hourReport~55 min readFoundational (2–3 yrs)

EU AI Act — Regulation (EU) 2024/1689 (EUR-Lex official text)

European Union — Official Journal

Published 13 June 2024

Why this week

Governance week needs the binding text structure, not only secondary explainers.

What to take away

Risk tiers ; which of your uses may be higher-risk; who owns the gap analysis.

Check your understanding

Week 8 · 3 short questions · no grades shared outside this device

1.Tiered governance done well means:
2.Widespread shadow AI (unapproved tools) is best interpreted as:
3.An acceptable-use one-pager for staff should emphasize:

Select an answer for each question.

Hands-on

~15 min

Your function’s tier table

Makes abstract policy concrete for your team.

  1. List five AI uses in your world.
  2. Assign each Tier 0–3 with a one-line rationale.
  3. Identify the approver for Tier 2+.
  4. Note one use currently operating above its approved tier.

Reflection

  • If a journalist asked who owns AI decisions in your function, could you answer in one sentence?
  • Where is shadow AI already happening on your team?