• Services
  • Who We Help
  • Resources
  • AboutStart a Conversation

    Article

    AI Governance: The Decisions a Policy Cannot Make

    AI governance connects approved uses, decision-making authority, human review, and the commitments an organization has made to others.

    By Dan Liutikas · October 3, 2026 · 6 min read

    Updated October 3, 2026

    An AI policy can establish rules, but it cannot decide whether a particular use is worth the exposure, who has authority to approve it, or what should happen when the assumptions change. Those are organizational decisions. Effective AI governance connects the policy to the people who can make them and the information they need.

    This distinction matters because the same product can support very different activities. Permission to summarize public material does not necessarily answer whether the organization may use the tool with confidential client files, rely on it in a consequential decision, or allow it to communicate directly with customers.

    Approval of a tool is only part of the decision

    Consider a hypothetical service firm that approves an AI application for internal research. IT confirms that the application works with the firm’s systems. Security approves the selected account configuration. Procurement completes the purchase. The team understandably describes the product as approved.

    A month later, an employee proposes uploading a client’s project files to generate a recommendation. The client agreement restricts disclosure of those files, and the proposed workflow relies on the generated answer in a deliverable the firm will stand behind. The earlier approvals addressed different questions. They did not necessarily authorize this use.

    The governance issue is the gap between the approval people think they received and the decision that was actually made. That gap can emerge without anyone deliberately ignoring the rules. A general “approved tools” list can become a substitute for evaluating the purpose, information, audience, and consequences of the next use.

    A clearer connection between the tool and its permitted uses can make adoption easier. Teams can proceed within an understood scope and recognize when a new proposal changes the decision.

    The person who sees the benefit may not control the risk

    A business sponsor may have a strong case for adoption: shorter response times, more consistent work, or capacity that the organization cannot otherwise afford. That person may also be accountable for the project’s financial performance.

    Other consequences can sit elsewhere. A new data use may affect the organization’s customer promises. A public claim may affect marketing and legal exposure. A workflow that changes staffing needs may affect employment obligations. A product dependency may affect every service team.

    These are reasons to make the decision visible across the relevant functions. They are not reasons to require every department to approve every experiment. The important distinction is between a person’s authority to spend a budget and the organization’s authority to accept the associated commitments and exposure.

    Legal counsel’s role is to identify those obligations, explain the available choices, and make the remaining risk understandable. The business decision belongs with the people authorized to make it. A legal assessment and commercial approval perform different functions, and both should be clear.

    Human review needs a credible place in the operating model

    A policy may require employees to review AI output before using it. Whether that requirement does useful work depends on the setting. A reviewer needs enough knowledge to recognize a problem, enough information to investigate it, and enough time and authority to act.

    Suppose a hypothetical team is expected to process hundreds of AI-generated customer responses each day. If its targets assume almost immediate approval, a requirement for careful review may describe something the operating model does not support. Management has a choice about the service, the staffing, the degree of automation, and the exposure it is prepared to accept.

    The issue becomes sharper when a person is nominally responsible for review but cannot see the underlying record or override the result. Naming an employee as the reviewer does not resolve the organization’s dependence on the system.

    This is why governance belongs alongside the business case. The expected efficiency should be evaluated with the supervision, correction, and exception-handling work needed to make the proposed use credible.

    Exceptions can become a second, unwritten policy

    Organizations have legitimate reasons to make exceptions. A customer deadline, an unusual project, or an emerging opportunity may justify a use outside the normal rule. The consequence depends on who approves the exception, what that person understands, and whether the exception remains limited.

    An exception granted for one project can become a practice used by an entire team. The supplier’s terms may then change, a new category of information may be introduced, or the output may begin reaching customers directly. A decision that once made sense may no longer describe the activity.

    Leadership needs a way to distinguish a deliberate exception from an unexamined expansion. Otherwise, the written policy and actual operations can tell different stories about the organization’s commitments and controls.

    The ability to change direction also matters. If a tool becomes central to delivery before anyone addresses suspension or replacement, the practical authority to stop using it may be much weaker than the policy suggests.

    The board’s role depends on significance and authority

    Boards should receive information suited to the decisions and oversight for which they are responsible. That does not require a technology tutorial or a request to approve every software purchase. It requires an explanation of material opportunities, dependencies, obligations, and unresolved choices.

    An initiative may warrant board attention because it changes the organization’s service model, creates substantial exposure, affects a mission-critical function, or falls within matters reserved to the board. The governing documents, applicable duties, and facts determine the appropriate role.

    A report that the organization has adopted an AI policy says little about those issues. Directors may need to understand which uses have become important, where management is relying on uncertain assumptions, and whether the organization can respond if the expected benefits or safeguards fail to materialize.

    NIST’s voluntary AI Risk Management Framework offers a structure for considering AI risk across an organization.1 It can inform the conversation, but it does not determine the authority of a particular board, authorize a particular use, or substitute for legal analysis.

    A policy cannot expand the organization’s legal permissions

    Internal approval does not, by itself, change a client agreement, a vendor license, a confidentiality obligation, or an applicable legal restriction. A commercially sensible use can still require a different arrangement with another party.

    For example, a supplier may permit processing of information that the organization has promised a client not to disclose for that purpose. The supplier’s permission addresses its side of the relationship. The client commitment remains a separate issue.

    The FTC has emphasized that AI companies’ privacy and confidentiality commitments matter when they obtain and use customer information.2 The broader organizational lesson is to connect the proposed use with the representations and obligations surrounding the information, rather than treating an internal policy as the whole legal answer.

    Governance should help the organization make and revisit decisions

    The useful outcome is an organization that understands which AI uses it supports, why those uses make sense, who may approve changes, and what information would cause it to reconsider. That can support faster decisions because the unresolved questions have a place to go.

    Org Law’s AI Governance & Use Policies work connects rules with approvals, oversight, and escalation. A focused AI Contract & Use Review can examine a proposed use alongside provider terms, data flows, and customer commitments.

    For the broader relationship among rights, contracts, reliability, and organizational responsibility, read the Business Leader’s Guide to Technology, AI, and Data Risk.

    Sources

    1. NIST, AI Risk Management Framework. Voluntary guidance; the NIST page notes an ongoing revision of AI RMF 1.0. The organizational scenarios and allocation-of-authority discussion are editorial analysis, not a claim that NIST mandates a particular board process.
    2. FTC, AI Companies: Uphold Your Privacy and Confidentiality Commitments (January 2024). Agency discussion of data-use representations and existing legal obligations.

    ORG LAW

    Talk with an attorney.

    Tell us what you need help with. We will follow up within one business day.

    Start a conversation