AI Governance Workshop

1 h 50 min
09:00
Min.

Make clear from the start: this is about practical team rules, not a blanket ban on AI use. That lowers the barrier to honest contributions during the stocktake.

09:05
Min.

Collect openly and without judgment which AI tools are already in use across the team – including informal or unapproved ones. Honest answers only happen without the threat of sanctions.

Consider an anonymous collection method (see our post on decoupled brainstorming)

09:20
Min.

Build an approved list instead of a ban list: which tools are cleared for which purposes, and how does a new tool get added? A pure ban list, in practice, mostly just drives more shadow usage.

09:40
Min.

Define which data – customer data, source code, trade secrets – may go into which kind of tool at all. This often reveals that the real question is an unresolved cloud and data-protection issue that predates AI tools entirely.

10:00
Min.

Clarify when AI-generated content needs to be disclosed and who is responsible for reviewing its quality.

10:15
Min.

Define who stays substantively responsible for AI-assisted outputs. Responsibility never shifts onto the tool itself.

10:30
Min.

Treat the rules you've drafted as a concrete proposal and adopt them via an objection round, instead of waiting for full consensus across the whole organization (see our post on facilitating consent decisions).

10:45
Min.

The rules are explicitly provisional. Fix a date roughly three months out to adjust them based on actual usage and new tools.

10:50