Guide · AI governance

AI governance without the framework theatre

Most AI governance material is written for organisations with a compliance department. This is written for a business with AI already in production and nobody watching it.

The three questions you should be able to answer

Before any framework, a business with AI in production should be able to answer these. Most cannot, and the inability is the actual risk:

  1. What AI is in use here? Including the tools bought on someone's card, the browser extensions, and the staff pasting work into free consumer tools.
  2. What data has left the business? To whom, under what terms, and whether anyone read them.
  3. What happens when it is wrong, and who would notice? If the answer is "nobody", there is no control, whatever the policy document says.

An AI audit exists to answer these, and the shadow-AI inventory is reliably the first surprise.

Build the inventory first

Everything else depends on this and it is usually skipped because the answer is uncomfortable. For each tool, record: what it is, who uses it, what data it touches, whether the vendor trains on that data, what it costs, and who owns it internally.

Two things fall out immediately. First, the unused-licence count, which is always higher than anyone expects and pays for the whole exercise. Second, the shadow usage — which is not a discipline problem but a signal that staff had a need the sanctioned tools did not meet.

Classify your data before you write policy

A policy that says "do not put confidential information into AI tools" fails because nobody agrees what that covers. Classify first, in terms specific to your business:

  • Public. Anything already published. No restriction.
  • Internal. Ordinary business information. Commercial AI under an enterprise agreement is usually fine.
  • Confidential. Client information, contracts, employee records, proprietary specifications. Enterprise agreement at minimum, and often self-hosted.
  • Restricted. Privileged, regulated, or contractually barred from third-party disclosure. Self-hosted only, or not at all.

Then the policy becomes a short routing table instead of a paragraph of judgement. "Use your discretion" is not a control and will not survive a review.

Verification is the control almost nobody implements

Every framework asks how you know the output was right. The usual answer is a human in the loop reviewing a sample, which is honest but weak — the reviewer is reading output that looks plausible, which is exactly what a language model is good at producing.

A stronger answer is an independent model checking the first. Ask a model to check its own work and it will generally agree with itself; that is a property of asking the same system twice, not a prompting failure. A different model from a different family is an actual check.

That is what CrossCheck AI does, and it is one of the few parts of AI assurance that can genuinely be automated. Apply it per workflow — in front of the work where being wrong is expensive, not everywhere.

The control set that actually matters

Six controls. Everything else is elaboration:

  1. Inventory, kept current. A stale inventory is worse than none because it creates false confidence.
  2. Data classification and a routing rule mapping each class to permitted tools.
  3. Access control. Retrieval scoped so people reach only what they should.
  4. Audit logging. Who asked what, which documents were retrieved, retained per your policy.
  5. Output verification on anything with financial, legal or clinical consequence.
  6. A documented decision record per use case — what it does, what it touches, what controls apply, what you decided against and why.

Disclosure — your own AI use, and your content

Two separate obligations that get confused. An AI answering your phone or chat must identify itself as an AI; that is a trust requirement and increasingly a legal one.

Separately, where AI materially produced content or a decision affecting someone, say so. Google's own guidance on content quality asks publishers to explain how content was created where a reader would reasonably wonder — and the same instinct is the right one for customer-facing decisions.

Neither obligation is satisfied by a line in your terms of service that nobody reads.

What we publish, and what we are building

Most AI governance writing is assertion. We would rather contribute measurements, and we are positioned to produce two that almost nobody else can:

  • Engine cost economics. We already publish what we actually pay per AI engine and pass it through at cost, at AI engine pricing. Maintained rather than a snapshot.
  • Model disagreement rates on real business documents. Because CrossCheck AI runs two independent models over the same real invoices, contracts and extractions, we can measure how often a second model contradicts the first on actual business paperwork. That is a number the industry talks about constantly and almost never measures.

Worth saying: The disagreement-rate study is in progress and not yet published. When it is, it will carry its method and sample size so you can judge it, and it will be dated. We would rather publish nothing than publish a figure you cannot check.

Questions people actually ask

Before you call

Do we need an AI policy if we only use ChatGPT?

Yes, and it can be one page. The question is not how many tools you have but whether anyone has decided what may go into them. Without that decision, staff are each making it individually.

Who should own AI governance?

Someone with authority to say no, and close enough to the work to know what staff actually need. In a smaller business that is usually an owner or operations lead, not IT.

Is a human in the loop enough?

It is better than nothing and weaker than people assume, because plausible wrong output is exactly what a reviewer is least likely to catch. Pair it with independent verification on consequential work.

How often should the inventory be reviewed?

Quarterly is realistic. Tools appear faster than that, so make adding to the inventory part of buying, not a separate exercise.

Does AI governance slow everything down?

Done badly, yes. Done well it speeds things up, because a clear routing table means staff stop asking permission case by case and stop pasting confidential material into free tools while they wait for an answer.

Want this applied to your business?

A short call, and an honest read on whether it is worth doing.

Certified across the platforms we build on

AWSGoogle CloudMicrosoft AzureAnthropicOpenAI