Claim a free live session
← The feed
The mandate

AI governance that doesn't kill adoption

Two failure modes: no policy at all, or a policy so broad that nothing gets approved. The fix is governing by risk tier rather than by tool.

Michael HalasCo-founder · A³7 min read
A governance discussion in a session room on the A³ campus

Both failure modes are common and they look nothing alike. In the first, there is no policy, so tools spread through expense claims and nobody can answer a regulator's question. In the second, a policy arrives written broadly enough to cover every conceivable risk, and the practical consequence is that no request ever clears review.

The second is more damaging, because it looks like control while producing shadow adoption at scale.

Govern by risk tier, not by tool

Tool-by-tool approval does not survive a market where a new capability appears monthly. Tiering does, because the tier is a property of the workflow rather than the software.

  • Tier 1 — no personal or confidential data, output reviewed by a human before it leaves. Self-serve within a published boundary.
  • Tier 2 — internal confidential data, or output that reaches a customer with review. Lightweight registration, standard controls, decided in days.
  • Tier 3 — personal data, regulated decisions, or output that reaches a customer unreviewed. Full review, and the only tier that should take weeks.

An approval path measured in days

Publish the tier definitions so a team can self-assess before asking. Give tier 2 a named owner with authority to decide alone, and a service-level commitment. Reserve the committee for tier 3. Most organisations run every request through the tier-3 path and then wonder why the business stopped asking.

A policy nobody can clear does not prevent risk. It relocates it somewhere you cannot see.

Where governance belongs in the sequence

After proof, before scale. Involving legal at the idea stage produces a review of a hypothesis and burns credibility. Involving them after rollout produces an emergency. The right moment is when a pilot has worked and you are deciding whether to widen it — at which point the questions are concrete and the review takes weeks rather than quarters.

Reading helps. Seeing the capability tested is better.

When you're ready to move from ideas to evidence, bring us the problem and we'll build the right session around it. The first one is free.