← All posts

AI Governance

The policy written to be read once

It was approved, circulated and filed. Nobody has opened it since, and the decisions it covers are still being made.

FOR APPROVAL NOT CONSULTED FOR USE ANSWERS THE QUESTION Both were approved. One is a control.

Approved in March. Opened twice since.

A policy nobody consults is not a control. It is a record that somebody once considered the question.

In short

A policy written for approval and a policy written for use are different documents. The first is comprehensive, hedged and organised by risk category. The second is short, specific and organised by the decision somebody is about to make. Most organisations write the first and are surprised that the second never emerged from it.

The policy exists. It went through legal, it was approved at the right level, and it is on the intranet. It covers acceptable use, data handling, human oversight, vendor assessment and model selection.

Somebody is about to decide whether a particular use of a particular tool is allowed. They will not open it.

Not because they are careless. Because the document is organised by risk category and their question is not a risk category — it is “can I use this for that”, and answering it from the policy means reading four sections and forming a judgement about which applies.

A policy written for approval is comprehensive. It has to be, because the people approving it are checking that nothing was omitted. It is hedged, because unhedged statements attract challenge in review. And it is organised the way risk is organised, because that is who reviewed it.

Every one of those properties makes it harder to use.

The document that gets approved and the document that gets used are not the same document, and most organisations only write the first.

FOR APPROVAL NOT CONSULTED FOR USE ANSWERS THE QUESTION Both were approved. One is a control.
The question somebody actually has is never a risk category.

A policy written for use looks different in three ways.

It is organised by decision rather than by category. Not “data handling” but “you are about to put customer data into a tool” — the situation somebody is actually in when they need it.

It answers rather than describes. “Permitted for internal drafts, not for anything that leaves the firm” is usable. “Should be assessed against the principles set out in section 4” is not, and it is the more common formulation.

It states who decides the edge cases, by name. Every policy has cases it does not cover. The difference between a usable and an unusable one is whether the person facing an uncovered case knows who to ask, or has to work it out.

The test is simple and most policies fail it. Give the document to somebody who was not involved in writing it, describe a real situation, and ask them what the policy says they should do. If they cannot answer in two minutes, the policy is a record that somebody once considered the question rather than a control on what happens next.

  • Comprehensive, hedged and category-organised are properties of approval, not of use
  • Organise by the decision somebody is making, not by the risk it belongs to
  • Answer the question rather than describing how to think about it
  • Name who decides what the policy does not cover

This describes policies we have been asked to review, usually because somebody noticed they were not being followed. Policies that are working are not brought to us, so this says nothing about how common the problem is.

Run the governance assessment

Limits

Engagement observation, not a study

Drawn from policies we were asked to review, usually because somebody had already noticed they were not being followed. Policies that are working are not brought to us.

It says nothing about how common this is

Because of that selection, we cannot say what proportion of AI policies have this shape. We can say it is the most frequent reason we are asked to look.

Approval documents are not the problem

A comprehensive, hedged, category-organised policy is the right document for the people approving it. The failure is having only that one, not having written it.

Questions

Does a usable policy not need to be comprehensive too?

You can have both, in two documents. One for the approvers, one for the people making decisions, with the second derived from the first and considerably shorter.

Who should write the usable version?

Somebody who has made the decisions it covers. A policy written entirely by people who will never apply it reads exactly like that.

How long should it be?

Short enough that somebody scans it while deciding. If it needs a contents page, it is the approval document.

What about the cases it does not cover?

Name who decides them. That single line does more work than any amount of additional coverage, because it converts an uncovered case from a judgement into a question.

How often should it be revisited?

When the tools change, which in this area is more often than an annual review cycle assumes. A date in the document saying when it was last checked is worth more than a schedule nobody follows.

Is this specific to AI policies?

No, and it is sharper here, because the tools change faster than the review cycle and the decisions are being made by people without a governance background.

Govil, A. (2026). The policy written to be read once. The Field Report, XONIK.

Written by Amit Govil, Founder, XONIK

More from the Field Report

A fortnightly letter on the distance between deciding and doing.

One piece of research or one working framework, every two weeks.

No sequence, no upsell, unsubscribe in one click.