Digital · Cloud · Cyber · Engineering · Operations
Cyber

A practical governance model for AI already in use

In most agencies, staff adoption of artificial intelligence tools precedes formal governance by a considerable interval. Usage occurs through individual accounts, browser extensions, and capabilities embedded within platforms the agency has already licensed. Governance boards, in the same period, are typically preparing to evaluate proposed deployments.

The resulting position is that policy addresses the deployment pipeline while exposure exists in current operations.

This is not a failure of intent. The policy environment developed rapidly, establishing governance is the correct response, and agencies are proceeding in good faith. Governance addressing only intended deployments, however, does not examine the exposure that exists.

Discovery

Current state must be established before policy is drafted. Three questions apply.

Which tools are in use? Sources include network and cloud access security broker telemetry, expense and procurement records, browser extension inventories, and artificial intelligence features embedded within licensed platforms. The final category is consistently underestimated. Most agencies hold more capability than they have catalogued.

Against which data? This determines severity. Use of a public model for open source research differs materially from the same tool processing controlled unclassified information, personally identifiable information, procurement sensitive material, or pre decisional content.

By whom, and for what purpose? The underlying requirement is material, because the objective includes redirection rather than restriction alone. Where staff use an unauthorized tool to summarize lengthy documents, restricting the tool does not eliminate the requirement.

Discovery is frequently uncomfortable. It is the only method of governing existing exposure rather than anticipated exposure.

Alignment to the NIST AI Risk Management Framework

The framework organizes into four functions, Govern, Map, Measure, and Manage, which operate effectively as a governance structure. NIST has continued its development, including an April 2026 concept note addressing a profile for trustworthy artificial intelligence in critical infrastructure.

Govern. Roles, accountability, and policy, including the Chief AI Officer and governance board structures M-25-21 requires. Decision authority must be explicit, as must the process where a requested tool is not authorized.

Map. Discovery output constitutes the artificial intelligence inventory, categorized by data sensitivity and consequence of error.

Measure. Evaluation and monitoring addressing accuracy, drift, failure modes, and logging sufficient to reconstruct a decision. Systems meeting M-25-21 high impact criteria additionally require pre deployment testing and impact assessment.

Manage. Acceptable use enforcement, incident handling for artificial intelligence specific failures, and periodic reassessment.

Tiering by consequence

A uniform policy is either sufficiently restrictive to displace usage into unmonitored channels or sufficiently permissive to provide no control. Tiering by consequence is more effective.

Low. Public data, human reviewed output, no decision authority. Light touch authorization.

Moderate. Internal non sensitive data, or output informing staff work. Authorized tools, defined data boundaries, required training.

High. Controlled unclassified information, personally identifiable information, or output informing decisions regarding individuals, funds, or operations. Full assessment, documented testing, logging, retained human decision authority, and ongoing monitoring.

The tiering process additionally requires organizations to articulate which decisions they will not permit a model to influence. That determination should be documented.

The authorized path

The most effective available control is an authorized capability materially better than the alternative. Where the authorized tool is slower, less accessible, and less capable, policy is superseded by convenience, consistently and without organizational visibility.

This requires investment in the authorized path: functional capability, reasonable access, clear guidance, and an expedited method of determining whether a specific use is acceptable. Governance limited to restriction generates workarounds it will not observe.

Incident response

Existing procedures assume categories that do not address artificial intelligence failure modes. Additional scenarios are required: sensitive data submitted to an external model, a model informed decision subsequently determined to be systematically incorrect, output that cannot be reconstructed, and a vendor modifying model behavior without notification.

Each requires a distinct response. None correspond directly to documented procedures.

The discovery finding with the greatest organizational impact is generally not an unauthorized tool installed by an individual. It is artificial intelligence capability delivered within a platform the agency has already licensed, enabled by default, and used by staff who reasonably concluded that functionality within an authorized product was itself authorized. That represents a procurement and configuration matter rather than a workforce compliance matter, and it requires the inventory to address software the organization considers already assessed.

Agencies managing this effectively are not those with the most restrictive policies. They are those that established current state before drafting policy.