AI governance and policy

Writing policy before deployment: accountability, records implications, and what you tell the public.

PremiumFull guide planned · 22 min read

The short version

Policy has to exist before deployment, not after the first incident. The questions that matter are who is accountable for an output, what becomes a public record, what data may be entered, and what a member of the public is told. These are governance and legal questions with a technology component, not the other way round.

Start here

If you read one thing on this subject, read this.

Official resourceNIST

Generative AI Profile (NIST AI 600-1)

The generative-AI companion to the AI Risk Management Framework, covering risks specific to systems that produce text and images.

Why it matters

The closest thing to a standard reference if you are writing department policy on generative AI. Cite it and the conversation stops being about opinion.

Questions to ask your vendor

Take these into the meeting. A vendor who answers them clearly is one worth continuing with.

  1. Does output from this system become a public record?
  2. What are we permitted to enter, and what must never be entered?
  3. Where is the human review step, and can it be skipped under load?
  4. What do we tell the public about how this is used?

The full guide is still being written

What is above is the Hub’s framing and the best outside reading we could verify — useful on its own, and honest about being a starting point rather than the finished piece. If something here is wrong, or you know a better source, that is worth telling us before the long version is written.

Send a note