The AI committee: who decides, who approves, who answers
Roles, a risk-based approval matrix, an acceptable use policy and a use-case inventory — the minimum executive governance for scaling without surprises.
*Seventh article in our series on enterprise AI, legacy integration and information governance.*
Executive summary
Without a decision structure, corporate AI swings between two equally bad extremes: blanket permission with no control, or paralysis from legal fear. The antidote is a small committee with real authority that classifies use cases by risk and delegates the low-risk ones. Good governance approves the trivial fast and concentrates attention on what can cause harm.
Who needs a seat
Five roles are enough; more than that becomes an audience.
| Role | Responsibility | Decision power |
|---|---|---|
| Executive sponsor | Priority and budget | Approves high-risk cases |
| Process owner | Defines expected outcome and measures it | Approves low-risk cases in their area |
| Information security | Data classification and controls | Reasoned technical veto |
| Legal / Privacy | Legal basis, contracts, subject rights | Reasoned legal veto |
| Architecture / IT | Integration, cost and portability | Defines the official technical path |
A veto must be reasoned and come with an alternative. A committee that only says no gets replaced, in practice, by tools outside its control.
Risk-based decision matrix
The criterion is not the technology, it is the consequence. Three levels suffice:
- 1.Low. No personal or confidential data, no external effect. E.g. summarizing an internal public meeting. Approved by the process owner, light record.
- 2.Medium. Confidential internal data or customer impact with human review. E.g. drafting a sales proposal. Approved by owner + security, full record.
- 3.High. Sensitive personal data, decisions affecting people, or automation without review. E.g. candidate screening, credit analysis. Committee approval, impact assessment and audit plan mandatory.
Publish the matrix. When people can predict the decision, they stop routing around the process.
A one-page acceptable use policy
If it does not fit on one page, nobody reads it. The essentials:
- What may never be entered into an external tool (with industry examples).
- What the official path is and how to request access.
- The human review rule: what requires approval before reaching a customer.
- The obligation to disclose when significant material was produced with AI support.
- A channel to report errors or incidents, with no penalty for good faith.
Use-case inventory
A committee without an inventory decides blind. Minimum record per case: name, owner, affected process, data used, risk level, approval date, outcome metric, and review date. A well-kept spreadsheet covers the first twelve months.
That inventory is also what lets you answer a customer, auditor or insurer quickly — and it connects directly to the audit trail discussed in The forgotten asset.
A cadence that works
- Monthly: the committee reviews new cases, incidents and metrics from cases in production.
- Quarterly: review the risk matrix and the policy based on what actually happened.
- Annually: review vendors, contracts and the portability strategy.
What to do on Monday
- Name the five roles with actual people and set a first meeting date.
- Classify existing use cases against the three-level matrix — including the informal ones.
- Publish the one-page policy alongside access to the official path.
- Set a maximum committee response time; slow governance loses to the personal tool.
Conclusion
An AI committee does not exist to authorize technology; it exists to define who answers when something goes wrong — and to make that answer predictable. With clear roles and classified risk, the company accelerates where it is safe and applies rigor where it matters.
Further reading
Engineering track:
- Policy as code for AI governance — the technical deep dive on this topic.
