Start with the use, not the tool
A product name alone does not explain the risk. The same tool may be used to rewrite a public paragraph, summarize confidential records, screen candidates, or recommend a maintenance priority. Governance should examine the purpose, data, people affected, and consequence of error.
Increase documentation, approval, and review as the potential consequence of error increases.
A seven-part review
Classify the use
Describe what the tool is doing, who is affected, and the consequence of an error. Separate low consequence drafting or brainstorming from uses that influence access, safety, employment, finances, student support, or public trust.
Name the purpose and owner
Write one clear sentence describing the approved purpose. Assign an accountable owner who understands the work, can answer questions, and can stop or change the use when conditions shift.
Set data boundaries
Define what information may and may not enter the tool. Exclude passwords, regulated records, confidential personnel information, student information, proprietary material, and other sensitive data unless an authorized process specifically permits it.
Design human review
Specify who reviews the output, what they must check, what evidence they need, and when they must reject or escalate it. A person clicking approve is not enough if that person lacks time, authority, or subject knowledge.
Document the decision
Keep a short record of the tool, version if known, purpose, owner, approved data types, review steps, known limitations, and approval date. The record should help another responsible person understand the use later.
Create an escalation path
Tell staff what to do when the tool produces harmful, inaccurate, biased, insecure, or unexpected results. Identify who can pause the use and who must be informed.
Review periodically
Revisit the use after changes in the tool, data, workflow, law, policy, or operating context. Confirm that the benefit still justifies the burden and risk.
Use classification questions
- Is the output internal support, a recommendation, or a final decision?
- Could an error affect safety, access, employment, finances, education, legal rights, or public trust?
- Does the use involve confidential, personal, regulated, or proprietary information?
- Can a qualified person independently verify the important parts?
- Would the organization be comfortable explaining the use to the people affected?
Minimum decision record
A short record is often more useful than a large policy that no one applies. Capture the approved purpose, owner, tool, permitted and prohibited data, required review, escalation contact, known limitations, and next review point. Keep it with the workflow documentation people already use.
What this framework does not do
It does not determine legal compliance, cybersecurity approval, procurement acceptability, or technical fitness. Those questions may require qualified internal reviewers or outside professionals. It provides a disciplined starting point for deciding what should be examined and owned.