Enterprise AI Policy

Table of Contents

The complete chapter-by-chapter structure of the Enterprise AI Deployment Policy, spanning Parts I–V and the appendices. Published chapters are linked; the Upcoming Releases section shows where the work is headed.

4 chapters published so far

Current Release

01

The AI Accountability Principle

States the principle on which the entire policy rests: AI is a technology tool, not a delegate, and accountability for AI output flows to the operator who used it, the role-holder accountable for the affected domain, and the deploying organization. This is Article 1. Every subsequent requirement, control, and overlay traces back to it, and a chapter that cannot make that trace does not belong in the paper.

View Details
02

Scope and Definitions

Defines what the policy governs and what it does not. A principle stated in terms of an AI system is only as clear as the organization's agreement on what an AI system is, so this chapter fixes that agreement: an AI system is technology that depends on a large language model's inference, and the chapter supplies a usable test for the boundary cases the definition does not settle on its own.

View Details
03

Stakeholders and Authority

Names the people, roles, and authority structures this policy protects, empowers, and constrains. Establishes who owns the policy itself, who enforces it, and how it relates to existing risk, audit, legal, and compliance functions. Without this chapter, the principles of Chapter 1 and the scope of Chapter 2 have no enforceable referent.

View Details
04

The Trust and Harness Framework

Establishes the four-tier classification system that determines how much weight an operator may place on AI output, what verification each tier requires, and what work each tier may and may not perform. The framework is the operational bridge between the Accountability Principle of Chapter 1 and the per-tool, per-task decisions employees make every day.

View Details

Upcoming Releases

PART II Planned

Tool Selection and Approval

Governs how AI tools enter the organization. Establishes the difference between sanctioned and shadow AI, the vendor evaluation criteria the organization applies before approval, the contractual requirements that protect the organization, and the approval pipeline that produces the AI Tool Register.

PART II Planned

Data Classification and AI Use

Maps the organization's existing data classification scheme to the AI tool tiers from Chapter 4. The chapter answers a single question that every employee asks every day: can I put this data into this tool?

PART II Planned

Decision Rights and Consultation Thresholds

Operationalizes the first corollary of the Accountability Principle: domain custodians retain review and veto authority over AI-assisted work products involving their domain. Specifies, by output type and consequence level, when an operator must consult the custodian before acting on AI output, when the custodian must approve, and when AI may not be used at all.

PART II Planned

Verification and Human Review

Codifies that AI output entering any system of record, or driving any decision with consequence, must have an independent verification step. Specifies what verification is, what verification is not, and who is responsible for performing it.

Check back frequently to see what’s new…

Subscribe for Updates

Receive notifications of new chapter releases, legislative updates, and policy amendments.