Deep Bench Briefings Recap: “AI Governance in Action: Turning Your AI Policy into Practice”
For business leaders, legal professionals, and executives embracing AI, writing an AI policy is only the first step. The real challenge is ensuring that policy becomes part of how the organization actually operates.
In the latest installment of FRB's Deep Bench Briefings series, Moish Peltz and Christopher Warren, Co-Chairs of the Artificial Intelligence Practice Group, explored what separates organizations that simply have an AI policy from those that have built effective AI governance.
The discussion focused on a reality many organizations are beginning to recognize: AI adoption is happening whether leadership plans for it or not. Success depends less on restricting AI use and more on creating practical governance that encourages innovation while establishing accountability, oversight, and continuous improvement.
To demonstrate that philosophy in practice, the presenters also showcased FRB's recently released open-source AI governance resources, including MyFirstAIPolicy.com and the firm's public-domain AI policy templates on GitHub. Designed for law firms and small- to medium-sized businesses, the resources provide a practical starting point for organizations looking to build an AI policy while reinforcing the central message of the session: a policy is only the beginning, and governance is what makes it effective.
An AI Policy Is Only the Beginning
The webinar opened with a straightforward message: creating an AI policy does not solve an organization's AI governance challenges.
As the presenters explained, many companies draft a policy, distribute it, and consider the project complete. In reality, that document is just the starting point.
An effective AI policy must be a living document that evolves alongside the organization as new AI tools emerge, workflows change, regulations develop, and employees discover new use cases.
Importantly, governance should never become an obstacle to innovation. Organizations that simply restrict or prohibit AI use often achieve the opposite of what they intended. Instead of eliminating AI, onerous restrictions or blanket bans frequently drive employees toward unapproved consumer tools, creating “shadow AI” that operates outside organizational oversight.
The better approach is creating what the presenters described as "a path to yes": a governance process that encourages employees to propose new AI tools and workflows while ensuring legal, security, and compliance teams remain involved in evaluating them.
Governance Requires Ownership and Accountability
One of the session's central themes was that governance only works when someone owns it.
Policies cannot exist in a vacuum. Every organization should designate an individual or team responsible for approving AI tools, maintaining governance documentation, monitoring usage, and updating policies as needs evolve.
Beyond overall ownership, accountability must exist at every level.
Employees using AI should understand their responsibilities, managers should oversee how tools are used within their teams, and leadership should maintain visibility into how AI affects operations.
Rather than serving as a document that sits untouched in a shared folder, AI governance should define clear processes for using approved tools, reviewing AI-generated work, documenting human oversight, and determining who is responsible when issues arise.
Policies Should Reflect How People Actually Work
Drawing from FRB's own experience developing and revising its internal AI policy, Moish and Christopher explained that governance should be built around real workflows, not hypothetical ones.
When the firm first developed its policy following the emergence of generative AI, the process involved speaking directly with attorneys, marketing professionals, finance personnel, and other departments to understand how employees wanted to use AI in their daily work.
As AI capabilities expanded to include autonomous agents, AI transcription tools, and increasingly sophisticated enterprise applications, the firm's governance framework evolved alongside those technologies.
The discussion highlighted an important principle: employees often identify valuable AI use cases before leadership does.
Organizations should create an environment where employees feel comfortable proposing new ideas, requesting approval for emerging tools, and participating in the ongoing refinement of governance practices. Rather than treating governance as a top-down exercise, organizations should view it as an ongoing conversation between leadership and the people using AI every day.
Training and Culture Matter More Than the Document
The presenters repeatedly returned to one idea: governance succeeds because of organizational culture, not paperwork.
Even the most comprehensive AI policy provides little value if employees do not understand it or feel discouraged from engaging with it. Organizations should provide meaningful, department-specific training that recognizes how AI use and associated risks vary across business functions.
For example:
- Marketing teams may focus on AI-assisted content creation while protecting confidential campaign materials and intellectual property.
- Law firms must preserve attorney-client privilege and maintain rigorous human review of legal work.
- Accounting firms handle highly sensitive financial information requiring strict confidentiality controls.
- Architecture and engineering firms may rely on AI for design work while ensuring human oversight for safety-critical decisions.
Although risks differ across industries, every organization benefits from fostering an environment where employees can openly discuss new AI capabilities, identify governance gaps, and help strengthen internal policies.
The presenters even suggested rewarding employees who identify governance weaknesses, drawing inspiration from cybersecurity "bug bounty" programs.
Choosing AI Tools Requires More Than Comparing Features
The discussion also explored how organizations should evaluate AI vendors and enterprise tools before approving their use.
Organizations should ask critical governance questions beyond just comparing features:
- Does the vendor train its models using customer data?
- How is sensitive information stored, retained, or deleted?
- Who owns AI-generated work product?
- Does the platform support enterprise monitoring and auditing?
- Can the organization enforce its governance policies within the platform?
The presenters noted that AI is no longer confined to standalone chatbots—existing enterprise software is increasingly embedding AI functionality into products organizations already use. As a result, governance should become part of broader vendor management and enterprise risk processes.
Mistakes Are Inevitable, the Response Matters
The webinar acknowledged an important reality: even strong governance cannot eliminate every mistake. Humans will occasionally misuse tools, overlook review procedures, or encounter unexpected outcomes.
The key is preparing for those situations before they occur. Organizations should establish incident response procedures that define how errors are identified, reported, corrected, and documented.
Every mistake should become an opportunity to improve governance. When an incident reveals a weakness, the appropriate response is not simply correcting the individual error—it is updating the policy, improving training, or strengthening review procedures.
As the presenters explained, if an organization's AI policy never changes, it likely is not engaging with the realities of everyday operations. Continuous refinement is evidence that governance is working.
AI Governance Is a Continuous Process
Toward the conclusion of the session, the presenters encouraged organizations to view AI governance as an ongoing operational function rather than a one-time compliance project.
New AI tools emerge regularly, existing software introduces AI features, regulatory frameworks continue developing, and internal business needs change. Effective governance requires organizations to monitor these developments, review policies on a recurring schedule, retrain employees, and reassess approved tools.
To help organizations move from theory to implementation, the presenters demonstrated MyFirstAIPolicy.com, FRB's free AI policy builder, along with open-source templates on GitHub. These resources include customizable templates for law firms and small- to medium-sized businesses, as well as an AI-powered tool that guides organizations through tailoring a policy to their technology stack, industry, and risk profile.
The presenters emphasized that these resources lower the barrier to getting started but do not eliminate the need for thoughtful governance. Every organization has unique workflows, regulatory obligations, and business objectives requiring careful customization and ongoing review.
Ultimately, the policy builder reinforces the webinar's central message: writing an AI policy is not the finish line. It is the foundation for building a governance program that grows with the technology, the business, and the people using it.
Key Takeaways
Throughout the webinar, one message remained consistent: organizations should not measure AI maturity by whether they have a policy, but by whether that policy actively shapes how AI is used.
For executives and business leaders, the practical lessons were clear:
- An AI policy is only the first step; governance requires continuous implementation and oversight.
- Blanket bans often create shadow AI rather than reducing organizational risk.
- Every governance framework needs clear ownership and accountability.
- AI policies should evolve alongside changing technology, workflows, and regulations.
- Training, culture, and employee engagement are just as important as written policies.
- AI vendors should be evaluated for data governance, confidentiality, ownership, and monitoring capabilities—not simply for features.
- Open-source resources like MyFirstAIPolicy.com can accelerate AI governance efforts, but every policy should be customized and regularly updated.
- Every AI-related incident should become an opportunity to improve governance rather than simply correct an individual mistake.
Organizations should not wait for AI governance to become perfect before taking action.
If your organization is developing an AI governance program, evaluating AI vendors, updating internal policies, or building a practical framework for responsible AI adoption, FRB's Artificial Intelligence Practice Group is ready to help. Contact us here or fill out the form below.

