Your AI Policy Is Probably Unenforceable. Here's What Actually Works

About this session

Most organisations have an AI policy. Very few have one that changes how people actually behave. The gap between a governance document and a production guardrail is where real risk lives; and it's a gap that policy language alone cannot close.

This talk draws on practical experience building AI governance frameworks inside a global SaaS product organisation. I'll walk through why traditional policy approaches fail when applied to AI (hint: if your governance model treats all AI features as a single risk category, it's already broken), and what I've found works instead: tiered governance models that distinguish AI features by risk profile, review frameworks that catch materially different data patterns across a product portfolio before they ship, and default-setting decisions that determine whether a feature launches in monitor mode or requires a separate impact assessment.

I'll cover the practical mechanics of reviewing generative AI integrations across multiple product lines (including how to identify when an integration that looks routine is actually doing something fundamentally different with personal data) and why the organisations getting AI governance right are the ones embedding legal and compliance review into the product development cycle, not bolting it on after launch.

This isn't a talk about regulation. It's about what happens inside the building, and why the gap between your AI policy and your production environment is the most dangerous space in your organisation.

Attendees will leave with a framework for building AI governance that actually works at the product level, not just the policy level.

Speaker

Key takeaways

  • Not all AI features carry the same risk, and governance frameworks that treat them as a single category will miss the ones that matter most. Attendees will learn how to build a tiered governance model that distinguishes AI features by what they actually do with data, so that low-risk deployments move fast while high-risk ones get the scrutiny they need.
  • The default settings you choose at launch quietly determine your entire risk profile. Attendees will understand why the decision between shipping an AI feature in monitor mode versus an active mode isn't a product decision - it's a governance decision - and how to build that distinction into the development cycle before it reaches production.
  • Governance that lives in a policy document but not in the product development workflow is governance in name only. Attendees will leave with a practical approach to embedding legal and compliance review into the product build process, including how to identify when an AI integration that looks routine is actually doing something materially different with personal data.

Related sessions