
Most organisations already have a policy file. It sits in a shared drive, it names a few banned tools, and the people who approve use cases have not opened it since the draft. Staff keep pasting work into whatever window is fastest. The file does not become a decision because it exists.
NIST's AI Risk Management Framework is the reference a leadership day should translate, not a PDF the room is asked to recite. The US National Institute of Standards and Technology published it on 26 January 2023, led by its Information Technology Laboratory. The framework is voluntary. NIST describes it as a way to bring trustworthiness into the design, development, use and evaluation of AI products, services and systems. On 26 July 2024 NIST released the Generative Artificial Intelligence Profile, NIST-AI-600-1, to help organisations identify risks that are particular to generative systems and choose actions that match their own priorities. The 1.0 text is being revised, which is another reason to teach the decisions rather than a line by line reading. The page is the NIST AI Risk Management Framework.
Two different jobs
The AI governance workshop is two tiers because the jobs are different. All staff need a half day on everyday use: what can go into a tool, when not to trust an output, and what shadow use looks like. Leaders, risk owners and the people who approve use cases need a day on the operating model. Most large organisations need both. Either tier can run on its own, and booking only the staff session leaves the approval question unanswered.
What the leadership day has to produce
Leaders leave able to classify a use, name an owner and approve or refuse it in language a squad can follow. The operating model is mapped to NIST, ISO 42001 and the EU AI Act, then translated into the rules the organisation already has. The point is not a new binder. It is a short path from a proposed use to a named yes, a named no or a named limit.
- Each class of use has an owner, and that owner is the person who carries the downside, not the person who is keenest on the demo.
- Staff have one plain statement of what may go into a tool, written against the tools they already open, not against a future policy.
- A use that can send, pay, file or tell a customer something has a recorded approval. A screenshot in a chat is not a record.
- Every pilot has an end date. On that date the permission stays, shrinks or stops.
Squads still need questions they can answer before an agent acts. That list is in AI governance for non-lawyers. The narrower question of who may let a system send is in who may let an internal agent send. The leadership day is where those answers become a rhythm, instead of a private note in a ticket.
What to refuse
Refuse a statute class for people who will never open a statute. Refuse a policy reading that does not mention the tools staff already use. Refuse a rule so heavy that the rollout you funded simply stops. Guardrails people can remember will beat a framework nobody follows. The workshop is practical language for leaders, not a course reserved for lawyers.
If you are choosing the day, ask who will approve the next use case after the session, and where that approval will be written down. If the answer is that everyone will be more aware, you have bought the staff tier and called it the leadership tier.
Source: NIST, "AI Risk Management Framework", released 26 January 2023, Generative AI Profile 26 July 2024.
