MCMartin ChristenTechnology & Advisory
← Perspectives

Data & AI governance / Editorial draft

AI governance starts with data.

Ownership, access and lifecycle decisions make governance concrete long before a model is selected.

Begin with what enters the system

AI governance becomes tangible when we ask what information a system consumes, where that information comes from and who has authority to use it. A model can be carefully selected while the surrounding data flow remains poorly understood. That gap affects both the usefulness of the result and the ability to explain it.

Give data an accountable owner

Classification is helpful only when it leads to decisions. Someone needs to determine whether information is suitable for the intended use, which access is appropriate and how long it should remain available. Ownership connects policy to those choices. It also creates a route for resolving ambiguity instead of allowing each implementation team to make its own assumptions.

Look beyond training

The relevant boundary includes prompts, retrieved documents, generated outputs, logs and integrations. Retrieval can introduce information that the user should not see. Logs can retain content longer than intended. An agent can carry a decision into another system. Each step deserves an explicit account of identity, permissions, retention and oversight.

Turn governance into engineering decisions

A governance statement should lead to concrete requirements: approved data sources, enforceable permissions, a defined retention approach, reviewable changes and a route for investigating unexpected behaviour. The requirements must fit the application context. A drafting assistant and an agent with authority to change records need different boundaries.

Keep the conversation connected

Data owners, security leaders, architects and engineers need a shared view of the intended use. The aim is to understand the information and authority entering the system, and to preserve that understanding as the system evolves. That is a practical foundation for responsible AI.

Continue the conversation ↗