Governance Sounds Like Someone Else’s Problem
AI governance sounds like something built for universities, government agencies, and companies with legal departments, cybersecurity teams, and a dedicated AI committee. That’s a problem if you run a small training company, work as an independent instructional designer, sell online courses, or manage learning for a small organization, because you likely use AI every day without anyone whose job is to govern it.
Maybe you use ChatGPT or Claude to develop course content. Your LMS just added AI-generated feedback. Your authoring tool can build assessments on its own. An AI video platform generates your presenters. Your transcription service produces meeting summaries. Your marketing platform personalizes messages using AI.
Do you need a governance committee for all of that? Probably not. Do you need some rules? Yes.
The practical answer is risk-based AI governance. Instead of treating every use of AI as equally dangerous, or building an approval process for everything, you apply more scrutiny when the consequences are greater. A tool that generates five alternative titles for a webinar shouldn’t need the same review as a system that evaluates learner performance.
Here’s a framework small training organizations can actually use.
Start With the Decision, Not the Tool
One of the easiest mistakes to make is labeling an AI product itself as “safe” or “risky.” That rarely holds up, because the same tool can be used for very different purposes.
Say your organization uses one generative AI platform three different ways. An instructional designer asks it to suggest titles for a course. The designer uploads learner feedback and asks it to identify common complaints. The organization uses it to determine which learners successfully demonstrated competency.
Same technology, three very different sets of consequences.
The risk comes from what the system is being asked to do, what information it receives, and what happens because of its output. That means your governance process should focus on AI use cases, not just maintain a list of approved and prohibited tools.
A Three-Level Framework
For most small organizations, three levels are enough.
Level 1, low risk. AI assists with routine work and has little direct impact on learners or employees.
Level 2, moderate risk. AI influences learning experiences, communications, or decisions, but a person reviews the output before it has any real consequence.
Level 3, high risk. AI evaluates people, influences consequential decisions, handles sensitive information, or operates with limited review.
You don’t need a complicated scoring formula. You need a consistent way to recognize when an AI use deserves more attention.
Level 1: Low-Risk AI Use
Low-risk uses generally involve assistance, not decision-making. The output is easy to review, correct, or discard, and an error would have limited consequences.
For an instructional design team, that could look like brainstorming course titles, generating alternative headings, suggesting scenario ideas, creating fictional character names, reformatting text, drafting discussion questions, building a first-pass course outline, summarizing your own notes, suggesting image concepts, or drafting internal project documentation.
Suppose you ask AI: “Give me 10 possible titles for a 30-minute course on giving constructive feedback.” A few of those titles will probably be terrible, and it won’t matter much. You review them, pick one, revise it, or ignore the whole list. That’s exactly the kind of activity where a lengthy approval process creates more burden than protection.
What governance does Level 1 need? Usually very little, though you still want a few baseline rules. Don’t enter confidential or personally identifiable information into an AI system unless the organization has approved that specific use. Review AI-generated material before publishing it. Verify factual claims when accuracy matters. Follow your existing copyright, accessibility, and content standards. That’s often enough for a low-risk activity.
Governance shouldn’t make people afraid to use AI for routine work. It should just tell them where the edges are.
Level 2: Moderate-Risk AI Use
Moderate-risk uses need more attention because AI starts shaping what learners actually experience or how people interpret information. This covers things like generating instructional explanations, creating assessment questions, producing learner-facing feedback, translating instructional content, building realistic workplace scenarios, analyzing aggregated learner feedback, generating AI presenters or voices, running a chatbot that answers course questions, or producing recommendations a qualified person reviews before acting on them.
Take an AI-generated quiz. At first glance, this feels low risk. The instructional designer asks AI for 15 multiple-choice questions, reviews them, and adds them to the course. But a poorly written assessment item can cause real problems. It might have two defensible answers. It might test a minor detail instead of the actual learning objective. The explanation attached to the “correct” answer might just be wrong.
If the quiz is a low-stakes knowledge check, that’s probably fine. If those same questions determine whether an employee gets certified to perform a task, the risk changes considerably. Context matters more than the feature itself.
What governance does Level 2 need? A documented review process. A qualified person should review AI-generated content before learners receive it. Factual information should get checked against an authoritative source. Assessment items should be reviewed against the learning objectives, and checked for bias, accessibility issues, or inappropriate assumptions where relevant. Learner data shouldn’t be uploaded unless the tool and the data use have already been approved. And someone needs to be clearly responsible for the final product, because “we used AI” can’t become the explanation for why nobody caught a problem.
Level 3: High-Risk AI Use
High-risk uses deserve real scrutiny. These are situations where AI output can meaningfully affect a person’s opportunities, evaluation, access, employment, certification, or educational outcome, things like automatically grading consequential assessments, determining whether someone demonstrated competency, recommending that an employee needs remediation, evaluating employee performance, flagging learners as “at risk,” making admissions or selection recommendations, analyzing individual learner behavior to predict outcomes, or acting on sensitive personal data without meaningful review.
Say a training provider offers a professional certification and introduces AI to evaluate participants’ written responses and decide who passes. That decision deserves far more scrutiny than using the same AI system to draft the course’s welcome email.
Before using AI this way, you should be able to answer some hard questions. How was the system validated? How accurate is it for this specific task? Does it perform differently for different groups of people? Can participants challenge a decision? Who reviews questionable cases? What information is being collected, and how long is it retained? What happens when the AI and a qualified reviewer disagree? Who’s ultimately accountable?
If you can’t answer those questions, the system probably shouldn’t be making the decision yet.
Five Questions That Determine Risk
You can classify most AI uses just by working through five questions.
1. What happens if the AI is wrong? Start with consequences. If AI generates a bad course title, you replace it and move on. If AI incorrectly decides someone failed a competency assessment, the fallout is a lot bigger. Ask what the realistic harm is if the output turns out to be inaccurate, biased, misleading, or incomplete. The greater the consequence, the stronger the controls need to be.
2. What data does the AI receive? Risk climbs whenever a system receives personal, confidential, proprietary, or sensitive information. An instructional designer asking AI to generate a fictional scenario is nothing like uploading actual employee performance records and asking for an analysis. Before entering anything into an AI system, figure out what information you’re providing, whether you actually have permission to use it that way, whether the system retains it, whether it can train the provider’s models, who can access it, and whether you even need to include it at all. Don’t upload data just because the system happens to be able to process it.
3. Is AI assisting or deciding? This is one of the most useful distinctions in the whole framework. “AI identifies patterns in course evaluations for the instructional designer to review” is a different sentence than “AI determines which instructors have received unacceptable course evaluations.” The first supports analysis. The second moves toward judgment about people. The closer AI gets to making the final call, the more review the process needs.
4. Can a person meaningfully review the output? “Human review” sounds reassuring right up until you look at how it actually works. If an employee gets 500 AI-generated recommendations and ten minutes to approve them, a person is technically involved, but that’s not meaningful review. Ask whether the reviewer understands how the recommendation was produced, has enough information to question it, has enough time, can actually override the AI, and is genuinely expected to use independent judgment. If the honest answer is no, you’re functionally looking at automated decision-making with an extra step.
5. Can the affected person challenge the result? This matters most for high-risk uses. If AI influences a real decision about someone, that person needs a reasonable way to question a result they believe is wrong. If an AI-supported assessment says an employee has to repeat training, what happens when that employee disagrees? Who reviews the case, what evidence gets considered, and can the original decision actually be changed? You don’t need an appeals court inside your training department. You do need a process.
Build a Simple AI Use Inventory
You can’t govern AI use you don’t know is happening. For a small organization, a spreadsheet is usually enough.
| Field | Example |
| AI tool | ChatGPT |
| Use | Draft scenario variations |
| User | Instructional designer |
| Data involved | No learner data |
| Output affects people? | No |
| Person reviews output? | Yes |
| Risk level | Low |
| Owner | Course development lead |
| Review date | January 2027 |
Don’t limit this to standalone AI tools. AI is increasingly baked into software you already use. Your LMS, authoring software, video platform, transcription service, analytics system, CRM, and communication tools may all have AI features running quietly in the background. You may already be using more AI than you realize.
A Few Non-Negotiable Rules
Small organizations don’t need a 40-page AI policy. Start with rules people can actually remember.
Protect data. Don’t enter confidential, personal, or sensitive learner or employee information into an AI system unless that specific use has been approved.
Verify before publishing. AI-generated instructional content gets reviewed by a qualified person before learners ever see it.
Don’t delegate consequential decisions casually. AI shouldn’t independently determine grades, certification, competency, or employment outcomes without proper validation and review.
Assign an owner. Every AI-supported process needs someone responsible for the final result.
Increase review as risk increases. A brainstorming prompt doesn’t need the same approval process as an automated assessment system.
These five rules won’t cover every situation you’ll run into. They’ll cover a surprising number of them.
Build Governance Into the Workflow
The easiest governance process is one people can follow while doing their actual job. Say an instructional designer wants to bring in a new AI feature. Instead of a lengthy application, have them answer a short set of questions: What are you using AI to do? What information will it receive? Will learners or employees see or be affected by the output? Who reviews it? What happens if it’s wrong? Would you call this use low, moderate, or high risk?
A low-risk use might get approved by the designer or team lead on the spot. A moderate-risk use might need documented review. A high-risk use might call in leadership, privacy, legal, or security, depending on your organization and what’s actually at stake. The point is proportionality. More risk should trigger more scrutiny, not more paperwork across the board.
Don’t Confuse Vendor Claims With Validation
A vendor might tell you its AI is accurate, secure, unbiased, enterprise-ready, or built specifically for education. Those claims are a reasonable starting point. They are not evidence that the system is right for your use.
If a vendor says its AI can accurately evaluate learner responses, ask how they reached that conclusion. What was tested? Who was included in the testing? What kind of responses were evaluated? How often does the system get it wrong? What happens with unusual or edge-case answers? Can you test it yourself using examples from your own context? The more consequential the use, the less you should be leaning on marketing copy alone.
Review AI Uses After You’ve Implemented Them
Approval shouldn’t be the finish line. AI products change constantly. Vendors update models. Organizations start using tools in ways nobody originally planned for. A chatbot introduced to answer basic navigation questions can quietly start answering policy questions. A tool built to generate practice questions can end up generating scored assessments. A low-risk use can turn into a moderate- or high-risk one without a single person deciding that on purpose.
Review your AI inventory on a regular schedule, every six to twelve months for most uses, more often for anything higher risk. Ask whether you’re still using the tool for its original purpose, whether the vendor has changed anything significant, whether you’re now feeding it different data, whether any problems have come up, whether the original risk classification still fits, and whether you still need the tool at all. Governance is a lot easier when it’s routine maintenance instead of a scramble after something goes wrong.
You Can Start Small
If your organization has no AI governance process right now, you don’t need to solve everything this month. Start with four moves.
First, find out where AI is already being used. Talk to the people creating courses, managing the LMS, producing media, analyzing learner data, marketing programs, and supporting learners.
Second, sort those uses into low, moderate, or high risk. Don’t burn hours debating borderline cases. The classification only needs to tell you how much attention something deserves.
Third, put your non-negotiable rules in place. At minimum, cover data protection, review of AI-generated content, consequential decisions, and accountability.
Fourth, go after your highest-risk uses first. If AI is generating course titles and also automatically evaluating learner competency, don’t spend your limited governance time on the titles. Start with the competency decisions.
Good Governance Makes Decisions Easier, Not Harder
Small training organizations run on limited time, limited staff, and limited budgets. A governance process that demands paperwork for every single use of AI will probably just get ignored.
The goal is to help people make better decisions, quickly. A useful framework tells an instructional designer: you can use AI for this; you can use AI for this, but someone needs to review the output; or, this use carries enough risk that we need to look at it more closely before moving forward. That’s governance people will actually follow.
AI doesn’t need to be either fully approved or fully banned as a category. A much more workable approach looks at what the system is doing, what information it receives, who’s affected, and what happens if it gets something wrong, then matches the safeguards to the consequences. For a small training organization, that’s often enough to turn AI governance from an abstract policy discussion into something that just becomes part of how you design courses every day.
Let’s Talk About Your Program
If you’re not sure how much AI risk is already sitting inside your courses, or you want a second set of eyes on how your programs are using AI right now, that’s exactly the kind of thing worth reviewing before it becomes a bigger problem.
I review and analyze existing programs and courses, then provide clear recommendations for strengthening and modernizing them, including where AI is genuinely helping and where it needs tighter guardrails.
Get in touch through the contact form on my website at https://yourelearningworld.com/contact/ and let’s take a look at what your program needs.

Leave a Reply