Doing AI Governance I Templates and tutorials for your AI Governance Policy


This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI.

Newsletter #51 - January 2026

Feature Article

Creating your AI Governance Policy

By James Kavanagh


This article draws on research and discussions with clients over the past year, including a review of more than 100 AI governance policies, both published and private. My intent was to identify what actually works in practice and what consistently fails. What I found was revealing.

Most AI governance policies fail before they're even finished. Organisations try to solve three distinct problems with a single document: strategic oversight for leadership, risk management for development teams, and practical guidance for employees wondering whether they can use ChatGPT for their marketing copy. The result is an unwieldy document that serves none of these audiences well. I've spent the past year watching this play out across industries and organisation sizes, and I've published new guidance on how to get this right.

The article walks through what I call the three-policy architecture: an AI Governance Policy for strategic direction, an AI Risk Management Policy for protective mechanisms, and an AI Use Policy for operational guidance. But more importantly, it addresses something I've become increasingly convinced separates governance that works from governance that fails. Good intentions never work. Mechanisms do. You can have ethical principles, advisory boards, and accountability structures. But if you're depending on teams to remember, care, and execute correctly under deadline pressure, you're building on sand.

The AI Governance Practitioner Program

Course 4: Writing AI Governance Policies

Including 5 governance document templates you can adapt to your organisation and deploy immediately.

From the Blog

Avoiding the 5 biggest mistakes writing AI governance policies

By James Kavanagh

A short video and article walking through how to write effective AI Governance policies while avoiding the worst mistakes that could undermine the success of your governance initiatives.


I've spent the last few months poring over AI governance, risk and use policies. Some published, some private internal copies from enterprises, public sector agencies and small businesses. I've spoken to dozens of practitioners to validate my thinking and refine what I thought I knew about what makes governance actually work.

From all that I've learned, here are the top five worst practices I've found in real policies, in reverse order. There are plenty more covered in the Course 4 of The AI Governance Practitioner Program, but these are the ones that cause the most damage.

The good news: they are all avoidable.

The AI Governance Director's Brief

Why Directors Find AI Policies Hard to Approve

A fortnightly brief for directors and senior executives with actionable guidance and insights for the governance of safe, secure and lawful AI. Published on LinkedIn fortnightly.

By Alexandra El-Shamy (Edition 7: Published 15 January 2026)


When an AI policy appears in a Board pack, many Directors describe a similar experience. The document looks substantial, it references important principles, the governance structures seem reasonable on paper, and yet something feels off.

Directors are consistently finding AI policies harder to assess and approve than other governance documents that come before a Board, and it has everything to do with how most AI policies are constructed.

A Final Note

Doing AI Governance is about going beyond the theory to do the real work of AI governance - the decisions, controls and accountability that make AI safe, secure and lawful in practice.

If anything in this edition sparked questions or you'd like to discuss your own AI governance journey, reach out.

I read every reply, every message and every comment. I'm here to help.

PS: Remember, only until the 31st January, Course 1 of the AI Governance Practitioner Program is open access. We have just 12 of the 100 spots offered remaining, so to secure yours, use code JANRESET at checkout when enrolling in Course 1. The code will remain valid until these last 12 enrollments are filled. NB. Open access to Course 1 ends 31 January. If you decide to continue through the Practitioner Program beyond Course 1, any progress you make during January will be preserved.

PS. You're receiving this as a subscriber to communications from AI Career Pro. We respect your privacy, so please unsubscribe through the link below if you do not wish to receive these communications in the future.

PO BOX 7087, Redhead, NSW 2290
Unsubscribe · Preferences

Doing AI Governance

Join over 4,500 subscribers and learn about the real work of AI governance. Moving beyond theory, we focus on the practical application of AI governance in real-world organisations with case studies, tools, templates and guidance. Led by James Kavanagh - the AI governance practitioner who led governance at both AWS and Microsoft.

Read more from Doing AI Governance

Hi Reader, Thank you for being part of the AI Career Pro journey. It means a lot to us. We wanted to let you know that we've just released a new AI Governance Assessment tool. It's free, and takes only 15 minutes to help you assess your capability as a practitioner alongside the governance capacity of your organization. You get your results emailed with tailored recommendations and an analysis of where you stand relative to peers in your region and industry. We built the assessment to help...

This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. Newsletter #55 - April 2026 Feature Article #1 The biggest risk in AI governance is waiting for the perfect moment to start. By James Kavanagh There have never been more frameworks, more conferences, or more confident agreement that AI governance matters. And yet, it's not clear that the talk is turning into action. I've been in those meeting rooms and conference halls....

This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. Newsletter #54 - March 2026 Feature Article Stop Copying Frameworks. Start Translating Them. By James Kavanagh Why writing your AI governance policy by transposing straight from a regulation, standard or framework is a shortcut to failure. And what to do instead. Most organisations approach AI governance the same way. They pick up the EU AI Act, ISO 42001, or the NIST AI...