← All field notes
AI operationsField observation / April 20263 min read

An AI policy is not an AI operating model

A policy can establish boundaries. It rarely explains how a useful idea becomes an approved, monitored capability with a real owner.

Policy sets boundaries; an operating model defines the path

An AI policy can define prohibited data, approved tools, disclosure expectations, and minimum security requirements. Those controls matter, but they do not necessarily explain how a legitimate proposal will be assessed, approved, deployed, monitored, and retired.

Without that second layer, responsible experiments may stall because approval authority is unclear. Other teams may bypass the official process when it cannot produce a timely decision. The organization can end up with both delayed legitimate work and unreviewed use.

Four operating questions must be explicit

The operating model does not need to begin as a large governance program. It needs to establish who decides, what evidence is required, how quickly reviews occur, and where decisions are recorded.

  • Decision rights: who can propose, assess, approve, pause, and retire a use case?
  • Risk tiers: what evidence and controls are proportionate to the data, decision, and consequence?
  • Outcome ownership: who owns the workflow, adoption, quality, cost, and failure after launch?
  • Monitoring: which signals show that performance, behavior, economics, or risk has changed?

Risk should change the path, not only the paperwork

A low-consequence internal drafting assistant should not require the same review as a system that affects employment, pricing, customer eligibility, or regulated data. A single review process creates the wrong burden at both ends: low-risk tools receive unnecessary scrutiny, while high-risk systems may not receive the specialized review they require.

Risk tiers should change the evidence required, the people involved, the review cadence, the permitted data, and the conditions that trigger a pause. The point is not to create labels. It is to make proportional decisions repeatable.

Every deployed AI system needs an owner

Teams often focus governance on the moment of approval. A new phase begins after launch, when real users, changing data, model updates, and day-to-day pressure expose conditions the initial review did not cover. Someone must own whether the workflow still produces the intended result and whether the cost and controls remain justified.

A useful operating model connects policy to delivery and ongoing accountability. Having a policy is not enough. The company should be able to explain who approved each deployed capability, what evidence supported that decision, who monitors it now, and which conditions would trigger a pause or retirement.

Andrew Erie leads Lavigne, joining important technology and AI projects at any stage and carrying them through delivery.

This page was first published July 31, 2026. The field date identifies when the underlying observation was recorded.

Bring the decision

What decision keeps coming
back to your desk?

Start with the technology, AI, product, vendor, or delivery decision that no one fully owns today.

Start a conversation