← All field notes
AI operationsField observation / April 20267 min read

An AI policy is not an AI operating model

A policy can establish boundaries. It rarely explains how a useful idea becomes an approved, monitored capability with a real owner.

Boundaries are necessary, but they do not move the work

An AI policy can define prohibited data, approved tools, disclosure expectations, and minimum security requirements. Those controls matter. But a policy is usually written to constrain behavior, while an operating model must help a legitimate idea move from proposal to reliable use.

Without that second layer, teams tend toward one of two outcomes. Responsible experiments stall because nobody knows who can approve them. Or motivated employees route around the policy because the official path cannot produce a timely decision. Neither outcome creates safe, useful adoption.

Four operating questions must be explicit

The operating model does not need to begin as a large governance program. It needs to answer the decisions that otherwise become political, inconsistent, or invisible.

  • Decision rights: who can propose, assess, approve, pause, and retire a use case?
  • Risk tiers: what evidence and controls are proportionate to the data, decision, and consequence?
  • Outcome ownership: who owns the workflow, adoption, quality, cost, and failure after launch?
  • Monitoring: which signals show that performance, behavior, economics, or risk has changed?

Risk should change the path, not only the paperwork

A low-consequence internal drafting assistant should not require the same review as a system that affects employment, pricing, customer eligibility, or regulated data. Treating every use case equally makes governance expensive where it should be lightweight and superficial where it should be rigorous.

Risk tiers should change the evidence required, the people involved, the review cadence, the permitted data, and the conditions that trigger a pause. The point is not to create labels. It is to make proportional decisions repeatable.

Every system needs an owner after launch

Teams often focus governance on the moment of approval. The harder work begins after the system meets real users, changing data, new model behavior, and operating pressure. Someone must own whether the workflow still produces the intended result and whether the cost and controls remain justified.

A useful operating model connects policy to delivery and delivery to ongoing accountability. It makes the safe path clear enough to use. The standard is not whether the company can say it has an AI policy. The standard is whether it can explain who approved a capability, on what evidence, who watches it now, and what would cause it to stop.

Andrew Erie leads Lavigne, providing fractional CTO and AI systems leadership for consequential technology decisions.

This page was first published July 31, 2026. The field date identifies when the underlying observation was recorded.

Bring the real decision

What keeps returning
to your desk?

Start with the technology, AI, product, vendor, or delivery decision that needs accountable ownership.

Start a conversation