Person standing at a glass-walled balcony, holding a mug, overlooking a lit city skyline; tablet, notebook, and glasses on a desk in the foreground.

Policies Don’t Lead

Over the past year, we’ve spent a lot of time helping organizations figure out what AI actually means for their business. We’ve also been doing the same work ourselves inside Don’t Panic Labs.

Along the way, something has become increasingly obvious to me. Almost everyone starts in the same place.

Someone asks Legal to draft a Responsible Use Policy. A governance committee is formed. Security starts evaluating models. The board wants an update on AI governance at the next meeting, and I understand why. Those are all responsible things to do. They’re just not the first things to do.

Leadership Comes Before Governance

I think we’ve accidentally convinced ourselves that governance is where AI starts. It isn’t. Governance starts after leadership has already made the decisions that matter.

Governance answers the question, “How will we make decisions?” Leadership answers the question, “What are we trying to accomplish in the first place?”

Those are not the same thing.

A governance framework can’t tell you whether your organization should aggressively embrace AI or cautiously adopt it. It can’t tell you whether every employee should have access to frontier models or only a handful of people. It can’t tell you whether your competitive advantage comes from moving faster than everyone else or being more trustworthy than everyone else.

Those aren’t governance decisions. They’re leadership decisions. Yet organizations ask lawyers to help them answer those questions every day. That’s asking the wrong people the first question.

Before anyone writes a Responsible Use Policy, leadership ought to spend time wrestling with questions that no policy template can answer. What role do we want AI to play in this organization? What work should become dramatically easier? Where do we expect people to exercise judgment instead of simply accepting an answer? What risks are we willing to take because the opportunity is worth it? What risks are we unwilling to take regardless of the opportunity?

Those conversations are hard, and they are supposed to be. The easy path is to download someone else’s policy, change the logo, and tell yourself you’re governing AI. The hard path is deciding who you intend to become because AI exists.

Ironically, the easy path usually creates the hard future. You end up with policies nobody believes, governance nobody understands, and employees trying to infer leadership’s convictions from a document written by Legal. That seems backward to me. One sentence has been rattling around in my head:

Compliance is a terrible place to discover your convictions.

Compliance exists to verify that you’re living up to your convictions. It’s the job of leaders to create them. This is why I think we’ve given the Responsible Use Policy the wrong responsibility.

A Responsible Use Policy shouldn’t be your organization’s first opinion about AI. It should memorialize the opinions leadership has already formed. That’s a very different way to think about the document. Instead of asking, “What should our AI policy say?” leadership first asks, “What do we actually believe?” Only after those beliefs are clear does it make sense to write them down.

The policy becomes a durable expression of leadership’s intent. Governance becomes the mechanism that helps people make decisions consistent with that intent. Compliance becomes the way we verify that reality matches what we said we believed. Each serves a different purpose, and each depends on the one before it.

I also think this changes how we should think about keeping the policy current. Most organizations treat policies like legal documents. They write them, approve them, and review them once a year unless something breaks. I don’t think a Responsible Use Policy is primarily a legal document. I think it’s a leadership document.

Leadership’s understanding of AI is going to change. The technology will change. Customers will change. The market will change. Hopefully, we’ll all learn a lot over the next few years. When leadership’s thinking changes, the policy should change with it. Not because Legal discovered a new clause that needs to be added, but because leadership has developed a better understanding of the organization it is trying to build.

Maybe the sequence should look something like this:

  1. Leadership decides who the organization intends to become because AI exists.
  2. Those convictions are memorialized in a Responsible Use Policy.
  3. People develop the capability and judgment to act consistently with those convictions.
  4. Governance creates consistency in decision-making.
  5. Controls and compliance verify that the organization is actually doing what it said it would do.

The order matters because policies don’t lead. People do.

author avatar
Bill Udell Managing Partner & Chief Operating Officer
Bill is happily creating a groundswell of change and innovation in the Silicon Prairie ecosystem with his buddies at Don’t Panic Labs. He can be found regularly at community events or busily working in coffee shops and boardrooms to create opportunities for collisions of entrepreneurs, community leaders, and the ecosystem.

Related posts