Most people see "AI governance" on a slide and reach for their coffee. Fair enough. But the boring document is doing more work than people give it credit for. Get it right and the firm spends its week experimenting, finishing on time, and producing decent work. Get it wrong, or skip it entirely, and people either ignore policy on personal devices or wait eighteen months for one to appear.
It Is a Strategic Question, Not a Compliance One
Read enough AI governance documents and a pattern emerges. Almost all of them answer the same three questions: risk, compliance, and a vague worry about whoever was last caught pasting client data into ChatGPT. All three are real. None of them is what the document is actually for.
AI gives every person in the firm a quiet productivity gift they did not have a year ago. Maybe two hours a week, maybe two days, depending on the job. Where that gift goes is the governance question, and almost nobody is treating it as one.
Why the Usual Approach Backfires
The default move is to commission a long document, hand it to legal, and publish forty-three pages that nobody opens. Two things happen next, in roughly equal proportions. Some clever people carry on regardless, often on personal accounts and sometimes on data the firm would prefer they had not touched. Everyone else goes the other way: no policy, no permission, no movement. Both groups are reacting to the same root cause. Governance was treated as the thing that says no, so people either ignored it or waited for it.
The interesting choice is not governance versus innovation. It is whether the governance document tells people what they can do, or what they cannot. The two read almost identically and produce opposite outcomes.
What a Useful Document Looks Like
The ones that work are short, specific, and answer the questions people actually have:
- Which AI engines are sanctioned.
- What kinds of data can go through which engine.
- Which uses are pre-approved, so nobody has to ask.
- Which uses need a quick review, and what that review actually involves.
- What the firm will not do, with the reasons attached.
That is more or less the lot. Three sides of A4, a version number, a name attached to it. The effect is that the Tuesday-morning question shifts from "am I allowed to use AI for this?" to "what is the best AI use for this?" The first is a waste of everyone's time. The second is a craft question, which is what you actually want people doing.
Where the Efficiency Actually Sits
Conversations about AI efficiency reach for "headcount" within about ninety seconds. That is not where the efficiency is. It is in the bits of the job nobody enjoys: the Friday status report, the meeting summary nobody reads, the compliance form identical to the last sixty. In a typical professional firm that category swallows a quarter to a third of an experienced person's week, and sensible AI use can trim half of it. That is hours per person per week, given back, to people the firm already employs.
The Bit About Going Home On Time
A surprising amount of professional overrun comes from a small number of unloved tasks at unfortunate moments: the 9pm email needing a polish, the Sunday-evening status update, the monthly compliance return. Governed AI use deals with that category in minutes rather than hours. People finish their day, eat dinner with whoever lives in their house, and return with a working brain. Burnout in this line of work is rarely caused by hard problems; it is the slow drip of dull, mandatory, badly-timed tasks at the edges of the week.
Why Constraints Help
The teams that experiment most usefully with AI are the ones with the clearest rules, not the most freedom. Freedom without rules is not freedom; it is uncertainty, and uncertain people either do nothing or do everything until something breaks. Give a team a one-page set of guardrails and they get on with it. The failures stay bounded; the wins accumulate.
Monday Morning
Write the policy floor on three sides of A4. Pre-approve the obvious wins, and make that list generous and specific. Make the review path real, with a two-week turnaround and a written outcome. Measure the right things: shadow AI use, time-to-decision, and hours recovered. And have the honest conversation about where the recovered time should go, whether that is client work, better thinking, or leaving at five on a Wednesday. All three answers are valid; pretending only one is acceptable is how firms quietly lose the people they were trying to retain.