AI governance: keeping control as usage grows.
Define who decides, what agents are allowed to do, which data they can access, how their actions are controlled and how to preserve reversibility.
Atlassian Platinum Solution Partner · Alongside IT departments since 2008 · Paris and Lyon
Governing without blocking.
AI does not only create new tools. It introduces new actors into the information system: assistants and agents able to consult data, use applications and sometimes act.
Who decides? What can the agent do? Which data does it access? Who checks its actions? How are they logged? And how do you stay able to change vendor?
AI usage often appears before the business has had time to build its framework. This is not necessarily a matter of discipline: teams use the tools available to solve real problems.
But moving from an AI that informs to an AI that acts changes the nature of the risk. Our aim is therefore not to slow projects down, but to give them enough of a framework to grow without building up a governance debt that is hard to pay back later.
Four dimensions to govern.
Which use cases should be prioritised? Who arbitrates? Who is accountable for the value created and the risks taken?
What can each agent do? Under what identity? With what rights? Within what scope of action? At what cost?
Which data can be sent to a model? To which vendor? Under which jurisdiction? With what traceability and what retention period?
Which obligations apply depending on the use case? What evidence should be kept? How is an incident handled?
Sovereignty runs through all four dimensions: it is not limited to where the data is hosted.
Our five-stage approach.
Governance is not a preliminary stage that holds projects up. It is built with them: a minimal foundation at the start, then enriched as usage grows.
Take stock of existing uses and agents, including local ones, and understand the data, the people involved, the risks and the dependencies already in place.
Define the decision framework: responsibilities, data classification, agent identity and rights, levels of human control, traceability rules and reversibility principles.
Apply the framework to real use cases, configure the controls, the logging and the operating rules without blocking projects.
Train the teams, spell out responsibilities, make the rules understandable and build governance into daily practice rather than into a theoretical document.
Review the agents, the costs, the rights, the vendors and the risks periodically; test reversibility and develop the framework at the pace of usage.
Three questions to settle very early.
An agent must have explicit rights, matched to its role and traceable. It should not simply inherit, unchecked, the rights of a user or of a generic service account.
Some actions can be carried out automatically, others checked afterwards, and the most sensitive ones validated before execution. The level of control depends on the risk attached to the action.
Can you change model, vendor or architecture without rebuilding your processes? Reversibility has to be considered from the design stage, not once the dependency is already in place.
Reversibility is not an end-of-contract matter.
An AI platform can work perfectly well and still create a serious dependency. What really matters is keeping the ability to choose: model, vendor, location, architecture and operating conditions.
Reversibility is part of designing governance, just as much as security or access rights.
Frequently asked questions
A question that finds no answer here is dealt with in a thirty-minute conversation, about your actual context rather than a general case.
Talk to an expertWhat is AI governance?
The set of rules and decisions that determine which uses are allowed, who decides them, which data can be used, what agents can do and how their actions are controlled and logged.
What is shadow AI?
AI uses or agents deployed locally without a central framework, or without the IT department having a full view of them. The point is not necessarily to ban them, but to make them visible and to be able to assess their risk.
Do you need to write an AI charter before starting?
Not necessarily. It is often more effective to build the framework from concrete use cases, then gradually draw shared rules from them.
When should an agent hand over to a human?
When the uncertainty or the potential impact goes beyond the accepted level of risk. A decision that is irreversible, financially binding or legally sensitive generally deserves more control than an action that can easily be undone.
How do you avoid becoming dependent on an AI vendor?
By designing the architecture so you can switch between several models where that is relevant, by keeping control of the contexts and the data, and by genuinely documenting the exit path.
Does governance have to be finished before the first project?
No. The two have to move forward together: set a minimum framework early enough, then enrich it as the use cases come. See also AI for business processes.
Going further: The Artificial intelligence overview·AI assessment & roadmap·AI for business processes·AI skills for IT teams