Lesson 3 · AI Governance Basics
Approved tools and data classification
- Length
- 27 minutes across 7 sections
- You will be able to apply
- The Approved Route
- You will produce
- Commit Statement
- You will work
- 3 gated questions
Personalize the practice
Apply this to your environment
These details adapt the application prompts and coach questions. They do not affect your score.
If the approved route is slower, you have not built a control. You have built a detour.
Core question
classification
Classify the work before you choose the route
Required practiceOmniCorp teams are asking for faster AI help. Classify each item using the lesson's data classes before you read the Approved Route framework.
Every organisation that restricts AI tools discovers the same thing about six weeks later: the restriction did not stop the use, it moved it. The work still needs doing, the deadline has not shifted, and there is a free tool on a personal device that does the job. The policy is intact. The data is gone.
The instinct is to enforce harder. The instinct is wrong, and understanding why is most of this lesson.
The pathology: Shadow Convenience
People do not route around controls because they are reckless. They route around controls because the sanctioned path is slower than the deadline allows, and because the harm from using an unapproved tool is invisible and deferred while the harm from missing the deadline is visible and immediate. Given that asymmetry, the rational choice for an individual is the one that damages the organisation.
The correction is to approve a route rather than a tool, and to make sure the route includes a fast way to ask for something new.
The work migrates to unapproved tools on personal devices within weeks, invisible and ungoverned.
- Prohibition without a lane
- The work migrates to unapproved tools on personal devices within weeks, invisible and ungoverned.
- Approved route with a request lane
- The sanctioned path is faster than the alternative, so people choose it without needing to be virtuous.
The Approved Route
Definition
An approved route is four things stated together for a given class of work: the classification of data permitted, the destination it may reach, the retention that applies once it arrives, and the request lane for work the route does not cover. Any policy missing the fourth element will be routed around, because a person with an uncovered task and a deadline has nowhere to go but outside.
The unit of approval is the route, not the tool. A tool is approved for nothing in general and something in particular. The same product can be an approved destination for internal drafting and a prohibited one for customer records, and stating it that way removes the argument about whether the tool is safe, which is a question with no answer.
When to Use It
Define routes before a tool arrives, not after. Redefine them when a tool gains a new feature that changes its destination, when a supplier changes sub-processors, and whenever the request lane produces the same request three times, because three identical requests mean a route is missing.
Use the request lane as your primary instrument. A lane with no traffic is not evidence of compliance: it is evidence that people have found somewhere else to go.
How to Apply It
- Classify data by what happens if it leaks, in words your colleagues already use, not by a scheme that needs a lookup table.
- State the destination as a named account and tenancy, because the same product under a personal login is a different destination.
- State retention and training use explicitly, including whether the destination retains prompts and for how long.
- Publish a request lane with a named responder and a stated turnaround, and measure the turnaround rather than the compliance rate.
| Class | Example | Permitted destination | Retention |
|---|---|---|---|
| Public | Published guidance, marketing copy | Any reviewed destination | No constraint |
| Internal | Process notes, draft plans | Enterprise tenancy only | Retained under the enterprise agreement |
| Confidential | Customer records, contracts, staff data | Enterprise tenancy with no training use, in region | Deleted on a stated schedule |
| Restricted | Health, biometric, criminal, children's data | No general purpose destination without a specific approval | Governed by the underlying obligation |
Worked example 1 of 3
OmniCorp Logistics banned consumer AI tools after a data review. Four months later Priya Raghunathan surveyed her dispatch teams and found that AI use had risen, not fallen.
- Priya Raghunathan
- You know the tools are not approved. Walk me through what happens at four o'clock on a bad Friday.
- Dispatch supervisor
- I have forty customer notifications to write and forty minutes. The approved route is a template in the portal that does not fit half these cases.
- Priya Raghunathan
- And when it does not fit?
- Dispatch supervisor
- I use my phone. Paste the shipment details, get the wording, retype it in.
- Priya Raghunathan
- Shipment details meaning addresses and customer names.
- Dispatch supervisor
- Yes. I know. There was nowhere to ask for anything better, so I stopped asking.
Priya's response was not enforcement. She built a route: confidential class, enterprise tenancy with training use disabled, thirty-day retention, and a request lane answered within two working days by a named person. Consumer-tool use in dispatch fell to near zero inside a month, because the approved path was now the fast one.
Why This Works
The route removes the asymmetry that drives the behaviour. When the sanctioned path is at least as fast as the alternative, the deferred, invisible risk no longer has to compete with an immediate, visible deadline, and people choose the approved option without needing to be virtuous about it. Controls that rely on individuals absorbing a cost fail on their worst day, which is the day they matter.
Naming the destination as an account rather than a product works because it makes the most common breach legible. Nobody thinks of opening the same familiar interface on a personal login as changing destination. Stating tenancy explicitly is what turns that from an oversight into a decision.
Worked example 2 of 3Optional depth
Marisa Delgado at OmniCorp Financial found her request lane had received two submissions in five months, which she initially reported as strong compliance. Sampling six teams changed the reading: nobody used the lane because the stated turnaround was fifteen working days and the actual turnaround was longer. The lane existed and was useless, which is worse than no lane, because it let the organisation believe it had one. Cutting the turnaround to three days produced nineteen requests in the following six weeks, four of which described uses nobody in governance had known were happening.
Worked example 3 of 3Optional depth
Jo Halvorsen at OmniCorp Studio has no enterprise tenancy and cannot afford one across every tool. Her route is narrower and honest: client names and unpublished client material never leave the two paid accounts she holds, everything else is public class, and the request lane is her, same day, by message. Eleven people, four minutes to define, and it is a real control because it states a destination, a retention position and a way to ask. Scale changes the size of the route. It does not change the four elements.
Edge Cases and NuancesOptional depth
Aggregation defeats classification: forty internal-class documents describing the same customer can constitute a confidential-class picture, and no per-item rule will catch it. Tools embedded in software you already approved arrive without passing any lane at all, which is why feature changes need the same treatment as new products. Client data under a contract may be more restricted than your own scheme, and the stricter obligation governs. And retention is often set by the destination rather than by you, so a route that states a deletion schedule the vendor does not honour is a route that states a fiction.
A named responder with a stated turnaround for work the route does not cover.
- Request lane
- A named responder with a stated turnaround for work the route does not cover.
- Retention
- How long data stays at the destination and whether the vendor honours the schedule.
- Destination
- The named account and tenancy the data may reach, not the product in general.
- Classification
- What happens if the data leaks, stated in words colleagues already use.
Knowledge check
Why does the Approved Route framework insist on measuring the request lane's turnaround rather than its volume?
Common Failure Modes
The route end to end
Alan Brixmoor at OmniCorp Public was asked to enable AI drafting for benefits correspondence, which involves health information, financial circumstances and children's details. He built the route before evaluating any product.
Classification: correspondence content was restricted class, because it routinely contains health and children's data, while the process guidance the team also drafted was internal class. Two classes, two routes, and the separation is what made the rest tractable.
Destination: internal class went to the enterprise tenancy immediately. Restricted class went nowhere for eleven weeks, until a deployment could be stood up in region with training use contractually disabled and sub-processors enumerated. Retention: thirty days for internal, seven for restricted, both verified by asking the supplier to demonstrate deletion rather than assert it. The demonstration failed the first time, which was the single most valuable thing the exercise produced.
Request lane: a named responder, three working days, published alongside the route. In the first quarter it received twenty-six requests. Three revealed uses already running that had never been declared, and two were approved as new routes within a fortnight. Alan's assessment was that the lane, not the restriction, was what brought the shadow work into view.
Decision point
Trevor Okafor at OmniCorp Retail learns that a merchandising team has been pasting supplier pricing agreements into a free AI tool for six months to summarise clause changes. The pricing agreements are confidential class. The team's output has been accurate and their reporting is now three days faster than any other region. What is your first move?
Self-check
Mark the level that describes you today. Nothing is submitted.
| Behaviour | Ready | Developing | Not yet |
|---|---|---|---|
| Responding to discovered shadow use | |||
| Specifying a destination | |||
| Reading the request lane |
Commit
Commit Statement
Complete every line in your own words, then sign and date it. Attach the four elements of one route you are responsible for.
| Window | Field application |
|---|---|
| Days 1 to 7 | Write the four elements for the AI work closest to you, and mark which of them you can evidence rather than assume. |
| Days 8 to 21 | Time the real turnaround on your request lane, end to end, by submitting a genuine request yourself. |
| Days 22 to 30 | Ask three colleagues what they do when the approved path does not fit the deadline, and build the route their answers describe. |
Four elements and a working lane will hold a team's data where it belongs. They will not survive contract negotiation with a supplier who will not enumerate sub-processors, a cross-border transfer question, or an auditor asking you to prove deletion actually occurred rather than that it was promised. Turning a route into contractual and technical assurance you can evidence is the capability the paid programs develop next.
Learner feedback