Industry Insights
July 30, 2026

How lean privacy teams build effective AI governance programs

Lean privacy teams succeed at AI governance by sharing the work across experts and integrating into existing processes.

By Anthony Prestia, VP of Privacy at TerraTrue

Many companies developing AI governance programs start with a standalone compliance process owned by the privacy team, which may be nothing more than a single individual. More often than not, this strategy fails because businesses won’t tolerate the burden of a new potential bottleneck in their development process. The governance programs that do tend to succeed distribute compliance work across a group of experts and, wherever possible, integrate into existing business tools and processes.

Even with a proper structure, AI governance programs face common challenges. Most are asked to address AI governance on top of their existing work without an increase in resources and, with AI functionality being added to existing tools, many find it difficult to even know where risk exists.

Below are the strategies I have seen work across a variety of industries, starting with a foundational principle upon which all other strategies depend. The full walkthrough is in the video, and a written version follows.

Establish an AI governance committee

AI governance is an interdisciplinary practice, and programs often fail when a single function is asked to carry the responsibility alone. Tasking one team, like privacy or security, to lead AI governance can be effective but a cross-functional group should be developed to address the risks that don’t fit neatly into expertise of just one function. We commonly see AI governance committees composed of representatives from legal, privacy, security, product, and engineering, though the right composition depends on what makes sense for your organization.

What an AI governance committee should do

The committee's first job is to identify the key AI risks for your organization and set guidelines on how to address them. Each function brings its own lens:

  • The legal representative may think through playbooks related to intellectual property and liability.
  • The security team might consider combating adversarial threats like prompt injection.
  • The privacy team will consider risks related to training AI on personal data and automated decision making.

This group may also identify specific AI tools or vendors that are approved for use across your organization. It might approve AI features within existing tools, or negotiate terms for blanket licenses to LLMs. These approaches help reduce the risk of employees putting confidential information into consumer-grade tools where it may be used for training and other purposes.

Who should sit on the committee

Start with your most senior people in each function that sits on the committee. These representatives will lay the groundwork for the committee – establishing priorities and org-wide risk tolerance – and, over time, you can begin to transition to deputies within those teams who can make decisions and operationalize the program day to day.

How often the committee should meet

Early on, it’s common for the committee to meet on a weekly or monthly basis. But, eventually, the goal is to meet only for one-off high risk situations or to reevaluate your founding principles on a yearly or quarterly cadence.

Integrate AI governance into your existing privacy review process

When assessing risks related to AI in their own products and services, many companies find it best to piggyback on existing privacy and security processes with high adoption.

Privacy teams are already considering risks related to processing personal data and automated decisionmaking. Evaluating algorithmic bias and transparency are a natural extension of that review.

Security engineers are already looking for vulnerabilities in software. Ensure prompt injection is among the risks they evaluate.

Product counsel can be equipped with the knowledge necessary to identify and escalate AI risks to the appropriate teams.

If there are gaps or pain points in your existing processes, this is a good time to address them. The programs we see with the best adoption are the ones that meet business stakeholders where they work. That might mean spending most of your day in Jira or in product planning meetings, or using a tool like TerraTrue to integrate those processes and automatically triage risk.

Consider both regulatory risk and business risks when starting your program from scratch

If you are starting from scratch and not sure where to begin, consider your risk profile in two tiers: regulatory risks and business risks.

Regulatory risks are questions like: Are you processing sensitive data? Do you offer products or services to children? Are you operating in a highly regulated space like finance? If so, compliance with specific regulations should be top of mind.

For business risks, look at the products, services, and data that would have the greatest impact on your bottom line if they were taken away. Some of these may not be inherently high risk, but their impact on the business should elevate their importance.

The goal is to identify your highest risk areas and find the people responsible for them.

Standardize AI terms with your vendors

If you’ve been in the privacy and security space for a while, you’ll instantly recognize the unilateral adoption of AI tools by employees as akin to the “shadow IT” scare of the SaaS boom. Back then, employees were signing up for SaaS platforms and providing them with confidential information without knowledge of IT departments. Now the same is happening with AI.

Nearly every SaaS product has incorporated AI features, and most companies do not have the bandwidth to manually review every single tool. The approach I recommend is to:

  1. Identify each vendor your business uses and determine which incorporate AI features. This might involve a manual review with your procurement team, or it might involve using tooling like TerraTrue.
  2. Group those vendors by risk. Decide which have the most business critical data, like product roadmaps, and which contain the highest risk data, like customer information. Start with those.
  3. Standardize your AI terms in a new addendum and work on training your procurement team to distribute it to new and existing vendors. This should become a natural byproduct of the overall procurement process, so you rarely have to think about it going forward.
  4. Negotiate blanket terms with providers that are commonly requested across the business, so employees have approved options and are less likely to sign up for tools with click-through terms.
  5. Add network-level security. Deploy tools that help you identify when people are using products and services that are not on your approved list.

The key to successful AI adoption is understanding how people want to use the technology and what they want to achieve. Armed with this information, you can help them select the right vendors, negotiate appropriate terms, and build pathways to achieving their goals.

Appropriately scope your AI reviews

Not every AI use case requires the same depth of review and you should focus your efforts on the areas that have the potential for the greatest human impact. Before starting a review it’s worth considering:

  • Does it affect someone's opportunities?
  • Does it reach vulnerable people?
  • Does it involve sensitive personal information?
  • Does it put trust with customers or employees at risk?

The more significant the consequences for individuals, the more you need to focus on careful human review and cross-functional judgment. This is how a lean team delivers outsized value back to the business.

Structured data makes that leverage compound. Jam City's VP of IT encoded years of privacy expertise into a custom AI agent built on TerraTrue's structured data, increasing review coverage 10x and depth 10x while running a lean operation across multiple studios.

What effective AI governance looks like

Effective AI governance is built into the processes your business already runs. It divides the burden across experts, stays agile, gets reevaluated on a regular basis, and meets the business where they are. That is the way you get adoption, and it is the way you identify and address the greatest risks to your business.

See how privacy, security, and AI reviews run inside the workflows your teams already use.

Book a demo

Frequently asked questions

What is an AI governance framework?

An AI governance framework is the set of guidelines, review steps, and ownership decisions that determine how an organization evaluates and approves its uses of AI. For lean teams, the most effective frameworks are built into existing privacy and security review processes rather than run as a separate program.

Who should own AI governance?

No single function should own AI governance alone. In most organizations the mandate goes to the privacy team, which struggles for two reasons: (1) Privacy functions are typically already stretched thin; and (2) AI risks do not fit neatly into the responsibilities of one function. Ownership works best when it is shared across a cross-functional group that includes legal, privacy, security, product, and engineering.

What is an AI governance committee?

An AI governance committee is a small cross-functional group that aligns on goals and risk tolerance for the use of AI across the business. It identifies the key AI risks for the organization, sets guidelines on how to address them, and often approves specific AI tools and vendors for company-wide use.

How often should an AI governance committee meet?

Most groups start by meeting once or twice a month while they establish goals and risk tolerance. Over time the cadence should drop. A mature committee comes together for one-off high risk situations and reevaluates its starting principles once a quarter or once a year.

What is shadow AI?

Shadow AI is the use of AI tools by employees outside of any approved review process. It closely resembles the shadow IT of the SaaS boom, when employees signed up for tools and put confidential information into them. The stakes are higher with AI, because certain tools make it more likely that information could leak or be used for training.

Do you need a separate process for AI reviews?

In most cases, no. If you already run a privacy or security by design program with good adoption, incorporate AI guidelines into those processes rather than starting an entirely new path. Privacy reviews can add algorithmic bias and transparency. Security reviews can add prompt injection. Product counsel can be equipped to escalate AI risks to the right teams.

How do you decide which AI use cases need deeper review?

Prioritize by human impact. The questions that matter are whether the use of AI affects people's opportunities, reaches vulnerable people, involves sensitive personal information, or puts trust with customers or employees at risk. The more significant the consequences for individuals, the more the case warrants careful human review and cross-functional judgment.

Build trust. Build fast. Build with TerraTrue.

Bring clarity to your entire sales process—track deals, automate follow-ups, and close with confidence in one purpose-built platform