AI Governance

Trust requires more than a policy.

AI governance defines where artificial intelligence may be used, who remains accountable, which information and sources are permitted, how results are tested, and when a system must stop. A policy can describe those decisions. It cannot make them for you.

Why education

Public work raises the consequence.

Education agencies communicate with families, administer programs, interpret policy, manage funding, protect sensitive information, and support decisions that affect students and educators. A weak internal draft can be corrected. An unsupported answer sent to a family or embedded in a workflow can become an institutional action.

That is why governance cannot end with a list of prohibited tools. It must connect acceptable use to actual work, named owners, approved sources, qualified review, monitoring, and correction.

The question is not only whether AI can do the work. It is what must be true before an agency relies on it.
The current gap

The foundation exists. The AI extension does not.

The Education Data Governance Framework, published in May 2026 by the Education Data Governance Collaborative, describes eighty-four capabilities across four domains and reflects work involving data professionals from nineteen states and the District of Columbia.

That framework gives public education a shared vocabulary for data governance. The supplied material notes that it does not address model inventories, training-data provenance, inference governance, or acceptable use of generative systems. That is not a flaw in the foundation. It is evidence that the technology moved faster than the vocabulary.

Agencies cannot wait for a future standard while staff are already using current tools. The practical response is to extend the governance structure they have, not build a competing bureaucracy with a newer logo.

The control environment
01

Purpose and authority

Define the use case, the people affected, the decisions allowed, and the limits of system authority.

02

Information and sources

Specify approved environments, protected information, authoritative material, lineage, and retention expectations.

03

Testing and review

Evaluate accuracy, usefulness, failure cases, and equity with qualified people before wider use.

04

Monitoring and correction

Assign ownership, watch performance, record incidents, correct errors, and preserve a stop mechanism that works.

Familiar questions

Extend the vocabulary rather than replace it.

AI does not require an entirely separate governance discipline. It requires familiar questions applied to technology with a shorter feedback loop and a longer reach.

Who decides, who owns, and who does the work?

A named person remains accountable for an output that leaves the building. Not “the team,” not “the vendor,” and certainly not “the algorithm,” which remains stubbornly unavailable for performance reviews.

How does work move, and who signs off?

Governance includes evaluation before use, review proportional to consequence, incident logging, and periodic reassessment. A one-time approval is not governance. It is a snapshot.

What must be true, and who says so?

Define where AI may be used, what information may enter it, which sources count as authoritative, and which decisions remain off limits regardless of how polished the output looks.

Where does the record live, and what carries the load?

Use approved environments, handle information according to its sensitivity, keep enough history to reconstruct what happened, and make sure the stop button is more than a reassuring sentence in a document.

A workable posture

Govern the consequence, not the novelty.

The same tool can help brainstorm a meeting agenda or help prepare a public response. Those uses may involve the same product, but they do not carry the same consequence. Governance should classify the work, not merely the tool.

Begin with bounded uses. Require stronger evidence as the consequence grows. Grant automated authority gradually. Then keep asking the purpose question: What decision gets better because we did this?

That question pulls the discussion away from impressive demonstrations and toward public responsibility. Which decision improves? Who is affected if the answer is wrong? How quickly would anyone know? The answers determine how much evidence a use case must earn.

Current laws, policies, procurement requirements, and vendor capabilities change. Any production governance framework must be reviewed against current authoritative requirements.

The dependency

AI governance cannot rescue ungoverned data.

A system grounded in sources whose meaning is disputed, quality is unknown, or permissible use is undocumented will produce answers no one can defend. The fluency is not reassurance. It can make uncertainty harder to see.

AI tends to surface every unresolved definition and unclear ownership boundary an agency has been carrying, only faster and sometimes more publicly than anyone planned. The foundation begins with data governance.

Practical starting point: choose a bounded use, name the accountable person, identify approved sources, define required review, and decide in advance what would cause the agency to stop.