AI governance for People teams

    Governance is not the brake. It is the steering. The People teams that stay fast with AI are the ones that decided early what they would never let it decide.

    Matthew Bradburn··

    Most AI governance work in People functions starts with a fear and ends with a policy nobody reads. The fear is real - bias, leakage, EU AI Act, candidate complaints, employment tribunals. The policy is real too. It exists in a Notion page nobody opens after the day it was written. In between, individuals make the actual calls about what AI does in the function, alone, one prompt at a time.

    That is the gap. Not "do we have a policy" but "does the policy meet the work." For the policy document itself, see the AI policy blueprint. This piece is about the operating posture underneath it.

    Steer, don't brake

    The instinct, especially under regulatory pressure, is to treat governance as a brake. Slow things down. Add approvals. Require sign-off. The result is predictable: the work routes around the policy. People still use AI. They just stop telling you about it.

    Good governance asks a different question. Where, in this function, does AI need to be in the loop? Where does it need to be only in the loop, with a human deciding? Where is the line, and who holds it?

    The four boundaries that matter

    Four boundaries matter more than anything else in a People-function AI policy. Get these right and the rest of the document is just paperwork.

    1. Decisions a model never makes alone

    Hiring decisions. Termination decisions. Performance ratings. Compensation calls. Reasonable adjustments and accommodations. Discipline outcomes. These are the six places where the consequence of a wrong call is high, the data is messy, and the bias risk is concentrated. The model can prepare, summarise, suggest, draft. The model never decides. A named human does. Always.

    Write that list down. Put it at the top of the policy. Everything else is detail.

    2. Data the model never sees

    Health information. Disability status. Salary detail tied to identity. Grievance content. Anything covered by special category data under GDPR. Anything covered by an NDA. Anything that, if it leaked, would damage trust permanently.

    The way this gets enforced is rarely "we trust people not to paste it." It is configuration. Approved tools that route to enterprise endpoints with no training. Workflows that strip identifiers before the model sees them. A short list of providers, not a long one.

    3. Outputs the human must always check

    Anything that goes to a candidate. Anything that goes to a regulator. Anything that goes into an employment record. Anything that becomes a written commitment. A model's draft only becomes the deliverable once a human has reviewed and signed off on it. That review is what makes the speedup safe.

    4. Logging that actually exists

    If the team is using AI in the work, you should be able to answer four questions in under five minutes:

    • Which workflows use a model?
    • Which model, and where does it run?
    • Where is the prompt and output history?
    • Who is accountable for each workflow?

    If you can't, you don't have governance. You have aspirations.

    What good looks like inside the team

    Governance shows up in the daily texture of the team, long before anyone rereads the policy doc. The People functions that get this right tend to look the same from inside.

    There is a single page - usually a one-pager, not a deck - that lists every AI workflow the team uses. The owner. The model. The data it touches. Whether it is in pilot, live, or retired. It is updated by the people who run the workflows, not by a central function.

    There is a regular review, monthly or quarterly. Short. The owners walk through what their workflow has done, what it nearly did wrong, what they are changing. New workflows are added. Old ones are retired. The review is boring on purpose. Boring is the goal.

    There is a named person - usually the operations lead, sometimes the CPO, sometimes a senior HRBP - whose job includes "the AI is in good order." Not "the AI strategy." The order of it. The hygiene.

    And there is a culture, slowly built, where surfacing a near-miss is a gift to the team, not a confession. The first time someone says "I almost let the model send that" and gets thanked instead of investigated, the system starts to actually work.

    The trade you are making

    Governance done well is a small tax on speed in exchange for a large reduction in tail risk. That trade is almost always worth it inside a People function. The risk here isn't cash, it's trust, and a People team that loses the company's trust because the model said something it shouldn't, or saw something it shouldn't, takes years to rebuild.

    The teams that move fastest with AI decided early, in writing, what they would never let the model do. Then they went hard on everything else.

    Write your four boundaries down this week. That's the whole first move.

    What this connects to

    Auto-recommended next reads in the People Ops cluster, ranked by shared concepts and headings:

    Common questions

    Why does most People-function AI governance fail?
    Because it gets written once and never checked against the work. Fast way to test it: ask the team when anyone last opened the policy doc. If nobody can answer, that's your diagnosis. The fix isn't a better document, it's a habit: a short recurring review (see the fourth boundary below) that keeps the rules attached to what people are actually doing with AI, not what someone imagined they'd do six months ago.
    What decisions should an AI model never make alone in a People function?
    Six: hiring, termination, performance ratings, compensation, reasonable adjustments and accommodations, discipline outcomes. The model can draft, summarise and suggest on all six. It never gets the final call, a named human does, every time. The way you actually catch a slip isn't a policy re-read, it's the workflow log from the fourth boundary: if a call came out of one of these six workflows with no named human sign-off next to it, that's the violation, and it should show up in minutes, not get found in an audit six months later.
    What data should the model never see?
    Health information, disability status, salary tied to identity, grievance content, anything under GDPR special category, anything under an NDA. The quick test before switching a tool on: does it need to see any of that to do the job? If not, it doesn't get access, whatever the vendor promises about training data. That's a configuration decision made once per tool, not a trust exercise repeated every time someone opens a chat window.
    How do you tell if you actually have governance, not just aspirations?
    Time yourself answering four questions: which workflows use a model, which model and where it runs, where the prompt and output history lives, who owns each workflow. Most teams fail on the third one. They can name the workflows and the model fine, but nobody can actually produce a log when asked. That gap, not the absence of a policy document, is what a tribunal or an external audit finds first.
    11 min

    When reading turns into doing

    The Grain Audit maps one People Ops process end to end, ranks the highest-return automations, and hands you a 90-day plan you keep whether or not we work together.

    Two weeks. GBP 2,000, credited in full against a programme. Three slots a month.

    Book a Grain Audit

    If this resonated, there's more.

    Subscribe to receive new Intelligence pieces as they're published. No noise, just the work.

    By subscribing you agree to our Privacy Policy. Unsubscribe any time.

    Diagnostic

    Where does your operating system stand?

    Take the AI Operating Index, a free 8-pillar diagnostic.

    Begin the index →