--- slug: ai-governance-policy type: pattern summary: "The written instrument by which a family office decides, before deployment, which AI tools it uses, for which tasks, with what data, and under whose oversight." created: 2026-07-14 updated: 2026-07-14 related: family-office-cybersecurity: relation: complements note: AI governance extends the office's data-security discipline to a new class of tool whose risks (model-training exposure, prompt leakage, laundered outputs) the cyber stack's identity and vendor layers do not fully cover. single-truth-source: relation: depends-on note: An office cannot govern the data it feeds to an AI tool if it cannot see that data; the consolidated source of truth is the data-readiness precondition that makes an approved-data list enforceable. spreadsheet-truth-source: relation: contrasts-with note: AI governance fails wherever the office's balance sheet lives in email-borne workbooks rather than a governed system; the shadow-spreadsheet antipattern defeats the data-readiness precondition the policy depends on. decision-rights-charter: relation: uses note: The charter supplies the authority map the policy points to for who may approve an AI platform, authorize a high-risk use case, or sign off on the family-data exposure boundary. reputation-risk-governance: relation: complements note: An AI data leak or a laundered fabrication in a public-facing document is a reputation event before it is an operational one; the two processes share an escalation path and a council-level owner. public-profile-decision: relation: complements note: The family's visibility posture determines how much of its data may touch external models at all; a publicly-named family sets a tighter external-tool boundary than a deliberately private one. investment-policy-statement: relation: complements note: The human-in-the-loop rule for any AI output that informs an allocation echoes the IPS's posture toward unverified claims; both refuse to let an unchecked assertion drive a decision. --- # AI Governance Policy > **Pattern** > > A named solution to a recurring problem. *The written instrument by which a family office decides, before deployment rather than after, which AI tools it will use, for which tasks, with what data, and under whose oversight.* *Also known as: AI use policy, AI acceptable-use policy, responsible-AI policy, family-office AI governance framework.* Someone in the office pasted a manager memo into a consumer chatbot last month to get a quick summary. Nobody authorized it, nobody logged it, and the memo named three funds, two trusts, and a beneficiary by name. The office did not decide to feed that data to an outside model; a junior analyst under deadline decided for it. The office is already using AI. The only open question is whether it's governed. ## Context A family office is small, data-rich, and under time pressure, which is exactly the profile of an organization whose staff adopt new tools ahead of any policy that would govern them. By 2026 the office's controller is drafting memos with a chatbot, the executive assistant is summarizing board packets, and the investment team is running first-pass diligence through a general-purpose model. Some of this is sanctioned. Most of it isn't, because no one has written down what sanctioned would mean. This pattern sits in the operations layer, beside the [Family Office Cybersecurity Stack](family-office-cybersecurity.md) and the [Single Source of Truth](single-truth-source.md). It inherits its authority from the family's governance instruments rather than from the IT budget: an AI Governance Policy is a governance decision about confidentiality, judgment, and delegated authority that happens to concern software, not a procurement decision that happens to concern risk. The advisory literature that converged on the term through 2025 and 2026 frames it the same way, treating responsible AI adoption as a leadership capability the office builds deliberately, not a vendor checklist it signs. The pattern applies to any single- or multi-family office whose staff have access to general-purpose AI tools, which by now is effectively all of them. It applies with particular force to offices holding the concentrated, identity-linked, multi-generational data that makes a family office an attractive target in the first place. ## Problem Ungoverned AI use in a family office fails in three specific ways, and a principal who has not named them will not see them coming. It leaks. Staff paste confidential family data (holdings, beneficiary names, trust structures, medical and travel logistics, draft deal terms) into consumer tools whose default terms permit the vendor to retain and train on the input. The family's most sensitive data crosses into an external model with no contract, no logging, and no way to retrieve it. It launders. An AI model produces a fluent, confident, and occasionally fabricated output (a mis-cited regulation, an invented comparable, a hallucinated grantee track record) and a staffer under deadline pastes it into an investment memo, a tax analysis, or a grant due-diligence file without verification. The fabrication acquires the authority of the office's letterhead and drives a real decision. And it contradicts. A family that has spent a decade building a considered posture on privacy, on how it treats the people its capital touches, and on what it will and won't put its name to, discovers that its staff's ad-hoc AI habits are quietly making decisions at odds with every one of those principles, because the principles were never translated into rules a tool could be held to. Underneath all three is a readiness problem. An office cannot govern the data it feeds an AI tool if it cannot see that data. Where the balance sheet lives in a governed [Single Source of Truth](single-truth-source.md), the policy can name what may and may not be shared; where it lives in the [Spreadsheet Source of Truth](spreadsheet-truth-source.md) antipattern's sea of email-borne workbooks, there is no boundary to enforce. ## Forces - **Staff adopt faster than oversight.** The tools are free, useful, and one browser tab away. A policy that arrives after eighteen months of unsanctioned use is writing rules for a habit already formed, and a policy that bans everything simply drives the habit underground into personal accounts the office can't see. - **Productivity is real and so is the exposure.** The same model that drafts a serviceable first pass of a quarterly letter in ninety seconds is the model whose free tier trains on what it's shown. The office wants the productivity without paying for it in confidentiality, and the two arrive in the same box. - **Data readiness gates everything.** Governing what data touches a model presumes the office knows what data it has and where it lives. An office without a consolidated source of truth has no enforceable notion of "restricted data," because it has no census of the data in the first place. - **Human-in-the-loop costs time.** Requiring a named person to verify every AI output that informs a decision reintroduces exactly the labor the tool promised to remove. Set the requirement too broadly and staff route around it; set it too narrowly and a fabrication reaches a committee. - **The policy must sound like the family, not like a vendor.** An AI policy copied from a corporate template governs a company the family isn't. To bind behavior, the rules have to descend from the family's own principles on privacy, judgment, and reputation, which means the family has to be in the room when they're written. ## Solution Write a short, enforceable policy that tiers AI use cases by risk, names an owner, and rests on a data-readiness foundation. Keep it to a few pages a busy analyst will actually read, and route it through the family's governance rather than the IT vendor. The working policy has five moving parts: 1. **A data-readiness precondition.** Before the office governs AI, it establishes what it is governing: a consolidated [Single Source of Truth](single-truth-source.md), a data classification (public / internal / restricted / household-private), and named data-governance roles. AI cannot be governed against shadow spreadsheets. 2. **A risk-tiered use-case map.** Not every AI use carries the same exposure, and a flat rule (ban it all, or allow it all) fails at both ends. Tier the uses and scale the oversight to the tier. 3. **An approved-platform list.** The office names the specific tools staff may use and the tier each is cleared for, favoring enterprise agreements whose contract terms forbid training on the office's inputs over consumer tools whose defaults permit it. 4. **A human-in-the-loop rule.** Any AI output that informs an investment, tax, legal, or family-facing decision is treated as an unverified draft until a named, competent human has checked it. The rule descends from the same evidence discipline the [Investment Policy Statement](investment-policy-statement.md) applies to any unverified claim. 5. **A named owner and a recertification cadence.** One person (typically the COO or chief of staff, under the authority the [Decision Rights Charter](decision-rights-charter.md) assigns) owns the policy, approves platforms and high-risk exceptions, and re-reviews the whole thing on a fixed cadence as the tools change. The risk tiers are the load-bearing part: | Tier | Representative use | Data permitted | Oversight | |---|---|---|---| | **Low** | Summarizing a public document; drafting non-confidential correspondence; general research on public information | Public and internal-only data; nothing classified restricted or household-private | Approved platform; no per-use review; staff self-serve | | **Medium** | Drafting an internal memo; first-pass analysis on de-identified figures; structuring a document from the office's own material | Internal data, and restricted data only after de-identification (no names, entities, or account numbers) | Approved enterprise platform with no-training terms; named-role sign-off on what gets de-identified; output labeled AI-drafted | | **High** | Anything informing an investment, tax, legal, or family-facing decision; diligence on a manager or grantee; analysis of the family's actual holdings | Restricted or household-private data only inside a contractually walled enterprise tenant, or not at all | Mandatory human-in-the-loop verification by a competent reviewer; owner approval for the use case; logged; no consumer tools, ever | The sequencing follows the tiers. An office that has not yet stood up its source of truth starts by permitting Low-tier use on an approved platform while it builds the data foundation the Medium and High tiers require. The High tier stays closed until the enterprise-tenant contracts, the classification scheme, and the human-in-the-loop discipline are all actually in place, not merely written down. > **⚠️ Contested ground** > > Two questions divide practitioners. The first is whether a family office should ever let its restricted data touch an external model at all, even a contractually walled enterprise tenant with no-training terms. One camp treats a well-negotiated enterprise agreement as sufficient; another holds that the only safe posture for a family's most sensitive data is a self-hosted or on-premise model the office fully controls, and that any external tenant is a residual risk sized to the family's profile. The second question is whether to ban consumer tools outright or to permit de-identified use. A hard ban is simpler to enforce and easier to audit; a de-identification allowance captures more productivity but depends on staff reliably stripping identifiers under deadline, which is exactly the discipline that fails first. Neither answer is unanimous, and the right one depends on the family's visibility posture (see [Public Profile Decision](public-profile-decision.md)), its appetite for building versus buying, and how much it trusts a de-identification step it cannot fully verify. ## How It Plays Out A second-generation single-family office at roughly $900M, ten staff, a foundation making $12M of annual grants, and a principal whose name appears on a university building. The COO learns, during an unrelated review, that an analyst has spent six months running manager diligence through a consumer chatbot's free tier, pasting in fund memos that named holdings, co-investors, and in two cases the family's own trust entities. Nothing has leaked that anyone can prove. But the office has no idea what the vendor retained, and the free-tier terms permitted training on every word of it. The office writes a four-page policy over a single quarter, and routes it through the family council rather than the IT contractor, because the council is where the family's privacy posture lives. The data foundation is already sound: the office runs a consolidated source of truth with a four-level classification scheme, so "restricted data" already means something enforceable. The policy names the COO as owner. It clears two approved platforms, both enterprise tiers with contractual no-training terms and single-tenant data isolation, at a combined cost of about $28K a year across the ten seats, which is a rounding error against the balance sheet. It tiers the use cases on the table above. It requires that any AI output feeding an investment-committee memo or a grant due-diligence file carry a named reviewer's sign-off, and it logs High-tier uses. The analyst's workflow moves onto the enterprise platform inside a week; the diligence he was doing is not just permitted but faster, because the walled tenant lets him paste the real memos he had been laundering through a consumer tool anyway. The near-miss that prompted the whole exercise becomes a governed, logged, contractually protected version of the work he was already doing. A second example, in the antipattern direction. A third-generation office at $2.4B, fifteen staff, no policy, and a standing assumption that "we don't really use AI here." In practice half the office uses consumer tools daily. During diligence on a $30M direct investment, an associate asks a chatbot to summarize the target's regulatory history and pastes the result, including a confidently stated but entirely fabricated consent decree that the target had never been subject to, into the investment-committee memo. The committee, reading the memo as the office's own verified work, spends a contentious meeting on a decree that doesn't exist and nearly kills a sound deal over it. Separately, and unnoticed for months, the family's philanthropy lead has been drafting grant reports in a consumer tool using real grantee names and financials, feeding a stream of the foundation's confidential partner data into a model whose terms permitted retention. The office discovers the second problem only when a peer family's near-identical exposure makes the trade press. The repair builds exactly the policy above, and takes the better part of a year, because retrofitting governance onto a formed habit is slower than governing it from the start. The prevention would have cost four pages and a quarter. ## Consequences **Benefits.** The family's confidential data stops crossing into external models by accident, because there's a named boundary and an approved-platform list that make the safe path also the easy one. Fabrications get caught at the human-in-the-loop gate before they reach a committee, so the office captures the tool's speed without laundering its errors into decisions. The office's AI use starts descending from the family's actual principles rather than contradicting them under deadline. And the office holds a defensible governance record: a council that can show a written policy, a named owner, a classification scheme, and a log of high-risk use has met a duty-of-care standard a co-trustee or a foundation regulator can recognize, which the office running on "we don't really use AI here" cannot. **Liabilities.** A policy nobody enforces is worse than none, because it manufactures the appearance of governance while the shadow usage continues; the named owner and the recertification cadence are the parts most likely to lapse, and the parts that matter most. The human-in-the-loop rule reintroduces real labor, and set too broadly it drives staff back to ungoverned personal tools where the friction is lower. The policy presumes a data-readiness foundation many offices have not built, so for those offices the honest first step is the [Single Source of Truth](single-truth-source.md), not the AI policy. The approved-platform contracts and the enterprise licenses are a standing cost the office defends year after year against the memory of the free tier that did almost the same thing. And the tools move faster than any policy: a document written against 2026's models needs re-reading against next year's, and an office that writes the policy once and shelves it has a governance artifact that ages into fiction. The deeper second-order effect is cultural. An office that governs its AI use deliberately signals to its most trusted advisors (counsel, the OCIO, the foundation's partners) that it treats its own operations with the same seriousness it expects of them, and that signal compounds across every diligence-sensitive relationship the family holds. An office whose AI habits are an accident of who adopted what signals the opposite, and pays for it the first time an unverified output or an uncontracted leak becomes visible outside the office walls. ## Sources - National Institute of Standards and Technology, [*AI Risk Management Framework (AI RMF 1.0)*](https://www.nist.gov/itl/ai-risk-management-framework), 2023 — the standards-body framework whose Govern / Map / Measure / Manage structure underlies this entry's treatment of AI governance as an owned, tiered, recertified program rather than a one-time policy document. - International Organization for Standardization and IEC, [*ISO/IEC 42001:2023 — Artificial intelligence management system*](https://www.iso.org/standard/81230.html) — the international management-system standard that establishes the named-owner, control, and continual-review discipline this entry's five-part policy structure reflects. - OECD, [*Recommendation of the Council on Artificial Intelligence (OECD AI Principles)*](https://oecd.ai/en/ai-principles) — the intergovernmental principles (transparency, accountability, human oversight) that ground this entry's human-in-the-loop rule and its insistence that an AI policy descend from the organization's own values. - Kirby Rosplock, [*The Complete Family Office Handbook*](https://openlibrary.org/works/OL20347629W), 2nd ed., Wiley, 2020 — the operating-handbook treatment of the family office as a governed operating unit, the frame within which this entry situates an AI policy as an operations instrument inheriting authority from the family's governance rather than from its IT function. --- *This entry describes a structural pattern and is not legal, tax, or investment advice. Consult qualified counsel and tax advisors licensed in your jurisdiction before adopting any structure described here.* --- - [Next: Family Office Exclusion (SEC Rule 202(a)(11)(G))](family-office-exclusion.md) - [Previous: Family Office Cybersecurity Stack](family-office-cybersecurity.md)