How Companies Can Improve AI Governance
As generative AI continues to transform industries from healthcare to advertising, it also introduces new risks around privacy, security, and intellectual property. In this episode, Rikka founder Charlyn Ho breaks down AI governance best practices for organizations using commercially available generative AI tools. In the age of GenAI, a proactive approach to AI governance isn't just smart, it's essential to build trust and reduce risk.
Transcript
What GenAI Risk Actually Looks Like
Generative AI, or GenAI, generates content, text, images, or music, by learning from huge datasets. That's straightforward enough. The risk shows up in how organizations handle the sensitive, confidential, or proprietary data that gets fed into these models.
Because GenAI models often process data on external servers, organizations can lose control over that information, which opens the door to unintentional data leaks or misuse. Using GenAI in business workflows adds two more risks:
- Unlawful discrimination, if bias in the training data isn't properly managed
- IP infringement, if the AI generates content that resembles existing copyrighted material
Six Ways to Build a Real AI Governance Framework
- Fix your agreements. Make sure contracts clearly define data ownership and usage rights, especially for AI-generated data. Add AI-specific clauses on data sharing, IP, and regulatory compliance.
- Align your data retention policy. Set clear rules for retaining and deleting AI-generated data. Regulatory requirements may require you to keep certain data, while customer agreements may require you to delete it within a set window. Reconcile the two before they conflict.
- Review your privacy and security policies. Update them for GenAI-specific risks, including stronger encryption and tighter data access controls. Document how AI-related decisions get made: transparency and accountability are the two principles regulators actually check for.
- Build a data taxonomy. Classify every data type, including AI-generated data, so you can manage each category separately and apply the right retention schedule to it.
- Train your people. A policy only works if people understand it and follow it. Build AI ethics and best practices into your training programs so responsible AI use becomes part of the culture, not just a document.
- Update your terms of service and privacy policy. As customers interact with AI features in your product, be transparent about how their data gets used, including whether it trains your models or a vendor's. Communicate changes proactively. Companies that don't tend to end up with the regulatory scrutiny and lost trust that come with getting caught quiet about it.
In a landscape that's still moving fast, a proactive approach to AI governance isn't optional. It's the only approach that holds up.
If your organization is building an AI governance program from scratch, or checking whether your current one actually covers these six areas, Rikka's AI Governance Assessment is built for exactly that.
















