What Should Companies Do to Enhance Their AI Governance?
As generative AI continues to transform industries from healthcare to advertising, it also introduces new risks around privacy, security, and intellectual property. In this episode, Rikka founder Charlyn Ho breaks down AI governance best practices for organizations using commercially available generative AI tools. In the age of GenAI, a proactive approach to AI governance isn't just smart, it's essential to build trust and reduce risk.
Transcript
What GenAI Risk Actually Looks Like
Generative AI, or GenAI, generates content, text, images, or music, by learning from huge datasets. That's straightforward enough. The risk shows up in how organizations handle the sensitive, confidential, or proprietary data that gets fed into these models.
Because GenAI models often process data on external servers, organizations can lose control over that information, which opens the door to unintentional data leaks or misuse. Using GenAI in business workflows adds two more risks:
- Unlawful discrimination, if bias in the training data isn't properly managed
- IP infringement, if the AI generates content that resembles existing copyrighted material
Six Ways to Build a Real AI Governance Framework
- Fix your agreements. Make sure contracts clearly define data ownership and usage rights, especially for AI-generated data. Add AI-specific clauses on data sharing, IP, and regulatory compliance.
- Align your data retention policy. Set clear rules for retaining and deleting AI-generated data. Regulatory requirements may require you to keep certain data, while customer agreements may require you to delete it within a set window. Reconcile the two before they conflict.
- Review your privacy and security policies. Update them for GenAI-specific risks, including stronger encryption and tighter data access controls. Document how AI-related decisions get made: transparency and accountability are the two principles regulators actually check for.
- Build a data taxonomy. Classify every data type, including AI-generated data, so you can manage each category separately and apply the right retention schedule to it.
- Train your people. A policy only works if people understand it and follow it. Build AI ethics and best practices into your training programs so responsible AI use becomes part of the culture, not just a document.
- Update your terms of service and privacy policy. As customers interact with AI features in your product, be transparent about how their data gets used, including whether it trains your models or a vendor's. Communicate changes proactively. Companies that don't tend to end up with the regulatory scrutiny and lost trust that come with getting caught quiet about it.
In a landscape that's still moving fast, a proactive approach to AI governance isn't optional. It's the only approach that holds up.
If your organization is building an AI governance program from scratch, or checking whether your current one actually covers these six areas, Rikka's AI Governance Assessment is built for exactly that.
What changed, and why
Readability: Cleaned up spoken-transcript patterns throughout: repeated "you wanna" / "you're gonna" became "you should" / "we're going to," the duplicated word in "business workflows flows" was fixed, and long run-on sentences were split. The six best-practice recommendations, originally a string of loosely connected paragraphs, are now a numbered list with a bolded lead-in for each, and the two extra GenAI risks (discrimination, IP infringement) are now bullets instead of one long sentence.
Subheadings: Added two H3s inside "Transcript" (What GenAI Risk Actually Looks Like / Six Ways to Build a Real AI Governance Framework), same pattern as the last two AI Series video pages, since there was no structure under the transcript label at all.
Title and meta: This page was also running long on both, 89 characters on the title and 254 on the description, and the description used an em dash, against house style. Both fixed at the top of the file.
CTA: Replaced the spoken sign-off ("Thanks for joining me, like and subscribe...") with a line pointing to the AI Governance Assessment, consistent with the last two videos. Keep the original sign-off in the video itself.
No change to the substance: all six recommendations are the same guidance Charlyn gave, only restructured and tightened.
















