Your AI Policy Isn't the Problem. Running It Alone Is.
Key takeaways from a July webinar with RIMÔN Law for association executives on why AI policy and governance have to work together, and what belongs in each.
Mark Franco (Rimôn Law) and I spent an hour this week with association executives on a question I hear in almost every consult: "Are we even allowed to put that in ChatGPT?" The honest answer is usually "it depends," and the thing it depends on is whether your association has a policy and a governance system working together, not just a policy sitting in a shared drive nobody has opened since it was approved.
Here's the distinction that shaped the whole session, and the one I'd want every association executive to walk away with.
AI policy and AI governance are not the same thing
AI policy is the rulebook. It's the written statement of what people can and can't do with AI.
AI governance is the system that makes those rules real and keeps them working. It's who's in charge, how decisions get made, and how the organization actually runs this day to day.
A policy without governance behind it asks your staff to remember and enforce every rule themselves: never paste member data into a public tool, never upload the dues file, never put certification items into a chatbot, never load board minutes. That list only gets longer as AI use spreads through your organization, and the longer it gets, the more you're asking individual staff to police themselves on something the organization should be catching automatically.
Governance is what moves that burden off the individual and onto the system. The stronger your governance, the shorter your policy can afford to be.
Why this is urgent now, not eventually
Three things came up in the session that I think every association executive should sit with:
Regulation is accelerating, and it scales with harm. Lawmakers are drafting rules that apply more scrutiny where the stakes are higher, particularly HR, finance, and healthcare-adjacent functions. If your association touches certification, membership eligibility, or employment decisions, you're closer to that scrutiny than you might think.
"Shadow AI" is already inside your organization. A staff member signs up for a tool on their own. The account is personal, not managed. Prompts may be retained to train the model unless someone changes a default setting nobody knew to look for. There's no admin visibility, no logging, no shared rules. It's fine for public information. It is not fine for member data, and your organization is responsible for the output either way.
Hallucinations have real, billed consequences now. Controlled studies still show hallucination rates of 3 to 27 percent. Air Canada was held responsible by a tribunal after its chatbot told a passenger he qualified for a bereavement fare that didn't exist. U.S. courts imposed more than $145,000 in AI hallucination sanctions in the first quarter of 2026 alone. "The AI hallucinated" is getting harder to use as a defense once a tool is doing customer-facing work without guardrails, testing, or disclaimers behind it.
None of this is theoretical for associations. Your vendors, your event platforms, and your own staff are already using AI in ways that touch your data and your members, whether or not you've written a policy yet.
The three things governance actually has to cover
Governance isn't one thing. In the webinar we broke it into three:
- Risk mitigation. Someone has to anticipate risk, own it, and monitor it. Not "AI is IT's problem" — a named person or committee.
- Technical safeguards. Managed sign-in through your organization's account, an enterprise tier with a no-training guarantee, permissions that don't let AI reach further than the user already can, and logging so use is reviewable after the fact.
- Clean data. One source of truth, not five copies of the employee handbook. Labeled and organized, so both the AI and your people know what a document actually is.
That third one surprises people. Data governance is the foundation AI governance sits on. If your records are duplicated, outdated, or scattered across folders, no policy will fix what the AI confidently gets wrong, because AI doesn't fact-check your data against reality. It trusts it.
I recommend creating a list of potential risks your association could face in using AI tools — from simple chats to member-facing chatbots, AI agents, and AI assistants — and then assessing the likelihood of those events occurring. You can divide up the risks into five types: technical, operations, strategy, brand/reputation, and legal/people/compliance. Then score each risk by how likely it is for your association (very likely, likely, possible), and start with the very likely risks. For most associations, that means member data in public tools, no approved-tools list, and no human review before AI output goes out the door.
The twelve sections a real AI policy needs
Once governance is doing its job, the policy itself gets a lot more manageable. Here's what belongs in it:
| Section | What it settles |
|---|---|
| Purpose and scope | Who it covers: staff, contractors, vendors, volunteers, board |
| Governance and oversight | Who owns the policy, the review cycle, who enforces it |
| Ethical use | Disclosure, checking for bias and hallucinations, human accountability |
| Data privacy and security | Prohibited data, anonymization, a tool approval process |
| Member and speaker content | Permission before their material goes into any tool |
| Copyright and IP | What AI may and may not touch |
| Human oversight | A named person reviews and owns every output |
| Training and awareness | No official use until staff complete the basics |
| AI in meetings and recordings | Rules for notetakers in board, committee, and member settings |
| AI agents and automation | Governance for tools that act on their own, not just chat |
| Approved tools list | The short list of what's allowed, kept current |
| Incident reporting | What to do the moment something goes wrong |
Two of these deserve a second look before you finalize anything. First, copyright: courts have consistently held that copyright protects human authors, not AI output on its own. The U.S. Copyright Office has been clear that a prompt doesn't earn protection; your ideas, your authorship, and your modification do. Second, privilege: in US v. Heppner, the court found AI prompts aren't generally protected by attorney-client privilege or work product doctrine, and your AI vendor's contractual promises don't change that. Neither of these is a reason to avoid AI. They're reasons to be specific about what goes into it.
Where to start
You don't need all of this built by Friday. Start here:
- Name a governance owner. Not a committee that meets quarterly — one person who's actually accountable.
- Build the risk register. Score it, focus on the 4s and 5s first.
- Close the shadow AI gap. A one-page staff guide and a way to request a new tool beats a ban nobody follows.
- Train twice a year, minimum. Record it for new hires. Pin a reminder somewhere staff actually look.
- Bring in counsel where it counts. Data privacy, retention, IP, and vendor contracts are worth a legal read before you finalize.
The associations that get this right aren't the ones with the longest policy. They're the ones where the governance is doing enough work that the policy can stay short, current, and something staff actually remember.
If you want to talk through where your association stands, Mark and I are both easy to find. My details and the full slide deck are at cathylada.com/services/ai.
Written by
Dr. Cathy Lada, D.Sc., CAE, AAiP
Content creator and writer sharing insights and stories.
