Lada Consulting

Your AI Policy Isn't the Problem. Running It Alone Is.

AI

Your AI Policy Isn't the Problem. Running It Alone Is.

Key takeaways from a July webinar with RIMÔN Law for association executives on why AI policy and governance have to work together, and what belongs in each.

D
Dr. Cathy Lada, D.Sc., CAE, AAiP
7 min read

Mark Franco (Rimôn Law) and I spent an hour this week with association executives on a question I hear in almost every consult: "Are we even allowed to put that in ChatGPT?" The honest answer is usually "it depends," and the thing it depends on is whether your association has a policy and a governance system working together, not just a policy sitting in a shared drive nobody has opened since it was approved.

Here's the distinction that shaped the whole session, and the one I'd want every association executive to walk away with.

AI policy and AI governance are not the same thing

AI policy is the rulebook. It's the written statement of what people can and can't do with AI.

AI governance is the system that makes those rules real and keeps them working. It's who's in charge, how decisions get made, and how the organization actually runs this day to day.

A policy without governance behind it asks your staff to remember and enforce every rule themselves: never paste member data into a public tool, never upload the dues file, never put certification items into a chatbot, never load board minutes. That list only gets longer as AI use spreads through your organization, and the longer it gets, the more you're asking individual staff to police themselves on something the organization should be catching automatically.

Governance is what moves that burden off the individual and onto the system. The stronger your governance, the shorter your policy can afford to be.

Why this is urgent now, not eventually

Three things came up in the session that I think every association executive should sit with:

Regulation is accelerating, and it scales with harm. Lawmakers are drafting rules that apply more scrutiny where the stakes are higher, particularly HR, finance, and healthcare-adjacent functions. If your association touches certification, membership eligibility, or employment decisions, you're closer to that scrutiny than you might think.

"Shadow AI" is already inside your organization. A staff member signs up for a tool on their own. The account is personal, not managed. Prompts may be retained to train the model unless someone changes a default setting nobody knew to look for. There's no admin visibility, no logging, no shared rules. It's fine for public information. It is not fine for member data, and your organization is responsible for the output either way.

Hallucinations have real, billed consequences now. Controlled studies still show hallucination rates of 3 to 27 percent. Air Canada was held responsible by a tribunal after its chatbot told a passenger he qualified for a bereavement fare that didn't exist. U.S. courts imposed more than $145,000 in AI hallucination sanctions in the first quarter of 2026 alone. "The AI hallucinated" is getting harder to use as a defense once a tool is doing customer-facing work without guardrails, testing, or disclaimers behind it.

None of this is theoretical for associations. Your vendors, your event platforms, and your own staff are already using AI in ways that touch your data and your members, whether or not you've written a policy yet.

The three things governance actually has to cover

Governance isn't one thing. In the webinar we broke it into three:

  • Risk mitigation. Someone has to anticipate risk, own it, and monitor it. Not "AI is IT's problem" — a named person or committee.
  • Technical safeguards. Managed sign-in through your organization's account, an enterprise tier with a no-training guarantee, permissions that don't let AI reach further than the user already can, and logging so use is reviewable after the fact.
  • Clean data. One source of truth, not five copies of the employee handbook. Labeled and organized, so both the AI and your people know what a document actually is.

That third one surprises people. Data governance is the foundation AI governance sits on. If your records are duplicated, outdated, or scattered across folders, no policy will fix what the AI confidently gets wrong, because AI doesn't fact-check your data against reality. It trusts it.

I recommend creating a list of potential risks your association could face in using AI tools — from simple chats to member-facing chatbots, AI agents, and AI assistants — and then assessing the likelihood of those events occurring. You can divide up the risks into five types: technical, operations, strategy, brand/reputation, and legal/people/compliance. Then score each risk by how likely it is for your association (very likely, likely, possible), and start with the very likely risks. For most associations, that means member data in public tools, no approved-tools list, and no human review before AI output goes out the door.

The twelve sections a real AI policy needs

Once governance is doing its job, the policy itself gets a lot more manageable. Here's what belongs in it:

SectionWhat it settles
Purpose and scopeWho it covers: staff, contractors, vendors, volunteers, board
Governance and oversightWho owns the policy, the review cycle, who enforces it
Ethical useDisclosure, checking for bias and hallucinations, human accountability
Data privacy and securityProhibited data, anonymization, a tool approval process
Member and speaker contentPermission before their material goes into any tool
Copyright and IPWhat AI may and may not touch
Human oversightA named person reviews and owns every output
Training and awarenessNo official use until staff complete the basics
AI in meetings and recordingsRules for notetakers in board, committee, and member settings
AI agents and automationGovernance for tools that act on their own, not just chat
Approved tools listThe short list of what's allowed, kept current
Incident reportingWhat to do the moment something goes wrong

Two of these deserve a second look before you finalize anything. First, copyright: courts have consistently held that copyright protects human authors, not AI output on its own. The U.S. Copyright Office has been clear that a prompt doesn't earn protection; your ideas, your authorship, and your modification do. Second, privilege: in US v. Heppner, the court found AI prompts aren't generally protected by attorney-client privilege or work product doctrine, and your AI vendor's contractual promises don't change that. Neither of these is a reason to avoid AI. They're reasons to be specific about what goes into it.

Where to start

You don't need all of this built by Friday. Start here:

  1. Name a governance owner. Not a committee that meets quarterly — one person who's actually accountable.
  2. Build the risk register. Score it, focus on the 4s and 5s first.
  3. Close the shadow AI gap. A one-page staff guide and a way to request a new tool beats a ban nobody follows.
  4. Train twice a year, minimum. Record it for new hires. Pin a reminder somewhere staff actually look.
  5. Bring in counsel where it counts. Data privacy, retention, IP, and vendor contracts are worth a legal read before you finalize.

The associations that get this right aren't the ones with the longest policy. They're the ones where the governance is doing enough work that the policy can stay short, current, and something staff actually remember.

If you want to talk through where your association stands, Mark and I are both easy to find. My details and the full slide deck are at cathylada.com/services/ai.

D

Written by

Dr. Cathy Lada, D.Sc., CAE, AAiP

Content creator and writer sharing insights and stories.