Join our Newsletter — 33% off our NHI Course

What should organisations do when AI initiatives span security, privacy, risk, and compliance teams

Organisations should assign clear ownership, define approval paths, and create a shared policy for data use, access, retention, and escalation. When AI spans multiple functions, responsibility often fragments unless governance is explicit. The strongest approach is to align security, privacy, legal, and business teams around a single operating model that sets boundaries before projects scale.

Why AI initiatives need a single operating model

When AI work crosses security, privacy, risk, legal, and compliance functions, the main failure mode is not usually a missing control, it is fragmented authority. Each team may approve one part of the design, but no one owns the end-to-end decision on data use, access boundaries, retention, exception handling, or escalation. A single operating model prevents projects from drifting into inconsistent local approvals.

That operating model should define which decisions are centralised, which are delegated, and which require joint review. It also needs a clear accountable owner for the programme, because shared concern is not the same as shared responsibility. Without that separation, teams can over-review low-risk activity while missing the decisions that actually create exposure.

For AI governance to work in practice, the policy needs to be concrete enough to guide project teams on day one. An AI agent security policy template is useful because it translates governance intent into operational rules for registration, access, oversight, tools, monitoring, and retirement.

How shared policy should handle data, access, and escalation

A useful shared policy does three things well. First, it sets the boundary for what data may be used, including whether sensitive, regulated, or customer data can enter prompts, fine-tuning, retrieval, or evaluation workflows. Second, it defines access rules, so project teams know who can approve use of systems, connectors, datasets, and outputs. Third, it codifies when exceptions must be escalated rather than handled informally.

Retention and deletion deserve the same clarity. AI initiatives often create secondary data copies in logs, vector stores, prompt histories, test sets, or model artefacts, and those copies can outlive the original business need. The enterprise AI copilot security guide is relevant here because it frames oversharing, connector control, and monitoring as governance problems, not just tooling problems.

Where AI touches regulated personal data, privacy review should not be bolted on at the end. The governance model needs to support purpose limitation, minimisation, and documented review of data flows before deployment. For teams handling EU personal data, the GDPR is a practical anchor for data-use, retention, and impact assessment decisions.

What good cross-functional governance looks like in practice

Good governance is visible in the operating rhythm, not only in documents. Teams should know who owns the intake process, who can approve a pilot, what evidence is required before production, and which changes trigger re-review. The best programmes treat security, privacy, risk, legal, and compliance as a coordinated control plane around the business owner, rather than as sequential blockers.

The hard part is keeping the process proportionate. If every AI use case needs bespoke committee review, teams will route around the process. If there is no review at all, shadow AI spreads faster than governance can catch up. The practical answer is tiered review, with higher scrutiny for higher data sensitivity, broader access, external exposure, or more autonomous behaviour.

For organisations looking for a formal benchmark for AI programme governance, ISO/IEC 42001:2023 gives a useful structure for accountability, risk treatment, and repeatable oversight across functions.

Risk and Threat Considerations

When governance is split across teams, the risk is cumulative: one group may approve data access, another may approve deployment, and nobody may own the combined exposure. That creates blind spots around sensitive data leakage, excessive access, weak retention, and inconsistent exception handling. AI projects then accumulate risk quietly because the control gaps sit between functions.

Failure mechanism: fragmented approvals, unclear ownership, and weak escalation paths allow one team’s assumptions to override another team’s safeguards, especially when projects move quickly from pilot to production.

Impact: organisations can expose regulated data, retain material artefacts longer than intended, and ship AI capabilities without a clear accountable decision trail, which makes incidents harder to contain and explain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022, ISO/IEC 42001:2023 and GDPR define the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 27001:2022 A.5.15 — Access control AI governance must define who can approve and use sensitive data and systems.
A.5.34 — Privacy and protection of PII The question includes privacy ownership and data-use boundaries across teams.
A.5.24 — Information security incident management planning and preparation Shared escalation paths are central when AI issues span several governance teams.
Recommendation — Define access rules for AI projects and enforce them before data or tools are approved. Require privacy review for AI uses that process personal data or create new data flows. Document escalation and incident ownership for AI exceptions, misuse, and data exposure.
ISO/IEC 42001:2023 AI management system Cross-functional AI oversight needs a structured management system and clear accountability.
Recommendation — Establish an AI management system that assigns owners, approvals, and review gates across functions.
GDPR Art.25 — Data protection by design and by default AI initiatives often require privacy and data-use decisions before deployment.
Art.35 — Data protection impact assessment AI projects spanning multiple teams often need formal risk review for personal data use.
Recommendation — Build privacy review into AI design so data minimisation and defaults are set up front. Perform a DPIA when AI processing is likely to create high privacy risk.
NIST SP 800-53 Rev 5 PM-9 — Risk Management Strategy The question is about aligning multiple teams around a single governance model.
AC-3 — Access Enforcement Shared AI governance must still enforce who may access data, tools, and outputs.
AU-6 — Audit Record Review, Analysis, and Reporting Cross-functional governance needs evidence of approvals, exceptions, and escalation decisions.
Recommendation — Define one risk strategy for AI initiatives so security, privacy, and compliance decisions stay aligned. Enforce access decisions consistently across AI platforms, datasets, and integrations. Review AI audit records to confirm that approvals and exceptions are traceable.
NIST AI RMF GOVERN The subject is AI governance across functions and decision-making roles.
Recommendation — Use the governance function to assign accountability, review paths, and escalation for AI use.

Practitioner Guidance

What to prioritise: Name one accountable owner for the operating model, then define which decisions require joint sign-off versus delegated approval. If that distinction is not written down, the governance process will be interpreted differently by each function.

What to verify: Check that every AI use case has an intake record, a documented data-use decision, an access approval path, a retention rule, and an exception route. The useful test is whether a project team can answer those questions without improvising.

Decision rule: If the use case touches personal, confidential, customer, or externally shared data, require explicit review before production. If it only uses low-risk internal data, use a lighter path but keep the same ownership model.

Practitioner takeaway: Cross-functional AI governance succeeds when teams share policy, not ambiguity, and when one owner is responsible for turning separate reviews into one enforceable operating model.