Citizen AI Governance · 3 projects

Citizen AI Governance

People will build and use AI on their own. Governance has to make the approved route the easy one, from idea to production.

The problem

Three gaps, one for each stage of a tool’s life inside a company.

  1. Shadow AI on personal licensesPeople already use AI tools through personal accounts and unregistered licenses. IT sees little of it, and blocking it only pushes it further out of sight.
  2. Ideas with no path to a specEmployees spot ideas and problems every day but have no structured way to turn them into a spec someone can prioritize. Prototypes never reach production, and requests arrive with no security check.
  3. Citizen-built apps with no maintainerEmployees build their own tools and automations. When the builder moves on, nobody owns what they left running.

How the three fit

Each project owns one stage and one question. Apps move between them through three hand-offs, and all three read and write the same app catalog. Every number in the demos is synthetic.

Diagram of the three stages, from idea to production. Stage 1, Discover, hands off to stage 2, Decide, when a found tool is formalized. Decide hands off to stage 3, Sustain, once a built app has a named maintenance owner. Sustain loops back to Decide when an app has no owner. All three stages share one app catalog.
  1. 1 · DiscoverShadow AI Discovery & AmnestyWhat's already happening, and what do we do about it?Status: Planned
  2. 2 · DecideInnovation & PRD MarketplaceWhich ideas get built, by whom, and under what conditions?Status: Live
  3. 3 · SustainCitizen App Registry & HandoverIs it still healthy, and who owns it now?Status: Live
One shared app catalog

All three projects read and write the same catalog of apps, so a tool keeps one record from the day it’s found to the day it’s retired.

  • Source
  • discovery
  • self_report
  • portal_request
  • prototype_import
  1. DiscoverDecideFormalize. A tool found on a personal license is triaged: stop, migrate or formalize. Formalize opens a pre-filled submission in the marketplace.
  2. DecideSustainOwner named. Once a marketplace PRD is assigned and built, the app moves to the registry, and it can’t reach production there without a named maintenance owner.
  3. SustainDecideNo owner. An app with no owner triggers a handover, a retirement, or a new marketplace submission.

The three projects

Design principles

  1. 01The approved route must be the fastest routeIf the approved route is slower than the workaround, people take the workaround.
  2. 02Rules decide, the model only assistsFixed rules make every blocking call, so each decision can be explained. The model can add a concern, never clear one.
  3. 03A maintenance owner is a gate, not a fieldNo named owner, no production. An empty field nobody checks protects nothing.
  4. 04Amnesty before enforcementMake it safe to say what you already use. Visibility first, rules second.

The real problem behind this

These projects are generalized and run on synthetic data. The real version of this problem, and what I did about it, is in the Keshet Media Group case study. For the rest of my background, see my résumé.