AI Risk Management: Comprehensive AI Use Policies are a “Must Have”

by John Jenkins

September 28, 2026

While almost every company is using AI in some way, this Goodwin memo says that few are doing what’s necessary to govern it effectively.  In particular, the memo notes that research shows that only 38% of businesses enterprises have instituted comprehensive policies defining acceptable AI use, and only 6% have instituted a policy governing AI use at the board level.  In order to address these and other AI-related risks, the memo recommends that companies take the following actions to beef up their AI governance efforts:

– Adopt an enterprise AI acceptable use policy. Every company needs a customized policy that defines approved and prohibited tools; rules for confidential, proprietary, and personal data, as well as the development and protection of intellectual property; procurement and vendor-diligence requirements (training rights, retention, and zero-data-retention configurations); human-review requirements for AI output; and clear consequences. This applies whether a company is building AI systems, deploying them as part of its customer offerings, or simply using them for internal purposes. The acceptable use policy provides a framework within which all of a company’s AI tools can operate safely. It is the single highest-leverage document in AI governance.

– Implement a board-specific AI use policy. Directors’ own use of AI raises distinct issues, including the confidentiality of board materials, attorney-client privilege and work-product waiver, an expanded and text-searchable corporate record, and deliberative candor. A board policy should address approved enterprise-grade tools, prohibited consumer tools, rules for privileged material, protocols for recordings and AI-generated minutes, and retention with legal-hold overrides.

– Formalize board oversight of AI governance. Boards should assign AI oversight to the full board or a designated committee, put management’s AI governance program on a regular reporting cadence (adoption metrics, incidents, shadow-AI findings, and regulatory developments), build director AI literacy, and confirm that D&O coverage reaches AI-related claims.

The memo says that an acceptable use policy, a board AI policy, and structured board oversight of AI governance represent minimum standards for 2027.