The session on Updating & Maintaining Policies & Procedures in the Age of AI highlighted how traditional compliance frameworks must adapt to AI-driven processes. Panelists emphasized that while the structure of policies remains consistent—purpose, scope, roles, and responsibilities—the governance and procedures must expand to account for AI’s unique risks and capabilities.
Lauren Valenzuela described policies as “the same skeleton, just a new nervous system,” underscoring the need to integrate AI oversight into existing compliance structures. Laura Baumann stressed that procedures must broaden to include auditing AI processes, while Aaron Mack noted that AI is more flexible for internal procedures than for client-facing policies.
Governance frameworks such as the NIST AI Framework, EU AI Act, and state-level regulations were cited as useful guides. Panelists warned against “shadow AI”—employees using unapproved tools outside secure environments—and emphasized the importance of enterprise accounts with proper safeguards.
The discussion also addressed human-in-the-loop oversight, defining clear triggers for when AI outputs must be reviewed, and highlighted risks around intellectual property, data privacy, and over-reliance on AI outputs. Ultimately, the panel agreed that the biggest risk may be not using AI at all, as competitors are already leveraging it to identify trends and scale operations.
🧠 Key Takeaways:
- Update Policies & Procedures: Create or revise AI use policies, define roles, and expand procedures to include auditing AI processes alongside human workflows.
- Adopt Governance Frameworks: Leverage elements from NIST, EU AI Act, and state regulations to build tailored compliance frameworks that fit your organization’s use cases.
- Strengthen Oversight & Controls: Prevent shadow AI by approving enterprise tools, define human-in-the-loop triggers, and document ownership/IP rights when AI is used in development.




