Most teams think they face a binary: a six-month governance program or nothing at all. While they debate the perfect framework, shadow AI use spreads, employees paste customer data into public tools, and features ship with no review. There is a third path. A focused one-week sprint can produce a minimum viable policy set, clear role assignments, and lightweight controls that unblock delivery instead of stalling it. Governance does not have to be a fortress to be real, it has to be present, usable, and shipped. Here is the five-day plan that gets you there.
The false choice between a fortress and nothing
When responsible AI comes up, most organizations frame it as a binary. Either you commission a comprehensive governance program that takes two quarters, a working group, and a consultant, or you do nothing formal and hope the teams building with AI use good judgment. Both options fail. The comprehensive program is still in draft when the business has already deployed three models, and the do-nothing path quietly accumulates risk as employees paste customer data into public tools and ship features with no review. The debate over the perfect framework becomes the reason nothing ships, and while it drags on, shadow AI use spreads with zero controls attached to it.
There is a third path, and it is the right one for almost everyone starting out: a one-week sprint that produces a minimum viable governance kit. Not a fortress, a foundation. In five working days a small team can ship the handful of policies that actually matter, assign the roles that make those policies real, and stand up lightweight controls that unblock delivery rather than stalling it. The design principle is that governance should be present, usable, and shipped, not exhaustive. An imperfect policy that everyone follows this month beats a perfect one that lands next year, because the whole point is to attach guardrails to work that is already happening. You iterate the kit later; you cannot iterate a document that was never written.
A five-day sprint to a working kit
Timebox the whole effort to one week and assign each day a single deliverable, an owner, and a "good enough to ship" bar. Resist the urge to make any artifact comprehensive; the goal is a v1 that is live and followed, with a scheduled review to improve it. Keep the artifacts short enough that people actually read them, one to two pages each, and write them in the language of the teams who have to comply.
| Day | Deliverable | Owner | "Good enough" bar |
|---|---|---|---|
| Mon | Acceptable-use policy: approved tools, banned data, when a human must review | Legal + AI lead | 1 page, covers 80% of daily cases |
| Tue | Risk-tiering rubric: classify each use case as low, medium, or high | AI lead | 3 tiers, 5 questions each |
| Wed | Role assignments: named owner, approver, and escalation path per tier | Exec sponsor | Every high-risk system has a named human |
| Thu | Lightweight controls: intake form, review gate for high tier, logging | AI lead + eng | One form, one gate, live in a shared tool |
| Fri | Rollout: publish, brief the org, set the 30-day review date | Exec sponsor + comms | Everyone knows where the kit lives |
Worked example. A 200-person software company had nine AI features in flight and no governance, and legal had been quietly nervous for a month. Instead of chartering a program, the AI lead and general counsel ran the sprint. Monday they shipped a one-page acceptable-use policy naming three approved tools and banning customer PII in any public model. Tuesday they wrote a five-question risk rubric; running their nine use cases through it flagged two as high-risk (an AI that emailed customers directly and one that touched pricing) and the other seven as low. Wednesday every high-risk case got a named approver and an escalation path. Thursday they stood up a single intake form and a mandatory review gate for high-risk launches, wired into the tool the team already used, plus basic logging. Friday they published the kit, ran a 30-minute all-hands, and booked a review for day 30. Total elapsed time: five days. The two genuinely risky features now had a human gate; the seven low-risk ones shipped freely instead of waiting behind a review that did not apply to them. That is the trade the sprint is designed to make.
Run the sprint, ship the kit
- Timebox to one week and name a single exec sponsor who can approve on the spot, because the sprint dies the moment an artifact needs a committee to sign off.
- Write a risk-tiering rubric first and run every live and planned use case through it, so your controls land on the two or three things that actually carry risk instead of taxing everything equally.
- Assign a named human owner and approver to every high-risk system; a policy with no name attached is a wish, not a control.
- Make controls lightweight and native: one intake form, one review gate for the high tier, and basic logging, built into a tool the team already opens daily so compliance is not a detour.
- Ship v1 with a scheduled 30-day review baked in, and tell the org the review date, so "we will improve it" is a commitment on the calendar rather than an excuse to delay launch.
What derails the one-week kit
- Chasing comprehensiveness. Trying to cover every edge case turns a week into a quarter. Fix: aim for the policy that handles 80 percent of daily cases and iterate the rest later.
- Applying the same controls to every use case. A heavy gate on low-risk work breeds resentment and workarounds. Fix: tier first, and reserve the review gate for high-risk systems only.
- Writing policies nobody reads. Ten-page documents in legal language get ignored. Fix: keep each artifact to one or two pages in plain language the teams actually use.
- Leaving roles unnamed. "The team is responsible" means no one is. Fix: attach a named owner, approver, and escalation path to every high-risk system before you publish.
- Shipping and forgetting. A kit with no review date calcifies and drifts out of date. Fix: book the 30-day review at launch and treat it as the first of a recurring cadence.
Have this shipped by Friday
- A one-page acceptable-use policy naming approved tools and banned data.
- A three-tier risk rubric with every live use case already classified.
- A named owner, approver, and escalation path for each high-risk system.
- One intake form and one review gate live in a tool the team already uses.
- A published kit, an all-hands brief, and a booked 30-day review date.