AI governance
AI clearance: content an AI may use only with permission
Starting questionHow do we control which AI system may use which piece of company information, separately from which person may read it?
Result
Works
AI clearance is a field on each knowledge object. Without explicit clearance, no AI system uses the content.
Through fields in the data model: every knowledge object carries confidentiality, AI clearance, use in the search index, and permitted output channels. Without explicit clearance, no AI system may use an object, and whoever writes does not approve.
What we built
We set up a self-hosted content and knowledge platform. Content lives there as linked knowledge objects rather than as individual web pages.
Every object carries fields for ownership, lifecycle, confidentiality, AI clearance, use in the retrieval index for language models, and permitted output channels. Without explicit clearance, no AI system may use an object.
What it means for business architecture
Governance belongs in the data model, not in a process bolted on afterward. Whoever writes does not approve. People and systems are two separate audiences. That turns an abstract principle of AI governance into something you can check and query.
Lessons learned
- The safe default is “not cleared”. Anything else opens up without anyone noticing.
- Maintaining content and clearing it are two roles. Mixing them means losing control.
- Revoking clearance has to purge the search index too, otherwise the content lives on inside the AI.
- AI clearance
- knowledge management
- data model
- governance