Field report 2 · AI governance
Knowledge with clearance: content an AI may only use with permission
How to control which AI system may use which piece of company information, separately from who may read it.
- Status
- Built Built and proven in our own use.
- Published
- Publisher
- SIMO GmbH, Aschaffenburg, Germany
Starting questionHow do we control which AI system may use which piece of company information, separately from which person may read it?
What we built
We set up a self-hosted content and knowledge platform. Content lives there as linked knowledge objects rather than as individual web pages.
Every object carries fields for ownership, lifecycle, confidentiality, AI clearance, use in the retrieval index for language models and permitted output channels. Without explicit clearance, no AI system may use an object.
What it means for business architecture
Governance belongs in the data model, not in a process bolted on afterwards. Whoever writes does not approve. People and systems are two separate audiences. That turns an abstract principle of AI governance into something you can check and query.
Learnings
- The safe default is “not cleared”. Anything else opens up without anyone noticing.
- Maintaining content and clearing it are two roles. Mixing them means losing control.
- Revoking clearance has to purge the search index too, otherwise the content lives on inside the AI.
- AI clearance
- knowledge management
- data model
- governance