Use whenRecruiting the minimum viable council — after the sponsor and lead are named, before the first meeting.
OutputA seated council with named people, protected time, and owned first assignments.
1
Minimum viable council
Role
What they bring
What they own
Name
Protected time / week
Executive sponsor
Budget authority or strong influence over it (CEO, COO, CFO, CIO)
Resolving conflicts, connecting the work to organizational priorities, funding decisions
AI enablement lead
Program management capacity and standing to coordinate across functions
Running the program, managing the use-case portfolio, accountability between meetings
IT / security representative
Knowledge of systems, identity, data protection, and vendor technical evaluation
Provisioning, access, integrations, technical support
Frontline workflow representative
Deep knowledge of how the work actually happens
Reality-testing whether proposed solutions are useful, usable, and realistic
Risk / legal / compliance / privacy
Regulatory obligations, contracts, privacy, intellectual property, records, and escalation; may be internal or external
Risk triage, specialist-review triggers, and the review and escalation path
These are five functions, not necessarily five people. In a smaller organization, one person may cover multiple functions and specialist review may be external or on call.
2
Expanded council — larger or regulated organizations
Needed?
Role
What they cover
Who?
HR / learning and development
Role changes, training, communication, adoption
Finance or procurement
Business cases, vendor contracts, budget discipline, benefits validation
Data or analytics
Data availability, quality, permissions, measurement
Operational leaders
From the functions that own priority workflows
For regulated or sensitive work, make the risk / legal / compliance / privacy function a standing seat rather than an on-call reviewer.
3
The council's first assignments
✓
#
Assignment
Owner
Due
1
Inventory current AI use, including unofficial or "shadow" use
2
Establish interim acceptable-use guidance — enough to make experimentation safe, not a final policy
3
Identify important workflows and organizational pain points
4
Define a simple risk-tiering process
5
Select two or three pilot workflows
6
Assign each pilot an owner, users, a baseline, and success measures
7
Determine what tools, data, training, and approvals each pilot requires
8
Establish a feedback and support mechanism
9
Review results and decide what should scale
Do not begin with a comprehensive AI policy or licenses for everyone — these nine generate the information every later decision depends on.
You should now have