Sidecar Blog

Beyond the 30-page policy: A practical approach to AI governance

Written by Sidecar Team | Jul 22, 2026 10:30:00 AM

Many association leaders face a common instinct when a new technology arrives. They want to protect the organization by building a wall of rules. When artificial intelligence began to permeate the professional world, the immediate response for many was to draft a comprehensive AI policy. This often resulted in documents that were technically thorough but practically useless. At the American Speech-Language-Hearing Association (ASHA), the initial attempt at an AI policy followed this path. The document was sent to the IT security unit, where it was redlined and expanded until it reached 30 pages. It was a document that covered every possible risk but was so voluminous that no staff member would ever realistically read it. This is the trap of fear-based governance. It prioritizes the avoidance of mistakes over the pursuit of progress. To drive meaningful AI adoption, associations must move beyond the 30-page binder and toward a framework of guiding principles that empower staff to experiment safely.

The failure of fear-based risk management

Traditional risk management in the association sector often relies on exhaustive documentation. The goal is to anticipate every negative outcome and create a rule to prevent it. While this approach works for established processes like financial audits or physical security, it fails in the fast-moving world of artificial intelligence. When a policy is 30 pages long, it acts as a deterrent rather than a guide. Staff members who are curious about using AI for routine tasks, such as summarizing listserv emails or drafting member communications, may feel paralyzed by the sheer volume of restrictions. These are exactly the types of AI use cases that map perfectly to existing association workflows, yet they are often the first to be abandoned when rules are too rigid. They worry that they will unintentionally cross a line they didn't even know existed. This fear effectively snuffs out innovation before it can begin.

In many cases, these long policies are the result of a disconnect between technical security teams and organizational leadership. An IT security unit is trained to see vulnerabilities. When they look at a tool like a large language model, they see potential data leaks, copyright issues, and security gaps. Their natural response is to redline any policy until it is ironclad, especially as cybersecurity threats have become more sophisticated. However, an ironclad policy is often a heavy one. If the resulting document is too dense for the average employee to digest, the policy fails its primary objective: to guide behavior. Instead of a clear path forward, the organization is left with a document that sits on a digital shelf while staff members either ignore AI entirely or use it in the shadows without any guidance at all. Effective AI governance requires a balance between security and utility. It must be accessible enough that a staff member can recall the core rules while they are in the middle of a task.

Shifting from restrictive rules to guiding principles

Realizing that a 30-page document would not serve the organization, leadership at ASHA looked for a different model. They found inspiration in a peer organization that had managed to condense its AI policy into just eight pages. This was a significant improvement, but even an eight-page document required customization to fit the specific culture and mission of the association. This process of "ASHA-izing" the policy involved stripping away the legalese and focusing on foundational principles that staff could actually use. The goal was to create a set of guiding principles that were clear, concise, and actionable. These principles do not attempt to cover every edge case. Instead, they provide a mental model for how the organization approaches technology.

Guiding principles work because they treat staff members as capable professionals rather than potential liabilities. For example, rather than listing every type of data that cannot be entered into an AI tool, a principle might state that staff must maintain the same standards of confidentiality with AI as they do with any other public-facing tool. This allows the policy to remain relevant even as the technology changes. If a new AI tool is released tomorrow, the principle still applies. This approach also makes the governance process more agile. It provides the guardrails necessary for safe experimentation without the weight of an over-engineered policy, addressing the barriers that often have more to do with organizational culture than the technology itself. When staff understand the "why" behind the rules, they are more likely to follow them.

The human-first philosophy of AI governance

At the heart of effective AI governance is a human-first perspective. Vicki Deal-Williams, CEO of ASHA, emphasizes that the primary goal of any technology investment must be to help people. In the context of a professional association, this means ensuring that AI supports the clinicians, researchers, and students who make up the membership. If the technology loses sight of humanity, it loses its purpose. This philosophy should be baked into the organization's guiding principles. One of the most effective ways to do this is to establish a rule that a person must be at the beginning and the end of every AI use case. This means that a human is responsible for the prompt and a human is responsible for the final output. AI is a tool for the staff, not a replacement for their judgment.

This human-first approach is particularly important for maintaining trust and credibility. In fields that rely on evidence-based practice, the accuracy of information is paramount. AI tools can produce hallucinations or biased results. By requiring a human to review and verify every AI-generated output, the association protects its reputation as a source of trusted knowledge. This principle also addresses the concerns of staff members who may fear that AI will replace their roles. When governance is framed as a way to enhance human work rather than automate it away, buy-in increases. Staff members begin to see AI as a way to free up capacity for more meaningful, person-to-person interactions. For a clinician, this might mean using AI to handle documentation so they can spend more time with a patient. For an association staff member, it might mean using AI to summarize member feedback so they can spend more time developing new programs. The technology handles the routine, while the human handles the connection.

Practical implementation and socialization

Creating the principles is only the first step. The second step is ensuring that staff members actually understand and embrace them. Before launching major AI initiatives, like internal innovation days, it is important to socialize the guiding principles. This involves more than just sending an email with a PDF attachment. It requires active conversation. At ASHA, leadership held an all-staff meeting to go over the principles and ensure they were clear. They used existing communication channels, like their internal text messaging system, to keep the conversation going. By making the principles a part of the daily dialogue, they became a living part of the culture rather than a static set of rules.

This socialization process also provides an opportunity to address staff concerns directly. Some employees may be worried about the environmental impact of AI, while others may be concerned about data privacy. A set of guiding principles should provide a framework for these discussions. It allows leadership to say, "We hear your concerns, and here is how our principles address them." This transparency builds trust. It shows that the organization is not just jumping on a trend but is moving forward with intention. Once the foundational principles are in place and understood, the organization can release its "suspender group"—those enthusiastic early adopters who have been waiting for permission to innovate. With clear guardrails in place, these staff members can experiment with AI in a way that is both creative and safe. The governance becomes the floor that supports their work, rather than the ceiling that limits it.

Governance as a living document

AI governance is not a one-time project. It is an ongoing process of refinement. As staff members experiment with new tools and discover new use cases, the guiding principles may need to evolve. The association should maintain an AI enablement team or a similar cross-functional group to monitor how the principles are being applied in practice. This team can gather feedback from staff, identify new risks, and share success stories. By keeping the governance framework flexible and concise, the association ensures that it can adapt to the rapid pace of technological change. The goal is not to have a perfect policy on day one, but to have a functional one that grows with the organization. When governance is built on trust, clarity, and a human-first perspective, it becomes a powerful driver of AI adoption. It provides the confidence staff members need to jump into the game of innovation, knowing that the ropes are turning and the association is ready to support them.