Evaluating and updating existing policies for AI
Almost every organization adopting AI already has privacy, security and data policies that half-cover the problem, written before anyone there had trained a model. Working out which of those to extend, and what to add, is cheaper and more durable than writing
Why this matters for the exam
Almost every organization adopting AI already has privacy, security and data policies that half-cover the problem, written before anyone there had trained a model. Working out which of those to extend, and what to add, is cheaper and more durable than writing a separate AI rulebook.
What you need to know
A company that has run a privacy program for ten years already says personal data matters. What its policy does not yet say is what happens when personal data becomes training data.
The last topic covered the nine policy areas AI adds. This one covers the other half of the job: the policies the organization already has, and what each of them is missing.
Extending the existing policy set
The starting move is a gap review. An organization checks its existing policy framework against the way it actually intends to use AI, then tailors what it has before writing anything new. A solid data governance framework is usually the best foundation to build from, because it already answers questions about where data comes from and who may use it.
Keeping AI inside the existing policy set has a practical payoff. It stays attached to the compliance function the organization already runs, with the same owners, the same review cycle and the same audit trail. A parallel AI rulebook drifts from the policies people actually follow.
Four policies to start with
| Existing policy | What AI adds to it |
|---|---|
| Data privacy | Processing and disclosure obligations specific to AI, including what it means when personal data becomes training data. |
| Security | AI-specific attack surfaces: adversarial manipulation of inputs, and vulnerabilities in the model itself. |
| Data governance | The scale and provenance demands training data creates — where every dataset came from and whether it may lawfully be used this way. |
| Intellectual property | Ownership and use rights for AI-generated output, and for any proprietary algorithms involved. |
Two different documents: privacy and data governance
Data privacy and data governance policies are often treated as one document. AI separates them.
A data privacy policy covers lawful basis, notice and individual rights, and it applies to personal data. A data governance policy covers lineage and provenance, quality and fitness for purpose, and it applies to data generally, personal or not.
Most training data raises the governance questions whether or not it raises the privacy ones. A scraped image corpus with no personal data in it still needs to answer where it came from, what rights attach to it, and whether it is fit for the use it is about to be put to. Those are governance questions, and a privacy policy does not reach them.
A logistics company already has a data governance policy. It says datasets must have a named owner, a documented source, and a review date.
Extending it for AI means adding four clauses:
- Whether the license covering a dataset permits training, as opposed to analysis.
- Whether the data is representative of the population the model will run on.
- Whether derived and synthetic data inherit the restrictions of the data they came from.
- What record is kept when a dataset is used to retrain a model months after it was first approved.
All four fit inside the governance policy the company already maintains.
What guides the updating
Risk and intent shape how far to take it. Resources are limited, so the deepest work goes where the exposure is greatest rather than being spread evenly across every policy. Intent sets the rest: a company working at the frontier of AI capability needs its security, privacy and risk-acceptance policies set for that, and a company adopting proven tools in a settled area needs less.
Domain IV returns to this as a pre-deployment step, with a longer checklist that adds engineering and platform policies.
Next up: the risks these policies exist to manage, and how an organization sizes them.
Remember
- Extend the existing privacy, security, data-governance and intellectual-property policies rather than building a parallel AI policy set.
- An existing data governance framework is usually the best foundation, because it already answers where data comes from and who may use it.
- A data privacy policy covers lawful basis, notice and rights for personal data. A data governance policy covers lineage, provenance, quality and fitness for data generally.
- Intellectual property policy has to cover both AI-generated output and any proprietary algorithms involved.
- Concentrate updating effort where risk is greatest, and set the policies to match how far the organization intends to push its use of AI.
Practise this topic
Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.
Previous: Policies across the AI life cycle, and use case assessment
Next: Categories of AI risk, and risk assessment and calculation
Back to the AIGP study guide.
AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.