The organizations that struggle with AI governance are not usually the ones who moved too fast. They are the ones still designing the perfect framework in month nine, while shadow AI spreads underneath them. The goal for your first 90 days is not perfection. It is a program that is actually running, however modestly, and getting better each cycle.
Here is a plan that gets you there, broken into three phases of about a month each.
Days 1 to 30: build the foundation
The first month is about authority and structure. You are not trying to govern anything yet. You are putting in place the things that let you govern.
Adopt a policy and a standard
You need two documents. A policy that says what must be true, approved at a level that gives it weight. And a standard that says how, the actual process and controls people follow. Do not write these from a blank page if you can avoid it. Start from a solid template, tailor the placeholders to your organization, and get them approved through your normal governance process. The point of month one is to have something adopted, not something flawless.
Charter and seat a committee
Someone has to be able to say yes or no to an AI system, and that authority needs to be written down. Charter a governance committee. Define who sits on it, what counts as a quorum, how decisions get made, and which decisions need the whole group versus a single owner. Then actually seat it and hold a first meeting, even if the agenda is thin. A committee that exists on paper but has never met is not a committee.
Days 31 to 60: get visibility
You cannot govern what you cannot see, and right now you almost certainly cannot see most of it. Month two is about finding the AI already in use, including the parts nobody registered.
Run an amnesty-based inventory sweep
Here is the single most important tactic in the whole 90 days, and the one people get wrong most often. Do not launch your inventory as an enforcement action. The moment teams hear policing, every experiment goes underground, and you end up cataloguing the fraction people are willing to admit to.
Announce a penalty and you will inventory the 20 percent people are comfortable showing you. Offer amnesty and you get closer to the whole picture.
Instead, open a defined window. Tell every team to register every AI tool and agent they are using, with a clear promise: no penalties, no retroactive blame for anything they surface now. You are trading forgiveness for honesty, and it is a trade worth making. You will learn about tools you had no idea were in production, and the agents buried inside SaaS products nobody classified as AI.
Classify what you find
As things come in, score them. Not just business impact, but how autonomously each one acts, what it is authorized to affect, how much human oversight sits on it, and how sensitive its data is. This is where a working classification tool earns its keep, because doing it by hand across dozens of systems gets slow fast. The output you want by the end of month two is a real inventory with a risk profile attached to each entry.
Days 61 to 90: run a first cycle
Month three is where it becomes a program instead of a project. You take the inventory you built and actually operate governance against it.
Put the highest-risk systems through the process
Start with the systems your classification flagged as highest risk. Run each one through the full process your standard describes. Assess it, document the decision, get the committee sign-off where the tier requires it, and set its review date. You are not trying to process everything in month three. You are proving the machine works end to end on the cases that matter most.
Turn on the recurring parts
Governance is not a one-time pass. Set the clocks running. Each system gets a review cadence based on its risk. Monitoring gets switched on for the ones that need it. Expirations get tracked so approvals do not quietly outlive their relevance. By the end of the month, the program has a heartbeat. It will keep running after you stop pushing it.
What you should have at day 90
Ninety days in, you are not done. Nobody is ever done with governance. But you should have all of this in place:
- An approved policy and standard people actually follow.
- A committee that meets and decides.
- A real inventory of AI in use, including the shadow AI the amnesty surfaced.
- A classification on every system that captures autonomy and authority, not just impact.
- A first set of high-risk systems fully governed, with review clocks running.
That is a functioning program. It is not the finished article, and it is not supposed to be. It is the thing that keeps improving instead of the perfect plan that never ships.
The 90-day plan, done for you
The AI Governance Accelerator includes the policy, standard, and committee charter ready to tailor, a working classification engine, and the full 90-day rollout with worked playbooks and the amnesty inventory approach.
Get the Toolkit →