Key points
- AI governance is an HR matter because the riskiest AI uses are people decisions such as screening, rating and flagging employees.
- Principles like fairness and transparency only work once they are translated into rules a line manager can apply.
- Tiering AI use cases by risk lets you move fast on low-risk productivity tools and apply real scrutiny where people are affected.
- Create a Chief AI Officer only when you can give the role a written mandate, real authority and a clear boundary with existing executives.
Most organisations I work with in the GCC already have AI at work. Some of it was bought deliberately, such as a screening tool in recruitment or a chatbot on the HR portal. Much more of it arrived quietly, through employees using public assistants to draft emails, summarise reports and write job descriptions. Governance usually comes last, often after something embarrassing has already happened.
This article sets out how I would govern AI at work if I were the CHRO: what your guidelines should actually say, who should own which decisions, how to involve employees without creating a talking shop, and whether you need a Chief AI Officer. It includes a risk-tiering table you can apply this month.
Why AI governance lands on HR's desk
AI governance is often framed as an IT or legal problem. The technology sits with IT and the contracts sit with legal, so that seems sensible. But the uses that carry the most risk are people decisions: who gets shortlisted, who gets flagged as a flight risk, whose performance is rated below expectations, which roles get redesigned.
Those remain HR's decisions whether or not an algorithm is involved.
If a screening tool quietly filters out candidates with career breaks, the organisation made that decision, not the vendor.
Employees and regulators will see it that way, and a supplier's contract will not repair the damage.
There is a second reason. AI changes jobs. Agents that draft, analyse, reconcile and respond take over tasks, and the remaining work has to be reorganised into roles people can grow in. That is organisation design and workforce planning, which I cover in workforce planning when part of the workforce is AI. Governance that ignores the job consequences can be technically compliant and organisationally blind.
The GCC adds its own pressure. Many government and semi-government entities are under clear direction to adopt AI quickly, and national workforce programmes such as Emiratisation in the UAE and Saudisation in KSA mean hiring and development decisions already receive close attention. A tool that disadvantages national candidates, even unintentionally, becomes a reputational and regulatory problem at once.
Principles are easy, decision rules are the work
Almost every AI policy I read contains the same five words: transparency, fairness, accountability, privacy and human oversight. I agree with all of them. On their own they are close to useless, because nobody can apply a principle to an ordinary Tuesday afternoon decision.
The test of a good guideline is whether a line manager can read it and know what to do. "AI should be used fairly" fails that test. "No AI tool may reject a candidate unless a person has reviewed the rejection" passes it.
So translate each principle into rules:
- Transparency becomes: employees and candidates are told, in plain language, when AI informs a decision about them and what it does.
- Fairness becomes: any tool that scores or ranks people is tested for adverse impact across groups such as gender, nationality and age band, before launch and at a fixed interval afterwards.
- Accountability becomes: every AI use case has a named business owner, a named person who can switch it off, and a record of who approved it.
- Privacy becomes: a short list of data that may never be entered into external tools, such as salaries, medical information, performance ratings and anything that identifies a named employee.
- Human oversight becomes: a written list of decisions where AI may recommend but never decide.
You can anchor these rules in recognised references such as the OECD AI Principles or the risk-based logic behind the EU AI Act, which helps with credibility. But write the rules for your own organisation. A policy copied from a global template tends to cover everything and guide nothing.
A risk-tiering table for AI use cases
Not every AI use deserves the same scrutiny. Treating a meeting summariser like a promotion algorithm will either stall adoption or, more likely, push people into using tools where you cannot see them. Tier the use cases instead.
| Tier | What the AI does | Examples | Minimum controls |
|---|---|---|---|
| 1. Personal productivity | Helps an individual with their own work, with no decision about another person | Drafting, summarising, translating, building slides | Approved tools list, data rules, short training |
| 2. Process support | Automates or speeds up a process, with output checked by a person | Answering HR policy questions, drafting job descriptions, scheduling interviews | Named owner, accuracy checks, clear route to a human |
| 3. People-affecting recommendations | Scores, ranks or flags people, while a person makes the final call | CV screening, flight-risk flags, skills matching for internal moves | Bias testing before launch and periodically, explanation to affected people, documented human review |
| 4. Automated people decisions | Makes, or in effect makes, a decision about a person | Automatic rejection, automated rating or pay changes | Default answer is no. Executive approval, legal review and an appeal route if allowed |
When organisations first do this exercise, they usually find plenty of Tier 1, some Tier 2 and a handful of Tier 3 uses nobody formally approved. Tier 4 should be rare, and if a vendor's product drifts into it through an update, you want to know before your employees do.
The tiers also show where to spend governance effort. Tier 1 needs a short rulebook and training. Tier 3 needs a proper review before launch and a scheduled re-review afterwards.
Who owns what
Ownership is where most AI governance falls apart. A committee is formed, everyone attends, and nobody can say who decides.
I recommend separating four roles:
- Executive sponsor. Usually the CEO or a deputy. Sets the ambition and settles conflicts between speed and risk.
- Governance owner. Owns the policy, the tiering, the register of use cases and the review process. Depending on your structure this could be a Chief AI Officer, the Chief Digital Officer or the head of risk.
- Use case owners. The business leader who benefits from each AI use is accountable for its outcomes, including its errors. That is not IT, and it is not the vendor.
- Review panel. A small cross-functional group of HR, legal, information security, data and a business representative that reviews Tier 3 and Tier 4 cases. Keep it to five or six people and give it a service standard, for example a decision within ten working days.
A simple RACI across the lifecycle of a use case (propose, assess, approve, operate, monitor, retire) will expose the gaps quickly. The gap I see most often is monitoring. Tools are approved at launch and nobody looks at them again, even after the supplier changes the model underneath.
Keep a register as well. A spreadsheet that lists each use case, its tier, owner, data used, approval date and next review date is enough to begin. You cannot govern what you have not listed.
Involving employees without creating a talking shop
The people who use AI every day see problems that dashboards miss: the chatbot that confidently quotes an outdated policy, or the screening tool that seems to favour one kind of CV. Governance run only by IT and legal loses that knowledge.
Yet "involve employees" often turns into a large ethics forum that meets quarterly and produces minutes. Three mechanisms work better.
- A reporting channel. A simple way for anyone to flag an AI output that looks wrong, unfair or unsafe, with a named team that responds. Treat it like any other speak-up channel, with confidentiality where needed and visible follow-up.
- Champions in each function. Two or three people per function who get deeper training, help colleagues use approved tools well and feed issues back to the governance owner.
- User testing before launch. For Tier 2 and Tier 3 cases, ask the people affected to test the tool before it goes live. They will find problems faster than any audit.
Training matters, but keep it practical. Employees need to know which tools are approved, what data never goes into them, how to check outputs and where to report problems. A one-hour session and a one-page guide will achieve more than a long e-learning module on AI ethics.
One warning from experience. Organisations that ban public AI tools outright rarely stop their use. They simply lose sight of it. Offering an approved alternative with clear rules is safer than a ban nobody follows.
Deciding whether you need a Chief AI Officer
The Chief AI Officer role has become visible quickly, and I am often asked whether an organisation should create one. My answer depends on the problem you are trying to solve.
A dedicated role makes sense when AI is central to your strategy or products, when many AI initiatives are scattered across functions and need consolidating, or when a government mandate calls for a single accountable executive. In those situations a senior leader who combines technical literacy with business judgement can set priorities, stop duplication and own the governance framework.
It makes less sense when the role would be a title without authority or budget. A Chief AI Officer who reports three levels down, with no say over technology investment or HR policy, becomes a coordinator who is blamed for things they cannot control. In a mid-sized organisation, a CIO or Chief Digital Officer with a clear AI charter is often the better answer.
Whatever you decide, write the mandate first and test it against existing roles. Be explicit about where this role's authority ends and the CIO's begins, who owns data governance, and who decides on reskilling when AI changes a job family. Overlap between the CIO, the Chief Digital Officer, the Chief Data Officer and the CHRO is the most common source of friction I see, and it is avoidable with a one-page decision-rights map.
Whoever holds the role, the CHRO should be a standing partner. AI decisions change jobs, skills, spans of control and performance expectations, and those sit squarely in HR's domain.
Matching governance to how your organisation leads
Governance lives inside culture, so it has to fit how your leaders already work. Younger, AI-native companies tend to move fast, decide with data and keep hierarchy flat, but often have little formal governance. Established enterprises, including most GCC government entities and family groups, have strong controls and clear chains of command, but can treat every AI request as a special exception.
Neither pattern works on its own. Established organisations need to make the low-risk path fast, with pre-approved tools and a Tier 1 rulebook that lets people start without asking permission. Faster-moving organisations need a small amount of structure around Tier 3 decisions before they create a problem they cannot explain.
For leadership development, add practical AI fluency to your leadership competency framework: knowing what agents can and cannot do, how to question an output, and when to escalate. Leaders do not need to become technical, but they must stay accountable for decisions made with AI's help.
Where to start
- Build a register of every AI use in the organisation, including tools employees use informally. A short anonymous survey and a conversation with IT will get you most of the way.
- Tier each use case with the table above and flag anything in Tier 3 or Tier 4 that has not been reviewed.
- Publish a one-page Tier 1 rulebook covering approved tools, forbidden data, how to check outputs and where to report issues.
- Name a governance owner, plus a use case owner and a review date for every Tier 2 and Tier 3 use.
- Settle the Chief AI Officer question by writing the mandate first, and assign it to an existing executive if it does not justify a new role.
At Humanyx we design AI agents and the organisation around them at the same time, which is why governance is part of the design work from the first day rather than an afterthought.