โ†
AI for Social Work & Human Services
Strategic ยท M17 ยท lesson 17 of 19 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Standing Up Human-Services AI Governance
๐Ÿ“–
now learning

Standing Up Human-Services AI Governance

15 min

The agency had done everything it was supposed to do, on paper. There was an AI policy, twelve pages of it, approved by the director eighteen months ago. There was a line in the procurement rules requiring a privacy review. There was a training module every caseworker had clicked through. And yet when an advocate filed a complaint that a benefits unit had been using an AI eligibility tool that quietly applied an outdated income threshold to roughly 300 determinations, the question that mattered had no answer: who, by name, was responsible for catching that? The policy said the agency valued responsible AI. It did not say whose job it was. The training said verify the output. It did not say who checked that verification was happening, or what they did when it was not. Responsible AI was, in this agency, everyone's hope and no one's actual job. Governance is the discipline that closes that gap. It is the difference between an agency that believes in responsible AI and an agency where responsible AI is a named person's responsibility, with the authority, the cadence, and the accountability to make it real.

Why a Policy Is Not Governance

The most common and most expensive mistake an agency makes with AI is to confuse writing a policy with governing AI. A policy is a document. It states principles, sets rules, and assigns nothing to no one. Governance is a living structure: people with defined roles and real authority, meeting on a defined cadence, making and recording defined decisions, and answerable when those decisions go wrong. A policy without governance is a statement of good intentions that nobody operates. The opening scenario is what that looks like in practice: a perfectly reasonable AI policy and 300 wrong benefits determinations, because the policy described a destination and named no driver.

The distinction matters more in human services than in almost any other field because of what the program's spine demands. The cardinal rule, that AI informs and humans decide, is not self-enforcing. Equity auditing is a continuous practice, not a one-time check, and continuous practices need an owner or they quietly stop. Due process and privacy are the perimeter, and a perimeter needs someone walking it. Each of the program's non-negotiables describes work that has to keep happening, on a schedule, with someone accountable for whether it happens. That is precisely what governance provides and a policy alone cannot. A policy can say equity audits will be conducted. Only governance can ensure that in the third quarter, when the unit is short-staffed and the caseloads spiked, the equity audit actually got done and someone noticed if it did not.

A policy says what the agency believes. Governance says whose job it is, on what schedule, with what authority, and what happens when it fails.

Think of governance as the load-bearing structure beneath the policy. The policy is the architectural rendering; governance is the steel. An agency that has spent its energy on the rendering and skipped the steel has a beautiful document and a building that cannot hold weight. When the contested hearing comes, when the advocate files the complaint, when the legislature asks how AI is being controlled, the policy is read aloud and then the real question follows: show us it was operated. Governance is the answer to that question.

Who Belongs at the Table

Governance fails when it is staffed by the wrong people, and the most common error is to treat AI governance as an information-technology (IT) matter and seat it with technologists alone. In human services this is a serious mistake, because the decisions AI touches are legal, ethical, and practice decisions before they are technical ones. The composition of the governance body determines whether it can see the harms it exists to prevent. Three perspectives are non-negotiable at the table, and the lesson title names them: legal, equity, and practice.

Legal counsel belongs at the table because every consequential AI use in this field runs into the rights perimeter. A benefits denial implicates due process: notice, a fair hearing, the right to challenge. A removal recommendation implicates a parent's constitutional rights and a body of dependency law. A risk-screening signal implicates equal-protection and anti-discrimination obligations. The data flowing through every tool implicates confidentiality regimes the agency cannot delegate away. A governance body without legal counsel cannot reliably tell whether a proposed AI use is lawful, and it cannot anticipate how an advocate or a court will challenge it. Legal is not a reviewer who sees the decision after it is made; legal sits at the table while the decision is being made.

Equity

Equity expertise belongs at the table because the program is equity-first by design and history proves it must be. Predictive and screening tools can encode the inequities in their training data, and the field has watched it happen: the long debate over the Allegheny Family Screening Tool, the Dutch childcare-benefits scandal that wrongly accused thousands of families of fraud, Michigan's MiDAS system that falsely flagged tens of thousands of people for unemployment-benefit fraud. The person who carries the equity perspective in governance is the one who asks, before deployment, whose error rate is higher, which communities bear the burden of a false flag, and whether the tool was audited for disparate outcomes across the populations the agency serves. Without that voice, equity becomes the afterthought the program forbids it to be.

Practice

Practice expertise, the caseworkers, investigators, and eligibility staff who actually use the tools, belongs at the table because governance designed without them produces controls that look good on paper and break in the field. The practitioner is the one who knows that the verification step the policy requires takes twelve minutes per court report, that a unit carrying 28 families per worker will not find those minutes unless the workflow is redesigned, and that a control workers cannot actually perform under caseload pressure is a control that exists only in the document. Practice at the table is also how the decision-aid culture is built rather than imposed: workers who helped design the governance are far likelier to hold the line it draws.

Beyond these three, mature governance bodies add data and security expertise, a privacy officer, and, increasingly, community and advocate representation, because the people most affected by these tools have standing to shape how they are used. But the irreducible core is legal, equity, and practice. An agency that can seat only three voices should seat those three.

What Governance Actually Decides

A governance body that meets but does not decide anything specific is theater. To be real, it must own a defined set of decisions, and those decisions must be the ones that determine whether the agency's AI use is safe, lawful, and equitable. The core decisions are concrete.

  • Use-case approval. No AI use goes live without governance approval. Each proposed use is assessed for benefit, equity and due-process risk, verification needs, and a go or no-go decision, exactly the discipline the L1 capstone memo introduced, now operated at the agency level by a body with authority to say no.
  • The kill list. Governance maintains a written list of decisions AI must never make or even support, the most sensitive calls where the agency has decided the risk is unacceptable. Naming these in advance is far stronger than judging case by case under pressure.
  • Equity-audit cadence and response. Governance sets when equity audits run, who runs them, what thresholds trigger action, and what the agency does when an audit finds a disparate outcome, including the authority to suspend a tool.
  • Verification standards. Governance defines what verification is required for each AI-assisted document type before filing, and how compliance is checked, so verification is a governed standard rather than an individual habit.
  • Vendor and procurement gates. Governance sets the due-diligence bar a vendor must clear, connecting to the privacy and security obligations the agency can never delegate, before any contract is signed.
  • Incident response. Governance owns what happens when an AI tool causes or nearly causes harm: how it is reported, investigated, remediated, and learned from.

Work the use-case decision through an example, because it shows governance doing its actual job. A program manager proposes using an AI tool to auto-draft the narrative summary in safety assessments to save time. Governance assesses it. Legal flags that the safety assessment feeds directly into removal recommendations, placing the narrative inside the rights perimeter. Equity asks whether auto-drafted narratives might systematically describe certain families in more alarming language drawn from training-data patterns. Practice notes that workers under pressure may accept the draft narrative with less scrutiny than they apply to their own writing, precisely because it reads well. Governance approves the use with conditions: the tool may organize and format the worker's own observations but may not generate characterizations, every safety-assessment narrative requires documented verification before filing, and the use is added to the equity-audit schedule with a low threshold for suspension. That is governance: not a yes or a no shouted from a policy, but a structured decision that lets a benefit through while building the controls that keep it safe, with a named body accountable for the outcome.

Cadence, Authority, and the Audit Trail

Three operating properties separate governance that works from governance that exists on an org chart. Each one closes a specific failure mode the opening scenario exposed.

Cadence is the schedule on which governance operates, and it is what turns continuous practices into actual practice. Equity auditing is a continuous practice or it is nothing; the cadence is what makes it continuous. A governance body that meets quarterly to review the equity-audit results, the incident log, new use-case requests, and vendor changes is operating. A body that meets when someone remembers to call a meeting is not. The cadence should match the risk: high-risk uses like screening support reviewed more often than low-risk uses like internal document formatting. The 300 wrong benefits determinations in the opening scenario happened in the gap between an annual policy and no operating cadence; a quarterly governance review of eligibility-tool accuracy would have caught the outdated threshold long before 300 families were harmed.

Authority is the power to make decisions stick, and it is what separates a governance body from an advisory committee. If governance can recommend suspending a tool but a program director can override it to keep hitting throughput numbers, governance has no authority and the throughput numbers will win every time, because the pressure to move cases is relentless and the harm from a biased tool is diffuse and deferred. Real governance has the charter-backed authority to halt a use, to require remediation, to block a procurement, and to say no to a senior leader. Without that authority, governance becomes the body that gets briefed after the decision and asked to bless it. The authority must be granted explicitly, in writing, by the agency head, because a governance body's power to say no to its own organization is exactly the power that erodes first under operational pressure.

The audit trail is the record of what governance decided and why, and it is what makes the agency's AI use defensible to the outside. Every use-case approval with its conditions, every equity-audit result and the response to it, every incident and its remediation, every vendor decision, is recorded. This record is not bureaucratic overhead. It is the answer to the question the advocate, the court, the legislature, and the oversight body will eventually ask: how is this agency controlling AI, and can you show us? The agency in the opening scenario could produce a policy and nothing else. The agency with real governance can produce the decision record: here is when we approved this tool, here are the conditions we imposed, here is the equity audit from last quarter, here is the incident we caught and how we fixed it. That record is the difference between defensible practice and a hope that nothing went wrong.

Making It Someone's Actual Job

The deepest failure the opening scenario reveals is diffusion of responsibility: responsible AI was everyone's value and no one's assignment. Governance fixes this by converting a shared value into specific, named accountability, and this is the move that makes everything else operable.

It starts with a named owner. An agency does not need a large new department to begin; it needs one person who owns AI governance as part of their actual job description, with the time, the authority, and the mandate to operate it. In a large agency this becomes a dedicated role, an agency AI lead. In a small one it may be a deputy director who carries it alongside other duties. The size of the role scales with the agency, but the principle does not: AI governance must be somebody's named responsibility, evaluated as part of their performance, not a committee's collective good intention. The 300 wrong determinations happened because no one's job was to catch them; the fix is to make it explicitly someone's job, with the authority to act when they do.

From the named owner, accountability flows down into roles that connect governance to the daily work. Supervisors are accountable for verifying that their unit's AI-assisted documentation meets the governed verification standard, the same way they are accountable for the quality of all documentation. Caseworkers are accountable for verifying their own AI-assisted output and for the contents of any record filed under their name, because the cardinal rule and professional liability both place the consequential decision with the human. The equity function is accountable for running the audits on cadence and escalating disparate outcomes. Each of these accountabilities is written, assigned, and reviewed, so that when something goes wrong the question who was responsible has an answer before the harm rather than after it.

Start small and make it real rather than waiting to build it perfectly. An agency at the beginning of its AI journey can stand up meaningful governance with a named owner, a small body seating legal, equity, and practice, a quarterly cadence, a use-case approval gate, a kill list, an equity-audit schedule, and a decision record. That is enough to govern, and it is enough to ensure the agency never finds itself, as the one in the opening scenario did, holding a policy it believed in and a harm no one was assigned to prevent. Governance grows from there: more roles, finer cadence, community representation, integration with incident response. But the first and most important step is the smallest one, which is to make responsible AI a named person's actual job rather than the whole agency's shared hope.

Key Takeaways

  • A policy is not governance. A policy states what the agency believes; governance is the living structure of named people, real authority, a defined cadence, recorded decisions, and accountability when things go wrong. An agency can have a perfect AI policy and still harm families if responsible AI is everyone's value and no one's job.
  • Governance is what makes the program's non-negotiables operable: the human-decision rule, continuous equity auditing, and the due-process and privacy perimeter all describe ongoing work that needs an owner and a schedule or it quietly stops.
  • The irreducible core of the governance table is legal, equity, and practice. Legal sees the rights perimeter, equity sees the disparate-outcome risk that history (Allegheny, the Dutch childcare-benefits scandal, Michigan's MiDAS) proves is real, and practice sees whether a control can actually be performed under caseload pressure. AI governance is not an IT matter seated with technologists alone.
  • Governance must own concrete decisions: use-case approval with go or no-go authority, a written kill list of decisions AI must never make, the equity-audit cadence and response, verification standards, vendor and procurement gates, and incident response.
  • A real use-case decision lets a benefit through while building the controls that keep it safe, with conditions (for example, organize observations but generate no characterizations, require documented verification, add to the equity-audit schedule with a low suspension threshold) and a named body accountable for the outcome.
  • Three operating properties separate working governance from an org-chart body: cadence (the schedule that makes continuous practices continuous and would have caught 300 wrong determinations), authority (charter-backed power to halt a use and say no to senior leaders, granted in writing by the agency head), and the audit trail (the recorded decisions that answer how is this agency controlling AI, and can you show us).
  • Governance converts a shared value into named accountability: an owner whose actual job is AI governance, supervisors accountable for unit verification, caseworkers accountable for their own output and any record under their name, and an equity function accountable for audits on cadence.
  • Start small and real rather than waiting for perfect: a named owner, a body of legal, equity, and practice, a quarterly cadence, a use-case gate, a kill list, an equity-audit schedule, and a decision record are enough to govern and to ensure no harm goes unassigned.