Standing Up a Learning-AI Governance Practice
A safety course built mostly by AI shipped to 4,000 maintenance technicians on a Thursday. By the following Wednesday the lockout/tagout module had been completed by 3,100 of them, and one of those technicians had filed a near-miss report after following a step that did not match the plant SOP. In the conference room where the head of learning, the compliance officer, the legal counsel, the IT security lead, and the accessibility specialist finally sat down together, the first question was not "how do we fix the step." It was "who, exactly, was supposed to have caught this, and why were these five people meeting for the first time after the course shipped instead of before." Standing up a learning-AI governance practice is the discipline of making sure that meeting happens before the course ships, not after.
Why a Heroic Individual Is Not a Governance Model
Most learning teams that adopt AI do not start with a governance practice. They start with a hero. One careful instructional designer who happens to be skeptical, who reads every AI draft against the source, who knows that an AI-narrated video still has to pass an accessibility review, who quietly catches the invented policy threshold before it reaches a learner. For a while, that person is the whole control system. The function ships fast and ships safe, and everyone assumes the system is working. It is not working. A single conscientious person is not a system; they are a single point of failure with a calendar. When they are on leave, when they are pulled onto a launch, when they leave the company, the catch rate drops to zero and nobody notices until the near-miss report lands.
A governance practice is the answer to that fragility. The term means a standing, named group with the authority to set the rules for how AI is used in learning, the standards every AI-built course must clear, and the consequences when those rules are not met. Why you care: governance is what turns one careful person's instincts into a written rule that every course must clear regardless of who built it, who was on leave, or how tight the deadline was. The hero verifies because they are careful. The governance practice verifies because the rule says it must, and the rule does not get tired, does not go on vacation, and does not get overruled by a CEO who wants the catalog rebuilt by Q3.
This is the inversion at the heart of the strategy tier. AI collapsed the cost of producing a course to minutes, which the Josh Bersin Company frames as the disruption of a roughly 400 billion dollar corporate-learning market. When production is nearly free, the scarce, valuable thing is no longer the ability to make a course. It is the ability to prove the course is correct, accessible, and defensible, at the scale of a whole catalog, without depending on one tired hero. Governance is the operating system for that proof.
A control system that depends on one careful person is not a control system. It is a single point of failure that happens to be doing a good job today.
The Five Seats at the Table
The defining move of a learning-AI governance practice is putting five functions at one table with real authority, because the risks of AI-built learning do not respect a single department's boundaries. A hallucinated safety step is a content problem, a compliance problem, and a legal problem at once. An AI-narrated video that fails accessibility is a design problem and a legal-exposure problem. A learner-data question about whether transcripts train a vendor's model is an IT-security and a privacy problem before it is a learning problem. No one function can see all of these. Five, together, can.
Learning and Development
L&D owns the craft and the outcome: the objective, the alignment, the assessment validity, the build, and the proof that the course changed behavior. In the governance practice, L&D is usually the convener, because L&D is the function accountable for what the workforce is taught and the one whose name is on the course. L&D brings the evidence-based instructional design discipline, the knowledge of where AI is load-bearing across the lifecycle, and the verification habits that the other four seats will turn into enforceable rules. Critically, L&D does not get to mark its own homework. The point of the table is that the function building the course is not the only function judging it.
Compliance
Compliance owns the question that ends careers: does every regulated, safety, or policy claim in this course trace to an approved source of truth, and can we prove who verified it. Compliance is the seat that insists on the SME sign-off log, the tamper-evident record of who approved every regulated claim and when. Why you care: when a regulator or an internal audit asks "who verified the lockout/tagout procedure before 4,000 people were trained on it," the sign-off log is the answer, and a function without one is improvising in front of an auditor. Compliance turns the bright-line rule into policy: AI does not author a regulated or safety claim that ships unverified, full stop.
Legal
Legal owns exposure: intellectual-property risk in AI-generated media, synthetic-media disclosure obligations, the contractual terms with AI vendors, and the liability when a wrong course causes harm. Legal is the seat that reads the vendor contract and asks whether the company has indemnification when the model invents a fact, what happens to learner data, and whether an AI avatar's likeness is licensed. Legal also owns the cold truth that anchors the whole program: "the AI wrote it" is not a defense. Accountability does not transfer to the vendor, and Legal is the seat that makes sure the organization never pretends otherwise.
IT and Security
IT and security own the plumbing and the data: which AI tools are approved, whether learner data and SME transcripts leave the building, whether a tool trains the vendor's model on your content, and how AI systems connect to the LMS and the identity stack. This is the seat that catches the quiet failure nobody decided on purpose: an instructional designer wires a convenient AI tool into the workflow, pastes in a confidential policy and a roster of learner records, and nobody ever decided whether that data was allowed to leave. IT and security turn that accident into a decision, made on purpose, written down.
Accessibility
Accessibility owns the gate that AI-generated experiences love to fail. The seat brings the conformance standard, WCAG 2.2 AA, the W3C Recommendation from October 2023 that is the accessibility target for the experience, and Section 508, which incorporates WCAG by reference in US federal contexts. Why you care: an AI-narrated video with auto-generated captions that mangle a safety term, an AI-built interaction that a keyboard cannot reach, or an AI image with no meaningful alt text will fail an audit and expose the organization, no matter how fast it was produced. Accessibility is the seat that enforces the bright-line rule: an AI-generated experience that fails WCAG 2.2 AA does not ship, full stop. It is a gate, not a polish step.
Authority Is the Whole Point
A governance practice without authority is a book club. Five thoughtful people can meet monthly, share concerns, nod gravely about hallucination risk, and change nothing, because when the deadline arrives the course ships anyway and the meeting was advisory. The thing that separates a governance practice from a discussion group is a single, uncomfortable power: the authority to stop a course from shipping. If the table can be overruled by a louder voice or a closer deadline, it is not governing. It is decorating.
Authority shows up in three concrete forms. First, the authority to set the standard: the table defines the written rules every AI-built course must clear, and those rules are policy, not suggestions. Second, the authority to enforce the gate: a course that fails the standard does not ship, and no individual designer, manager, or executive can wave it through. Third, the authority to be the named owner when something goes wrong: the governance practice, not a scapegoated individual, owns the incident response, the fix, and the documentation. The reason this matters is the same reason the hero model fails. Without enforcement authority, the rule is only as strong as the most pressured person on the most pressured day, and AI's speed guarantees that every day is a pressured day.
This is also where the practice earns its keep against the loudest force in the building, the executive who read that AI makes training "10x faster" and wants proof of speed. The governance table does not say no to speed. It says speed is fine on the left side of the lifecycle, where AI drafts and sorts and retrieves, and judgment is required on the right side, where a human owns the verified claim, the validated item, and the sign-off. The table's authority is what keeps the right side from being amputated in the name of the left.
A governance practice that cannot stop a course from shipping is not governance. It is a meeting that happens to discuss risk while the risk ships anyway.
What the Practice Actually Produces
A governance practice is not a feeling or a value statement. It produces specific, durable artifacts that outlive any individual and answer the questions an auditor, a regulator, or a CFO will ask. The table below maps the artifact to the question it answers and the seat that owns it, so the practice can be audited as readily as the courses it governs.
| Artifact | The question it answers | Primary owner |
|---|---|---|
| Approved-tool register | Which AI tools are allowed, and what data may they touch? | IT and security |
| The written course standard | What must every AI-built course clear before it ships? | L&D, compliance, accessibility |
| SME sign-off log | Who verified every regulated claim, and when? | Compliance |
| Accessibility conformance record | Does the experience meet WCAG 2.2 AA? | Accessibility |
| Vendor and data-use agreements | What are our rights, and does our content train their model? | Legal and IT |
| Synthetic-media disclosure policy | When and how do we tell learners a presenter is AI? | Legal and L&D |
| Incident-response playbook | What happens when a wrong course already shipped? | The whole table |
| Governance decision record | Why did we approve, block, or escalate this build? | The convener |
Read down the middle column. Every row is a question someone with authority over your organization can ask, and the artifact is the difference between answering in one calm sentence and improvising under pressure. A function with these artifacts is not slower than a function without them. It is the same speed on the build and infinitely faster on the day someone asks "who verified this," because the answer already exists and is written down. The artifacts are also what let the practice scale: a new designer inherits the standard and the register on day one instead of inheriting the hero's undocumented instincts.
Note the relationship to the program's pipeline. The goldmine of this whole curriculum is a source-to-certified-course pipeline that is fast and defensible end to end: grounded generation on a verified source, aligned objectives and valid items, accessible-by-construction media, SME verification with a sign-off log, and measurement to behavior and results. The governance practice is the operating model that owns that pipeline at the level of the function, not the individual course. L4 is where the pipeline stops being a thing one designer does well and becomes a thing the organization does reliably.
A Worked Example: Before and After
Return to the safety course that shipped to 4,000 technicians and watch the same organization run the same build twice.
Before (the hero, absent). A new compliance refresh is due. The instructional designer who usually catches problems is on parental leave. A capable but less skeptical colleague picks up the build, uploads the old course and a rough brief into the AI authoring tool, and generates a clean forty-screen module with a quiz overnight. It looks finished, so it goes into the LMS. There is no written standard the build had to clear, no required SME sign-off on the procedure steps, no accessibility gate, and no register saying which tool was approved or whether the plant's confidential SOP should have been pasted into it. Three of those four controls existed only in the absent hero's head. The reversed lockout/tagout step ships to 4,000 people, and the near-miss report is the first time anyone with authority looks at the course. In the meeting that follows, five functions discover they have never met, and the only honest answer to "who was supposed to catch this" is "nobody, formally."
After (the practice, standing). The same refresh is due, the same hero is on leave, and the same colleague picks up the build. This time the build runs through a standing governance practice. The approved-tool register tells the colleague exactly which AI tool is sanctioned and that the SOP may be loaded into it because the vendor contract forbids training on the company's content. The written course standard lists what the build must clear before it ships: every regulated claim traced to an approved source, an SME sign-off logged, a passing accessibility conformance record, and a validity check on the assessment items. The colleague drafts at AI speed, then routes the procedure section to the named SME, who catches the reversed step and signs the corrected version into the log. The accessibility seat clears the captions and contrast. The course ships a day later than the "before" version and arrives correct, accessible, and documented. When an internal audit asks six months later who verified the lockout/tagout procedure, the answer is one sentence and a log entry, and no five-person emergency meeting is required, because those five people already met, before the course shipped, the way the practice is designed to make them.
The difference between the two runs is not talent and not effort. It is whether the controls lived in one person's head or in a standing practice with authority and artifacts. The module was nearly identical. The accountability was not.
Standing It Up Without Boiling the Ocean
The objection every learning leader raises is that this sounds like a heavyweight committee that will slow everything to a crawl, which is exactly the disaster AI was supposed to end. The objection is fair and the answer is design. A governance practice is not a monthly tribunal that reviews every screen of every course. It is a tiered system that puts heavy scrutiny where the risk is and almost none where it is not.
The lever is risk tiering. A microlearning nudge about the new cafeteria hours is not a regulated safety course, and treating them identically is how governance earns its reputation for sludge. A sane practice sorts builds into tiers. High-risk builds, the regulated, safety, compliance, and high-volume courses where a wrong fact ships to thousands, get the full standard: traced claims, logged SME sign-off, accessibility conformance, validity checks, and a governance decision record. Low-risk builds get a lightweight self-attestation against the same standard, spot-audited rather than fully reviewed. The table's authority is reserved for where it matters, so the practice is a gate on the dangerous 20 percent of the catalog and a light touch on the rest. Speed survives precisely because scrutiny is targeted.
Start small and make it real before making it big. Stand up the table with the five seats and a single written standard for the highest-risk course category you own, usually safety or regulatory compliance training. Build the approved-tool register and the sign-off log for that category first. Run three builds through it, fix what is clumsy, and only then widen the standard to the rest of the catalog. A governance practice that governs one category well is worth more than a binder that governs everything on paper and nothing in practice. The goal is not bureaucracy. The goal is that the meeting which happened after the near-miss report happens before the course ships, every time, without depending on a hero being at their desk.
Key Takeaways
- A single careful person is not a governance model; they are a single point of failure with a calendar, and AI's speed makes that fragility expensive the moment they are absent.
- A learning-AI governance practice is a standing, named group with the authority to set the standard every AI-built course must clear and to stop a course that fails it from shipping.
- Five seats belong at the table: L&D (craft and outcome), compliance (traced claims and the sign-off log), legal (exposure and contracts), IT and security (approved tools and data), and accessibility (the WCAG 2.2 AA gate).
- Authority is the whole point: a practice that can be overruled by a louder voice or a closer deadline is a book club, not governance.
- The practice produces durable artifacts, an approved-tool register, a written standard, a sign-off log, a conformance record, vendor agreements, a disclosure policy, an incident playbook, and a decision record, that outlive any individual and answer the questions an auditor will ask.
- The three bright-line rules become enforceable policy: no unverified regulated claim ships, no experience that fails WCAG 2.2 AA ships, and no AI scenario about people ships unchecked for bias.
- Risk tiering keeps the practice fast: the full standard applies to high-risk regulated and safety courses, and a lightweight self-attestation covers the low-risk rest.
- Accountability never transfers to the vendor; "the AI wrote it" is not a defense, and the governance practice is how an organization makes sure it never has to find that out the hard way.
Skill.re