Start with the use, not a generic policy
Define the intended task, users, decisions and affected people. A drafting assistant for internal notes has a different risk profile from a system that prioritizes public cases, evaluates workers or influences safety decisions. Write down what the model is not allowed to decide.
Map data, access and recourse
Identify personal, confidential and operational information in the workflow. Review permissions, retention, vendor terms and the route for correction or human recourse. In public or essential services, design for exclusion, language variation, accessibility and people who cannot use the digital channel.
Treat governance as a lifecycle
Tamil Nadu’s IT policy note describes TNAIM activity around identifying government AI use cases and developing proofs of concept; the same document raises responsible AI considerations including ethics and data compliance. NIST’s AI RMF offers a voluntary structure for governing, mapping, measuring and managing risks across AI use. Neither replaces legal review or local policy obligations.
Document and review decisions
Maintain an inventory of use cases, owners, evidence, approval points, incidents and changes. Reassess when data, model, workflow or affected population changes. A responsible process should make it easy for staff to report failures and for leaders to pause a use that is not meeting its safeguards.