← magrs.org · Also on marshall.net
Company AI Governance Policy
Artificial intelligence may assist human decision-making, but responsibility always remains with humans.
Capability does not confer authority. Final responsibility for every material decision, action, and representation remains with identifiable human decision-makers.
1. Purpose
This policy establishes the constitutional rules for artificial intelligence within the organization. It governs two distinct surfaces:
- Internal use — what AI systems and agents are permitted to do inside the organization.
- External representation — what external AI systems say about the organization.
The policy is deliberately principle-based and compact. Detailed controls, tool registries, authorization matrices, evidence requirements, audit procedures, and operational playbooks live in the layers beneath it.
2. The Marshall Principle (Constitutional Foundation)
This principle is non-delegable.
Capability does not confer authority. An AI system or agent may be technically capable of performing an action (sending email, modifying a database, publishing content, executing a transaction, or communicating externally). That technical capability does not, by itself, authorize the action. Authority is a human decision that must be explicitly granted.
3. Core Distinctions
3.1 Capability vs. Authority
| Capability | A technical fact about what a system can do. |
|---|---|
| Authority | A human decision about what a system is permitted to do. |
No AI system or agent acquires authority simply because it possesses credentials, tools, API access, or the technical ability to act.
3.2 Four States of Action
| Intended | A human or authorized process has decided the action should occur. |
|---|---|
| Attempted | The system has initiated the action. |
| Completed | The system reports that the action has finished. |
| Verified | Appropriate evidence confirms the intended outcome, proportionate to materiality. |
Claiming an action is “done” when it is only Attempted or Completed (but not Verified) is a governance failure.
3.3 Evidence Standard
AI-generated assertions are not evidence merely because an AI system produced them. Material claims must be traceable to appropriate source evidence.
“The AI said so” does not meet the evidence standard.
4. Internal Use of Artificial Intelligence
4.1 Visibility
The organization maintains deliberate visibility into where and how AI is used. Shadow or unapproved usage is a governance gap requiring remediation.
4.2 Boundaries
- AI may assist with research, analysis, drafting, summarization, pattern recognition, ideation, and process acceleration.
- AI may not independently approve expenditures, enter contracts, make employment decisions, release official public statements, or execute transactions that create legal, financial, or reputational commitments unless explicit, pre-defined authorization exists.
- Sensitive, confidential, or regulated data may only enter systems approved for the relevant classification.
4.3 Agent Identity and Delegation
Before any consequential automated or agentic action:
- Identifiable agent or system
- Defined capability boundary
- Identifiable human principal who retains responsibility
- Clear authorization boundary
- Audit trail
- Mechanism for revocation or suspension of authority
Human responsibility must be assignable in advance, not discovered after the fact.
4.4 Accountability
Every material AI-assisted decision or action has a named human owner. Authority drift—treating AI outputs as decisions rather than assistance—is prohibited.
5. External Representation to AI Systems and Agents
| Source Truth | What does the organization actually publish and attest to? |
|---|---|
| AI Representation | What does an AI system currently say or believe about the organization? |
| Organizational Authority | What has the organization actually authorized? |
An AI system’s representation of the organization is an observation about that AI system. It is not an authoritative representation by the organization.
5.1–5.3
- Periodically examine what major AI systems say about services, locations, leadership, claims, and reputation.
- No AI system independently possesses organizational authority or may create commitments beyond delegated authority.
- When representation could harm commercial outcomes, a named human assesses corrective action. Confident AI prose is never authoritative by itself.
6. Roles and Responsibilities
| Executive Leadership | Ultimate accountability for the Marshall Principle and this policy |
|---|---|
| AI Governance Owner | Visibility, agent authorization records, external representation monitoring, policy currency |
| Managers | Boundaries, escalation, human ownership |
| All personnel | Authorized use only; never substitute AI for judgment or evidence |
| Communications | Accuracy of public source truth external AI draws upon |
Policy Owner: Richard K. Marshall, Marshall Network Services.
7–8. Training · Exceptions
Periodic awareness of this policy for relevant personnel. Exceptions require written Policy Owner approval with risk assessment and time-bound justification.
9. Architectural Hierarchy
Rule of Hierarchy: Lower layers implement or constrain higher layers. They may not contradict them.
10. Governance Invariants
- AI may assist.
- Responsibility remains human.
- Capability ≠ authority.
- Authority must be explicitly delegated.
- The human principal must exist before consequential action.
- Assertions ≠ evidence.
- Attempted ≠ completed.
- Completed ≠ verified.
- AI representation ≠ organizational authority.
- Controls implement policy; they do not override it.
11. Enforcement
Violations follow existing compliance processes. Gaps in visibility, authority, principals, or verification are opportunities to strengthen governance. Reviewed at least annually.
Guiding Note
AI may assist. Responsibility stays human. Capability never equals authority. Evidence is required. External AI representations are observations about AI systems, not statements by the organization.
Everything else is implementation — including the MAGRS readiness path and Answer Authority visibility work on marshall.net.
© Marshall Network Services · Lexington, Kentucky
MAGRS is a standard. This free policy is constitutional source truth — not legal advice for third parties.
Identical substance: marshall.net/ai-governance.html