← magrs.org · Also on marshall.net

Free document · Keep it

Company AI Governance Policy

Version 1.2 — Constitutional / policy layer
Effective: 15 August 2026
Policy owner: Richard K. Marshall · Marshall Network Services
Review: annual, or upon material change in AI capability, agent autonomy, or regulation
Plain text: ai-governance.md

Free AI Readiness Assessment Download .md Free Snapshot (marshall.net)
The Marshall Principle
Artificial intelligence may assist human decision-making, but responsibility always remains with humans.

Capability does not confer authority. Final responsibility for every material decision, action, and representation remains with identifiable human decision-makers.

1. Purpose

This policy establishes the constitutional rules for artificial intelligence within the organization. It governs two distinct surfaces:

  1. Internal use — what AI systems and agents are permitted to do inside the organization.
  2. External representation — what external AI systems say about the organization.

The policy is deliberately principle-based and compact. Detailed controls, tool registries, authorization matrices, evidence requirements, audit procedures, and operational playbooks live in the layers beneath it.

2. The Marshall Principle (Constitutional Foundation)

This principle is non-delegable.

Capability does not confer authority. An AI system or agent may be technically capable of performing an action (sending email, modifying a database, publishing content, executing a transaction, or communicating externally). That technical capability does not, by itself, authorize the action. Authority is a human decision that must be explicitly granted.

3. Core Distinctions

3.1 Capability vs. Authority

CapabilityA technical fact about what a system can do.
AuthorityA human decision about what a system is permitted to do.

No AI system or agent acquires authority simply because it possesses credentials, tools, API access, or the technical ability to act.

3.2 Four States of Action

IntendedA human or authorized process has decided the action should occur.
AttemptedThe system has initiated the action.
CompletedThe system reports that the action has finished.
VerifiedAppropriate evidence confirms the intended outcome, proportionate to materiality.

Claiming an action is “done” when it is only Attempted or Completed (but not Verified) is a governance failure.

3.3 Evidence Standard

AI-generated assertions are not evidence merely because an AI system produced them. Material claims must be traceable to appropriate source evidence.

“The AI said so” does not meet the evidence standard.

4. Internal Use of Artificial Intelligence

4.1 Visibility

The organization maintains deliberate visibility into where and how AI is used. Shadow or unapproved usage is a governance gap requiring remediation.

4.2 Boundaries

4.3 Agent Identity and Delegation

Before any consequential automated or agentic action:

Human responsibility must be assignable in advance, not discovered after the fact.

4.4 Accountability

Every material AI-assisted decision or action has a named human owner. Authority drift—treating AI outputs as decisions rather than assistance—is prohibited.

5. External Representation to AI Systems and Agents

Source TruthWhat does the organization actually publish and attest to?
AI RepresentationWhat does an AI system currently say or believe about the organization?
Organizational AuthorityWhat has the organization actually authorized?

An AI system’s representation of the organization is an observation about that AI system. It is not an authoritative representation by the organization.

5.1–5.3

6. Roles and Responsibilities

Executive LeadershipUltimate accountability for the Marshall Principle and this policy
AI Governance OwnerVisibility, agent authorization records, external representation monitoring, policy currency
ManagersBoundaries, escalation, human ownership
All personnelAuthorized use only; never substitute AI for judgment or evidence
CommunicationsAccuracy of public source truth external AI draws upon

Policy Owner: Richard K. Marshall, Marshall Network Services.

7–8. Training · Exceptions

Periodic awareness of this policy for relevant personnel. Exceptions require written Policy Owner approval with risk assessment and time-bound justification.

9. Architectural Hierarchy

CONSTITUTION → POLICY → GOVERNANCE → CONTROLS → PROCEDURES → OPERATIONS → EVIDENCE → VERIFIED OUTCOME

Rule of Hierarchy: Lower layers implement or constrain higher layers. They may not contradict them.

10. Governance Invariants

  1. AI may assist.
  2. Responsibility remains human.
  3. Capability ≠ authority.
  4. Authority must be explicitly delegated.
  5. The human principal must exist before consequential action.
  6. Assertions ≠ evidence.
  7. Attempted ≠ completed.
  8. Completed ≠ verified.
  9. AI representation ≠ organizational authority.
  10. Controls implement policy; they do not override it.

11. Enforcement

Violations follow existing compliance processes. Gaps in visibility, authority, principals, or verification are opportunities to strengthen governance. Reviewed at least annually.

Guiding Note

AI may assist. Responsibility stays human. Capability never equals authority. Evidence is required. External AI representations are observations about AI systems, not statements by the organization.

Everything else is implementation — including the MAGRS readiness path and Answer Authority visibility work on marshall.net.

AI Readiness Assessment MAGRS home marshall.net

© Marshall Network Services · Lexington, Kentucky
MAGRS is a standard. This free policy is constitutional source truth — not legal advice for third parties.
Identical substance: marshall.net/ai-governance.html