← All guides

AI governance

Who should approve AI use at work?

A practical way to route workplace AI questions to managers, security, privacy, legal, HR, or another responsible owner.

Published
August 2, 2026
Reading time
6 minutes

What is the short answer?

There is rarely one person who should approve every workplace AI use.

The right approver depends on why the use needs approval. A security concern should not wait in a general manager’s inbox, and an employment decision should not be treated like an ordinary software request.

The policy should route the question to a named role or team instead of telling employees to “seek approval” with no destination.

When can a manager approve it?

A manager may be the right person when the issue is ordinary business judgement: whether the task is appropriate, whether someone has time to review the result, or whether the output may be used internally.

The manager should not be expected to waive privacy, security, legal, contractual, or employment controls outside their authority.

When should security or IT be involved?

Send the question to security or IT when it concerns:

  • a new or unapproved tool;
  • account access, browser extensions, integrations, or connected systems;
  • credentials, source code, security findings, or restricted information;
  • vendor security and data-handling controls;
  • automated actions inside company systems.

Approval of the tool still does not approve every possible use of it.

When should privacy, legal, or compliance be involved?

Privacy review may be needed when personal information is processed, particularly when the purpose is new, the information is sensitive, or people may not expect the use.

Legal or compliance review may be needed for contractual restrictions, regulated activity, intellectual property, external claims, or uses that affect another person’s rights or opportunities.

HR should normally be involved when AI is used for recruitment, performance, discipline, monitoring, or another employment process.

Who owns the final decision?

The business remains responsible for how AI is used. Approval should identify who owns the use after the initial “yes,” including who reviews outputs, watches for problems, and stops the use when conditions change.

NIST’s AI Risk Management Framework recommends clearly defined roles for AI oversight and executive responsibility for AI risk decisions. It also treats governance as continuous rather than a one-time gate. See the NIST AI RMF Core and its guidance on human-AI roles.

What makes an approval useful?

A useful approval records:

  • the proposed task and intended result;
  • the tool and account;
  • the information involved;
  • how the output will be used;
  • required safeguards and human review;
  • the approver and date;
  • when the decision must be reviewed again.

“Approved” without conditions can be misleading. Approval for summarising public material does not automatically extend to customer records or automated decisions.

What if nobody knows who should decide?

That is a policy gap. The safe response is to pause the proposed use and send it to a default owner, such as the policy, risk, privacy, or security lead. The organisation can then update the route so the next employee receives a direct answer.

Can I Use AI? lets a company name its approval contacts, publish the policy as a fixed version, and give employees a clear next step for each proposed use. Completed checks retain the result, reasoning, and policy version used.

This article provides general operational guidance, not legal advice.