Marketing Brings the Use Case. IT Checks the Data Path. Legal Checks the Exposure.
That’s the AI-approval process I’d want at any organization, and most places have nothing like it.

But this is what that meeting should address:
Marketing brings the use case. Not the tool’s marketing copy, the actual task. “We want to draft newsletter content faster” is a use case. “We want to use AI” is not.
IT checks the data path. Where does information go once it enters the tool? Does the vendor store it, train on it, or delete it after the session? This is the question most teams skip, and it’s the one that matters most for tier 3 requests.
Legal checks the exposure. Contracts, data privacy language, anything that touches member consent. For tier 1 requests, this step is negligible. For tier 3, it is core.
The review doesn’t need a monthly meeting. A shared form works: marketing fills in the use case and tier, IT and legal get pinged only when the tier calls for it. Tier 1 never reaches their inbox. Tier 3 always does.
Here we close the gap from my post about the registry spreadsheet. A registry only knows what gets reported to it. Pair it with this review process, and a manager asking their team directly what they’re using twice a year, and the gap starts shrinking.
That’s the framework. A registry that tracks what’s in use. Tiers that sort by risk. A review process that only pulls in legal and IT when the risk calls for it.
This gives your team a place to ask the question before a newsletter goes out with member data in it.