Eric Appiah · 5 June 2026 · 6 min read
In almost every corporate training session I run, I ask how many people in the room already use an AI tool for work. Most hands go up. I then ask how many know what their organisation's policy on it is. The hands go down, and there is usually some laughter, because everyone recognises the gap immediately.
That gap is the actual governance situation in most organisations. Not an absence of AI use, but an absence of any agreed position on it — while use continues daily.
The risk is mundane, not dramatic
The scenarios that cause problems are rarely exotic. Someone pastes a client contract into a tool to summarise it. Someone drafts a performance review with AI assistance and does not check the reasoning it invented. Someone sends a customer an answer that was fluent, confident, and wrong. None of these require bad intent. All of them are ordinary consequences of capable people using a capable tool without a shared understanding of the boundaries.
A workable policy fits on two pages
Long AI policies do not get read, and unread policies do not change behaviour. The version that works answers a small number of concrete questions in language your staff actually use.
- What may never be entered into an external AI tool — typically client-identifiable information, personal data of staff or customers, credentials, and unreleased commercial information.
- Which tools are approved, and who to ask about one that is not on the list.
- Where a human must review output before it goes anywhere — anything customer-facing, anything with legal or financial consequence, anything that becomes a record.
- When AI assistance must be disclosed, internally or to a client.
- Who to tell when something goes wrong, and an explicit assurance that reporting it early is not a disciplinary matter.
That last point does more work than the rest combined. If staff believe that admitting a mistake will be punished, you will not hear about the mistakes, and you will lose the only early warning you had.
Where Act 843 fits
Ghana's Data Protection Act 2012 does not mention artificial intelligence, and it does not need to. Its obligations attach to the processing of personal data regardless of the tool. If personal data leaves your control and enters a third-party service, that is processing, and you need a lawful basis, a considered position on where it goes, and the ability to answer a data subject who asks.
Organisations that treat AI governance as separate from data protection tend to write a policy that satisfies neither. The two questions are the same question.
Start before the incident, not after
The organisations handling this well are not the ones with the most sophisticated policies. They are the ones that had a straightforward internal conversation early, wrote down what they agreed, told everyone, and revisited it when something surprising happened. That is achievable in a fortnight, and it is considerably easier than doing it in the week after a client asks why their contract was fed into a public tool.
