# Company AI Governance Policy

**Version:** 1.2 (Final Constitutional / Policy Layer)  
**Effective Date:** 15 August 2026  
**Policy Owner:** Richard K. Marshall · Marshall Intelligence / Marshall Network Services  
**Review Cycle:** Annual, or upon material change in AI capabilities, agent autonomy, or regulatory requirements  
**Public URL:** https://marshall.net/ai-governance.html  
**This file:** https://marshall.net/ai-governance.md (free plain text)

---

## 1. Purpose

This policy establishes the constitutional rules for artificial intelligence within the organization. It governs two distinct surfaces:

1. **Internal use** — what AI systems and agents are permitted to do inside the organization.
2. **External representation** — what external AI systems say about the organization.

The policy is deliberately principle-based and compact. Detailed controls, tool registries, authorization matrices, evidence requirements, audit procedures, and operational playbooks live in the layers beneath it.

---

## 2. The Marshall Principle (Constitutional Foundation)

> **Artificial intelligence may assist human decision-making, but responsibility always remains with humans.**

This principle is non-delegable.

**Capability does not confer authority.**  
An AI system or agent may be technically capable of performing an action (sending email, modifying a database, publishing content, executing a transaction, or communicating externally). That technical capability does not, by itself, authorize the action. Authority is a human decision that must be explicitly granted.

Final responsibility for every material decision, action, and representation remains with identifiable human decision-makers.

---

## 3. Core Distinctions

### 3.1 Capability vs. Authority

| Concept | Meaning |
|---------|---------|
| **Capability** | A technical fact about what a system *can* do. |
| **Authority** | A human decision about what a system *is permitted* to do. |

No AI system or agent acquires authority simply because it possesses credentials, tools, API access, or the technical ability to act.

### 3.2 Four States of Action

| State | Meaning |
|-------|---------|
| **Intended** | A human or authorized process has decided the action should occur. |
| **Attempted** | The system has initiated the action. |
| **Completed** | The system reports that the action has finished. |
| **Verified** | Appropriate evidence confirms that the intended outcome actually occurred, at a level of assurance proportionate to the materiality of the action. |

Claiming an action is “done” when it is only Attempted or Completed (but not Verified to the required degree) is a governance failure.

### 3.3 Evidence Standard

AI-generated assertions are not evidence merely because an AI system produced them.

Material claims that the organization treats as fact, relies upon for decisions, or presents externally must be traceable to appropriate source evidence.

**“The AI said so” does not meet the evidence standard.**

---

## 4. Internal Use of Artificial Intelligence

### 4.1 Visibility

The organization maintains deliberate visibility into where and how AI is used, what it produces, and how it influences decisions and actions. Shadow or unapproved usage is treated as a governance gap requiring remediation.

### 4.2 Boundaries

- AI may assist with research, analysis, drafting, summarization, pattern recognition, ideation, and process acceleration.
- AI may not independently approve expenditures, enter contracts, make employment decisions, release official public statements, or execute transactions that create legal, financial, or reputational commitments unless explicit, pre-defined authorization exists.
- Sensitive, confidential, or regulated data may only enter systems that have been approved for the relevant data classification and that meet contractual and technical requirements.

### 4.3 Agent Identity and Delegation

For any consequential automated or agentic action, the following must exist **before** the action occurs:

- An identifiable agent or system
- A defined capability boundary
- An identifiable human principal who retains responsibility
- A clear authorization boundary
- An audit trail
- A mechanism for revocation or suspension of authority

**Human responsibility must be assignable in advance, not discovered after the fact.**

### 4.4 Accountability

Every material AI-assisted decision or action has a named human owner. Employees remain fully responsible for the accuracy, appropriateness, and consequences of work they produce or approve with AI assistance. Authority drift—treating AI outputs as decisions rather than assistance—is prohibited.

---

## 5. External Representation to AI Systems and Agents

Three layers must never be conflated:

| Layer | Question |
|-------|----------|
| **Source Truth** | What does the organization actually publish and attest to? |
| **AI Representation** | What does an AI system currently say or believe about the organization? |
| **Organizational Authority** | What has the organization actually authorized? |

An AI system’s representation of the organization is an **observation about that AI system**. It is not an authoritative representation by the organization.

### 5.1 Visibility of External Representations

The organization periodically examines what major AI systems currently say about its services, locations, leadership, claims, and reputation. Material inaccuracies, omissions, or harmful characterizations are identified and assigned for assessment.

### 5.2 Representation vs. Authority

AI systems may communicate externally as authorized instruments of the organization (for example, customer-service agents, support chat systems, or approved content generators).

However:

- No AI system independently possesses organizational authority.
- No AI system may create commitments, obligations, or representations beyond its explicitly delegated authority.
- An AI system speaking *on behalf of* the organization in an operational sense does not equal that system *holding* organizational authority.

### 5.3 Accountability

When an AI representation is inaccurate or incomplete in a way that could affect customers, partners, or commercial outcomes, a named human is responsible for assessing the issue and determining whether corrective action is warranted.

AI-generated descriptions are never treated as authoritative simply because they appear confident or widely repeated.

---

## 6. Roles and Responsibilities

| Role | Primary Responsibility |
|------|------------------------|
| Executive Leadership | Ultimate accountability for adherence to the Marshall Principle and this policy |
| AI Governance Owner (or designate) | Maintains visibility, agent authorization records, external representation monitoring, and policy currency |
| Department / Function Managers | Ensure team members understand boundaries; escalate issues; enforce human ownership |
| All Employees & Contractors | Use AI only within authorized boundaries; maintain human responsibility; never treat AI output as a substitute for judgment or evidence |
| Communications / Marketing | Support accuracy of public source truth that external AI systems are likely to draw upon |

**At this organization:** Policy Owner and human principal for Magi Send / commercial commitments = **Richard K. Marshall**.

---

## 7. Training and Awareness

All relevant personnel receive periodic awareness of this policy, the Marshall Principle, the distinction between capability and authority, the four states of action, the evidence standard, agent delegation requirements, and the three-layer external model. New hires are introduced to the policy during onboarding.

---

## 8. Exceptions

Exceptions to capability boundaries, data restrictions, or agent authorization rules require written approval from the Policy Owner (or designated AI Governance Owner) and must include a documented risk assessment and time-bound justification.

---

## 9. Architectural Hierarchy

```
CONSTITUTION
    ↓
POLICY
    ↓
GOVERNANCE
    ↓
CONTROLS
    ↓
PROCEDURES
    ↓
OPERATIONS
    ↓
EVIDENCE
    ↓
VERIFIED OUTCOME
```

**Rule of Hierarchy**  
Lower layers may implement, operationalize, or constrain the layers above them. They may not contradict them.

---

## 10. Governance Invariants

1. AI may assist.  
2. Responsibility remains human.  
3. Capability ≠ authority.  
4. Authority must be explicitly delegated.  
5. The human principal must exist before consequential action.  
6. Assertions ≠ evidence.  
7. Attempted ≠ completed.  
8. Completed ≠ verified.  
9. AI representation ≠ organizational authority.  
10. Controls implement policy; they do not override it.

---

## 11. Enforcement and Continuous Improvement

Violations are handled under existing disciplinary and compliance processes. Gaps in visibility, unclear authority, missing human principals, unverified claims of completion, or conflation of AI representations with organizational authority are treated as opportunities to strengthen governance.

This policy is reviewed at least annually. Conceptual expansion of this document is intentionally resisted; further development belongs in the operational layers beneath it.

---

## Guiding Note

The Marshall Principle remains the fixed point:  
**AI may assist. Responsibility stays human.**

Capability never equals authority.  
Evidence is required.  
Actions must be capable of verification proportionate to their materiality.  
External AI representations are observations about AI systems, not statements by the organization.

Everything else is implementation.

---

*Constitutional / policy layer. Free to visitors of marshall.net. Not legal advice for third parties. Operationalization lives below this document.*
