Step 2 | Comply: Enable unified governance
Compliance isn’t a checkbox 
It’s a fundamental mission responsibility. While everyone shares responsibility for privacy, your risk, legal and privacy teams need to be woven into the fabric of your data operations. They aren’t gatekeepers but enablers, helping shape how data serves the mission while protecting citizen trust. The goal is embedding privacy into your agency’s DNA, making it part of how you think about and use data, not an afterthought. 
As your agency explores AI, remember that algorithms are only as good as the data they learn from. AI governance isn’t separate from data governance—it’s an extension of it and organizations like NIST have developed frameworks to make it easy for you to ensure you’re on the right track. The same teams that help govern your data should help shape your AI strategy. Start by understanding what AI projects are already happening across your agency.
Creating this baseline helps you govern AI initiatives properly from the start.