AI Governance Policy Updates 2024: Turn the Rulebook Into an Operating Control for Central Valley Organizations — Datapath managed IT, cybersecurity, and compliance
Back to Blog
GENERAL Insights Published August 26, 2026 Updated August 26, 2026 11 min read

AI Governance Policy Updates 2024: Turn the Rulebook Into an Operating Control for Central Valley Organizations

The most important AI governance policy updates from 2024 were not a single new law for every business. They were a shift toward documented AI inventories.

JW

By

Joel Walker

Territory Sales Manager

CaliforniaCentral Valleycompliance

Quick summary

  • The most important AI governance policy updates from 2024 were not a single new law for every business. They were a shift toward documented AI inventories, risk-based approval, testing, human oversight, vendor accountability, and evidence that an AI system works as promised. For a Modesto school district or Central Valley clinic, the practical move is to turn those ideas into a repeatable operating workflow—not a policy PDF nobody follows.
  • What changed in AI governance policy during 2024?
  • Is an AI acceptable-use policy enough?

The most important AI governance policy updates from 2024 were not a single new law for every business. They were a shift toward documented AI inventories, risk-based approval, testing, human oversight, vendor accountability, and evidence that an AI system works as promised. For a Modesto school district or Central Valley clinic, the practical move is to turn those ideas into a repeatable operating workflow—not a policy PDF nobody follows.

At 7:42 a.m. in Modesto, a district curriculum director opens a new AI-assisted lesson-planning tool before the first bell. The vendor promises that teachers can paste reading-level data and receive differentiated assignments in seconds. The director has already approved the tool for “instructional support,” but nobody has decided whether student names, disability accommodations, attendance information, or individualized education program notes may be included in the prompt.

A teacher is about to paste a spreadsheet into the tool. The decision is no longer theoretical. The district must answer three questions immediately: What data is entering the system? What decision will the output influence? And who can stop the workflow if the result is wrong or the vendor changes how it handles prompts?

That is the useful way to read the AI governance policy updates of 2024. The year produced important government guidance and policy milestones, but the operational lesson for Datapath customers is more specific: AI governance belongs in identity management, vendor review, data classification, ticketing, audit logs, and executive accountability.

What changed in AI governance policy during 2024?

Several developments made 2024 a turning point for practical AI governance:

  • NIST published its Generative AI Profile on July 26, 2024, as a companion to the AI Risk Management Framework. It helps organizations identify generative-AI-specific risks and select risk-management actions aligned to their goals.1
  • The Office of Management and Budget issued Memorandum M-24-10 on March 28, 2024, requiring federal agencies to implement minimum practices for safety-impacting and rights-impacting AI, including testing, monitoring, human oversight, and documentation.2
  • California’s 2023 executive order on generative AI directed state agencies to produce procurement, use, and training guidelines by January 2024, including attention to safety, algorithmic discrimination, privacy, and notice when content is generated by AI.3
  • Colorado enacted SB24-205 in May 2024, creating a risk-based framework for high-risk AI systems and assigning duties to both developers and deployers. The law’s specific requirements were scheduled to apply beginning February 1, 2026.2
  • The Federal Trade Commission’s September 2024 Operation AI Comply made clear that businesses cannot use “AI” as a shield for deceptive marketing or unsupported performance claims.4

These developments do not mean every Modesto manufacturer, Modesto healthcare group, or Modesto, California financial institution is automatically subject to every federal-agency rule. They do mean your organization needs a defensible method for deciding what AI may do, what data it may touch, and what proof is required before deployment.

Is an AI acceptable-use policy enough?

No. An acceptable-use policy is a starting point, not governance.

A policy may say, “Do not enter confidential information into public AI tools.” That is sensible, but it leaves unanswered questions that employees face during real work:

  1. Is a Microsoft 365 Copilot tenant configured by the organization an approved tool?
  2. May a clinic use an AI transcription service for patient conversations?
  3. Can a school employee paste a de-identified behavior summary into a public chatbot?
  4. Who approves an AI tool connected to email, the EHR, student information system, accounting platform, or dispatch records?
  5. What happens when a vendor adds a plug-in, changes its training terms, or introduces an autonomous agent?

A workable policy needs a decision path. At Datapath, we recommend connecting the policy to a lightweight AI intake process:

  • Identify the use case: summarization, drafting, classification, recommendation, decision support, or automated action.
  • Identify the data: public, internal, confidential, regulated, financial, health, student, criminal-justice, or credentials and secrets.
  • Identify the consequence: what happens if the output is inaccurate, biased, unavailable, or disclosed?
  • Identify the access path: browser, SaaS integration, API, Microsoft 365, EHR plug-in, ticketing system, or custom application.
  • Assign an owner: a named business owner, technical owner, security reviewer, and executive decision-maker.
  • Define the stop condition: what evidence, incident, drift, or vendor change requires suspension or reapproval?

That turns “AI governance” from an abstract committee topic into a controlled change-management workflow.

What should an AI governance policy contain?

1. An AI inventory that reflects reality

Do not limit the inventory to software purchased by IT. Include browser extensions, meeting assistants, note-taking tools, coding assistants, built-in AI features in productivity suites, and vendor systems that use AI behind the scenes.

For each use case, record:

Inventory fieldExample for a Datapath customerWhy it matters
Business ownerDirector of Special EducationSomeone is accountable for the outcome
System and vendorLesson-planning SaaS with generative featuresThe vendor and version can change
Data involvedTeacher prompts; no student identifiers permittedSets the data boundary
Decision or workflowDrafts differentiated assignments for teacher reviewSeparates assistance from automation
Access methodSSO, browser, or SIS integrationDetermines identity and logging controls
Human checkpointTeacher approves before distributionPrevents unreviewed output from reaching students
Evidence retainedApproval ticket, test results, vendor terms, review dateSupports accountability and reapproval

The inventory should be usable by the people who operate technology. A spreadsheet may be sufficient for a small organization; a service-management platform or governance register may be better for a mid-market business with dozens of tools.

2. A risk tier that changes the approval burden

Not every use case deserves the same amount of paperwork. A tool that rewrites a public marketing paragraph is different from one that ranks applicants, recommends patient follow-up, drafts a child-welfare report, or summarizes a 911 call.

A practical three-tier model works well:

  • Low risk: brainstorming, grammar correction, or summarizing public information. No confidential or regulated data; ordinary human review.
  • Moderate risk: internal knowledge search, ticket summarization, code assistance, finance analysis, or operational recommendations. Approved tenant, access controls, test cases, logging, and a named owner.
  • High risk: anything that materially affects a person’s education, healthcare, employment, credit, public benefits, safety, legal status, or access to services. Formal review, documented testing, human decision authority, monitoring, and an appeal or escalation path.

This is where NIST’s AI RMF and 2024 Generative AI Profile are useful. NIST presents the framework as voluntary and cross-sectoral, organized around governing, mapping, measuring, and managing AI risk.1 For a Datapath customer, that structure can become a quarterly operating rhythm rather than a compliance slogan.

How do 2024 updates affect K-12 districts?

For a K-12 district in Modesto, Ceres, Manteca, Merced, or Fresno, the first policy question is not whether teachers may use AI. It is whether the district can explain what happens to student information when they do.

FERPA regulations address disclosure and recordkeeping for personally identifiable information from education records5. The Department of Education’s regulations require educational agencies and institutions to maintain records of requests for access to and disclosures of personally identifiable information, including the parties involved and their legitimate interests.

That does not mean every AI prompt is automatically a FERPA disclosure. It does mean the district should not treat an AI vendor as an invisible convenience layer. Before approving a tool, ask:

  • Does the vendor receive education-record information or only public content?
  • Is the vendor acting under the district’s direction, and is that relationship documented?
  • Can the district control retention, deletion, onward disclosure, and administrator access?
  • Are prompts and outputs logged in a way the district can review?
  • Can staff use the system without placing names, student IDs, IEP details, or disciplinary information into an unapproved service?

The control is not “ban AI.” The control is an approved-use matrix tied to data classification, account provisioning, teacher training, and a documented exception process. Our K-12 IT team can help districts connect that policy to the systems staff already use.

What does AI governance look like in healthcare and clinics?

An Modesto clinic using AI to draft visit summaries has a different operational risk from a business using AI to write a social-media post. The clinic must preserve clinician judgment, control access to protected information, and validate that the output is accurate enough for the intended workflow.

A good policy should specify whether an AI tool may:

  • transcribe a conversation;
  • draft a clinical note;
  • suggest coding or billing classifications;
  • summarize a patient message;
  • recommend a follow-up task; or
  • send information into the EHR without human approval.

The more directly the tool influences care, billing, or patient communication, the stronger the testing, access, audit, and human-review requirements should be. Use a HIPAA-focused IT engagement to align the AI decision with identity controls, endpoint configuration, vendor review, and incident response. The goal is not merely to obtain a vendor statement that says “secure.” The goal is to know which account accessed which data, what the system produced, who approved it, and how the organization can investigate an error.

What does AI governance mean for local government and public safety?

A county IT department or public-safety organization in the Central Valley should be especially cautious when AI touches dispatch, incident narratives, evidence retention, or law-enforcement systems.

For example, an AI transcription assistant may appear useful for turning dispatch audio into a searchable summary. But governance must answer whether the tool can access criminal-justice information, whether raw audio and generated text have different retention rules, whether a dispatcher must verify the transcript, and whether the output becomes part of an official record.

The workflow should include:

  1. approval by the business and security owners;
  2. documented data-flow mapping from microphone or CAD system to vendor and storage location;
  3. test scenarios using representative but controlled data;
  4. an accuracy and failure review by dispatch personnel;
  5. access logging and retention rules;
  6. a manual fallback if the AI service is unavailable; and
  7. a documented incident path if the output is wrong or sensitive data is exposed.

Do not attach a specific CJIS version or deadline unless your compliance team has verified the applicable authority and current contractual requirements. Instead, map the AI workflow to the organization’s existing criminal-justice security, access, logging, incident-response, and evidence-handling controls. Datapath’s CJIS compliance services can help make that mapping operational.

How should you evaluate an AI vendor in 2024 and beyond?

A vendor questionnaire is not enough if nobody tests the answers. Require evidence that matches the use case.

Ask the vendor for:

  • the exact product and feature being approved;
  • data-flow and subprocessors information;
  • retention, deletion, and training-use terms;
  • administrative roles and audit-log capabilities;
  • access to security documentation and incident-notification terms;
  • model or feature-change notification procedures;
  • testing or evaluation evidence relevant to the promised function; and
  • a clear description of what the product cannot reliably do.

The FTC’s 2024 enforcement action against companies making unsupported AI claims is a useful business-control reminder. The agency stated that there is no AI exemption from existing laws, and its action against an “AI lawyer” provider alleged that the company had not tested whether its output matched the expertise it claimed to replace.4

For your organization, translate that into a procurement rule: a vendor may describe capabilities, but your approval record should document the evidence, limitations, and conditions under which the tool is allowed to operate. That is particularly important for finance teams approving wires, HR teams screening candidates, and public agencies communicating with residents.

How do you make the policy enforceable?

A policy becomes real when it changes a system or a decision. Start with five enforcement points:

Identity and access

Use SSO where available, require strong authentication, remove personal accounts from approved workflows, and review OAuth permissions. An AI agent should never inherit broad access simply because a user has it.

Data loss prevention

Block or warn on uploads of sensitive documents to unapproved services. For Microsoft 365 environments, connect sensitivity labels, DLP, endpoint controls, and approved enterprise AI configurations.

Change management

Treat a new plug-in, model, connector, or autonomous action as a material change. Require reapproval when the data source, decision purpose, vendor terms, or level of automation changes.

Monitoring and review

Track usage, failed prompts, incidents, access anomalies, quality complaints, and material changes in output. OMB M-24-10 requires federal agencies to use adequate testing, ongoing monitoring, periodic human review, and alternative human oversight or opt-out mechanisms in applicable AI uses.2 A private organization may not be bound by that memorandum, but the operating discipline is a strong model.

Training and accountability

Teach employees what may be entered, which tools are approved, how to recognize fabricated output, and where to report a problem. Assign a person—not a committee in the abstract—to own each production AI use case.

A practical 30-day AI governance update plan

If your current policy is a one-page acceptable-use document, do not try to solve everything in one board meeting. Use a focused first month:

Days 1–5: Find the real usage. Review SaaS administration, browser, DNS, endpoint, and identity signals. Interview department leaders. Ask what staff are already using, not just what IT purchased.

Days 6–10: Classify the data and workflows. Mark which use cases touch student, health, financial, personnel, public-safety, customer, or proprietary information.

Days 11–15: Create the decision matrix. Define allowed, approved-tool-only, restricted, and prohibited uses. Name the approval owner and required human checkpoint for each category.

Days 16–20: Review vendors and permissions. Examine contracts, retention, training use, subprocessors, integrations, OAuth grants, privileged accounts, and logging.

Days 21–25: Test two real workflows. Choose one low-risk workflow and one consequential workflow. Record expected results, failure modes, reviewer responsibilities, and stop conditions.

Days 26–30: Publish and operate. Train staff, open a request path for new tools, schedule a quarterly review, and place the inventory and approvals where IT and leadership can retrieve them.

Where should a Datapath customer start?

The 2024 AI governance policy updates point to a durable operating model: know what is in use, understand what data it touches, test what it produces, preserve human authority, and retain evidence of the decision.

That model fits a Modesto school district, an Modesto clinic, a Fresno-area public agency, a credit union in Modesto, California, or a mid-market company in Modesto. The tools and regulations may differ, but the accountability problem is the same: an AI system can move faster than the organization’s ability to explain it.

Datapath helps customers connect AI governance to the controls they already need—managed cybersecurity, vendor risk management, vCISO leadership, identity controls, data protection, and incident response. If your organization cannot yet produce an inventory of approved AI uses, start there. Then schedule a Datapath consultation to turn the inventory into a policy your team can actually enforce.


Footnotes

  1. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile | NIST 2

  2. March 28, 2024 M-24-10 MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES FROM: Shalanda D. Young SUBJECT: Advancing Governance, 2 3

  3. Executive order | GenAI

  4. FTC Announces Crackdown on Deceptive AI Claims and Schemes | Federal Trade Commission 2

  5. FERPA | Protecting Student Privacy

See also

Disclaimer: This blog is intended for marketing purposes only, and nothing presented in here is contractually binding or necessarily the final opinion of the authors.

Need a practical roadmap for regulated-industry IT performance?

Datapath can benchmark your current model and define the next 90 days of high-impact improvements.

Book an IT Consultation