The most common question after a leader decides to take AI governance seriously is also the one with the most misleading answers online: where do I start? Search it and you'll get a confident, universal checklist. Write a policy. Form a committee. Pick your tools. Run training.
The trouble is that the right first move isn't universal. It depends entirely on where you're starting from. The same step that's exactly right for one company is a waste of a month for another, because they're standing in different places. Start with the wrong move for your stage and you build carefully on sand.
If you're starting from scattered use
Some organizations are at the beginning: AI is everywhere, but nothing structures it. No policy, no owner, no agreed line on data. If that's you, the first 30 days are not about a grand framework. They're about the two things everything else depends on, a basic policy people can actually follow and a simple way to tell which data is safe to use (green, yellow, red is enough). Skip those and any training or rollout you layer on has nothing to stand on. This is the foundation, and there's no shortcut past it.
If you're aware but unstructured
Other companies already have leadership attention and some loose guidance. The gap isn't awareness, it's that nothing is solid. For them, the first month is about turning attention into structure: assigning a real owner, writing the informal guidance down into something concrete, giving people a classification they'll actually use. The raw material is there. The work is making it stick instead of evaporating the next time someone's on a deadline.
If you're already governed
A few organizations have the foundation: a real policy, classification, an owner, AI tied to actual work. Their first 30 days look nothing like the first two cases. The risk here isn't a missing foundation, it's a foundation going stale as the tools keep changing. So the early moves are about durability: a training rhythm instead of a one-time session, policy reviews on a calendar instead of after an incident, and a standing way to vet the next tool without reopening every settled question. The job shifts from building governance to keeping it alive.
Why the order matters so much
Each stage's right first move is the wrong move for the others. Run sophisticated training across a company that has no policy and no data classification, and you've taught people to use tools well with no line telling them what's safe, polished behaviour on an unsound base. Go back to write a foundational policy at a company that already has a good one, and you've spent a month re-deciding settled questions while the real gap, staleness, widens.
This is the whole reason the universal checklist fails. It assumes everyone is at the same starting line. The single most useful thing you can do before day one is figure out which stage you're actually in, because that answer determines everything that should follow.
That's exactly what the AI Readiness Assessment is for. It places you on the maturity spectrum across all five dimensions and points to the one move that matters most from where you stand, in about two minutes. It's the same five-dimension read our Governance Audit goes deep on, and it's the fastest way to make sure your first 30 days are spent on the right thing.
There's no universal first step. There's only the right first step for where you are, and the fastest way to waste a month is to take someone else's.
Keep reading
Part of a series on AI governance, the structure underneath the tools.
- The 4 Stages of AI Governance Maturity. The stages that decide which first move is yours.
- What a Good Governance Audit Actually Covers. What actually happens once you know your stage.