It is already in use, and that is the starting point.
By the time governance is discussed, people are using assistants for drafting, summarising and analysis, usually with tools they chose themselves. A policy written as though adoption has not started describes a situation that does not exist. The first useful act is an inventory: what is being used, by whom, on what data, and for what.
The risk is rarely the model. It is the data and the decision.
Two questions separate a harmless use from a serious one: what information does it see, and does its output affect somebody. Summarising a public document is not the same as ranking candidates or setting a price. Treating those alike produces either a policy that blocks useful work or one that permits things it should not.
We inventory, classify, then set proportionate controls.
Record each use with its owner, its data, and whether a person or a system acts on the output. Classify on that, not on the tool. Set controls to match: disclosure where output is published, a human decision where a person is affected, retention rules where the data is sensitive, and a review date on everything. Then make registering a new use easy, or the inventory goes stale within a quarter.
What you are left with.
A register of AI use with named owners, a classification anybody can apply without a specialist, controls proportionate to the risk rather than uniform, and a route to approve a new use in days. Not a policy document nobody reads.

