
AI governance covers what staff may put into these tools, what must be checked before the output is used, and when the use has to be disclosed. Most organisations are writing those rules after adoption has already happened, which changes the task from prevention to correction.
The Gap Between Adoption and Policy Is Structural
A capable tool reaches a working professional through a colleague, a social feed, or a free tier that requires no approval from anyone. Trying it costs a few minutes and produces a visible result on the same afternoon.
Writing a policy about that tool involves legal review, a data protection assessment, a discussion about which functions are affected, and a decision about enforcement. Those steps take weeks at best in a business with the appetite to attempt them.
The mismatch is not a failure of diligence by anyone involved. Individual adoption runs on curiosity and immediate benefit, while organisational rulemaking runs on consensus and risk assessment, and the two operate at incompatible speeds.
Assuming the gap can be eliminated leads to the wrong programme of work. The realistic objective is a narrow gap with visibility into what is happening inside it, rather than a closed gap that has never existed anywhere.
The gap also reopens with every capable release. A policy written about one category of tool becomes partially obsolete when the same vendor adds a feature that changes what data the tool touches.
Governance therefore has to be designed as something that gets revised, not as a document that gets finished. Businesses treating it as a one-time drafting exercise find their rules describing a landscape that no longer exists.
Speed of change is not the only reason the gap persists. Staff adopting a tool are answering a question about their own work, while policy writers are answering a question about the whole organisation.
Procurement Cannot Solve a Capability Problem
The instinctive response is to control the tools through purchasing and network restrictions. Approved platforms are selected, accounts are provisioned, and everything else is blocked at the firewall.
That approach worked reasonably well for software that had to be installed on a company machine. It works poorly for capability that is available through any browser and on every personal phone in the building.
Blocking a domain removes it from the corporate network and leaves it fully available on the device in every pocket. Staff who found the tool useful will continue using it and will stop mentioning that they do.
The blocking approach therefore converts visible use into invisible use. Nothing about the underlying risk changes, and the business loses its only source of information about where the risk sits.
Restriction also carries a productivity charge that rarely gets counted. Staff who were working faster with a tool return to slower methods, and the people most affected are usually the most capable ones.
Understanding the shape of unsanctioned tool use inside organisations that never approved it tends to change the response from restriction toward disclosure. Knowing what is being used is worth more than a rule that pushes the same activity out of sight.
Approved provisioning still matters and does a different job. Paying for business accounts gives the organisation terms it can rely on and a place to send staff who want a legitimate route.
What the Gap Actually Exposes
The first exposure is data leaving the business. Staff paste customer records, supplier terms, draft contracts and internal figures into services whose retention terms nobody in the business has read.
Free consumer tiers deserve particular attention in this area. Terms for consumer accounts frequently differ from the business equivalents, and the difference usually concerns whether submitted content is retained or used for training.
The second exposure is output that reaches a customer without review. Generated text is fluent and confident regardless of accuracy, which removes the usual signals that a draft needs checking.
Errors that would have been caught in a rough draft pass through a polished one. Reviewers read for tone and structure, find both acceptable, and never test the underlying claims.
The third exposure is contractual rather than technical. Client agreements and supplier terms increasingly contain clauses about automated processing, and staff using these tools have no visibility into which agreements say what.
The fourth exposure concerns the provenance of finished work. When a piece of work is later questioned, nobody can establish how it was produced, which turns a routine query into an investigation.
A fifth exposure sits in undeclared dependency on one person. Work quietly reorganises around a tool that a single employee pays for personally, and the capability leaves the business when they do.
Rules That Can Be Written Within the Month
An adequate first policy is short enough to be read in one sitting. Long documents produce compliance theatre, since nobody consults a policy they cannot remember the shape of.
The first rule concerns what may go into the tools. A plain statement of what may never be entered into an external tool, naming customer identifiers, credentials, unpublished financials and anything covered by a confidentiality obligation.
The second rule concerns review of what comes out. Any output reaching a customer, a regulator or a decision maker has to be checked by a named person against a source. The check itself has to be recorded somewhere.
The third rule concerns which routes are approved. Naming the tools the business has provisioned, and stating that anything else requires a short conversation rather than a formal request, keeps the disclosure barrier low enough to be used.
The fourth rule concerns what clients are told about it. Deciding in advance what will be said if a customer asks whether these tools were involved prevents an improvised answer under pressure.
The fifth rule concerns ownership of the policy itself. Somebody has to be responsible for reviewing the policy on a stated cycle, because a rule set with no owner ages into irrelevance without anyone noticing.
Practical evaluation of which of these tools a smaller business should actually be running belongs alongside the rules rather than after them. Approving a small number of specific tools gives staff a legitimate route and makes the input rules concrete.
Each of these exposures is manageable once it is known about. What makes them dangerous is that all of them are invisible until something goes publicly wrong.
Amnesty Produces Better Information Than Enforcement
Businesses that discover widespread unapproved use face a choice about how to respond. Punishment is available and destroys the visibility that made the discovery possible.
A stated amnesty produces a far better result. Asking staff to declare what they have been using, with an explicit commitment that nobody will face consequences for past use, produces a map of actual practice within days.
The map is usually surprising in useful ways. Adoption tends to cluster in functions nobody expected, and the tools in heaviest use are often not the ones the business was worried about.
That information changes what the rules need to cover. Policy written against a real inventory addresses situations that exist, while policy written against imagined risk addresses situations that do not.
The declaration also identifies the informal experts inside the business. Staff who adopted early usually understand the failure modes better than anyone in management, and they make credible advocates for the rules that follow.
Repeating the exercise periodically keeps the map current. A short standing question in an existing management meeting is sufficient, and it costs less than any monitoring system.
Governance as a Habit Rather Than a Document
The written policy is the smallest part of the work. What determines whether governance holds is a set of recurring behaviours that keep the rules connected to what people are actually doing.
The first behaviour is asking about it routinely. Managers who include tool use in ordinary conversations about how work was produced normalise the topic and remove the sense that admitting to it invites trouble.
The second behaviour is reviewing the rules on a schedule. Someone reads the policy against the current tool inventory at a stated interval, and the review takes an hour rather than a project.
The third behaviour is deciding openly and quickly. When staff request a new tool, answering within days, with reasons, teaches everyone that the approved route is faster than the unapproved one.
Speed of response is the mechanism that keeps the whole system honest. A request that sits unanswered for a month trains the requester to stop asking, and one silent refusal undoes a great deal of written policy.
The fourth behaviour is correcting people without punishing them. Where a rule was broken, the useful response separates the person from the process and asks why the approved route was harder than the alternative.
The plain fact about this subject is that the organisation was never in control of the sequence. Tools capable enough to change how work is done arrived in the hands of individuals first. No amount of policy discipline could have reversed that order. What remains available is the choice between governing a practice that is visible and pretending to govern one that is not. Businesses that accept the sequence and work with it end up with usable rules. Those that insist on the sequence they wanted end up with a document and no visibility.
Frequently Asked Questions
Where should a business start if it has no policy at all?
The right starting point is an inventory rather than a document. Asking each function what tools are currently in use, under an explicit amnesty, produces the information that any sensible policy has to be built on. Writing rules before knowing the actual practice guarantees a mismatch between what the policy addresses and what staff are doing. The inventory usually takes days and the first policy can follow within the same month.
Is blocking these tools ever the right answer?
Blocking makes sense for specific tools with terms that are genuinely incompatible with the obligations the business carries. It fails as a general strategy because the capability remains available on personal devices that the business does not control. A blanket block converts a manageable visible problem into an unmanageable invisible one. Selective restriction paired with an approved alternative works considerably better than restriction alone.
Who should own this inside a smaller business?
Someone senior enough to make decisions and close enough to the work to know what is being produced. Placing it entirely with a technical function tends to produce rules about systems rather than about practice. Placing it entirely with a legal or compliance adviser tends to produce rules nobody can follow. A named operational owner, with access to both perspectives, is the arrangement that survives contact with daily work.
How detailed does a first policy need to be?
Short enough that staff can recall its main provisions without looking. A page covering inputs, review obligations, approved tools, client disclosure and ownership is enough to manage the material risks. Detail can be added once the business understands where its actual exposure sits, which becomes apparent within a few months of the policy existing. Starting with a long document delays the start and improves nothing.
What about staff using personal accounts on personal devices?
That situation cannot be prevented and can be addressed through obligation rather than through control. The rules that matter concern what information may leave the business and what has to be checked before work is delivered, and both apply regardless of which device was used. Framing the policy around information and output rather than around equipment closes the loophole. Attempting to police personal devices generally fails and damages trust in the process.
How often should the rules be revisited in practice?
On a stated cycle, with an owner responsible for the review, and additionally whenever a tool in active use changes materially. Quarterly review suits most smaller businesses, since it is frequent enough to track the pace of change and infrequent enough to be sustained. The review should compare the policy against the current inventory rather than reading the policy in isolation. Reviews that never produce a change are usually reviews that never looked at practice.
No comments:
Post a Comment