AI Governance: Between the Prompt and the Policy

BLOG

TL;DR – AI adoption is already happening across the organization, often faster than security teams can see, assess or govern it. To protect the organization, start by understanding how it’s used, assessing the risks and building AI governance that can evolve with the technology.

  • Visibility first: Understand which tools, data, users and business processes are already interacting with AI
  • Governance based on risk: Not every AI use case carries the same exposure
  • Continuously evolve  AI governance: Organizations need clear ownership, practical guardrails, employee awareness and a way to continuously reassess AI use as technology and business practices, priorities and risk change

There is a version of AI adoption that happens in a boardroom, with executive sponsors, approved vendors, security reviews and carefully documented use cases. And then there’s a version happening at 10:17 AM on a random Tuesday morning. 

An employee has a document that needs to be summarized. A developer is trying to solve a problem with unfamiliar code. Someone in finance needs to make sense of a large dataset. A sales representative wants to prepare for upcoming customer meetings. They open a browser and use a readily available  AI tool (ChatGPT, Claude, etc.) and the work gets done.

For an employee, this is productivity. For the security organization, it may be an interaction IT never sees and the data is no longer protected by enterprise controls.

That Shadow AI gap is becoming one of the more consequential challenges of AI adoption. Organizations are trying to establish policies and AI governance while it’s already becoming embedded in the way people work. The technology is moving through the organization from the bottom up, while governance is traditionally built from the top down.

Those two things are now colliding.

The Visibility Problem is Bigger Than Shadow AI

The term “shadow AI” has become a convenient way to describe employees using AI tools outside approved channels. But the label can make the issue sound simpler than it is.

The bigger concern is visibility. AI is becoming part of ordinary work before many organizations have established what they need to know about how it is being used.

That raises some basic questions:

  • What information is being entered into these systems?
  • Which applications can access company data?
  • Where does the data go?
  • Who has access to that data?
  • How long is it retained?
  • Which AI-generated outputs are being used to make business decisions?
  • Who is accountable when an AI-enabled process produces an unexpected result? 

A policy can address some of these questions, but it cannot provide visibility into the activity the organization does not know is happening.

Recent research from the FAIR Institute found that 80% of organizations surveyed are either actively using AI or experimenting with it within their cyber risk programs, including 43% that are currently in the experimentation phase.¹

Experimentation is often where governance is least mature. Employees are discovering useful applications and incorporating them into their work while organizations are still establishing the policies, ownership and controls needed to govern them.

That makes visibility an important starting point for AI governance. Before an organization can determine what should be restricted, approved, monitored or encouraged, it needs to understand what is already happening.

This changes how security teams should think about employee behavior. 

An employee who pastes sensitive information into an AI tool may not be disregarding security. They may not understand the distinction between an approved enterprise application (with enterprise protections in place) and a consumer service (with no security controls). They may simply be trying to solve a problem with a tool that makes the work easier.

Treating every instance as a failure of compliance misses the more important issue: the organization has not yet made the safe path clear enough, visible enough or useful enough.

Organizations Are Responding From Very Different Starting Points

Organizations have responded to that uncertainty in very different ways. Some have restricted AI completely because a clear boundary feels easier to manage. Employees, however, still have work to do and the demand for tools that make that work faster and easier does not disappear because access is restricted, so they find workarounds to the restrictions.

Other organizations have taken the opposite approach, allowing experimentation to proceed with relatively relaxed restrictions and are learning about the risks as adoption develops.

Neither approach addresses the underlying questions of how AI becomes part of the organization’s operation model.

A more mature approach begins to distinguish between use cases rather than treating AI as one category of risk. An employee using an approved tool to summarize publicly available information presents a different set of considerations from a business process that sends sensitive customer information to an external model. A coding assistant working with proprietary source code raises different questions from an application generating marketing copy. The technology may be similar, but the exposure, business impact and appropriate level of oversight vary considerably.

That distinction matters because effective AI governance cannot treat every use case the same way. Organizations need enough understanding of where AI is being used, what information it touches, who would have access to that data (e.g., will it be used to train AI models) and what decision it influences to determine where controls and oversight are warranted.

The result is a more deliberate approach to AI, one that creates room for more useful applications while giving the organizations a clear basis for deciding where boundaries belong.

Regulation is Formalizing Expectations

As AI adoption accelerates, organizations are facing a growing set of expectations for how AI should be understood, governed and managed. The NIST AI Risk Management framework gives organizations a structured approach for identifying, measuring and managing AI risks. Its Generative AI Profile addresses risks specific to generative AI. At the same time, the EU AI Act is also establishing requirements around areas including AI literacy, transparency and high-risk AI systems as its implementation progresses. 

For organizations operating in regulated industries, AI can also intersect with requirements that already exist around cybersecurity, privacy, intellectual property, export controls and third-party risk.

Rather than building a separate compliance program for AI, organizations need to update their existing risk and compliance processes to account for the nuances of AI adoption. This includes addressing practical questions around AI ownership, oversight, data handling and risk. Those that begin answering these questions now can build AI governance into the risk and compliance processes they already have, rather than creating a separate program that struggles to keep pace with adoption.

AI Governance Requires a Risk-based Approach

When considering how to securely enable AI across an organization, the first step is to understand the organization’s risk appetite and tolerances. From there, organizations can map AI adoption and governance to their existing risk profile, identifying where different uses of AI may create different levels of exposure and where additional controls may be appropriate.

This approach shifts the focus from asking whether AI is broadly “safe” or “unsafe” to understanding the specific risks associated with how AI is being used. Common risk frameworks provide a way to evaluate those risks in terms of factors such as potential frequency and magnitude of loss, creating a more consistent way to compare scenarios that might otherwise be difficult to put on the same scale.

For example, consider two AI use cases:

  1. An AI application might occasionally produce an error that creates a small amount of operational inconvenience
  2. Another might expose sensitive information or introduce a dependency into a critical business process

Both are AI risks, but they represent very different levels and types of exposure and may warrant very different controls. They are not necessarily risks that the organization should treat the same way.

Instead of asking whether an AI application is safe, leaders can ask more practical questions:

  • What could happen? 
  • How often could it happen? 
  • What could the resulting loss look like?
  • How much exposure is the organization willing to accept? 
  • Are the proposed controls proportionate to that exposure?

That shift — from trying to eliminate uncertainty to making informed decisions about it — is at the heart of effective AI governance.

Governance Should Make the Right Behavior Easier

Once an organization understands where AI is being used and which scenarios matter, governance becomes much more practical. Instead of trying to create rules for every possible application, organizations can establish clear boundaries around the areas that carry the greatest risk. 

  • Employees need to know which tools they can use, what information they can share, when human review is required and when a use case warrants additional scrutiny. 
  • Security teams need visibility into the systems and data involved. 
  • Business leaders need a practical way to make decisions about AI use without sending every question through an unnecessarily heavy review process.

This is where governance can break down. 

  • A policy without visibility becomes a statement of intent. 
  • Visibility without ownership becomes a dashboard. 
  • Technology without a decision framework creates more information without necessarily creating better decisions.

Effective governance connects all three: visibility into what is happening, clear ownership for deciding what should happen and a risk-based framework for determining where controls and oversight are appropriate.

The framework also needs to recognize that governance cannot be static as AI capabilities are changing rapidly and new tools and use cases appear without necessarily passing through the original governance process. As the technology, data and business context change, organizations need to revisit their assumptions, reassess risk and adjust their controls.

That’s what makes AI governance into an operating capability rather than a one-time compliance exercise. Creating a repeatable way to understand how AI is being used, make informed decisions about that use, align with business priorities and risk and adapt as the technology and the organization evolve.

From Awareness to Action

The first step in governing AI is understanding the environment you already have.

Security teams need to know where AI is being used, what data and systems it touches, how employees and applications are interacting with it and where existing policies or controls may not reflect reality. From there, organizations can begin defining ownership, prioritizing risks and establishing practical guardrails that support responsible adoption without unnecessarily slowing the business.

That conversation doesn’t need to start with a massive AI governance program. It can start with a clear view of your current exposure and an honest discussion about where your organization needs visibility, ownership and control.

GuidePoint Security briefings can help your organization assess its current AI risk posture, identify gaps in visibility and governance and define practical next steps for responsible AI adoption.

Schedule a security briefing with our Governance, Risk and Compliance experts to assess your AI risk landscape and discuss a governance approach aligned to your organization.

Source: 1. FAIR Institute, 2026 State of Cyber Risk Management Report, sponsored by GuidePoint Security, 2026.

FAQs

Shadow AI is the use of AI tools by employees outside approved enterprise channels. It creates visibility gaps because security teams cannot monitor or govern interactions they do not know are happening.

AI governance works best as a shared responsibility across security, compliance, legal and business leadership. Each group brings a different lens that no single owner can replicate.

Traditional IT governance manages known systems with predictable behavior. AI governance must also account for how models use data, where outputs influence decisions and how rapidly new tools enter the environment.

An AI risk assessment should inventory all AI tools in use, classify data exposure by use case and evaluate controls against your existing risk framework. The goal is a prioritized remediation path tied to business impact.