Your Team Is Already Using AI. But Who Is Governing It?

AI Governance

AI didn’t arrive in most businesses through a formal implementation project.

It just arrived.

Someone started using ChatGPT to draft an email. Marketing started using AI to create content. HR used it to help with a policy. A manager uploaded a spreadsheet for analysis. Someone else discovered an AI tool that could save them three hours of work.

Before long, AI became part of the way the business operates.

And that’s a good thing. The productivity gains are real.

But there’s another side to this that I think many businesses are overlooking:

Do you actually know how your people are using AI?

More importantly, do you know what information they are putting into it?

Think about what gets copied and pasted into AI tools every day: customer information, employee records, contracts, proposals, financial information, policies, procedures, pricing, intellectual property and sometimes entire documents.

Most employees aren’t doing anything malicious. They’re simply trying to get their work done faster.

But from a governance perspective, that creates a very different conversation.

We protected our information. Then we started pasting it into AI.

For years, businesses have spent significant amounts of money protecting information.

We implemented access controls, firewalls, Microsoft 365 permissions, confidentiality agreements, document-control systems, information-security policies and data-protection processes.

Then AI came along.

Now someone can potentially take information from that controlled environment, paste it into an external AI platform and ask:

“Can you analyse this for me?”

That’s where organisations need to start asking some uncomfortable questions.

Where did that information just go?

How is it being processed?

Is it retained?

Can it be used for training?

Was the employee authorised to share it?

Does it contain personal information?

Does it contain your client’s confidential information?

Does it contain your intellectual property?

And perhaps the biggest question:

Do you even know that it happened?

I’m not suggesting businesses stop using AI

Quite the opposite.

AI is quickly becoming one of the most useful productivity tools available to businesses. Trying to ban it completely will probably just result in people finding ways to use it without telling you.

The better conversation is about governance.

Which AI platforms are approved?

What information can employees put into them?

What information is off limits?

Where should sensitive information be processed?

When does an AI-generated answer require human review?

Who is accountable when AI is used to support a business decision?

And when are we going to start properly sandboxing our intellectual property, personal information and confidential business data?

Because information leakage isn’t the only risk.

AI can confidently give you the wrong answer.

It can introduce bias into decisions.

People can rely on outputs without checking them.

Copyright and intellectual-property questions can arise.

Personal information can be processed without people fully appreciating what they are doing.

And accountability can become very blurry, very quickly.

“The AI told me to do it” isn’t going to be a particularly useful defence when something goes wrong.

This is where ISO/IEC 42001 becomes interesting

ISO/IEC 42001 is the international management-system standard specifically focused on artificial intelligence.

What I like about the management-system approach is that it doesn’t start with “stop using AI.”

It starts with understanding how AI is being used, what risks and opportunities that creates, and then putting appropriate governance around it.

The standard provides a framework for establishing and continually improving an Artificial Intelligence Management System (AIMS). It applies not only to organisations developing AI, but also to organisations using AI-enabled products and services.

That distinction is important.

You don’t have to be an AI company to have an AI governance problem.

If your employees are using AI to perform their jobs, AI is already part of your organisation.

Start with one simple exercise

Ask your management team:

What AI tools are currently being used in our business?

Then ask:

What company, customer and employee information is being entered into those tools?

The answers might surprise you.

From there, governance becomes far more practical.

Identify the AI tools being used. Understand what they’re being used for. Assess the risks. Decide which platforms are approved. Establish rules around sensitive information. Assign accountability. Train your people. Determine where human oversight is necessary.

Then monitor it.

That’s essentially what good management systems have always done: create enough structure to manage risk without getting in the way of the business.

ISO itself describes ISO/IEC 42001 as a way of managing AI-related risks and opportunities through policies and processes while still supporting responsible innovation.

AI adoption has already happened. Governance needs to catch up.

The question isn’t whether your business should use AI.

Your people probably already are.

The question is whether you’re going to wait for an incident before you start governing it.

AI presents an enormous opportunity for productivity, automation and better decision support. Businesses should absolutely explore that opportunity.

But we also need to know where our information is going.

We need to protect our intellectual property.

We need to protect personal and confidential information.

We need people to understand the boundaries.

And we need somebody to remain accountable.

Use AI. Encourage your people to use it. But govern it.

Because AI might be moving incredibly quickly.

Your responsibility for the information you put into it hasn’t disappeared.


Leave a Reply

Your email address will not be published. Required fields are marked *

This is a staging environment