Governments and large organisations are facing an uncomfortable truth.
Artificial intelligence is no longer something staff only access by visiting a website called ChatGPT.
It is being built into search engines, browsers, phones, productivity tools, meeting platforms, operating systems, cameras, glasses, watches, earbuds, vehicles and devices that barely look like “technology governance” problems at all.
And yet, many organisations are still trying to govern AI as though it is just another application that can be approved, blocked, monitored or removed from a corporate laptop.
That world no longer exists.
The old model of technology control was built around a simple idea: if the organisation controlled the device, the network and the software, it could control the risk.
That model still matters.
But it is no longer enough.
Because AI is becoming ambient.
It is not just a tool people open.
It is becoming part of the environment they work in.
And that changes everything.
The biggest AI risk may be the use you cannot see
A government department might block access to a public AI chatbot on a work computer.
But can it stop someone using AI on their personal phone?
Can it stop them using an AI assistant in their browser?
Can it stop them using smart glasses, AI-enabled earbuds, a personal laptop, a home network, or a consumer app that now has AI quietly built in?
In many cases, no.
That does not mean governance is pointless.
It means governance has to evolve.
Because the real choice is not between employees using AI and employees not using AI.
The real choice is between:
visible, governed AI use
and
invisible, unmanaged AI use.
That distinction matters.
When organisations make safe AI use too slow, too confusing or too restrictive, people do not simply stop using AI.
They find workarounds.
They use personal accounts.
They use personal devices.
They use unofficial tools.
They copy and paste results back into corporate systems.
They email themselves outputs.
They quietly use AI because it helps them get their work done.
Most of the time, this is not malicious behaviour.
It is often the behaviour of capable, motivated, overloaded employees trying to keep up with modern expectations.
But it creates a serious problem.
The organisation loses visibility.
It loses auditability.
It loses the ability to guide safe practice.
It may not know what information was shared, where it was processed, whether the output was checked, or whether a decision was influenced by an unreliable result.
That is not governance.
That is risk with the lights off.
A blocked chatbot is not an AI strategy
One of the most common mistakes organisations can make is assuming that blocking a tool means they have controlled the risk.
They have not.
They may have only moved the risk somewhere they can no longer see it.
This is why AI governance cannot be built only around approved tool lists and blocked websites.
Those things still have a place.
But they are not enough.
AI tools are changing too quickly. Existing products are adding AI features constantly. Devices are becoming intelligent, connected and capable of recording, transcribing, translating, summarising and assisting in real time.
A governance model based only on naming specific tools will always be chasing the last version of the problem.
The better model is to govern the behaviour, the data, the task and the risk.
Instead of asking only:
“Is this tool approved?”
organisations need to ask:
What information is being used?
Is it public, internal, sensitive, confidential, personal or restricted?
What is the person trying to do?
Will the output influence a decision?
Does the result need human review?
Where is the data processed?
Is the use logged?
Is the environment appropriate for the risk?
That approach is more durable.
Because whether AI is inside a browser, phone, laptop, meeting tool, search engine, pair of glasses or internal server, the same principle applies:
The rules should follow the data, the context and the risk.
Not just the logo on the tool.
Training is not the soft part of AI governance
For years, training has often been treated as the soft side of technology governance.
Useful, yes.
But secondary to procurement, policy, risk registers, security controls and approval processes.
With AI, that thinking is backwards.
Training is now a core control.
People need to know what they can and cannot do.
They need practical guidance on what kinds of information can be used with which tools.
They need to understand the difference between using a public AI tool with public information and using an approved enterprise platform with appropriate contractual, security and data protections.
They also need to understand that not all AI deployment models are the same.
Public cloud AI is not the same as enterprise AI.
Enterprise AI is not the same as private cloud AI.
Private cloud AI is not the same as sovereign cloud.
And none of those are the same as local or on-premise models operating inside a controlled environment.
This matters enormously.
Some teams handle sensitive information every day: legal, procurement, regulation, biosecurity, human resources, cyber security, executive services and many others.
Their caution is understandable.
But caution without capability can become paralysis.
If decision-makers believe the only version of AI is “send sensitive material into a public chatbot”, they may design policies that block legitimate, safe and valuable use cases.
The question should not be:
“AI, yes or no?”
The better question is:
“Which AI model is appropriate for this task, this data, this risk and this environment?”
That is a much more useful conversation.
Policy cannot be written by spectators alone
There is another uncomfortable truth.
Many people shaping AI policy are not using these tools deeply in their day-to-day work.
That is a problem.
You cannot effectively govern a capability you have not experienced.
That does not mean every policymaker needs to become a machine learning expert.
But it does mean they need hands-on literacy.
They need to understand what these tools can actually do.
They need to experience the productivity gains, the risks, the hallucinations, the limitations, the workflow changes and the practical reality of using AI under pressure.
AI can draft, summarise, compare, translate, analyse, code, interrogate documents, explore data, generate options, prepare training material and automate repetitive work.
In the right hands, the productivity improvement is not marginal.
It can be transformational.
If AI policy is written only from a risk perspective, without understanding the benefits, the result will be predictable:
excessive caution,
unclear rules,
poor adoption,
and a growing gap between official policy and actual behaviour.
Good governance needs both perspectives.
Security, privacy, legal, procurement and records management must be at the table.
But so must the people who use AI daily and understand its real-world value.
We should use AI to help govern AI
This is where the conversation needs to become more ambitious.
AI should not only be something organisations govern.
It should also become part of how they govern.
That may sound counterintuitive.
If AI creates new risks, should we really use AI to manage those risks?
Yes, carefully.
Because static policies, annual training sessions and manual reviews are too slow for the world we are entering.
AI governance needs to become more dynamic, contextual and immediate.
Imagine a shared project workspace containing documents, spreadsheets, emails, meeting notes, stakeholder lists, research material and draft briefings.
An AI governance assistant could help identify risks before mistakes occur.
It could flag that a document appears to contain personal information.
It could suggest that material should be de-identified.
It could warn staff before sensitive content is copied into a public AI tool.
It could recommend an approved internal AI system.
It could remind people when human review is required.
It could identify possible legal sensitivity.
It could provide just-in-time guidance at the point of use.
That is a very different model of governance.
Instead of expecting every employee to remember every rule in every situation, the organisation could provide practical support when and where people need it.
That is powerful.
Because good governance should not rely on someone remembering a policy they read six months ago.
It should help them make a better decision in the moment.
Assistive governance, not surveillance
This must be handled carefully.
There is a fine line between helpful governance and intrusive surveillance.
The goal should not be to create a digital compliance officer hovering over everyone’s shoulder.
That would damage trust.
The better model is assistive governance.
AI governance agents should help people do the right thing.
They should guide, warn, educate and escalate only where appropriate.
They should be transparent about what they monitor, why they monitor it, and how the information is used.
The purpose should be to reduce accidental misuse, not create a culture of fear.
Tone matters.
A good governance system should not immediately accuse someone of doing the wrong thing.
It should explain the risk and suggest safer options.
For example:
This content appears to include sensitive or personal information. It may not be suitable for use with a public AI tool. Consider removing identifying details, using the approved internal AI platform, or seeking advice before proceeding.
That is not punitive.
It is practical.
And that is the kind of governance people can work with.
The safest path must also be the easiest path
This may be the most important principle of all.
If the approved AI pathway is slower, clunkier and less useful than the unofficial workaround, people will choose the workaround.
That is human nature.
It is also organisational reality.
Governance cannot depend on making the right thing difficult and hoping people do it anyway.
The safest path must also be the easiest path.
That means approved AI tools must be genuinely useful.
Guidance must be clear.
Training must be practical.
Low-risk use cases should be easy to start.
Medium-risk use cases should have lightweight review.
High-risk use cases should have stronger controls.
Sensitive use cases should have specialist pathways.
Some uses should remain prohibited unless explicitly approved.
But the operating model needs to be tiered, practical and fast enough to keep up.
Government and large organisations also need safe experimentation environments where teams can test AI use cases with approved tools, safe data, proper supervision and clear evaluation.
Without that, innovation moves elsewhere.
Often quietly.
Often invisibly.
Often outside the governance model entirely.
Safety first, but not safety only
AI introduces real risks.
Privacy breaches.
Hallucinated outputs.
Poor decision-making.
Bias.
Data leakage.
Unauthorised recording.
Over-reliance.
Cyber exposure.
Loss of public trust.
These risks are serious and must be managed.
But failing to modernise is also a risk.
Slow service delivery is a risk.
Burnt-out staff are a risk.
Manual processes are a risk.
Poor access to information is a risk.
Inconsistent advice is a risk.
Falling behind other sectors is a risk.
Losing talented staff to more modern workplaces is a risk.
AI governance must account for both sides of the equation:
the risk of using AI badly,
and the risk of failing to use AI well.
The goal should not be reckless adoption.
But it should not be safe stagnation either.
The goal should be responsible acceleration.
The real question
We are entering a world where AI is embedded into the tools, devices and environments around us.
Trying to govern that world with legacy controls alone will not work.
The question is no longer:
“How do we stop people accessing AI?”
The better question is:
“How do we make responsible AI use the easiest, safest and most trusted option?”
That means clear data rules.
Practical training.
Useful approved tools.
Safe experimentation.
Private and controlled deployment options.
Strong protections for sensitive information.
AI-supported governance.
And policy shaped by people who understand both the risks and the opportunities.
Because if organisations make safe AI use too hard, they will not prevent AI use.
They will drive it underground.
And invisible AI use may be the greatest risk of all.
Make sure to share your own thoughts with the author by leaving a comment below
Log in or sign up to continue the conversation