Artificial intelligence is no longer theoretical in government. It is not futuristic. It is not experimental. It is already embedded in how many of us work every day.
Yet across the public sector, we are entering a tense and fragile phase. The technology is accelerating rapidly. Governance frameworks are emerging just as quickly. And somewhere in the middle are public servants trying to do their jobs well.
This is a reflection from that middle.
AI Is Already Changing the Way We Work
For many knowledge workers, generative AI has transformed productivity. Tasks that previously took five days can now be completed in one and a half. Drafting, summarising, analysing, designing, coding, modelling and documentation have all been accelerated.
More importantly, the quality of outputs has improved. AI, used well, acts as a thinking partner. It reduces cognitive load. It removes blank page paralysis. It allows staff to explore ideas more deeply and produce better work in less time.
That has cultural implications.
When people are less overwhelmed, they think more clearly. When they feel capable, they take initiative. When they see rapid progress, they build confidence. AI, in this context, is not just a productivity tool. It is a capability amplifier.
In innovation-focused teams, access to these tools is becoming foundational. You cannot meaningfully pursue innovation while simultaneously restricting access to the most powerful cognitive tools available.
The Governance Response
At the same time, the risks are real.
Generative AI can hallucinate. It can mislead. It can mishandle sensitive data if used carelessly. It can introduce bias. It can create reputational exposure.
Governance is necessary. Few serious practitioners would argue otherwise.
The problem emerging in many agencies is not whether to govern AI, but how.
In some environments, the response has been to treat all AI systems as equal risk. Narrow AI, embedded tools, low risk generative use cases and high stakes decision systems are sometimes grouped under the same policy umbrella.
That creates a practical problem.
If every AI tool requires a full assessment before use, and hundreds of tools are already in circulation, manual review processes simply cannot scale. An assessment backlog of 12 to 24 months is not unrealistic under traditional compliance workflows.
During that period, innovation stalls.
Or something else happens.
The Shadow AI Effect
If access is blocked without a clear, sanctioned pathway, people do not stop using AI. They route around the controls.
They use personal accounts. They use home networks. They use mobile devices. They transfer outputs manually.
From a cyber security and privacy perspective, this is worse than managed usage. Visibility disappears. Logging disappears. Contractual protections disappear.
Blanket restrictions often feel safer in theory. In practice, they can increase unmanaged risk.
The reality is that many public servants have already experienced transformative productivity gains. Asking them to revert to pre-AI workflows for 18 months while assessments crawl through process is not a neutral change. It is a regression.
That creates disengagement. And in some cases, it drives talent away.
The Capacity Bottleneck
One of the core issues is assessment capacity.
If hundreds of tools require evaluation, and each evaluation involves collecting vendor information, mapping policy clauses, assessing privacy impact, reviewing security posture and drafting documentation, the compliance workload becomes enormous.
Manual governance does not scale in an AI-saturated environment.
But the solution is not deregulation. It is modernisation of governance itself.
Using AI to Govern AI
The same technologies transforming productivity can be applied to compliance workflows.
AI can:
Collect structured vendor information
Classify intended use cases
Map use cases against policy criteria
Flag high risk attributes
Draft assessment summaries
Recommend risk tiers
A human remains in the loop to make the final decision.
This is not autonomous governance. It is workflow automation and decision support.
In environments where hundreds of tools exist, automated first pass assessment may be the only viable way to regain control without paralysing innovation.
Yet proposals like this can sound futuristic or premature. The challenge is not capability. The capability exists today. The challenge is trust and institutional familiarity.
That trust must be built through constrained pilots, narrow scope, clear human oversight and measurable outcomes.
Education as a Risk Control
Another under-prioritised lever is education.
No policy document can keep pace with week to week changes in AI capability. But workforce literacy can dramatically reduce misuse.
When staff understand:
What data must never be shared
When outputs require verification
What constitutes high risk use
Where enterprise managed environments are safe
Risk drops significantly.
Training is not a soft control. It is a primary behavioural safeguard in fast moving technological environments.
Balancing Innovation and Safety
The public sector does not need to choose between innovation and governance. It needs proportionality.
Low risk internal productivity use cases should not face the same burden as systems influencing health, policing or regulatory decisions.
Class based approval pathways, tiered risk frameworks and AI assisted assessment processes offer practical middle ground.
Without that balance, two outcomes become likely:
Innovation stagnates under compliance weight.
Unmanaged shadow usage increases outside official channels.
Neither outcome serves the public interest.
A Cultural Question
Beyond productivity and compliance, there is a cultural dimension.
AI, used responsibly, reduces stress. It increases confidence. It allows staff to explore ideas and deliver higher quality work. It can foster a belief that ambitious goals are achievable.
In innovation teams, access to modern tools is not a luxury. It is part of maintaining morale and attracting capable people.
Public sector agencies that modernise governance while enabling safe AI use will build internal capability. Those that default to prohibition risk losing both visibility and talent.
The Path Forward
The path is not laissez faire adoption. Nor is it blanket restriction.
It is managed enablement.
That means:
Clear risk tiers
Defined safe use classes
Automated first pass assessment
Human oversight
Workforce education
Transparent logging and monitoring
AI is not waiting for governance cycles. It is already embedded in how work gets done.
The question is whether governance will evolve fast enough to guide it constructively, or whether we create friction that pushes it underground.
For the public sector, the stakes are not just technological. They are cultural.
Innovation and safety are not opposites. But aligning them requires deliberate design.
Now is the moment to design governance that scales with reality, rather than attempting to slow reality down.
Make sure to share your own thoughts with the author by leaving a comment below
Log in or sign up to continue the conversation