
A few years ago, when generative AI first became widely accessible, there was enormous excitement around experimentation. For many organizations, the question was simply: “How do we get our employees using AI?”
The first phase of AI adoption mostly focused on individual experimentation and productivity enhancements: employees using Large Language Models (LLMs) as assistants for isolated tasks within their existing workflows, whether drafting content, summarizing information, brainstorming, analyzing data, or assisting with code.
What we now see as the “second phase” is the shift toward AI agents and agentic AI, where AI is increasingly used to automate multi-step processes and, in some cases, larger portions of entire workflows.
Instead of a person prompting an LLM at every step, they may establish a goal, parameters, and permissions, and an AI agent can then plan and execute a series of actions toward that goal with much less human intervention.
This doesn’t necessarily mean taking the human completely out of the loop. Rather, the human role is changing. We may shift from directly performing or prompting each individual task to setting goals, establishing guardrails, granting appropriate permissions, monitoring performance, and reviewing higher-risk decisions or outputs.
And that increased autonomy is also why governance becomes increasingly important.
From “shadow AI” to everyday AI
As AI adoption has changed, so has the question organizations need to ask. The conversation is increasingly becoming: “How are our employees using AI, and how do we make sure they are using it safely?”
AI has become much more embedded in everyday workflows, but the risk of shadow AI hasn’t disappeared. Shadow AI refers to employees using AI tools for work without their organization’s knowledge, approval or oversight. In some ways, normalization makes it more important to address.
An employee may not think twice about using an AI tool to summarize a document, analyze information, or help write an email. But from the organization’s perspective, that could mean company or customer data is being shared with a third-party system that hasn’t been reviewed or approved.
One of my biggest concerns is that we can also begin to lose the audit trail. If AI is involved in hundreds or thousands of small decisions or actions across an organization, we need to understand who or what contributed to those decisions.
There can also be a tendency for people to distance themselves from accountability because “the AI produced it.” But AI doesn’t remove human accountability. If an employee chooses to use AI-generated output, particularly in a professional context, there still needs to be a person responsible for reviewing and validating its use.
Trying to eliminate widespread AI use isn’t realistic anymore. In fact, overly restrictive policies can have the opposite effect: employees who see genuine productivity benefits may simply find ways to use the technology without telling their employer, creating even more shadow AI.
We’ve been here before with other technologies. There was fear and uncertainty around calculators, computers, and eventually smartphones as they entered workplaces and classrooms. We didn’t eliminate the technology; instead, we learned how to use it responsibly and put safeguards around it. AI needs to follow a similar path.
Practical governance doesn’t need to mean a 100-page policy
AI governance can sound like an enormous undertaking, particularly for small and mid-sized organizations that see what major enterprises are doing and assume they need to replicate it.
But good governance doesn’t have to be complicated to be valuable.
For an SME, I would rather see a simple, well-thought-out governance framework that employees actually understand and follow than a 100-page policy that nobody reads.
At a minimum, organizations should establish what AI tools are approved, what kinds of information should never be entered into them, where human review is required, who is accountable for AI-assisted work, and what employees should do if something goes wrong.
A practical AI governance framework should answer some very basic questions, such as: Where are we using AI? What are we using it for? What data is going into it? What could go wrong? Who is responsible for it? And what do we do if something does go wrong?
For organizations that realize employees are already using AI extensively but have very little governance in place, I would start with three things.
First, start with data safety and explain it in simple language. Employees need to understand what they should not be entering into unapproved AI tools, including personally identifiable information, sensitive information, customer data, and proprietary company information.
Second, establish human review as the default. AI-generated content shouldn’t automatically become finished work. Employees should review and validate outputs before sending them to clients, using them to make decisions, or passing them on to the next stage in a workflow.
Third, establish accountability. Using AI doesn’t transfer responsibility to the AI. If I ask an AI system to create something and then choose to use that output, I remain accountable for how I use it.
Teach people how to think about AI risk
As with anything, the most effective way to teach people is not simply to tell them what they can’t do. Good AI governance should educate and empower employees, not just restrict them.
A long list of “don’ts” can become something employees feel they have to memorize rather than understand. AI is also evolving so quickly that a governance model built entirely around specific tools or prohibited use cases can become outdated very quickly.
Organizations are better served by teaching foundational principles that remain relevant as the technology changes: understand what data you’re sharing, consider the risks of the tool you’re using, review the output, and remain accountable for how you use it.
I like to think about it in terms of driving. A useful guardrail doesn’t say “stop driving.” It says, “Stay within the lines and drive under the speed limit.”
The same principle can apply to AI. Instead of simply saying, “Don’t use this type of tool,” guidance might say, “You can use an approved AI tool for this task, but don’t enter personally identifiable, sensitive, or proprietary information, and make sure a person reviews the output before it goes to a client.”
You don’t get a driver’s licence without learning how to drive, and AI should be treated similarly. We don’t teach drivers every possible situation they will encounter on the road; we teach them the rules, risks, and judgment they need to navigate new situations safely. AI literacy should work the same way.
Responsible adoption, not restricted adoption
Over the next 12 to 24 months, organizations that succeed will be those with clear but flexible governance frameworks that can evolve alongside AI.
Successful organizations will also teach their employees how to think about AI risk rather than simply giving them a list of tools or use cases to memorize. The specific tools will change, but the foundational questions remain relatively consistent.
Two questions every employee should learn to ask are: 1. What data am I putting in? and[Text Wrapping Break]2. What is my intended use of the output?
Ultimately, I think we need to empower employees to pause and think, and give them frameworks for how to approach this, rather than expecting them to memorize every possible AI risk.
Governance is not about limitation; it’s about guidance and direction. Good governance should enable organizations to use AI more confidently and safely and, as a result, potentially at a greater scale.
The goal should be responsible adoption, not restricted adoption. If employees understand the boundaries, the risks and their own responsibilities, organizations can move beyond experimenting with AI and toward using it more intentionally and confidently across their operations.

