Whatever your business has decided about artificial intelligence, your staff have already decided for themselves. They are pasting client emails into chatbots to draft replies, running documents through AI to summarise them, generating code, cleaning up spreadsheets, writing proposals. Some of it is sanctioned. Most of it is not even known about. The question is no longer whether to allow AI in your business. That decision has been made, by everyone, without you.
That is not a reason to panic, and it is certainly not a reason to ban it — bans simply push the use underground, where you cannot see it at all. It is a reason to govern it. And governance comes down to three questions most businesses have never answered.
Who owns the risk?
When a member of staff uses an AI tool on company work, the business carries the consequences — but usually nobody has been made responsible for that. If an AI-generated document goes to a client with an error in it, who is accountable? If a tool produces something that turns out to infringe someone else’s rights, whose problem is it? Right now, in most businesses, the honest answer is that the risk is unowned. It lands wherever it lands. Naming who owns AI risk is the first act of governance, because an unowned risk is one nobody is managing.
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
Who owns the output?
AI tools produce work, and that work goes out under your business’s name. Two things need settling. First, accuracy: AI confidently produces wrong answers, and if nothing requires a human to check AI output before it reaches a client, you are one fluent, plausible error away from an embarrassment or a liability. Second, ownership and terms: depending on the tool and how it is used, the status of what it produces — and what the provider may do with what you put in — is not something to assume. The output is your business’s responsibility regardless, so the control that matters is a human accountable for anything AI-assisted before it leaves the building.
Who owns the data?
This is the one with teeth, and it is a data governance question before it is an AI question. When staff paste client information, personal data or commercially sensitive material into a public AI tool, that data has left your business and gone to a third party — often with no agreement in place governing what happens to it. Under data-protection law, that can be a breach in itself. You cannot protect data you do not know has left, and AI tools have become one of the largest uncontrolled exits for it. If you do not know what data is going into which tools, you have the same blind spot that produces untrustworthy data elsewhere in the business — now pointed at your most sensitive information.
The regulatory backdrop is already moving
Two things are tightening at once. Data-protection law already applies to AI use today — there is nothing to wait for. And the EU’s AI Act is phasing in: its bans on the most harmful AI practices have applied since early 2025, with broader obligations rolling out across 2026 and beyond, and like data-protection law it reaches businesses outside the EU that serve the EU market. Clients are moving faster than regulators in practice — procurement teams are already asking suppliers how they use AI and how they protect data fed into it. The first client or regulator to ask will make the absence of any policy visible immediately.
What to do
The move is not a ban and not a free-for-all. It is a governance layer: find out what is actually being used and on what data, decide which tools are approved and for what, set clear rules on what data may never go into a public tool, require human review of AI output that reaches clients, and give staff the brief training that turns a policy into behaviour. Done well, this enables AI use safely rather than suppressing it — and suppressing it only creates shadow IT in its newest and fastest-growing form. The document that holds it together is the subject of the AI policy every business should have.
The question was never whether to allow AI. It is who owns the risk, the output and the data — and building the governance layer before a regulator or a client asks you to. We will work out where your exposure is and how to close it.
Start a ConversationFree interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming