In a great many organisations, artificial intelligence arrived without a decision being taken. Nobody signed off a strategy. People simply began using tools that were free, useful and already open in another browser tab.
By the time the question reaches a governance forum, the honest framing is not “should we adopt AI” but “what is already happening, and what do we do about it”.
Prohibition rarely survives contact with usefulness
The instinct to ban is understandable, and it almost never works. If a tool saves someone an hour a day, a policy prohibiting it produces two outcomes: reduced compliance, and reduced visibility. The use continues, but now it happens quietly, on personal accounts, outside anything the organisation can see or control.
The alternative is not permissiveness. It is literacy plus boundaries.
What literacy actually means here
AI literacy is not knowing how to write prompts. It is being able to answer four questions about any output a system produces.
What is this system actually doing? Not at a research level, but well enough to know that it is producing plausible text rather than retrieving verified fact, and what that implies about trusting it.
Where does it fail? Confident fabrication, stale information, subtle omission, and a general tendency to agree with the framing of the question it was asked.
What must never go into it? Client-confidential material, personal data, unpublished commercial information, credentials. This is the boundary most organisations most need to make explicit, and the one most often left implicit.
Who is accountable for the output? The person who used the tool. Not the vendor, and not the model. If a professional puts their name to something, they own it, however it was drafted.
Why this is governance work
Every one of those four questions is an accountability question wearing technical clothing. They determine what records you need, what training you owe your staff, what you must be able to show a client or a regulator, and where the line of professional responsibility sits.
That is why AI policy written purely by a technology team tends to be unenforceable, and AI policy written purely by a legal team tends to be unusable. It needs both, drafted together, with input from people who actually do the work being automated.
A minimum viable position
Organisations that have not yet formalised anything can make meaningful progress with four decisions:
- A clear statement of which categories of information must never be entered into an external AI tool.
- A named list of approved tools, and a route to request additions rather than a blanket refusal.
- A verification expectation proportionate to the stakes: what must be checked, by whom, before an AI-assisted output is relied on or sent externally.
- A short, mandatory literacy session so that the rules are understood rather than merely circulated.
None of that requires a mature AI strategy. It requires an honest conversation about what is already happening, and a willingness to teach rather than prohibit.
The organisations that will govern AI well are not the ones with the most restrictive policies. They are the ones whose people understand what they are working with.