Alchemical schematic of an AI governance policy as a connected gear-and-compass mechanism

Writing an AI Governance Policy People Will Actually Follow

June 11, 2026
Executive Summary
  • Most AI governance frameworks fail the moment they meet a real workday. They get written as a binder, filed where nobody looks, and quietly routed around by people just trying to finish their work.
  • The gap is real and growing. 85% of organizations have woven AI into core operations, but only 25% have any real visibility into how employees actually use it, per Optro. You cannot govern what you cannot see.
  • The shadow is already inside the building. An estimated 60 to 70% of organizations are exposed to "shadow AI," unapproved tools threaded into daily workflows, according to TechnologyRadius.
  • The fix is not more rules. It is fewer, better-placed ones: risk tiers that match approval depth to actual stakes, a sanctioned path that beats the workaround, and a policy that lives in the tools instead of a PDF.
  • Build it the way you would design any process people follow: make the right thing the easy thing, write down who decides what, and put the whole thing on a review cadence so it ages with the technology instead of against it.

I have read a lot of AI governance policies. Most of them share a single fatal trait: they were written to be defensible, not to be followed. You can tell within a paragraph. The document is addressed to an imaginary auditor rather than to the person at 4:40 on a Thursday who just wants to summarize a contract without breaking a rule they have not read. That person is going to use the tool either way. The only question your policy gets to answer is whether they do it on a path you can see, or one you cannot.

That is the whole game, and almost everyone plays it backward. We write the policy to feel safe, then act surprised when the org treats it like the terms of service: scrolled past, agreed to, ignored. A governance framework that nobody follows is not a safeguard. It is a liability with a cover page, because now you have documented the standard you are failing to meet.

Engraving of a policy document with construction lines routing around it, illustrating why AI governance frameworks get bypassed in practice

Why most AI governance frameworks fail on contact

Start with the numbers, because they are unusually clear about the shape of the problem. Per Optro, 85% of organizations have already integrated AI into core operations, while only 25% report comprehensive visibility into how their people are actually using it. Sit with that ratio for a second. More than four out of five companies are running on AI, and three out of four of those are essentially flying without instruments.

Nature abhors a vacuum, and so does a workforce under deadline. Into that visibility gap walks shadow AI: the personal ChatGPT account, the browser extension nobody vetted, the "I'll just paste it into this free tool" that happens ten thousand times a day across an enterprise. TechnologyRadius estimates 60 to 70% of organizations are exposed to it. And the exposure is not theoretical. Grip Security reports AI-related SaaS attacks climbed roughly 490% year over year, with more than 80% of those incidents touching sensitive or regulated data. The unapproved tool is not just a compliance footnote. It is the door people are walking your data through.

Here is the behavioral part, and it is where the affection comes in, because the people doing this are not villains. They are responding rationally to a policy that made the compliant path harder than the noncompliant one. If the sanctioned tool requires a ticket, a two-day wait, and a training module, while the shadow tool requires a tab, you have not written a policy. You have written an incentive to evade it. People follow the path of least resistance with a reliability that would be admirable if it were not so inconvenient. The failure is rarely the employee's. It is almost always a design flaw in the policy itself.

Data Society puts the structural version of this plainly: governance fails when ownership is unclear, when it gets stranded in legal or compliance, and when it stays an abstract framework instead of being wired into the everyday decisions people actually make. A policy that does not specify who decides what, on which project, reviewed how, is not a policy. It is a wish.

Nested concentric rings as a diagram of AI risk tiers from open to restricted

Risk tiers instead of blanket bans

The single most useful move you can make is to stop governing AI as one thing. "AI" is not a risk. Pasting a public press release into a chatbot to fix its grammar and feeding customer health records into an unvetted model are not the same activity, and a policy that treats them identically will get the easy case wrong in both directions: too strict for the grammar fix, not strict enough to stop the real exposure.

Risk tiers fix this, and you do not have to invent the concept. The EU AI Act already sorts the world into four buckets: unacceptable uses that are banned outright, high-risk uses that carry strict obligations around oversight and data governance, limited-risk uses that mainly need transparency, and minimal-risk uses left largely alone. You can borrow that shape without adopting the regulation. Summarized for humans, it reads: ban the genuinely dangerous, scrutinize the high-stakes, label the medium, and get out of the way of the trivial.

Translate that into your own three or four tiers, defined by what the use touches rather than which tool it uses. A workable starting cut:

TierWhat it coversApproval depth
GreenPublic or non-sensitive data, reversible output, human reviews everythingUse freely, no approval
YellowInternal data, drafts that inform decisions, low blast radiusSelf-serve sanctioned tools, logged
OrangeCustomer or regulated data, or output that acts without reviewNamed approver, documented
RedAnything that moves money, makes legal commitments, or is irreversibleProhibited or executive sign-off

The point of tiers is not bureaucracy. It is proportion. The vast majority of daily AI use is green, and a policy that lets green move at the speed of work buys you the credibility to be strict where it counts. A blanket ban does the opposite. It treats your most trivial use case and your most dangerous one with identical suspicion, which teaches people that the policy does not understand their job, which is the precise moment they stop listening.

A single line flowing through gates of decreasing size, depicting an AI approval path that does not bottleneck

The approval path that doesn't bottleneck

A risk tier is only as good as the approval path attached to it, and approval paths are where most governance dies of its own weight. The instinct, especially after a scare, is to route everything through a committee. The committee meets weekly. The queue grows. People wait twice and then stop asking. Congratulations: you have built a system whose main output is shadow AI.

The fix follows directly from the tiers. Match approval depth to stakes, and let the low tiers self-serve. Green needs no approval because there is nothing to approve. Yellow needs a sanctioned tool and a log, not a human in the loop. Only orange should require a named person to say yes, and that person should be close to the work, not three levels up in a function that does not understand the use case. Red is the only tier that earns a real gate, and red should be rare, reserved for the cases where what an AI agent cannot yet be trusted to own genuinely matters.

What makes this hold together is embedding the approval where the work happens. Gartner-style guidance summarized by Optro notes that policies fail when enforcement is not embedded and when the tooling is fragmented. The practical reading: an approval that lives in a separate ticketing system is an approval people will route around. An approval that is a button inside the tool they are already using, with the logging automatic and invisible, is one they will actually use. The best governance is the kind people comply with without noticing, because compliance was built into the path rather than bolted onto it.

This is also where a model and tool inventory earns its keep. You cannot assign tiers to tools you do not know exist. A living inventory, even a simple one, of which AI tools are sanctioned for which tiers turns "is this allowed?" from a research project into a lookup. The same logic powers a well-run agentic department: the value is not the autonomy, it is the operating model around it that decides what may proceed on its own and where a human still steps in.

Ghosted geometric forms surfacing toward a compass rose, representing shadow AI becoming visible without surveillance

Catching shadow AI without surveillance

Now the uncomfortable part. You can write perfect tiers and a frictionless approval path and still have shadow AI, because some of it predates your policy and some of it is just habit. The wrong response is to reach for surveillance: keystroke logging, traffic inspection, the digital equivalent of searching everyone's bag on the way out. It poisons the trust the whole policy depends on, and it does not even work, because the most determined evaders move to their phones.

The better response treats shadow AI as a demand signal rather than a crime. People are using the unapproved tool because it solves a problem your sanctioned stack does not. So find out which problem. If half the company is quietly using the same outside transcription tool, the lesson is not "punish them." It is "we have a transcription gap, and we should sanction a tool that fills it before someone pastes a board call into a free service." Shadow AI is unmet demand wearing a disguise. Read it that way and it becomes the most honest product feedback you will ever get about your own tooling.

Where you do need visibility, get it at the data layer, not the person layer. Data classification, knowing what counts as sensitive and what tools may touch it, lets you monitor where regulated information flows without watching individual humans work. That is the distinction that keeps governance from curdling into spyware: you are governing the data and the tools, not policing the people. Deloitte finds that oversight works best when it is embedded into everyday workflows and shared ownership rather than imposed as a periodic compliance exercise, which is a polite way of saying the same thing: governance that feels like a partnership gets followed, and governance that feels like a stakeout gets evaded.

A celestial-mechanical loop of gears and orbits, symbolizing a living AI governance review cadence

Keeping your AI governance framework alive after launch

The last failure mode is the quietest. You write a good policy, you launch it, everyone nods, and then the document calcifies while the technology underneath it changes every quarter. Eighteen months later you are governing a 2026 reality with a policy written for tools that no longer exist, and the gap between the rules and the work has reopened, this time with the policy on the losing side.

A governance framework is a living document or it is a dead one. There is no third state. The maturity curve here is steep: Deloitte finds only about one in five companies have a mature governance model for autonomous, agentic AI, even as that is exactly the kind of AI spreading fastest. The market knows this is the hard part: Grand View Research pegs the AI governance market at $308 million in 2025 and projects it past $3.5 billion by 2033, and Gartner expects governance-platform spending alone to hit $492 million in 2026. People are paying real money to solve the problem of a policy that does not keep up.

You can solve most of it without buying anything, by borrowing the structure of the NIST AI Risk Management Framework, which organizes the work into four plain functions: Govern (set the roles and policies), Map (understand each use in context), Measure (track the risks with real metrics), and Manage (act on what you find, then repeat). The word doing the work in that list is "repeat." Govern is not a launch. It is a loop.

In practice that means a standing review cadence, quarterly is a reasonable default, where you do four things: refresh the tool inventory, look at what shadow AI surfaced, retire rules that no longer match reality, and reassign tiers as the stakes shift. It means clear ownership, because Data Society's core finding is that governance stranded in one function does not stick; it needs cross-functional ownership with genuine executive sponsorship. And it means an audit trail, the dull infrastructure that makes the whole thing real, so that when something goes wrong you can see what was decided and why, and when something goes right you can prove it.

A policy people actually follow is not the strictest one. It is the one that understood, from the first draft, that it was competing with the path of least resistance, and chose to win that competition by design rather than by decree. Make the sanctioned path the easy path, write down who decides what, watch the data instead of the people, and keep the document breathing. Do that and governance stops being the thing that slows the work down. It becomes the thing that lets you move faster, because for once you can see where you are going. The mediator between the head and the hands, as the old line goes, must be the heart. The same is true of the thing that sits between your people and the machines.

Brass alchemical frieze section break in Automata Intelligentsia brand style

Frequently Asked Questions

What is an AI governance framework?

It is the set of policies, roles, and processes that define how an organization approves, monitors, and stays accountable for its use of AI. A practical one is usually organized around a few risk tiers, a model and tool inventory, an approval workflow, data classification rules, logging and audit trails, and a regular review cadence. The goal is not to document every possible use but to make the safe path the default one.

What is the NIST AI Risk Management Framework?

It is a voluntary framework from the U.S. National Institute of Standards and Technology built around four functions: Govern, Map, Measure, and Manage. Govern sets the roles and policies, Map puts each AI use in context, Measure tracks the actual risks, and Manage acts on them and feeds the result back into the loop. It is deliberately framework-agnostic, so you can use its structure without adopting any specific tooling.

What goes in an AI governance policy?

At minimum: acceptable-use rules, data classification that says what information may go into which tools, a set of risk tiers, an approval workflow tied to those tiers, a model and tool inventory, logging and audit trails, human-oversight requirements for higher-risk uses, and a review cadence. The shorter and clearer each of these is, the more likely people are to follow it.

What is shadow AI and how do you handle it?

Shadow AI is employees using AI tools that have not been reviewed or approved, usually because the sanctioned options are slower or do not exist. The durable fix is not surveillance. It is to treat shadow AI as a demand signal, sanction tools that fill the gaps people are working around, classify your data so you can watch where sensitive information flows, and make the approved path easier than the workaround.

How do you enforce an AI policy without killing productivity?

Match approval depth to risk. Let low-risk, public-data uses move with no approval at all, let internal-data uses self-serve through sanctioned tools with logging, and reserve named approvers and hard gates for genuinely high-stakes or irreversible actions. Then embed the rules in the tools people already use, so compliance is the path of least resistance rather than an extra step.

How often should you update an AI governance policy?

Treat it as a living

Back to Blog

Need Help?

Schedule a time to meet with us using the calendar below...