Skip to content

AI Is Already at Work. But Who Is Governing It?

AI Governance Image - Blog

Imagine an ordinary Monday morning in your workplace.

Someone in HR uses a public AI tool to summarise employee performance reports. A salesperson uploads a customer proposal and asks AI to improve it. A finance executive uses AI to analyse confidential figures. Meanwhile, a customer-service chatbot answers questions without anyone regularly checking whether those answers are correct.

Everyone is trying to work faster. Nobody intends to create a problem.

But has anyone asked what information is being shared, whether the AI output is accurate, or who will be accountable if something goes wrong?

This is why AI governance matters.

I recently obtained the ITIL® AI Governance (Version 5) certification. As a PeopleCert Ambassador for ITIL, advisor, consultant and practitioner, I wanted to deepen my understanding of how organisations can gain real value from AI while managing its risks responsibly.

One lesson became very clear: AI governance is no longer a future concern. It is an immediate business responsibility.

AI may already be inside your organisation

Many organisations believe they are still considering whether to adopt AI.

In reality, their employees may already be using it.

Generative AI can draft emails, prepare reports, summarise meetings, analyse documents, create presentations and generate software code. These tools are easy to access, and employees naturally use them to save time.

Agentic AI goes further. Instead of only producing an answer, an AI agent may be allowed to carry out actions. It could update records, send messages, schedule meetings, process requests or interact with other systems.

There is a major difference between asking AI to suggest an email and allowing it to send that email automatically.

There is also a difference between asking AI for a recommendation and allowing it to make a decision affecting a customer, employee or supplier.

The more authority we give AI, the more clearly we must define its boundaries.

Governance should enable AI, not block it

The word “governance” can sound like more policies, approvals and delays.

Good AI governance should do the opposite. It should help people use AI safely, responsibly and confidently.

Think about the brakes on a car. They are not there to stop the car from moving. They allow the driver to travel with greater control.

AI governance serves a similar purpose. It helps an organisation decide:

  • Where AI should be used
  • What information it may access
  • Which decisions require human approval
  • What level of risk is acceptable
  • Who is responsible for the outcome
  • How performance and risks will be monitored
  • What happens when something goes wrong

Without these answers, AI adoption can grow faster than the organisation’s ability to manage it.

When a confident answer is completely wrong

Imagine an employee using AI to prepare an important report.

The AI produces an impressive response containing industry statistics, research findings and professional references. Everything looks convincing, so the employee includes the information without checking the original sources.

Later, the team discovers that some statistics are inaccurate and several references do not exist.

By then, the report may already have been shared with senior management or a client.

This is sometimes called an AI hallucination. AI can generate incorrect or invented information in language that sounds confident and believable.

The risk is not limited to reports. An inaccurate technical recommendation could create a security weakness. An invented legal reference could damage a case. Incorrect customer advice could lead to complaints or financial loss.

Human review must therefore be meaningful. It is not enough to quickly read the answer and assume it is correct. Important information should be checked against reliable sources before it is used.

What are employees sharing with AI?

Consider another common situation.

An employee needs to review a long document. To save time, the employee copies it into a public AI tool and asks for a summary.

The document may contain customer information, employee records, financial results, contracts, business plans or intellectual property.

The employee may only be thinking, “This will save me two hours.”

The organisation must ask:

  • Was the employee allowed to upload that information?
  • Where will the information be processed or stored?
  • Could it be retained or reused?
  • Does this comply with privacy and contractual obligations?
  • Has the tool been approved for this purpose?

Unapproved AI use is often called Shadow AI.

Shadow AI is difficult to manage because the organisation may not know which tools are being used, what information is being shared or which decisions are being influenced by AI.

Banning AI completely is unlikely to solve the problem. Employees need approved tools, practical guidance and clear examples of what they may and may not do.

Agentic AI increases both value and risk

Imagine an AI agent managing customer complaints.

It reads the complaint, checks the customer’s history, decides whether compensation is appropriate, updates the account and sends a reply.

This could reduce response times and improve efficiency.

But what happens if the agent misunderstands the complaint? What if it accesses more personal information than necessary? What if it repeatedly approves incorrect refunds before anyone notices?

Agentic AI needs clearly defined permissions, approval points, monitoring and a reliable way for a human to stop or override its actions.

The question should not only be:

“What can this AI agent do?”

We must also ask:

“What should it be allowed to do without human approval?”

The benefits of effective AI governance

AI governance is often discussed only in terms of risk. However, it can also create significant business value.

When responsibilities and boundaries are clear, employees can use AI with greater confidence. Leaders can approve worthwhile use cases more quickly because the risks have already been considered. Customers are more likely to trust AI-enabled services when meaningful human oversight exists.

Effective governance can support:

  • Safer and faster AI adoption
  • Better-quality decisions and outputs
  • Clear accountability
  • Stronger protection of sensitive information
  • More consistent customer experiences
  • Earlier detection of bias and errors
  • Better control over third-party AI tools
  • Greater trust among employees and customers
  • A clearer path from experimentation to business value

Governance should always be proportionate. An AI tool that improves an internal email does not require the same controls as a system that selects employees, approves payments or makes decisions affecting customers.

The right level of governance depends on the purpose, impact, autonomy and risk of each AI use case.

Six questions to ask today

If you are unsure where to begin, start with these questions:

  1. Where is AI currently being used in our organisation?
  2. What information is being shared with it?
  3. Which decisions are influenced or made by AI?
  4. Where is human review required?
  5. Who is accountable for the outcome?
  6. How do we know the AI and its controls are still working?

If your organisation cannot answer these questions clearly, you have identified your starting point.

Is your organisation ready?

The organisations that benefit most from AI will not necessarily be those using the greatest number of tools.

They will be those that understand where AI creates value, recognise the associated risks and remain accountable for the outcomes.

Do not wait until confidential information is exposed, a customer is misled or an automated decision causes harm.

The right time to establish AI governance is now.

At REETUS, we help leaders and professionals move from uncertainty to practical action.

You can:

  • Build your knowledge through ITIL® AI Governance certification training.
  • Engage our consulting services to establish or strengthen AI governance.
  • Request an AI governance assessment to identify current AI use, governance gaps, risks and improvement priorities.

Whether you represent a large organisation or a growing business, responsible AI begins with visibility, clear decisions and accountability.