Used, but not governed?

According to McKinsey’s 2025 Global AI survey most organizations are still in the experimentation or piloting phase when it comes to the use of AI. However, 78 % of organizations use AI in at least one business function and 71 % report regular use of generative AI.

AI use is no longer limited to the tech nerds at the IT departments or innovation teams. It is spreading across HR, finance, legal, communications, research, translation, marketing, data management, and customer service. In practice, this means AI increasingly touches almost every part of organizational activity.

The reality is that AI is already being used in many organizations, often without clear oversight, leadership, or accountability. Employees test tools independently, integrate AI into workflows, upload information into external systems, or rely on AI-generated outputs without formal guidance or governance structures in place.

The window for ad hoc experimentation without governance is closing fast.

This creates what is often referred to as “shadow AI”: the use of AI systems outside approved organizational frameworks.

And shadow AI creates real risks:

  • inconsistent decision-making
  • confidentiality and cybersecurity concerns
  • poor-quality or inaccurate outputs
  • legal and compliance exposure
  • fragmented practices across departments
  • lack of accountability when mistakes happen
  • erosion of trust internally and externally

In many ways, organizations should now start from a presumption of AI use. Just as discussions around AI training increasingly begin from the assumption that copyright-protected content has likely been used to train AI models, leadership should assume that AI is already being used somewhere within the organization, whether formally approved or not.

The key governance question is therefore no longer: “Are we using AI?” Instead it is: “Are we governing its use?” And if the answer is unclear, that itself is a governance issue.

Leadership should assume that AI is already being used somewhere within the organization.

AI governance is not about stopping innovation or eliminating experimentation. It is about ensuring that experimentation happens responsibly, strategically, with proper oversight and risk management. Because when usage happens but nobody is really governing or leading it, organizations do not simply lose control over technology decisions. They lose control over accountability, consistency, risk management, and ultimately trust. And this creates serious governance problems.

If you want to ensure that people in your organization are not only using AI but the usage is also governed, I am happy to help you in the process.

Leave a comment