Give your employees clear rules, approved tools and boundaries that actually make sense while keeping your business and its data under control.
Artificial intelligence has moved into the workplace faster than most businesses have developed rules for using it.
And let's be realistic. Your employees are probably already using it.
They're using ChatGPT, Microsoft Copilot, Gemini and dozens of AI-powered applications to write emails, analyze documents, summarize meetings, research competitors, create proposals, troubleshoot problems and automate everyday work.
That's not necessarily a bad thing.
We're doing it too.
It's only been a few years since we started using AI in our own business in any meaningful way. Even with restrictions and controls around how we use it, it's already difficult to remember working without it. We've picked up speed and can do things today that simply weren't practical a few years ago.
So this isn't an argument against AI.
It's an argument for knowing what the hell is going on with it inside your business.
Because somewhere in your company right now, a perfectly well-intentioned employee could be doing something like this:
- A salesperson uploads a customer spreadsheet because they want help analyzing it.
- Someone in HR asks an AI tool to rewrite an employee evaluation.
- Someone in accounting uploads a financial report.
- A manager pastes part of a contract into an AI assistant and asks what it means.
- An employee connects an AI application to their email or cloud storage because it saves them an hour every week.
Nobody is trying to create a security problem.
They're trying to get their work done.
But now you have some fairly important questions to answer.
Where did that information go?
What can that AI access?
What happens to the information after it gets there?
Can the AI do anything on behalf of that employee?
And does anyone in the company actually know?
That's the business problem behind AI governance, and increasingly why we think AI security needs to be treated as part of the company's overall cybersecurity strategy.
So what is AI governance, really?
Forget the formal definition for a minute.
For most businesses, AI governance is simply deciding how AI is allowed to operate inside your company before everyone makes those decisions individually.
It answers some pretty basic questions.
- Which AI tools can our employees use?
- What company information can they give those tools?
- Which AI systems can access our email, Microsoft 365, SharePoint, OneDrive, CRM or other systems?
- Who approves a new AI application?
- What can AI do automatically?
- What still requires a human?
- Can we see and audit what is happening?
- What happens when something goes wrong?
You do not need a 90-page AI policy that nobody will read.
You need enough governance to know what's being used, what it can access, what the risks are and who is responsible for it.
That's also broadly consistent with the National Institute of Standards and Technology's AI Risk Management Framework. NIST organizes AI risk management around four functions: Govern, Map, Measure and Manage, and has published additional guidance specifically for generative AI.
Translated from government-speak into business-speak:
Know what you're using. Know what it can touch. Understand the risk. Put controls around it. Keep paying attention.
That's AI governance.
The first problem is probably the AI you don't know about
One of the easiest things for a CEO to say is:
"We haven't implemented AI yet."
Maybe the company hasn't.
Your employees probably have.
They don't need an IT project, a purchase order or permission from management. They need a browser.
This is an old technology problem wearing new clothes.
We've dealt with shadow IT for years. Employees discover an application that solves a problem, create an account and start using it without IT or management knowing about it.
Now we have shadow AI.
And AI makes the problem more consequential because these tools don't just store information. They can analyze it, combine it, summarize it, connect to other systems and increasingly take actions.
There is some evidence that this behavior is already widespread. Microsoft's 2024 Work Trend Index found that 78% of surveyed AI users were bringing their own AI tools to work, increasing to 80% at small and midsized companies.
The data is a couple of years old now, but the lesson isn't.
If your employees see an obvious productivity advantage and the company doesn't give them a reasonable way to use it, some of them will find their own.
That gives us the first rule of AI governance:
Don't make the rules so restrictive that everyone learns to work around them.
The problem isn't AI.
The problem is AI you aren't managing.
Give people somewhere safe to use it
This is where companies can get AI governance completely backwards.
They start with a list of everything employees cannot do.
Don't use ChatGPT.
Don't upload documents.
Don't connect anything.
Don't experiment.
That sounds safe.
It may actually make you less safe.
If AI genuinely makes someone's job easier and the company simply bans it, you haven't necessarily eliminated the behavior. You may have eliminated your visibility into the behavior.
A better approach is to provide approved tools and reasonable boundaries.
Enterprise AI platforms are not necessarily the same as someone opening a personal account on the internet.
For example, Microsoft says prompts and responses in Copilot Chat under enterprise data protection aren't used to train its foundation models. Microsoft also provides administrative, auditing, retention and compliance capabilities around those interactions.
OpenAI similarly states that it does not train its models on data from ChatGPT Business, Enterprise and its API platform by default.
Google says Workspace customer data isn't used to train its underlying generative AI models outside Workspace without permission.
That does not mean any of those platforms automatically make every use of AI safe.
It means the account, service agreement, identity controls, data handling and administrative capabilities matter.
Before approving an AI platform, someone should understand:
- How does the provider use our prompts and uploaded information?
- Is our information used to train models?
- How long is it retained?
- Can we control access?
- Can employees use company identities?
- Can activity be audited?
- What other systems can the AI connect to?
- What permissions do those connections receive?
- What happens to company information when an employee leaves?
Those questions matter a lot more than whether one chatbot writes a slightly better email than another.
AI can expose problems you already have
This is the part I think many businesses are going to discover the hard way.
AI doesn't just create new security problems.
It can make existing ones much easier to find.
Consider Microsoft 365.
An employee might technically have permission to access thousands of files across SharePoint, Teams and OneDrive.
Before AI, that employee would have to know those files existed, know where to look and manually find what they wanted.
AI changes that.
Now the employee can simply ask.
Microsoft's own documentation explains that Copilot can use organizational information the user already has permission to access.
That's an important distinction.
Copilot isn't necessarily breaking your permissions.
It may be exposing how bad your permissions already were.
If someone in sales has access to something they shouldn't, AI can make finding that information dramatically easier.
If everyone can access everything, connecting AI to everything isn't the place to start.
Fix the permissions first.
This is why AI governance quickly becomes a cybersecurity and data-governance conversation.
Then AI started doing things
There is another change happening that deserves more attention from business owners.
The first generation of AI mostly answered questions.
You asked something. It answered.
Now we're moving toward AI agents that can take actions.
Consider the difference.
"Summarize these emails."
That's useful.
Now compare it with:
"Read my email, determine what needs my attention, update our CRM, create follow-up tasks and respond to anything routine."
That's a different animal.
The AI now has access to your email, potentially your customers, your CRM and the ability to communicate as you.
Useful?
Absolutely.
But you've also given software authority to act.
Security organizations are paying attention to this. OWASP's current guidance for generative AI applications identifies risks including prompt injection, sensitive information disclosure, improper output handling and excessive agency, where an AI system has too much functionality, permission or autonomy.
That last one is particularly important for business owners.
The more AI can do, the more carefully you need to decide what it should be allowed to do.
Reading an email is one permission.
Sending one is another.
Drafting a payment request is one thing.
Approving a payment is something else entirely.
The difference matters.
Someone still has to own the decision
AI can be remarkably convincing.
It can also be remarkably convincing while being wrong.
We've all seen it.
That's why the question isn't simply whether AI can perform a task.
The better question is:
What happens if it gets this task wrong?
If AI rewrites an internal email badly, the consequence is probably small.
If AI incorrectly interprets a contract, approves a financial transaction, recommends terminating an employee, responds to a security incident or makes a commitment to a customer, the consequence can be very different.
The amount of human oversight should increase with the consequence of the decision.
That's the rule.
AI can research.
AI can summarize.
AI can recommend.
AI can draft.
AI can automate plenty of things.
But somewhere in the process, a human being still needs to own consequential decisions.
AI can assist with judgment. It should not quietly replace accountability.
What I would do if this were my business
Because it is.
At Makios, we're dealing with exactly the same questions our clients are dealing with. We want the productivity. We want our people experimenting. We want to figure out what AI can do for us.
We also don't want customer information, company data or access to critical systems wandering into places we can't control.
For a small or midsized business, I wouldn't turn AI governance into a six-month project.
I'd start here.
1. Find out what people are already using
Before writing the policy, understand reality.
Ask.
ChatGPT? Copilot? Gemini? Claude? Meeting assistants? AI inside the CRM? Browser extensions? Industry-specific tools?
You can't govern what you don't know exists.
And don't turn the discovery process into a witch hunt. If employees think admitting they use AI will get them in trouble, congratulations, you just made shadow AI harder to find.
2. Decide what you're willing to approve
Give employees legitimate options.
Choose business-grade AI platforms where the security, privacy, identity and administrative controls fit your organization.
Then make the approved list easy to understand.
3. Decide what AI can and cannot see
Not every piece of company information carries the same risk.
You might think about information in simple categories such as:
Public Information you're comfortable putting into an approved AI system.
Internal Normal company information that stays within approved business AI platforms.
Confidential Customer data, financial information, personnel information, contracts and other information requiring tighter controls.
Highly sensitive Passwords, authentication tokens, API keys, Social Security numbers, regulated information and other data that should never be handed to an AI system without specific authorization and controls.
Your categories may be different.
The point is that an employee shouldn't have to call the CEO every time they want ChatGPT to improve a paragraph.
Give people boundaries they can actually understand.
4. Use company identities
Business AI should generally be tied to business accounts.
That gives you a way to control authentication, manage access, apply security policies and disable the account when someone leaves.
Your company's intellectual property should not slowly accumulate inside personal AI accounts you don't control.
5. Clean up permissions before giving AI broad access
Review SharePoint.
Review OneDrive.
Review Teams.
Review shared drives.
Review your CRM and other major systems.
Ask whether people still need the access they have.
AI doesn't magically fix poor access control.
It makes good access control more valuable.
6. Decide where humans stay in the loop
Make this explicit.
Hiring.
Termination.
Legal decisions.
Financial approvals.
Security actions.
Customer commitments.
Regulatory decisions.
Anything else where being wrong has a meaningful consequence.
AI can absolutely help with these areas.
That doesn't mean AI gets the final vote.
7. Pay attention to what the AI can do, not just what it can read
This becomes increasingly important as agents become common.
Can it read?
Can it write?
Can it delete?
Can it send?
Can it purchase?
Can it approve?
Can it change permissions?
Can it execute code?
Can it interact with another system?
Access and authority are not the same thing.
Govern both.
8. Train people without putting them to sleep
Your employees do not need a three-hour lecture on large language models.
They need to know four things:
What can I use?
What can I put into it?
What do I need to verify?
What am I not allowed to let it do without approval?
If you can't explain your AI policy in language employees understand, the policy isn't finished.
Don't forget about the AI nobody calls AI
AI governance gets harder because AI isn't contained in ChatGPT, Copilot or Gemini anymore.
It's showing up everywhere.
Your CRM.
Accounting software.
Cybersecurity tools.
Meeting applications.
Browsers.
Search engines.
Productivity software.
Industry-specific applications.
And increasingly, the feature is simply turned on during an update.
So when a vendor announces its shiny new AI feature, somebody needs to ask a few boring questions before everyone clicks Enable.
What can it access?
Where does the information go?
What permissions does it receive?
Can we turn it off?
Can we audit it?
Can it take actions?
Boring questions have prevented quite a few exciting disasters.
The law is starting to care too
AI governance isn't only becoming an IT issue.
It's increasingly a legal and regulatory issue.
Here in Texas, the Texas Responsible Artificial Intelligence Governance Act took effect January 1, 2026. Among other things, the law establishes requirements and restrictions around certain uses of AI, including particular disclosure obligations, biometric data, discrimination and prohibited uses.
Not every provision applies to every company or every use of AI.
And this article certainly isn't legal advice.
But Texas isn't alone. AI regulation is developing across jurisdictions, industries and use cases.
The larger point for a CEO is simpler:
"I didn't know we were using it" is becoming a pretty weak business strategy.
You need some visibility.
You need some rules.
And somebody needs to own them.
AI governance is becoming part of cybersecurity
The more you look at AI governance, the more familiar it starts to look.
Identity.
Authentication.
Permissions.
Data classification.
Endpoint security.
Monitoring.
Vendor management.
Incident response.
Human approval.
These aren't new ideas.
AI just makes them more important.
The NSA, FBI, CISA and international partners have published guidance specifically addressing protection of data used to develop and operate AI systems.
So I don't think AI governance should become some isolated project owned by whoever happens to be the biggest AI enthusiast in the company.
Business leadership needs to own the business decisions.
IT and cybersecurity need to own the technical controls.
HR, legal and compliance need to be involved where appropriate.
And employees need enough freedom to actually use the technology productively.
That's governance.
Not a giant binder.
Not banning ChatGPT.
Not buying Copilot licenses and declaring victory.
Knowing where AI is in your business, what it can touch, what it can do and where a human is still responsible.
This is why we built Makios Cloud Security for AI
We're dealing with these same questions inside Makios, and increasingly with our clients.
It became pretty clear to us that telling a business to "have an AI policy" wasn't enough.
You need to know what AI is being used. You need control over identities and access. You need to understand what company data AI can reach. You need reasonable rules for employees. And as AI becomes more capable, you need to know when it's simply helping someone work and when it's actually acting on behalf of the business.
That's why we created Makios Cloud Security for AI.
It's our approach to helping businesses put practical security and governance around AI without turning it into another giant IT project or trying to stop employees from using the technology.
The objective isn't less AI.
It's AI you can actually account for, govern and trust inside your business.
We should be using more AI, not less
That's ultimately where I land on this.
I don't want AI governance to become another reason for businesses to move slowly.
Quite the opposite.
I think we're still scratching the surface of what these tools are going to let small and midsized businesses do.
AI can give a 20-person company capabilities that would have required significantly more people, money and time only a few years ago.
That's a big deal.
But the more capable the technology becomes, the less comfortable I am with nobody knowing where or how it's being used.
So give people good tools.
Let them experiment.
Encourage them to find better ways of working.
Protect the company identities.
Fix the permissions.
Put boundaries around sensitive information.
Keep humans responsible for consequential decisions.
And pay very close attention when AI moves from answering to doing.
The goal isn't to keep AI out of your business.
The goal is to get as much value from it as you can without losing control of the business in the process.
The Bottom Line
AI isn't something most businesses still need to prepare for. It's already here.
Your employees are using it. Your software vendors are building it into their products. And increasingly, AI isn't just answering questions. It's gaining access to company information and being given the ability to take actions.
That's why AI governance matters.
The goal isn't to slow AI down or bury everyone in policies. It's to know what you're using, what it can access, what it can do and where a human still needs to be responsible.
If you're a CEO or business owner and you've made it this far, don't start by forming an AI committee.
Start with five questions:
- What AI tools are our people already using?
- What company and customer information are we putting into them?
- Which AI platforms have we actually approved?
- What can those systems access and what can they do?
- Where have we decided a human still has to make the call?
If you can't answer those questions today, don't panic.
You probably don't have an AI crisis.
You have an AI visibility problem.
And that's a much better place to start.







