From the Wild West to ground rules: an AI governance project in about two weeks
Ken Johnson, our Solutions Architect, led an AI governance project for a client. When asked to describe where the company's AI use stood at the start of the project, he called it the Wild West.
Some people were dabbling. Others were using AI formally and sending in requests. Inside the company, the mood went from "hey, that's kind of cute" to "we need to get control of this quickly."
Start with the big picture, not the tools
Before anyone looked at a single setting, Ken asked two questions. What rules should people play by? And what is the company trying to get out of AI in the first place?
Without those answers, a policy is just a list of things people will work around.
What we found
Once the goals were on the table, the team looked at how AI was actually being used. Here is what they found:
Personal and business AI accounts were mixed together.
The personal accounts were invisible to the company's central admin systems, so nobody could monitor or track usage. If a threat or breach had come through one of them, nothing could have stepped in.
Company accounts were under a central admin, but it wasn't locked down.
Some company data was exposed because settings that let the AI provider train its models on that data were still on.
Most people didn't understand the risks.
None of this was carelessness. People were trying to work faster, and the limits weren't clear. Ken's take: efficiency could have come at the cost of a major breach.
A framework with three levels
A policy alone doesn't cover this, so the team built a three-level framework. Together, they answer who does what to achieve which outcome.
Strategic: what the company wants from AI, and the rules to play by.
Tactical: who is responsible for decisions and approvals.
Operational: who can make a request, and what technical safeguards sit underneath.
The connector decision
One operational safeguard deserves its own mention: limiting connectors.
A connector lets an AI tool reach into other systems, like email, files, and calendars. That's what makes AI useful for real work, and it's also a way in. Not all connectors are built the same. Some come from reputable companies and follow strict security frameworks. Others are publicly sourced and a bit more Wild West.
So the team limited connectors on purpose, instead of just discouraging them. Fewer connectors means less room for an AI agent to be turned against you, which is what agentic attacks are about. It manages the risk before anything goes wrong.
How long it took
The acceptable use policy took three days from kickoff. From first conversation to implementation took about two weeks. Part of that time was waiting on the client's formal approvals. The policy itself came together quickly. Getting sign-off took longer.
If your company looks a bit like this
You don't need a project to start. Ask each department which AI tools they used this week, and whether people signed in with a work account or a personal one. Write the list down. That list is where governance begins.
We put the rest of the starting points into a short, free checklist. Grab the free DIY AI Governance Checklist, or take the free self-assessment to see where your risks are.
Want help putting ground rules around your company's AI?
Our team is here. Call 630-682-0080 or email sales@overdrive-it.net, and we'll start with a conversation about how AI is being used at your company today.