The AI policy is fourteen pages. It was drafted by legal, reviewed by risk, approved by the executive committee and published to the intranet with a mandatory read-and-acknowledge.
Ninety-four per cent of staff have acknowledged it. Roughly none could tell you what it permits them to do with a customer email, which is the only question any of them has ever actually had.
This is the standard shape of AI governance in most organisations right now: a document that describes a desired state, mistaken for a mechanism that produces one.
Governance is a practice, not a publication
The most widely used reference here is the US National Institute of Standards and Technology’s AI Risk Management Framework, built around four functions: Govern, Map, Measure and Manage. Govern is the cross-cutting one, and NIST describes it as cultivating a culture of AI risk management, establishing accountability, and making the other three functions repeatable.
Two things in that framing are routinely skipped. Govern is defined as cultivating a culture, which a document does not do. And the framework treats AI as socio-technical — impacts emerge not only from models and data but from how people build, deploy and use them.
If impacts emerge from use, then governance has to reach use. A policy reaches acknowledgement.
The obligation is about capability, not rules
For organisations operating in the EU this is now more than good practice. Article 4 of the EU AI Act, in application since 2 February 2025, requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and others using AI systems on their behalf — taking into account their technical knowledge, experience, education and training, and the context of use.
Read that against a fourteen-page policy. The obligation is framed around people’s ability to make informed decisions about AI and to understand its risks and possible harms. It is a capability requirement, it applies to deployers rather than only builders, and it is explicitly contextual — which is close to the opposite of a uniform document issued to everyone.
An organisation whose entire response is a published policy and an acknowledgement rate has taken a measure, but a thin one. Literacy is what the obligation actually asks for, and literacy is built, not circulated.
Why policies get neutralised
People do not generally break rules they understand, agree with and can follow while doing their job. They break rules that fail one of those three tests, and the information systems literature has studied how they justify it.
Steffi Haag and Andreas Eckhardt, whose work on shadow IT examines why employees adopt tools their organisation neither provides nor approves, identify performance expectancy, effort expectancy and social influence as the drivers, and have studied users’ justifications for violating IT usage restrictions through the lens of neutralisation theory — the reasoning by which people set a rule aside without regarding themselves as rule-breakers.
| What the policy assumes | What is true at the desk |
|---|---|
| People know whether their data is in scope | “Personal data” is a legal category; a person has an email from a customer |
| The approved tool is available for the task | It is, for some tasks, and nobody has said which |
| Asking permission is a reasonable step | It takes a fortnight and the work is due Thursday |
| Non-compliance is deliberate | The rule was ambiguous and the deadline was not |
| Acknowledgement implies understanding | Acknowledgement implies a button was clicked |
Every row is a design fault rather than a discipline problem, and each one is fixable without weakening the underlying control.
Four failure modes
Written for the wrong reader. A policy drafted to satisfy a regulator or a board is optimised for defensibility, which produces abstraction. Abstraction is unusable at the point of decision. The same organisation needs both documents — the defensible one and the operational one — and usually produces only the first.
No mapping to actual tasks. “Do not input confidential information” requires every employee to perform a legal classification, unaided, several times a day, under time pressure. A recruiter needs to know whether interview notes are in scope. A support agent needs to know about a customer’s account reference. Give the answer for the twenty tasks that account for most of the exposure and the classification problem disappears.
No route that is faster than the workaround. If the approved path requires a business case and a fortnight’s wait, effort expectancy decides the outcome regardless of what the policy says. Governance that cannot be complied with quickly is not governance; it is a stated preference. A same-week decision route for low-risk use cases does more for compliance than any amount of communication.
Enforcement that is only blocking. Blocking has its place, particularly for regulated data. As a general instrument it removes visibility without removing behaviour — the use migrates to a personal device where there is no logging and no boundary at all. Shadow AI is the predictable result, and it is a worse risk position than the one being solved.
What governance-as-capability looks like
- Task-level rules, per role, in the vocabulary of the work. One page for each major function listing what is fine, what needs a check, what is never acceptable — using the names people actually use for things.
- A register of approved uses rather than approved tools. Tools change quarterly; the question “may I use a model to draft a first response to a complaint?” does not. A register also makes precedent reusable instead of re-litigated.
- Named decision rights and a service level. Who decides a new use case, and by when. Without a stated turnaround, the answer defaults to whatever the requester can get away with.
- A checking standard proportionate to stakes. Internal draft, one read for sense. Anything with numbers, verify every number. Anything leaving the organisation, a named second reader. This belongs in governance because it is the control that catches the failure.
- An honest disclosure route. People will not report that a model produced something wrong if reporting means admitting they used it — which is why the trust conversation is a governance input, not a separate HR topic.
Measure whether it is working, not whether it was read
Policy attestation rates measure distribution. Four measures that indicate whether governance exists:
- Can people state the boundary for their own role without looking it up? Ask ten people in one function. The result is usually clarifying and occasionally alarming.
- Approval turnaround, and the number of requests. Very few requests is not compliance; it is usually evidence that nobody thinks asking is worthwhile.
- The gap between sanctioned and estimated total use. A wide gap means the rules have been routed around.
- Error disclosure. Are people reporting when the tool got something wrong? Silence is not safety.
These share a property: none can be satisfied by publishing anything. That is what makes them useful, and it is the same reason criteria that can be met without the underlying thing being true are worthless.
State the trade-off out loud
Every restriction has an adoption cost, and governance discussions tend to price only one side. Prohibiting a category of use protects against a harm and forfeits a benefit. Both belong in the decision, and writing down the forfeited benefit is what stops governance drifting into blanket caution — which has its own risk profile, just a less visible one.
Microsoft and LinkedIn’s 2024 Work Trend Index found 78 per cent of AI users bringing their own tools to work, alongside 60 per cent of leaders saying their organisation lacked a plan and vision for implementing AI. The second number produced the first. In the absence of a usable sanctioned route, people built one, and the governance question was settled by default rather than by decision.
A policy nobody can follow while doing their job is not a control. It is a record of an intention, and it will be produced after an incident to demonstrate that the organisation had views. Governance that works is duller than that: specific rules, per role, that a person can apply in ten seconds, backed by a fast route for the cases the rules do not cover.
More on leading AI-enabled change in the AI Adoption Readiness Hub, or use the AI Adoption Readiness Assessment to establish whether your policy has reached practice.
