AI Is Great But Stupid [Part 3]: Governing AI

Allyson Edwards (Senior Consultant) • July 17, 2026

Effective AI governance isn't about halting innovation with static policies. It's about adapting your existing compliance concepts to handle automated speed and scale.

Short on time? You can listen to this audio summary in under 3 minutes.

Length: 2 min 46 sec

  • Read Full Transcript

    Hi, I'm Allyson Edwards from AdviseUp Consulting, and this is The Bottom Line.


    At this point in our series, AI might be starting to sound more risky than useful. But these challenges aren't a reason to avoid the technology entirely; instead, they're a reason to govern it thoughtfully.


    The reality is that AI adoption is happening faster than formal oversight structures. Employees are experimenting with tools independently, integrating AI into existing processes, and entering sensitive data into systems that haven't been fully vetted by leadership.


    The biggest misconception about AI governance is that it belongs entirely to your IT department. In reality, AI affects nearly every part of an organization, and the risks differ wildly based on the use case. An AI tool used to summarize meeting notes creates very different operational exposures from one reviewing contracts, analyzing insurance claims, or assisting with hiring decisions. Governance has to account for those differences.


    Effective governance starts with visibility. Organizations should already be asking what tools our employees are actually using, what data is being entered, and who validates the outputs?


    Once you understand your footprint, you don't need to reinvent the wheel. It’s about adapting existing governance concepts to these new technological risks through four practical controls.


    First, approved AI tool inventories. Document exactly which tools are approved, restricted, or prohibited to eliminate unvetted privacy and compliance gaps.


    Second, prompt and data handling guidelines. Give employees clear boundaries about what information can be entered into these tools, and how prompts should be structured to protect sensitive data.


    Third, access restrictions and permission right-sizing. AI tools can only be constrained by the permissions they are given. If an employee has broad access rights, an AI system operating through their credentials inherits those same capabilities. You must enforce least-privilege access.


    And fourth, model drift monitoring. Unlike traditional software, AI systems change over time as models update and input patterns shift. Governance cannot be a one-time implementation exercise; it requires recurring testing and human-in-the-loop validation.


    Here is the bottom line, AI governance is not about eliminating risk entirely. We all know that’s a losing proposition. It’s about creating enough structure and oversight to use the technology responsibly while still benefiting from its capabilities.


    The businesses that succeed with AI won't be the ones that trust it blindly. They will be the ones that govern it thoughtfully.


    Stay tuned for our final installment where we'll pivot from high-level oversight to the daily habits, tips, and tricks that will make your team more effective AI users.


    Thanks for joining The Bottom Line.

In the first article of this series, we explored what artificial intelligence actually is. In the second, we looked at where AI goes wrong. 


At this point, AI may be starting to sound more risky than useful, but these challenges aren’t a reason to avoid AI entirely. They’re a reason to govern it thoughtfully. 


Organizations already know how to manage risk through governance, controls, oversight, and accountability. AI is no exception. Organizations and their leadership just need to put the time and effort into mitigating the new risks that AI exposes.

AI Governance Is Not Just an IT Issue


One of the biggest misconceptions about AI governance is that it belongs entirely to technical teams. In reality, AI affects nearly every part of an organization, from operations to human resources to cybersecurity. This is because AI is used by nearly every part of an organization, which means it influences decisions, workflows, communications, and risks.


And the risks that an AI tool poses will differ wildly based on what it’s being used for. An AI tool used to summarize meeting notes creates very different risks from one reviewing contracts, analyzing claims, approving code changes, or assisting with hiring decisions. Governance needs to account for those differences.


In many organizations, AI adoption is happening faster than formal oversight structures are being implemented. Employees are experimenting with tools independently, integrating AI into existing processes, and entering sensitive data into systems that may not yet be fully vetted. This is often either allowed or even encouraged by leadership, as AI is seen as the tool of the future, and therefore its adoption is seen as a necessary part of growing as a business. 


That creates governance gaps, not necessarily because employees are acting improperly, but because organizations are still learning where AI can be used and those use cases are expanding more rapidly than controls covering them are.

Questions Organizations Should Already Be Asking


Effective AI governance starts with visibility.

Organizations should already be asking questions about their AI usage:

What tools are their employees using?

What data is being entered into them?

Who validates the AI-generated outputs, and how do they do so?

How are AI activities logged and monitored?

These questions should all be familiar from existing governance programs. The difference is that AI introduces a new level of speed, scale, and ambiguity into environments that were originally designed around human-driven processes.

Building Your Framework


Once leadership understands their current footprint, the focus must shift to active management. Implementing these fundamental steps keeps operations secure without slowing down innovation

Risk Assessments

One of the most practical ways to approach AI governance is through risk assessments.


Organizations don’t need to treat every AI use case the same way. A low-risk productivity tool doesn’t require the same level of oversight as an AI system that interacts with financial reporting, healthcare decisions, software development, or regulatory compliance.


Risk assessments help organizations evaluate:

  • The sensitivity of the data involved
  • The impact of incorrect outputs
  • The level of automation, regulatory exposure
  • Whether humans remain appropriately involved in decision-making

This is especially important because AI risks are often operational rather than purely technical.

For example, LLM usage in the software development lifecycle could lead to concerns around AI systems performing actions traditionally reserved for humans, such as the approval of pull requests or change management activities. It’s a concern if AI actions are indistinguishable from human actions in system logs, or if AI systems take unintended actions while attempting to complete assigned tasks. 

Importantly, the risk isn’t that the AI system is acting maliciously. The risk is that existing controls are designed with human behavior in mind. AI changes the assumptions behind these controls.

Human Oversight

While I mentioned that human-in-the-loop controls aren’t always enough to prevent issues with AI outputs in the last article, they’re still one of the cornerstones of effective AI governance. This is particularly critical in environments where there are many, complex systems that work together that must be parsed accurately, such as regulatory obligations, financial reporting, or operational decisions. 


Organizations should clearly define when AI outputs require review, who is responsible for that review and approval, and what level of validation is expected.


Otherwise, organizations risk gradually shifting decision-making authority to systems that are not capable of accountability or professional judgement.

Practical AI Governance Controls


AI governance does not always require entirely new control structures. Instead, it involves adapting existing governance concepts to new technological risks.

Examples of Practical Controls

  • Approved AI Tool Inventories

    Organizations should document which AI tools are approved, restricted, or prohibited. This reduces the risk of employees using unvetted tools that may introduce privacy, security, or compliance concerns. 

  • Prompt and Data Handling Guidelines

    Prompting is more than just a productivity skill. Poor prompting practices can unintentionally expose sensitive data, generate misleading outputs, or bypass intended safeguards.


    Employees need clear guidance about what information can be entered into AI tools, how prompts should be structured, and what types of data require additional protections

  • Prompt Injection Guardrails

    Prompt injection is where malicious or inaccurate inputs are used to manipulate AI systems into ignoring intended safeguards or performing unintended actions. For example, if a user can type “ignore previous instructions” to get around the safeguards that have been put in place.


    Organizations should consider implementing prompt filtering or guardrails and restricting sensitive system instructions. 

  • Review and Approval Requirements

    AI-generated outputs should not automatically bypass existing review controls simply because they were produced quickly or appear polished. Organizations should define where human review is mandatory and document approval expectations accordingly.

  • Managing Human Review Fatigue

    One particularly practical issue that comes from human review is “human review overload,” where AI-generated outputs can be so numerous or so large that meaningful human review becomes difficult. 


    This is an easy risk to overlook.


    A way to combat this particular risk is by updating review guidelines to more specifically consider AI output sizes by putting in place specific expectations around documentation and testing requirements.

  • Access Restrictions and Permission Right-Sizing

    AI systems can inherit excessive user permissions through credentials or personal access tokens. This can create significant governance concerns because AI tools can only be constrained by the permissions that they’re given. If an employee has broad access rights, an AI system operating through that employee’s credentials may inherit the same capabilities. 


    Organizations should evaluate whether AI tools are operating with least-privilege access, how credentials are delegated, and whether AI systems have unnecessary access to critical systems or data.


    Traditional identity and access management principles still apply, arguably even more critically, in AI environments.

  • Logging and Monitoring

    Traditional logging mechanisms may not adequately distinguish between human and AI-generated activity, especially when AI systems can act using delegated user identities.


    As a result, organizations may need AI-specific logging and monitoring controls, including:

    • Identifying when AI systems perform actions
    • Tracking prompts and outputs, when appropriate
    • Monitoring for unauthorized behavior
    • Implementing alerts for high-risk AI activities

    Without visibility, organizations may struggle to investigate incidents, identify policy violations, and demonstrate compliance.

  • Model Drift Monitoring

    Unlike traditional software, AI systems can behave inconsistently as models are updated, use cases evolve, prompts change, or input patterns shift. This gradual change in AI behavior over time is called “model drift.”


    As a result of these changes, governance cannot be treated as a one-time implementation exercise. Organizations need recurring testing, performance monitoring, and human-in-the-loop validation, along with defined drift protection plans for higher-risk AI applications.

  • Training and AI Literacy

    AI governance cannot succeed if employees don’t understand the technology that they’re using. Training should include:

    • Acceptable use expectations
    • Privacy considerations
    • Output validation
    • Prompting practices
    • Bias awareness
    • Escalation procedures

Governance Must Evolve Alongside AI Usage


One of the more difficult aspects of AI governance is that AI usage changes quickly. A tool that starts as a low-risk productivity assistant can gradually become integrated into decision-making, operational workflows, or even customer-facing activities. Governance expectations will need to evolve alongside those changes, making static policies insufficient.



Organizations need governance programs that adapt to usage through risk assessments, ongoing monitoring, recurring training for users, and periodic control evaluations.


The organizations with the clearest understanding of how AI is actually being used will be the ones that create the most effective governance programs.

The Most Important Takeaway


  • AI governance is not about eliminating risk entirely; we all know that’s a losing proposition. 
  • It’s about creating enough structure and oversight for organizations to use AI responsibly while still benefiting from its capabilities.
  • The organizations that succeed with AI will be the ones that understand its strengths, recognize its weaknesses, and build thoughtful controls them, rather than the ones that trust it blindly.

Govern AI with Confidence

Managing AI risk isn't about halting innovation: it's about building structure. Contact AdviseUp to discuss tailoring a robust AI governance framework that protects your data while maximizing efficiency.

Lets Talk

"AI is Great But Stupid" Series

Understanding what AI is lays the foundation for everything that follows: how it fails, how it should be governed, and how it can be used This series is designed to move professionals from AI-hype to AI-competence.


Part 1: Understanding What AI Actually Is

Part 2: Where AI Goes Wrong
Part 3:
Governing AI  (reading now)

Part 4: Practical Tips That Actually Help (upcoming)

AI robot standing beside a small dog in a cage labeled wolf.
By Allyson Edwards (Senior Consultant) June 16, 2026
Explore common AI failures like hallucinations, hidden bias, and missing context. Learn how audit and compliance teams can govern risks and build AI controls.
Tia Persky
By Tia Persky June 9, 2026
Explore how international travel to Portugal, Ireland, and Morocco taught one future leader that authentic human connection is the foundation of good business.
Skyscrapers view from a low angle.
By Kristel Jose (Guest Writer) May 29, 2026
Master SOX compliance in 6 months. Discover the five pillars to transition from zero documented internal controls to 100% audit readiness without runaway fees.
More posts