AI operating governance · Field note

AI usage belongs in workflow governance, not blank-check access

TL;DR

Govern AI access where the work happens, and match the controls to what is at stake in that particular workflow.

What the paper develops

One AI account can carry two different risks

Your organization has approved an AI tool and wants more people to use it. The access decision looks responsible: an approved vendor, sign-on controls, an acceptable-use policy, and licenses assigned to the right employees.

Now follow two uses of the same account. One employee asks the tool to draft an internal meeting note. Another uses it in work that affects a customer. An agent might even trigger a later action. The license record looks the same in both cases. It cannot reveal the harm an error could cause or how much authority the AI had. It also leaves the review point and stop authority unknown.

That leaves the CIO or AI-governance leader with a bad choice. Heavy approval on every low-stakes use can drive people around the approved path. Blank-check access, meaning light controls on every use, lets high-impact work proceed without evidence, limits, escalation, or ownership.

Build the missing record around consequence

Account approval opens the capability; a separate workflow record must name the work AI may perform, the decision or action it can influence, the evidence it must leave, and the owner who can stop it. That record lets the organization keep a low-stakes drafting path light. Work that shapes a high-impact decision or performs an external action gets stronger controls.

Use six controls for each high-impact workflow. Scope access to the approved work. Monitor actual use. Set limits on volume, rate, or autonomy. Retain evidence and logs. Name the review path, escalation path, and owner. Set a date to review how it is used.

The six controls stay the same while their weight changes. Internal drafting may need an approved tool, light monitoring, and clear information limits. Customer-impacting decisions need evidence, review, escalation, and ownership. AI tools that act also need limits on permitted actions and autonomy. Those limits contain a bad setup before it travels.

Monitoring is the practical starting point. It shows whether the controls work and whether dependence has changed. A customer-impacting use might track AI-triggered actions, human overrides, limit breaches, and escalations. Those signals show when dependence or autonomy has raised the stakes.

Usage limits contain operational harm. The owner can bound volume, rate, permitted actions, or autonomy. A bad setup can then stop before it reaches more systems or people. Cost may fall too, but low cost does not make the authority safe.

The approved route also has to meet a real workflow need and remain easy to find. If the path is impractical, people may choose tools outside it. Monitoring can expose that unmet demand. A high-impact use may still need to be blocked. Leaders can also correct the approved route for valid work.

Start with one usage-control record

Before expanding AI into a high-impact workflow, require one short record. Name the workflow, its owner, and the work AI may perform. List the signals to monitor and the limits on volume, rate, or autonomy. State what evidence to retain. Add the human review and escalation path, then set the next review date.

This does not require a heavy approval process around every user. Low-stakes work can be documented lightly. High-impact work gets the full control set before dependence or autonomy increases. As evidence changes, the owner can expand, narrow, redesign, or stop the use.

The sources support context-based governance, ongoing monitoring, guardrails, and human responsibility. They do not set one universal threshold. They also do not prove that this exact record improves adoption. The CIO or AI-governance leader must still judge each workflow on the data involved, the harm an error could cause, and the ability to recover. Simplify a record that never changes a control decision.

The organization can still expand AI access. It now knows where that access enters real work, what the AI may do, how a mistake is contained, and who decides when the use changes.

What to do next

Set AI permissions at the workflow level. Match the access, the review, and the evidence you require to the data involved, what happens if the output is wrong, and how easily you can recover.

WORKFLOWCONTROL EVIDENCEHUMAN OWNER

Inside the white paper

  • Why one AI account can carry two completely different levels of risk
  • Six controls that make a workflow governable, and when to reach for stronger ones
  • How to start with a single usage record instead of a blanket policy

Sources and notes

  1. Gabriel Morgan Asaftei, Roger Roberts, Abby Sticha, and Cécile Prinsen, "State of AI trust in 2026: Shifting to the agentic era," McKinsey & Company, March 25, 2026 — McKinsey's analysis extends the risk from wrong statements to wrong actions, tool misuse, and operation beyond guardrails.
  2. National Institute of Standards and Technology, "AI Risk Management Framework Core," AI RMF 1.0, 2023 — NIST's AI Risk Management Framework organizes risk work through govern, map, measure, and manage, and treats context of use as material.
  3. International Organization for Standardization and International Electrotechnical Commission, "ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system," 2023 — ISO/IEC 42001 sets requirements for an AI management system in organizations that provide or use AI.
  4. Chloe Autio, Reva Schwartz, Jesse Dunietz, Shomik Jain, Martin Stanley, Elham Tabassi, Patrick Hall, and Kamie Roberts, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, July 26, 2024 — NIST's Generative AI Profile calls for continuous monitoring, structured feedback, and incident response across the lifecycle.
  5. Taryn Plumb, "Roughly half of employees are using unsanctioned AI tools, and enterprise leaders are major culprits," CIO, January 29, 2026 — A survey commissioned by BlackFog found 49 percent of employees using AI tools their employer had not sanctioned; it shows how common the use is, not why.