When AI Showed Up Uninvited: Building a Corporate AI Governance Framework from the Ground Up

 
 

In early 2023, something shifted almost overnight. AI didn't knock on the corporate front door — it walked in through the side entrance, one employee credit card at a time.

The Moment the Problem Became Real

When ChatGPT went mainstream in early 2023, companies with open network environments quickly discovered something uncomfortable: employees weren't waiting for permission. Personal subscriptions to ChatGPT were appearing on corporate devices, charged to personal or corporate credit cards, with no policy in place, no security review, and no visibility into what data was being entered into these tools.

For many technology organizations, the wake-up call came from an unlikely place: the expense report. ChatGPT was in the news, employees were curious about what it could do for their work, and the evidence started showing up in T&E data before it showed up anywhere else. That combination — visible public excitement and quiet internal adoption — is what triggered the need for a new process. AI tools weren't like traditional SaaS applications. The data implications were different, the vendor terms were unfamiliar, and the pace of adoption was faster than anything a standard procurement process was designed to handle.

The Legal team and the Security & Privacy Office, working in conjunction with the broader technology organization, recognized this early and moved quickly. The goal wasn't to shut AI down. It was to build a governance structure that let the company benefit from these tools without exposing itself to unnecessary risk. The question was never "should we use AI?" It was "how do we use it responsibly before it uses us recklessly?"

Step One: Find the Footprint

Before you can govern something, you have to know where it lives. The first task in any AI governance effort is mapping the existing landscape — and in 2023, that turned out to be harder than it sounds.

Endpoint management tools were already in place. But ChatGPT and most early AI tools were accessed through the browser, not installed as applications — which meant the standard MDM visibility layer largely missed them. The gap wasn't a failure of the tools; it was a function of how employees were accessing AI. Browser-based SaaS operated in a blind spot that endpoint management wasn't designed to cover.

Two data sources filled that gap:

T&E and expense data. If an employee was paying for an AI tool — on a personal card, a corporate card, or submitting for reimbursement — it showed up in expense reports. This created a starting inventory of what tools were actually in use across the organization, regardless of whether IT had sanctioned them.

Web usage patterns. Network-level monitoring helped identify browser-based usage volume even when individual transactions weren't captured. It wasn't perfect visibility, but it was directional — enough to understand the scale of adoption and prioritize which tools needed immediate review.

Today, that discovery problem looks different. Cloud access security brokers and secure service edge platforms give IT real-time visibility into browser-based AI usage in ways that 2023-era endpoint management couldn't. The discovery step has gotten meaningfully easier. The governance decisions that follow it haven't.

Alongside finding the tools, the goal was to understand how they were being used. Conversations with employees who had adopted these products early revealed something important: in most cases, people had found genuine productivity benefits. They weren't using AI frivolously — they were trying to do their jobs better. That context shaped the entire governance approach. This wasn't a crackdown. It was a framework to protect what was working while managing what wasn't yet understood.

 

Six-step AI governance intake process diagram showing discovery, request submission, cross-functional committee review by Legal, Security, Technology and Finance, approval decision, pilot incubator, and company-wide rollout.

 

Building the Intake Committee: Four Functions, One Decision

The centerpiece of an effective AI governance model is a cross-functional intake committee. Any AI tool — whether proposed by an employee, a business unit, or the technology team itself — goes through this committee before it can be approved for company use. Four functions need to be at the table:

Legal reviews vendor terms of service and contracts with one primary focus: data exposure. The questions that matter most are whether the company's data is being used to train the vendor's models, what the liability limits look like in the event of a data breach, and what jurisdiction governs the agreement. For companies that have experienced data incidents in the past, Legal often brings a harder line to these negotiations — and that instinct is usually the right one. In practice, the standard became simple: if the protections weren't in the contract, there was no trial and no deal. Vendors who pushed back on data training terms or offered vague language around model learning didn't proceed. That line held even when the product was compelling.

Depending on how your organization is structured, HR may sit at the table directly or be represented through employment counsel embedded in Legal. Either way, that perspective needs to be in the room — AI tools that touch hiring, performance, or employee communications carry workforce policy implications that pure contract review won't catch.

Security & Privacy goes beyond certification checkboxes. SOC 2 compliance is a baseline — vendors that can't demonstrate it don't get past this review — but the evaluation also covers authentication mechanisms, encryption standards, and incident response protocols. One area that surfaced real complexity was biometric and voice data. AI meeting tools that transcribe calls and identify speakers by name are legally prohibited in certain U.S. states — Illinois BIPA is the most commonly cited — and restricted across much of the EU under GDPR. This isn't a hypothetical edge case. During one pilot, a transcription tool's speaker-identification feature was discovered mid-rollout. The feature was turned off immediately pending review, and the tool ultimately didn't proceed in its original form. Any governance framework needs a process to catch this category of tool before it reaches employees, because by the time you're evaluating it, someone has usually already tried it.

Technology serves two roles. First, it ensures the company isn't acquiring duplicative capabilities — if an approved tool already covers a use case, the committee needs to know before approving a competitor. Second, the technology team acts as the internal champion for the intake process itself: running committee meetings, working with requestors to articulate the productivity or revenue value being sought, and managing the vendor relationship through the review. If a request duplicated something already approved, the technology team surfaced that early. It saved time and kept the vendor landscape from sprawling.

Finance ensures that approved tools have a sanctioned payment vehicle and that costs are tracked centrally. One of the clearest risks the discovery phase surfaces is AI spend scattered across individual expense reports — subscriptions charged to personal cards, reimbursed ad hoc, with no central visibility. The solution is structural: moving approved tools from credit card purchases to purchase orders, which enables better pricing at the business unit or enterprise level and gives Finance the visibility it needs to manage the category over time.

In this structure, Finance also carried the Procurement function — meaning vendor negotiation happened at the same table as budget approval. That alignment matters more than it might seem. When the function reviewing vendor terms is the same one controlling the purchase order, the negotiation dynamic shifts in the company's favor. It also eliminates the hand-off friction that slows deals down in organizations where Finance and Procurement sit separately.

What the Committee Actually Did: Approve, Deny, and Shut Down

The intake committee's authority ran in three directions: approve, deny, and sunset tools already in use.

Denials happened for a range of reasons. A vendor whose terms were vague on whether corporate data could be used for model training didn't proceed — the hard line was that no corporate data would leave on uncertain terms, regardless of how useful the product appeared. Tools that duplicated existing approved capabilities were denied on cost grounds. Security findings that vendors couldn't resolve closed the door regardless of other merits.

The committee also reviewed tools already in use across the organization and made the same calls. Some were ratified. Some were shut down. The process didn't grandfather existing tools simply because they were already running.

One important nuance: regulatory complexity meant that a tool approved for employees in one region could be prohibited for employees in another. Approvals were sometimes conditional or geographically scoped. That kind of precision is only possible if the governance framework is designed to handle it from the start — not retrofitted after the fact.

The committee didn't take years to build — or even months. Within three months of recognizing the problem, a functioning cross-functional intake process was in place and actively reviewing tools. Speed of implementation matters — the vendor landscape was moving faster than any annual planning cycle could accommodate.

Incubators: Testing Before Committing

Governance doesn't mean saying no to everything. Once a tool cleared the intake committee, the technology team ran structured pilots — incubators — to evaluate real-world performance before any company-wide commitment.

The structure mattered as much as the intent. Pilot groups were small and cross-functional. Vendors typically offered access at no cost during pilots in exchange for structured feedback, which gave the company evaluation leverage it wouldn't otherwise have had. Office hours gave pilot participants a place to ask questions and surface issues in real time. A formal feedback capture process meant the committee was making its proceed or pass decision on actual data, not impressions.

The scoring approach was specific: the committee and vendor jointly defined core categories for the product, and pilot participants rated each category on a scale of one to ten with required comments. Below seven meant the tool didn't proceed. Seven to 7.9 put it on the fence. Eight to 8.9 was a likely yes. Nine to ten was a clear yes. But even a high score wasn't sufficient on its own — cost, security, and legal all retained veto authority regardless of how well a tool performed in the pilot. That balance between user feedback and cross-functional oversight was what made the process credible.

A pilot of a major productivity suite's AI workspace product in early 2024 reinforced something important about the vendor dynamic during this period: AI companies needed enterprise feedback badly, and that gave companies more negotiating leverage than they often realized. Structured feedback, delivered through a formal process, was worth something to vendors. Companies that figured that out early used it well.

Communication: Getting the Policy to the People

A governance framework that no one knows about doesn't govern anything. Employee communication was one of the most important — and most underinvested — parts of this work.

The message had to be framed carefully. Employees who had been using AI tools weren't made to feel like they had done something wrong. Many of them had found genuinely useful capabilities and were trying to do their jobs better. The communication acknowledged that, while explaining clearly why the new process existed and how to use it. The two things employees needed to know were simple: how to request approval for a new AI tool, and where to find the list of tools that were already approved. Making both paths frictionless was essential to driving compliance without creating resentment.

The rollout was generally well received — but not without friction. The group that pushed hardest was engineering, which wanted to move faster and try more tools than the process allowed. Holding that line was the right call. The governance framework was new, the vendor landscape was moving quickly, and letting one function operate outside the process would have undermined it for everyone. Speed is easier to recover from than a data incident.

The Bigger Lesson

AI governance doesn't have to be a drag on innovation — but it has to be intentional. The companies that got this right in 2023 and 2024 weren't the ones that moved slowest. They were the ones that moved deliberately: building a cross-functional process early, being clear about the criteria for approval, and treating employees as partners rather than suspects.

The framework described here wasn't perfect on day one. It evolved as new tools arrived, as regulatory guidance became clearer, and as the organization's own AI ambitions grew. But having a structure in place — a committee with real authority, a testing process before commitment, a scoring methodology that balanced user input with cross-functional oversight, and a communication strategy that brought employees along — meant the company could move fast on the tools that passed review. The governance infrastructure gave leadership the confidence to say yes.

The goal was never to be the team that blocked AI. It was to be the team that made it safe to say yes.

If your organization is still working through this, that's the kind of thing a scoping call is built for.

Next
Next

Hiking the Angeles Crest: What Goes Wrong and How to Avoid It