People Governance
What are our people doing with AI today?
The layer most enterprises discover last, and the one already in production everywhere: employees using AI. Sanctioned tools good enough to win, shadow-AI discovery and coaching, acceptable use that names real behaviors, literacy as a legal duty and a control, and access tiers that match trust to training. Every employee is now a model operator; the workforce is the widest AI attack surface and the biggest adoption lever at once.
Ungoverned employee AI use is your largest AI deployment — you just don't operate it.
Why leadership should care
- Shadow AI is the default state: data sent to GenAI apps grew 30x year over year, 72% of enterprise use flows through personal accounts (Netskope), and one in five breaches now involves shadow AI at a ~$670K premium (IBM, 2025).
- Bans demonstrably fail — Samsung's leak-then-ban arc just moved usage to personal devices. Sanctioned alternatives plus coaching measurably work.
- AI literacy is now a legal duty (EU AI Act Art. 4) and a rollout precondition: Macquarie put 99% of employees through mandatory GenAI training around its bank-wide rollout.
- Which sanctioned AI tools do we give everyone, and are they good enough to out-compete shadow use?
- What is our acceptable-use line on data classes, verification duties, and client work?
- Is AI training mandatory, role-based, and tied to access?
Gemini Enterprise (formerly Agentspace)
GAEmployee AI
The governed employee agent workplace over enterprise data.
A sanctioned alternative good enough to out-compete shadow AI.
Workspace AI control center
GAGoogle Workspace
Per-OU Gemini controls, DLP/IRM exclusions, context-aware access.
Granular employee-AI rollout that honors existing document permissions.
Chrome Enterprise Premium
GAEndpoint
Browser DLP over AI sites: paste, upload, and URL controls.
Shadow AI at the endpoint — governs what leaves the browser to any AI tool.
Security Command Center AI Protection
GASecurity Command Center
AI inventory discovery, virtual red teaming, AI/agent threat detection.
AI security posture management — including shadow AI inside your cloud.
AI/ML Privacy Commitment
GAContractual
Customer data is not used to train Google models without permission.
The first procurement blocker, answered contractually rather than by policy blog.
Cards link to official documentation. Status is a snapshot (August 2026) — verify per component before contractual commitments. Full mapping and honest gaps: 08 · Google Cloud.
Your employees adopted AI before your governance did — the only question is whether they did it inside or outside your visibility.
- The Air Force didn't ban shadow AI — it out-competed it with a governed sandbox, then graduated everyone to an enterprise platform. That arc is repeatable.
- Blocking failed everywhere it was tried alone: usage just moved to personal accounts. The winning play is paved road + discovery + coaching.
- Macquarie's number to quote is 99% — not model accuracy, training completion. Workforce readiness is a control.
- Your AI policy is only as real as the browser: if paste-to-personal-chatbot works silently, the policy is a suggestion.
- What does your network data say about which AI tools employees actually use?
- If an engineer pasted source code into a personal chatbot right now, what would happen?
- Is your sanctioned assistant genuinely better than what employees use in the shadows?
- Who has completed AI training, and does anything unlock — or lock — based on it?
- What do client contracts and professional duties say about your teams' AI use — and who checked?
HCA Healthcare
Google CloudHealthcare
Don't bolt review onto the workflow — design the UI so review is the workflow.
Highmark Health
Google CloudHealthcare
Centralize access and measure usage first — governance data is what lets you expand safely.
TELUS
Google CloudTelecom
Model choice and governance aren't in tension when the gateway owns the controls.