Skip to content
Layer 7The governance stack/ People

People Governance

What are our people doing with AI today?

The layer most enterprises discover last, and the one already in production everywhere: employees using AI. Sanctioned tools good enough to win, shadow-AI discovery and coaching, acceptable use that names real behaviors, literacy as a legal duty and a control, and access tiers that match trust to training. Every employee is now a model operator; the workforce is the widest AI attack surface and the biggest adoption lever at once.

The risk, in one line

Ungoverned employee AI use is your largest AI deployment — you just don't operate it.

Why leadership should care

  • Shadow AI is the default state: data sent to GenAI apps grew 30x year over year, 72% of enterprise use flows through personal accounts (Netskope), and one in five breaches now involves shadow AI at a ~$670K premium (IBM, 2025).
  • Bans demonstrably fail — Samsung's leak-then-ban arc just moved usage to personal devices. Sanctioned alternatives plus coaching measurably work.
  • AI literacy is now a legal duty (EU AI Act Art. 4) and a rollout precondition: Macquarie put 99% of employees through mandatory GenAI training around its bank-wide rollout.
72%
of enterprise GenAI use flows through personal accounts — Netskope Cloud & Threat Report, 2025
Decisions only leadership can make
  • Which sanctioned AI tools do we give everyone, and are they good enough to out-compete shadow use?
  • What is our acceptable-use line on data classes, verification duties, and client work?
  • Is AI training mandatory, role-based, and tied to access?
Read the claims right
RegulationEU AI Act Art. 4 (AI literacy)PracticeShadow-AI threat research (IBM, Netskope)PracticePaved-road adoption patternPracticeAcceptable-use policy discipline
In the room — discussion points

Your employees adopted AI before your governance did — the only question is whether they did it inside or outside your visibility.

  • The Air Force didn't ban shadow AI — it out-competed it with a governed sandbox, then graduated everyone to an enterprise platform. That arc is repeatable.
  • Blocking failed everywhere it was tried alone: usage just moved to personal accounts. The winning play is paved road + discovery + coaching.
  • Macquarie's number to quote is 99% — not model accuracy, training completion. Workforce readiness is a control.
  • Your AI policy is only as real as the browser: if paste-to-personal-chatbot works silently, the policy is a suggestion.
Questions to ask your organization
  • What does your network data say about which AI tools employees actually use?
  • If an engineer pasted source code into a personal chatbot right now, what would happen?
  • Is your sanctioned assistant genuinely better than what employees use in the shadows?
  • Who has completed AI training, and does anything unlock — or lock — based on it?
  • What do client contracts and professional duties say about your teams' AI use — and who checked?