Dmitriy Stepanov is Co-founder, CTO, CAIO, and Business Process Automation Expert at Glorium Technologies.
Corporate AI use has become much more governed. But permission-based policies have little to do with managing the risk. “Do not enter confidential data into AI tools”—the compliance department’s favorite opening move for AI governance. From Big Four consulting frameworks to enterprise legal teams to countless internal memos about responsible AI, the idea that restricting data inputs is the foundation of AI governance has become the default assumption.
Before policies were in place, employees pasted client data into ChatGPT, fed proprietary code into public models and uploaded meeting recordings without a second thought. Now companies issue acceptable-use agreements, such as approved tool lists, data classification matrices, training modules and signature lines. The result looks governed, auditable and compliant. And so, the assumption follows: the risk is managed. However, the compliance gaps tell a different story.
AI Governance Has A Compliance Problem
Having a policy and managing the risks are not the same thing. Governance failures still happen even in organizations that have done everything right on paper. IBM’s 2025 Cost of a Data Breach found that organizations that experienced breaches lost an additional $670,000 in additional costs per incident compared to those with little or no shadow AI. Gartner found that 69% of cybersecurity leaders suspect employees are using prohibited tools anyway, regardless of the policy. The numbers speak for themselves: writing the policy and changing the behavior are two different problems.
The tool restriction addresses data security, but it is only one aspect of the problem. The real work in AI governance needs to address three gaps that most policies never touch:
• Task-routing problem, where AI improves some work and actively degrades other work.
• Intellectual property void, where AI-generated output may not be legally protectable.
• Executive credibility gap, where leadership violates the policies it has approved.
Most organizations think they are managing a data security problem. They are actually managing a business architecture problem—one that keeps adding new categories of risk. Data classification rules and approved vendor lists have matured, particularly for customer-facing workflows. However, the bigger risks remain unaddressed. And they tend to surface at the worst possible moment.
The Task-Routing Problem
Most organizations treat AI policy as a list of approved tools and prohibited behaviors. Governance specialists mean something more structural. A real AI governance framework has two layers:
• A risk identification layer: The taxonomy of harms AI can introduce
• A decision-routing layer: Function-level guidance on when and how to use AI
The reason task routing matters is something discussed in a meta-review by the International Center of Law and Economics called the “jagged frontier.” When AI is applied to suitable tasks, it can reduce task completion time by 15-50%. However, if applied to tasks beyond its capability boundary, it actively degrades performance because employees over-rely on outputs that look authoritative but are wrong. Without a proper framework, the policy cannot tell employees what it most needs to tell them. And once the task categories are established, other governance layers slot in naturally: who reviews AI output, what documentation is required, what disclosure obligations apply.
You will find this kind of task-level specificity in almost any effective AI governance program. A tool-approval list alone is not sufficient. What makes an AI policy effective is not its restrictiveness but its precision.
The Copyright Gap Most Policies Miss
Corporate AI output has come under closer scrutiny by intellectual property law in recent years. In January 2025, the U.S. Copyright Office published its official position: prompts alone do not constitute authorship. Work produced by AI is not copyrightable unless a human made sufficient creative contributions to the output.
The practical effects cut both ways. Content production is faster and cheaper. Teams move easily between drafting proposals and generating documentation. But an entire category of work product (the AI-generated proposal, the machine-written code comment) is now unprotectable, legally exposed and commercially vulnerable.
The protections are still available if you earn them. AI can serve as a starting point that authors substantially transform. Deliverables remain protectable if you document the editorial process, and intellectual property law still offers a wide range of compliance pathways.
The Credibility Problem At The Top
Tool restrictions and compliance documentation made AI governance more visible. However, they did not make it precise. The policies of Fortune 500 companies, regulated industries and federal agencies are often extensive and generic. Easy to audit, because the categories are clear. Hard to enforce, because the guidance is not.
As mentioned earlier, when Gartner surveyed 302 cybersecurity leaders, they found that 69% of organizations suspect employees are using prohibited AI tools, regardless of what policies dictate. Corroborating research found that 93% of executives and senior managers admit to using shadow AI, the highest rate of any employee tier. Three-quarters of those shadow AI users admitted sharing potentially sensitive information with unapproved tools.
This is what the executive credibility gap looks like in practice. When the people responsible for setting said policies are frequent violators, the problem becomes one of legitimacy.
Restrictive Is Not The Same As Effective
The story of corporate AI governance is not one of restriction, of open access being locked down. It is a story of increasing structural precision, and of increasing awareness of risks that were always there but never named. The first shift was recognizing task-level routing as the foundation of effective governance. The second was discovering that IP exposure, liability gaps and executive accountability are policy requirements, not optional additions.
If you want to govern AI effectively, stop worrying about how many tools are on your approved list. Start thinking about how precisely your policy routes decisions by risk level. Is the guidance function-specific? Does it address intellectual property? Does it name the person who owns compliance?
Restrictive policies are not effective policies. Precise ones are. And corporate AI governance, on the whole, has become more precise over time—not by becoming more restrictive, but by becoming more task-specific, more risk-aware and more structurally accountable.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


