Even after a company publishes an AI usage policy, sales representatives may still use personally registered tools to summarize customer emails, while procurement staff may paste supplier quotations into external services for comparison. Employees may not intend to violate company rules; approved tools may simply be difficult to find, deadlines may be tight, or employees may not know which data must not be entered. In these situations, even the most comprehensive policy cannot provide effective control when employees actually use AI.
TechOrange cited Pax8 research indicating that approximately 78% of employees use AI tools that their employers have not approved. Another survey of more than 400 U.S. small and medium-sized business executives found that 90% of companies had begun adopting AI, but only 23% had a written policy. Pennsylvania Bank also reported an incident in which an employee, seeking to save time, entered customer names and Social Security numbers into an unauthorized large language model, ultimately requiring the bank to file a report with the U.S. Securities and Exchange Commission. These figures do not necessarily represent Taiwanese enterprises, but the cases offer an important reminder for managers: AI governance must be implemented through permissions, workflows, and records to be effective in day-to-day operations.
Why Written Policies Fail to Prevent Workplace Shortcuts
“Do not enter confidential data” may appear clear, but two gaps emerge in practice. First, employees may not be able to immediately determine how a quotation, customer complaint record, or quality-control photo should be classified. Second, even when employees understand the rules, they can still open external tools, upload data, or connect to external services as usual. If an enterprise places the entire burden of compliance on employee vigilance, it can only investigate after an incident has already occurred.
A good starting point is to identify shadow AI—that is, AI tools employees use independently without company approval. IT teams can review endpoint and network logs to determine which services employees are using, while business units can provide details about the purpose of use, the data entered, and how the resulting output is subsequently used. The purpose of this inventory is not to immediately block every tool, but to determine where data is already going and why existing approved tools have not been adopted.
Policy language should also be rewritten as specific, auditable rules. For example, “Sales staff may use approved tools to organize public product information but may not upload non-public quotations or customer contact details” is easier to implement than “Users must pay attention to information security.” As a first step, IT, information security, compliance, and the two departments with the highest levels of AI usage can jointly identify the ten most common AI use cases. For each one, they should clearly specify the permitted tools, data, and output purposes before addressing less frequently used scenarios.
Put Roles, Data, and Actions into a Single Matrix
To make governance measures operational, enterprises must answer three questions: Who may use the system? What data may they access? What actions may they perform? A three-column permission matrix covering roles, data, and permitted actions is recommended. Roles should distinguish at least among general users, department managers, administrators, and read-only users. Data can be classified into four levels: public, internal, confidential, and regulated. The actions column should not simply say “use AI”; it should distinguish among querying, uploading, generating content, calling external services, and executing scripts.
Consider procurement price comparisons. An AI Agent may organize publicly available specifications and access approved historical procurement data. However, if the data includes confidential reserve prices or suppliers’ personal information, the enterprise should restrict the data sources, execution environment, and external connections. Data classifications must also be enforced through technical configurations. Otherwise, the same user may still copy confidential content into an unauthorized service.
EgentWrX enables enterprises to define what each person may do with an AI Agent and which data they can access based on the organizational structure. It can also allow an AI Agent to access databases through the corporate intranet on a read-only basis, while denying external connections by default and allowing individual domains as needed. Enterprises can begin with one workflow—such as sales quotations, procurement price comparisons, or customer service summaries—define the data each role may access and the actions it may perform, and then have the responsible data owner confirm the settings. Do not attempt to cover every department with a single permission model from the outset.
Build Human Approval and Record-Keeping into Workflows
“Important content should be reviewed by a manager” is still not specific enough. Employees do not know what qualifies as important, and the workflow cannot determine where it should pause. Every AI workflow should define the conditions requiring human confirmation, such as when content contains customer data, an amount exceeds a departmental threshold, input criteria are ambiguous, different data sources conflict, or a script is about to be executed. Enterprises must also specify who is responsible for approval, which step an approver may return the workflow to, and which checkpoints cannot be skipped.
Record-keeping must extend beyond the final answer. At a minimum, an audit trail should answer the following questions: Who initiated the task and when? What data did the AI Agent access? Which services did it call? What output did it generate? Who approved its release? What actions were subsequently performed? EgentWrX audit logs can record AI Agent activity and support verification of whether records have been altered. The system also records when administrators download audit records. In addition, administrators can require a workflow to undergo human approval before handoff, allowing it to continue only after a designated person has approved it.
Enterprises should also designate who is responsible for reviewing records, how often reviews should occur, and how anomalies should be handled. It is advisable to conduct quarterly spot checks of activities involving confidential or regulated data. These checks should verify whether permissions remain appropriate for each person’s role, whether approvals were properly completed, and whether all external services are on the allowlist. If employees repeatedly bypass the workflow, first determine whether the approved tools meet their operational needs before deciding whether to adjust the tools, permissions, or training approach.
For an AI usage policy to be enforceable, the management team must map each written rule to system permissions, workflow checkpoints, and retrievable records. Begin with a clearly defined workflow that handles sensitive data, and have information security, IT, and the relevant business unit jointly confirm the permission matrix and approval criteria. Expand the scope only after completing an initial audit. This approach makes it easier to identify gaps than issuing company-wide principles from the outset.
FAQ
Our company already has an information security framework. Do we still need a separate AI usage policy?
Yes. Enterprises can build on their existing processes for software approval, identity management, access control, and incident response. However, they must also define a list of approved tools, the types of data that may be entered, how AI-generated output should be reviewed, and which actions an AI Agent may perform. Otherwise, the rules may govern only accounts and devices without addressing AI-specific risks.
Which AI use cases should be reviewed in the first inventory?
Begin with use cases involving customer data, financial data, non-public quotations, regulated information, or scripts. Then document the users, tools, data sources, and intended uses of the output. High-sensitivity workflows that are used frequently should be prioritized when designing permissions and human-approval requirements.
Does every AI-generated output require managerial approval?
No. Enterprises should establish approval conditions based on risk. Employees can review work involving publicly available information themselves. A workflow should pause for confirmation by a designated role only when it involves customer data, exceeds a financial threshold, contains ambiguous conditions, or is about to execute a script. This prevents managers from being overwhelmed by low-risk work.
How often should audit records be reviewed?
The review frequency should reflect data sensitivity, with activities involving confidential or regulated data audited at least quarterly. Reviews should not merely confirm that records exist. They should also verify that user permissions remain appropriate for current roles, that approvers actually reviewed the content, and that anomalous external connections have been addressed.
References
- Applying Information Security Principles to AI Governance: 78% of Employees Use Unauthorized AI Tools, and Enterprises Can Adopt Tiered Access Controls — TechOrange’s summary of the Pax8 survey, the banking incident, and recommendations for AI governance.
