Are you really in control of your AI tools?

Many organisations now have AI policies, controls and approved tools in place, but recent surveys highlight that there is a growing gap between governance on paper and knowing how AI is actually being used across teams and departments. 

AI governance concept represented by blue blocks featuring AI, data, cloud and technology icons, topped with the letters “AI”.

The growing use of AI is exposing gaps between governance policies and real-world use

AI risk can show up in very different ways. Phishing emails drafted with new layers of sophistication, a grievance built on AI-generated case law or an unapproved chatbot fed a spreadsheet of client data. Each issue might seem manageable when viewed in isolation, but it becomes more complex when teams are using a mix of tools, all with different levels of oversight. 

This fragmentation creates a wider AI governance challenge, with five areas in particular now putting existing controls under pressure.

The risk of shadow AI

At desk level, employees may be reaching for unapproved tools to get through everyday tasks, often uploading company or personal data without fully understanding where that data goes next. And because this activity sits outside approved systems and processes, organisations generally have limited visibility over which tools are being used and what information is being shared. 

A written AI policy, on its own, rarely closes the gap. Policy sets the expectation, but effective control comes from governance, oversight and ongoing AI literacy. This leads to employees understanding the risk they’re creating before they create it, not after the fact.

AI in cyber security

The issue of AI within cyber security is an area of risk that most will already be somewhat familiar with. AI hasn’t fundamentally reinvented cyber threats, but it is making many of them more effective and difficult to detect. Phishing and social engineering attempts are becoming harder to distinguish from genuine communication, and AI is helping attackers scale these approaches in ways that were previously too labour intensive to sustain. At the same time, organisations are connecting AI tools into more of their own systems and data, opening routes to sensitive information that didn't exist a year ago.

The more difficult question is whether existing safeguards, and the testing behind them, have kept pace with how the threat and the organisation’s own exposure are changing.

AI in HR and employment

Employees are increasingly turning to tools like ChatGPT to draft grievances, challenge redundancy decisions or build a case for an employment claim, sometimes leaning on AI-generated content or citations that are inaccurate or fabricated. . HR teams are using AI themselves to review documentation, summarise complex cases, and support growing workloads involving sensitive employee data.

These uses create different risks. HR teams need to identify inaccurate or misleading AI-generated material, while their own use of AI raises challenges around data protection and human oversight.

There is also a third-party dimension to consider. Using external suppliers adds another layer of complexity around how employee data is used, what protections are in place and who is responsible if something goes wrong.

The issue of assurance and third parties

Organisations increasingly need evidence that their suppliers are governing AI appropriately, while also being ready to provide similar assurance to their customers.

Stanford's 2026 AI Index found that ISO/IEC 42001 is already influencing responsible AI decision making at 36% of organisations surveyed, with NIST AI RMF influencing a further 33%, a sign that this shift toward formal standards is well underway rather than theoretical.

The practical challenge is deciding what evidence provides meaningful assurance, rather than simply adding another questionnaire or compliance check. Assurance should show that the controls around an AI system are proportionate to the risks it creates.

The EU AI Act

Most of the EU AI Act's provisions now apply, with high-risk obligations following from December 2027. That extended runway buys organisations more time to prepare, but AI Act compliance shouldn’t be treated in isolation. Where AI involves personal data, existing data protection obligations need to be built into governance and compliance processes..

Existing frameworks can also play a part. Approaches such as NIST AI RMF give organisations a structured way to assess AI risk and strengthen existing governance processes. 

Bringing everything together

When viewed as a whole, these issues show how varied AI risk has become. It changes depending on how and where the technology is being used in the organisation. The question running through all five areas is whether organisations have enough visibility and control to keep pace with that change.

That's the focus of the DPO centre's upcoming AI Reality Check webinar day, part of their Privacy Puzzle Global Webinar Series.  Bringing together specialists from across the Axiom GRC group, including WorkNest Secure, WorkNest People, VinciWorks, IS Partners and Corestream GRC, the DPO Centre is running five expert-led sessions on 20th October, each exploring a different area of AI risk. 

Each session runs for 45 minutes and includes a live Q&A, giving you the opportunity to put your questions directly to the panel, and you can register for one session or join all five. If you want to understand more about where AI risk is emerging and how to manage it, the AI Reality Check webinar series is one to put in the diary.

Next
Next

University of Maryland opens quantum Discovery Center with Microsoft as investment hits $500m