Skip to main content

How Do I Govern AI Use Without Banning the Tools?

10 September 2026 | David and Goliath

Quick answer

You govern AI use by measuring it before you legislate, sanctioning the majority that is fine, and applying a guardrail to the narrow slice that carries real obligation. A ban you cannot enforce binds only the people who were already careful, and pushes everyone else onto personal devices where you can see nothing. The sequence matters more than the policy wording.

  • Measure for two weeks before writing policy, or you will ban the wrong things
  • Sanction the majority. Most AI use is unremarkable and should be made official
  • Guardrail the middle with warn and confirm rather than prohibition
  • An unenforceable ban is worse than no policy, because it removes visibility

Mentioned: David and Goliath, AI governance, shadow AI, Privacy Act, Akamai Workforce Protector

Most AI governance programmes fail in the same order. Someone drafts a policy, the policy prohibits broadly because nobody has the data to be specific, IT cannot enforce most of it, and within a quarter the document exists but the behaviour has not changed. The fix is not better policy wording. It is doing the steps in a different order.

Why does banning AI tools not work?

A ban only binds the people who were already going to ask permission. Everyone else has a deadline that did not move, so the work relocates to a personal phone or a home laptop, where there is no logging, no data loss prevention, and no audit trail.

That leaves the organisation in a worse position than before, because you have traded visibility for a document. An organisation that permits a sanctioned tool and can see how it is used is meaningfully safer than one with a prohibition and no idea what is happening.

What should come before writing the policy?

Two weeks of read only observation. You want a ranked list of what is genuinely in use, by how many people, through which accounts, and holding which permissions, before anybody drafts a rule.

Policy written before that list exists reliably makes two mistakes. It prohibits the tools nobody was using, which costs nothing and achieves nothing. And it stays silent on the ones everybody was using, because nobody knew to name them.

What does the data usually show?

It usually shows that the problem is smaller and differently shaped than the panic suggested. Three findings come up almost every time.

  • Most usage is unremarkable. Drafting, summarising, rewording, code explanation. None of it touches regulated information and all of it should be made official rather than tolerated.
  • The accounts are the issue, not the tools. Akamai measured 47.11% of enterprise AI conversations running through personal identities rather than corporate managed accounts (Source: Akamai, State of the Internet: Enterprise AI Usage Risk Report 2026, August 2026). That is the number that should reshape the policy, and it is almost always quoted inverted, so state it carefully.
  • Extensions carry more privilege than the tools. Akamai found almost 75% of AI browser extensions demand high or critical permissions (Source: Akamai research, 5 August 2026), a level that typically lets an extension read and change the content of pages the user visits.

What does a policy look like once you have the data?

It gets shorter, and it splits the population three ways instead of two. This is the structure we land on with most clients.

  1. Sanction. Name the tools people should use, provision them properly with corporate identity, and make that the path of least resistance. Most usage moves here on its own.
  2. Guardrail. For content that is borderline, warn and confirm at the point of submission, naming what was detected. This teaches rather than obstructs, and it changes behaviour more than a block does.
  3. Stop. A short list of genuine problems, specific enough that nobody argues with it. If this section is long, the measurement step was skipped.

How do you enforce a guardrail without stopping people working?

By redirecting rather than blocking. When someone reaches for an unsanctioned tool, send them to the approved equivalent with their work intact, instead of showing them a denial page and leaving them to solve the deadline elsewhere.

This is the behavioural difference that decides whether a control survives contact with the organisation. Controls people route around generate no data and no compliance. Controls that give people a working path generate both, and get quietly accepted.

Where does the Australian privacy obligation fit?

Where personal information is involved, your handling obligations under the Privacy Act do not lapse because the destination was a chat interface. That is the slice worth being strict about, and it is usually a small proportion of total AI activity rather than the whole of it.

Which is the practical argument for measuring first. Being strict everywhere is indistinguishable, to the people governed by it, from being arbitrary, and it spends your enforcement credibility on flows that never carried obligation.

How do you keep this current as tools change?

Treat the tool list as a rolling output rather than an annual document. AI features arrive inside software you already licence, under contracts signed before those features existed, so nothing in procurement will trigger a review.

That means the discovery has to run continuously, not once. The governance decision that ages fastest is the one made against a snapshot, because the snapshot was out of date the week a vendor shipped an update.

What tooling supports governing rather than banning?

Something that can see the interaction and act on it in the moment. Akamai Workforce Protector is what we deploy, through an extension covering Chrome, Edge, Firefox and Safari, with an optional endpoint agent when coverage needs to reach desktop AI applications and AI enabled IDEs.

State that boundary precisely when you take it internally, because an architect will test it. Browser coverage is agentless and installs through your existing device management, with no proxy and no traffic redirection. Desktop applications and IDEs are not agentless and do require the endpoint agent.

The detail that usually settles a privacy review is where classification happens. It runs inside the browser, and Akamai's position is that content, including personal information, stays there while only alerts reach the cloud console. That is architecture rather than an undertaking, which is a different order of assurance.

How does David and Goliath run this?

We run the fortnight of observation, then write the governance position with you rather than for you, because the sanction list has to be owned by the business and not by IT. The output is normally a much shorter policy than the first draft anyone writes.

If you have not started measuring, how to find out what AI tools your staff are actually using is the method. If the immediate worry is a specific behaviour, how to stop staff pasting customer data into ChatGPT deals with that directly, and what is shadow AI covers why a procurement audit will not find any of it.

Ready to move from reading to shipping?

Ten business days. Four modules. One agent live by the end.