Fair & Square Artificial Intelligence

Fair & Square Artificial Intelligence Get your AI-first business ready through AI Literacy and Governance Programs

The biggest AI governance mistake right now is not getting it wrong.  It is waiting too long to begin.Governance doesn't...
04/04/2026

The biggest AI governance mistake right now is not getting it wrong. It is waiting too long to begin.

Governance doesn't start when the framework is complete, the policy is polished, and every stakeholder has signed off.

By that point, AI is usually already in the business.

And when that happens, this is what “we’re still working on governance” often means in practice:
❌ teams are already using AI tools
❌ vendors already have AI embedded in services
❌ data is moving before controls are clear
❌ accountability is assumed rather than assigned
❌ leadership thinks oversight exists because a working group exists

That is not governance.

The organizations making progress are doing something much simpler:
they start before it feels perfect and they accept ambiguity because the delay is more costly.

This is usually done with:
✅ one intake path for AI use cases
✅ one basic inventory of what is already in use
✅ one simple way to separate low-risk from high-risk use
✅ one named owner for every decision
✅ one record of what was approved, rejected, or approved with conditions

Not elegant and more importantly, not final.

But real.

And that matters, because AI governance does not become effective when the policy is published.

It becomes effective when the organization can consistently answer the following questions:

▪ what are we using?
▪ who owns it?
▪ what data is involved?
▪ what level of review is needed?
▪ what happens if something goes wrong?

That is the shift.

From designing the perfect model to putting enough control in place now.

Because if AI is already being used, then delaying governance is not a neutral decision.

It is a very risky one.

Question for leaders: What is one practical AI governance control your organization could implement in the next 30 days?

03/19/2026

Back in the days of SOX, assessing a company's Control Environment was a key feature of assessing the quality of controls. AI introduces additional excitement into the mix.

So, AI risk management is crucial to a modern control environment because AI systems can go off the rails in unique ways—through bias, data leaks, model drift, or unclear “black box” decisions that old-school controls just don’t catch. By spotting these AI‑specific risks early, companies can add smart controls like data governance rules, human‑in‑the‑loop approvals, and constant model monitoring using frameworks such as the National Institute of Standards and Technology Risk Management Framework (NIST’s AI RMF).

When AI risk management is baked into everyday controls, it turns governance from a box‑ticking exercise into a real‑time safety net for AI experiments. Internal audit and risk teams can stress‑test models, challenge weird outputs, and hold vendors accountable, letting the business move fast with AI while staying fair, compliant, and trustworthy with customers and regulators.

Given how AI tools are everywhere these days, managing risks and instituting good governance (like AI Acceptable Use policies) is a key task that every company needs to take seriously.

Getting an AI Risk Assessment done will identify where the gaps are in the overall Control Environment, which tools are in use and by whom, and can quantify the potential costs of a breach.

DM for a sample AI Acceptable Use Policy.

03/16/2026

AI Governance is far more important than you might think. Just take the example of Shadow AI.

The reality is that somewhere inside your company right now, someone is pasting sensitive information into a public AI tool. I love a go-getter as much as the next leader but this creates a lot of exposure in the absence of quality governance.

The numbers should make every executive sit up a little straighter:

❌ 20% of data breaches now involve shadow AI
❌ Those breaches cost about $4.6M and almost $700K more than the average incident​
❌ 63% of organizations hit by AI-related breaches had no AI governance policy.​
❌ Only 17% of companies can technically stop employees from pasting confidential data into public AI tools​

On the last point, the implication is that 83% of businesses are defending the business with policy memos, annual training, and pure optimism.

That is not a cybersecurity strategy. That is a trust fall.

Here is the part many leaders miss:

Shadow AI is not a people problem. It is a path-of-least-resistance problem.

If the approved route to use AI takes ① 3 meetings, ② 2 approvals, ③ 1 risk committee and an endless series of reports and coversheets, the unapproved route (30 seconds to log-in to Claude) can seem pretty appealing.

So what can we as leaders do about it?

A quick way to test if you really have a Governance gap here is to ask yourself the following question:

If an employee pasted confidential company or customer data into a public large language model today, what would happen next?

🔹 Would anyone know? 🔹 Would anything trigger? 🔹 Would someone own the response?

Or would the organization discover it three quarters later in a post-incident review?

The good news is that this governance gap can be filled with a few practical moves:

✅Put together a comprehensive AI inventory (all the AI tools already in use, not just the ones on the approved list)
✅Create a short AI Acceptable Use Policy leaders can actually approve and employees can actually understand​
✅Make the governed path (almost) as fast as the rogue path

And perhaps most importantly, tie the conversation to money, exposure, and accountability. Governance may take a few minutes to explain clearly but “avoidable breach cost” gets attention every time.​

Over to you. What Shadow AI behavior are you most worried about right now?

◼Client data being pasted into public AI tools
◼A cart before the horse problem - AI strategy conversations happening before basic controls exist
◼No one knowing who owns AI governance

Looking forward to hearing your perspectives in the comments.

Address

Banff, AB

Website

Alerts

Be the first to know and let us send you an email when Fair & Square Artificial Intelligence posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share