Problem: Volume & visibility
AI tools accumulate without central awareness of what exists.
Most enterprises rolling out AI company-wide end up with two very different problems:
Both problems trace back to the same root cause: Governance that’s built for policy documents sitting outside of daily workflows.
Translating licenses into value requires knowing what is running in your environment, putting controls at the point where tools get shared or connected to data, and ensuring every operation beyond its original builder has a named owner behind it.
Let’s start from the moment AI licenses get purchased.
Leading up to the launch, there’s excitement around it. The enterprise embraces company-wide access to bleeding-edge features in Copilot, ChatGPT, Claude, Gemini, or an equivalent platform. Pilots of small teams run testing for months, and finally, the organization green-lights thousands of licenses.
After going live, usage climbs for a few weeks, then plateaus. Meanwhile, leadership eagerly starts asking for return metrics too soon, before supporting teams to get the most use out of tools.
This stall is well-documented:
Investment sits idle, and the teams that could be moving faster are not. While some stall due to lack of direction, others move forward anyway.
The counterpart to underutilized adoption is untracked and unauthorized adoption: Tool sprawl, unsanctioned use, agents gone rogue.
Sometimes the issue is in plain sight. But it may also go undetected until something goes wrong—like a sensitive data exposure, a compliance question, or an audit finding that surfaces the issue.
Tool sprawl refers to the sheer number of AI tools, assistants, and custom builds that exist across an organization without central awareness. People are building, which is great. But there is no oversight into what’s been built, by whom, or what’s being connected. It’s an accumulation problem that goes undocumented and easily compounds over very little time.
AI tools accumulate without central awareness of what exists.
17 different custom GPTs built, some of which do roughtly the same job; only 3 of 17 GPTs are documented.
No inventory means no ability to audit, govern, or decommission when the original owner leaves the team.
Unsanctioned AI use refers to employees using AI tools, often personal or consumer-grade, that have not been approved by the organization. In 2025, research showed 69% of organizations suspect or have evidence employees are using prohibited AI tools. People are trying to do their jobs faster and better and reach for the tools available to them. The problem is that shadow AI usage routinely exceeds what IT or governance teams can see, hiding risks from plain sight.
Employees use personal or unapproved tools in a work context without IT or security visibility.
A manger summarizes confidentail board materials in a free AI tool because it works better than the approved one.
Confidential data leaves the org with no log, no audit trail, and no record of what was shard or when.
Agents gone rogue refers specifically to AI systems that can take actions, and do, without governance or permission. An AI agent that sends emails, updates records, closes tickets, or triggers workflows can cause real downstream harm if something goes wrong before anyone notices. The risks compound when agents execute without human review at critical steps. They compound even more when those agents deploy into production and scale without formal oversight.
AI systems that act across tools and systems without enough human review during execution.
An agent connected to both email and a project management tool starts assigning tasks and sending deadline reminders based on misread signals.
The agent has been taking action for months. There is no owner, no review, and no way to trace what decisions it made or on whose behalf.
Agent-related security incidents are one of the leading enterprise AI risk categories, specifically because agents operate faster than point-in-time policy reviews can respond. Instead of restricting agent use, enterprises can enable it by building lightweight controls into the workflow itself, so that governance travels with the agent.
These blindspots represent missed opportunities. People are building, but the value is not translated and risk is not managed. The problems point to the same need, though: AI office maturity paired with practical enablement.
AI office maturity + practical AI enablement are the approach that stops investment from sitting idle and gives teams the clarity and resources to adopt AI safely.
So, how do leaders move past employees asking, “How do I proceed?” without the risks of either stalling or resorting to unauthorized tools when your organization’s answer isn’t clear?
The organizations building AI-literate, high-velocity teams are embedding controls at the point where decisions happen, allowing teams to move with confidence.
Here’s the advice our experts start with:
Start by pulling data from your environment.
Most IT and security teams find significantly more deployed than leadership expects when they look at source-of-truth logs. A dedicated cross-functional team can complete this in roughly a week with the right tooling.
This builds a map of where your organization is currently innovating, which is a useful signal for translating investments into returns.
A tool that drafts internal communications and requires human approval before sending carries a different risk profile than an agent with write access to a production system.
Map everything on two axes:
Tools in the high-autonomy, high-sensitivity quadrant need human-in-the-loop review before the next action executes. Tools in the low-autonomy, low-sensitivity quadrant need a named owner and basic documentation. The middle requires defined thresholds for when escalation kicks in.
In this context, publish is the exact point where someone tries to share, deploy, or connect a tool or agent to production data or systems. When this happens, the control needs to live in the workflow itself.
At Slalom, one of our customers (a professional services firm) found more than 130 distinct risks in a single deployment review, highlighting the need for formalized publishing criteria.
An agent that can write to a CRM, send email, or modify a record should require the same access review as a developer getting write access to a production database. Least-privilege principles apply. If an agent only needs to read pipeline data to generate a summary, it should not hold credentials that allow it to update deals.
Most agent builders default to requesting broader permissions than the task requires. Reviewing and narrowing those permissions down is not a governance burden, it is operational hygiene.
Every active agent, every shared assistant, every automated workflow needs a specific human who is accountable for its behaviour, its data connections, and its continued operation. When the person who built it moves to another role, ownership transfers explicitly or the tool gets decommissioned. This sounds obvious and is rarely enforced consistently, which is why so many agent-related incidents trace back to tools that outlived the person responsible for them.
The organizations seeing real returns from AI are the ones where employees:
When governance is built into the tools and workflows people already use, especially at the point of publish and based on clear risk tiers, AI pilots and transformation programs stop being a stalled investment or a hidden liability. AI becomes part of normal operations: it’s understandable, auditable, and adjustable, allowing your teams to adapt.
If your organization is dealing with stalled adoption or agents operating without clear oversight, Slalom can help you build everyday AI governance so teams can keep building with innovation while you keep visibility, accountability, and safety firmly in place.