Skip to main content



Everyday AI governance problems and solutions

Managing AI for daily use to prevent stalled adoption, tool sprawl, unsanctioned use, rogue agents, and everything in between

A young woman stands indoors holding a handheld microphone while speaking. She wears a sleeveless white top and layered necklaces, with her hair tied back. The background is softly lit with neutral tones, suggesting a presentation or event setting. Her expressive posture and slight smile convey an engaging, confident mood.
Diane Ortiz-MacLeod
Consultant,
Slalom
Published:
7 minute read

TL;DR

  • Many organizations struggle with either underused approved AI tools or unapproved AI use, limiting business value.
  • Effective AI governance is built into everyday workflows, not treated as a standalone compliance exercise.
  • Clear ownership, risk-based guardrails, and ongoing visibility help organizations scale AI safely and confidently.
  • The organizations seeing the greatest value from AI are those that balance innovation with accountability.

AI governance isn’t slowing innovation—it’s enabling it

Most enterprises rolling out AI company-wide end up with two very different problems:

  1. Underutilized adoption for some employees
  2. Unauthorized, untracked agents for others

Both problems trace back to the same root cause: Governance that’s built for policy documents sitting outside of daily workflows.

Translating licenses into value requires knowing what is running in your environment, putting controls at the point where tools get shared or connected to data, and ensuring every operation beyond its original builder has a named owner behind it.

The AI underutilization problem

Let’s start from the moment AI licenses get purchased.

Leading up to the launch, there’s excitement around it. The enterprise embraces company-wide access to bleeding-edge features in Copilot, ChatGPT, Claude, Gemini, or an equivalent platform. Pilots of small teams run testing for months, and finally, the organization green-lights thousands of licenses.

After going live, usage climbs for a few weeks, then plateaus. Meanwhile, leadership eagerly starts asking for return metrics too soon, before supporting teams to get the most use out of tools.

This stall is well-documented:

  • Only 39% of technology leaders are confident their organization's current AI investments will have a positive impact on financial performance, according to Gartner.
  • Slalom’s 2026 AI Research Report captures the execution gap: Executive confidence in AI strategy has climbed 30% year-over-year (YoY), yet only 38% of respondents believe the pace of innovation delivery keeps up with AI advancement.
  • An MIT study found that only 5% of AI initiatives have achieved meaningful ROI so far, with 95% stalling before yielding results.

Investment sits idle, and the teams that could be moving faster are not. While some stall due to lack of direction, others move forward anyway.

The AI blind spot problem

The counterpart to underutilized adoption is untracked and unauthorized adoption: Tool sprawl, unsanctioned use, agents gone rogue.

Sometimes the issue is in plain sight. But it may also go undetected until something goes wrong—like a sensitive data exposure, a compliance question, or an audit finding that surfaces the issue.

What is AI tool sprawl, and why is it a problem?

Tool sprawl refers to the sheer number of AI tools, assistants, and custom builds that exist across an organization without central awareness. People are building, which is great. But there is no oversight into what’s been built, by whom, or what’s being connected. It’s an accumulation problem that goes undocumented and easily compounds over very little time.

Problem: Volume & visibility

AI tools accumulate without central awareness of what exists.

Example

17 different custom GPTs built, some of which do roughtly the same job; only 3 of 17 GPTs are documented.

Blindspot

No inventory means no ability to audit, govern, or decommission when the original owner leaves the team.

What is unsanctioned AI use, and why is it a problem?

Unsanctioned AI use refers to employees using AI tools, often personal or consumer-grade, that have not been approved by the organization. In 2025, research showed 69% of organizations suspect or have evidence employees are using prohibited AI tools. People are trying to do their jobs faster and better and reach for the tools available to them. The problem is that shadow AI usage routinely exceeds what IT or governance teams can see, hiding risks from plain sight.

Problem: Policy & behavior

Employees use personal or unapproved tools in a work context without IT or security visibility.

Example

A manger summarizes confidentail board materials in a free AI tool because it works better than the approved one.

Blindspot

Confidential data leaves the org with no log, no audit trail, and no record of what was shard or when.

What are rogue AI agents, and why are they a problem?

Agents gone rogue refers specifically to AI systems that can take actions, and do, without governance or permission. An AI agent that sends emails, updates records, closes tickets, or triggers workflows can cause real downstream harm if something goes wrong before anyone notices. The risks compound when agents execute without human review at critical steps. They compound even more when those agents deploy into production and scale without formal oversight.

Problem: Autonomy & control

AI systems that act across tools and systems without enough human review during execution.

Example

An agent connected to both email and a project management tool starts assigning tasks and sending deadline reminders based on misread signals.

Blindspot

The agent has been taking action for months. There is no owner, no review, and no way to trace what decisions it made or on whose behalf.

Agent-related security incidents are one of the leading enterprise AI risk categories, specifically because agents operate faster than point-in-time policy reviews can respond. Instead of restricting agent use, enterprises can enable it by building lightweight controls into the workflow itself, so that governance travels with the agent.

Bake AI governance into everyday processes to fix underutilization and blind spot problems

These blindspots represent missed opportunities. People are building, but the value is not translated and risk is not managed. The problems point to the same need, though: AI office maturity paired with practical enablement.

AI office maturity + practical AI enablement are the approach that stops investment from sitting idle and gives teams the clarity and resources to adopt AI safely.

AI Office + AI Enablement

So, how do leaders move past employees asking, “How do I proceed?” without the risks of either stalling or resorting to unauthorized tools when your organization’s answer isn’t clear?

Slalom’s approach to everyday AI governance in practice

The organizations building AI-literate, high-velocity teams are embedding controls at the point where decisions happen, allowing teams to move with confidence.

Here’s the advice our experts start with:

1. Run inventory first.

Start by pulling data from your environment.

  • What OAuth tokens have been granted to third-party AI applications?
  • What agents are running with active permissions in your cloud environment?
  • What custom GPTs exist in your Microsoft tenant right now, and who owns them?

Most IT and security teams find significantly more deployed than leadership expects when they look at source-of-truth logs. A dedicated cross-functional team can complete this in roughly a week with the right tooling.

This builds a map of where your organization is currently innovating, which is a useful signal for translating investments into returns.

2. Segment by risk, not category.

A tool that drafts internal communications and requires human approval before sending carries a different risk profile than an agent with write access to a production system.

Map everything on two axes:

  1. Data sensitivity (what information it can access)
  2. Autonomy level (what actions it can take without review)

Tools in the high-autonomy, high-sensitivity quadrant need human-in-the-loop review before the next action executes. Tools in the low-autonomy, low-sensitivity quadrant need a named owner and basic documentation. The middle requires defined thresholds for when escalation kicks in.

3. Build the gate at publish.

In this context, publish is the exact point where someone tries to share, deploy, or connect a tool or agent to production data or systems. When this happens, the control needs to live in the workflow itself.

  • In Microsoft’s ecosystem, Copilot Studio shares controls and sensitivity labels applied before a tool can be distributed.
  • On OpenAI’s enterprise tier, custom GPT sharing restrictions and data connection governance are configured at the tenant level and reflected in each third-party connector.

At Slalom, one of our customers (a professional services firm) found more than 130 distinct risks in a single deployment review, highlighting the need for formalized publishing criteria.

4. Treat agent permissions like production access.

An agent that can write to a CRM, send email, or modify a record should require the same access review as a developer getting write access to a production database. Least-privilege principles apply. If an agent only needs to read pipeline data to generate a summary, it should not hold credentials that allow it to update deals.

Most agent builders default to requesting broader permissions than the task requires. Reviewing and narrowing those permissions down is not a governance burden, it is operational hygiene.

5. Put a named owner on everything.

Every active agent, every shared assistant, every automated workflow needs a specific human who is accountable for its behaviour, its data connections, and its continued operation. When the person who built it moves to another role, ownership transfers explicitly or the tool gets decommissioned. This sounds obvious and is rarely enforced consistently, which is why so many agent-related incidents trace back to tools that outlived the person responsible for them.

Final takeaways

The organizations seeing real returns from AI are the ones where employees:

  • Know what they’re allowed to build and use
  • Have a fast, clear path to move from experiment to production
  • Work inside a system that catches problems before they scale

When governance is built into the tools and workflows people already use, especially at the point of publish and based on clear risk tiers, AI pilots and transformation programs stop being a stalled investment or a hidden liability. AI becomes part of normal operations: it’s understandable, auditable, and adjustable, allowing your teams to adapt.

If your organization is dealing with stalled adoption or agents operating without clear oversight, Slalom can help you build everyday AI governance so teams can keep building with innovation while you keep visibility, accountability, and safety firmly in place.


SET AI IN MOTION

Move AI from experimentation into everyday operations.

 

  • Adaptable foundations
  • Human–AI workflows
  • Measurable outcomes

 

Trusted by organizations delivering:

 

  • $8B+ in customer value
  • 3x average ROI