Most enterprise AI governance is built to answer one question: what may an agent connect to? It is a reasonable question, and most organizations have already answered it conservatively. Very few are going to let an agent write to the CRM, and they are right not to.

The larger exposure in 2026 sits outside that question. It is an employee entering sensitive information by hand into a tool the company never bought, because the tool is doing something that matters and the sanctioned alternative does it worse. There is no integration to govern, no invoice to find, and no consent grant to audit.

I have watched that gap open from the inside.

As AI models have become more powerful, employees are putting new AI research tools in front of a field sales team everywhere. The company asked for it. The results are real: account briefs that took an afternoon came back in twenty minutes, and competitor teardowns went from "if I have time" to "of course."

IT doesn’t see it. The tools didn’t go around or outside a process; a process was never encountered. This was a sanctioned activity run by an employee doing what they were asked.

Nothing was hidden and nobody was careless. The deployment simply never intersected with IT.

The data question sits a layer below that, and it is not a tooling question at all. An employee is asked for a brief on an account. They have a new tool that produces one in twenty minutes instead of an afternoon. So they put the account into the new tool.

That is the entire mechanism. No integration, no purchase order, no bad intent. Multiply it by the number of people in your company who are under time pressure and have found something that helps.

An inventory exercise will not reach any of this. A review board governs what arrives at it, and none of this arrives, because nobody involved realizes they have anything to declare.

When something does go wrong, the call comes to you. Not because anyone decided it should, but because the org chart has nowhere else to send it. A CIO put it to me plainly: IT gets blamed even when it was an agent someone in the business built.

Four seats are now looking at this and reaching for fixes that undercut each other.

Consolidation is IT’s fix. It also removes the workarounds Operations has been using to hit its numbers.

Finance caps consumption, because the bill is the only part of this program written in a unit the business already reads. The week that cap lands, Finance becomes the department slowing AI down.

Operations pushes adoption harder, which enlarges the surface you were trying to reduce.

The board asks for a chat window for everyone. A CIO described that to me as giving people another place to do the work they were already doing, now with a mandate to do it better.

None of the four is wrong. They are four correct answers to four different questions, and nobody has been assigned to decide which question the company is asking.

The instrument that reaches the real exposure is a conversation, which is unsatisfying and also true. Nothing on your network is going to produce this number for you.

What I would ask a team outside IT, close to verbatim: "Tell me what you're already using that helps, and what you have to put into it to make it work."

The second half is the one that matters. The first gives you a tool name. The second gives you the data leaving the building.

The hedge sounds like a status update. "We're standardizing on the approved stack." That is a description of policy. You asked about behavior.

The input you need is not a list of approved tools. It is a written statement of what may be typed into an unmanaged system, and the name of one person who can grant approval without convening a group. Committees review. They rarely decide. The organizations moving fastest on AI mostly wrote that down years before AI made it urgent, which is why their speed looks like AI readiness and is actually governance maturity.

Here’s the secret to wining organizations: every control I have seen work here made the sanctioned path better than the unsanctioned one rather than blocking it.

This week: ask one team outside IT what they are using and what they put into it. The second answer is your risk register.

— Isaac

Reply

Avatar

or to participate

Keep Reading