The AI you did not choose arrived in an update
You approved a list of AI tools. It was right on the day it was written. The problem is that the ground does not stand still — and most of what changes never passes through a decision of yours.
Over the past few weeks, some of the systems your company already pays for gained artificial intelligence features. In an update. With no warning, or with a warning nobody read.
The tool nobody chose
This is the part almost no policy anticipates, and the house material settles it in one line:
This also applies to AI built into a system the company has already contracted: an AI feature that appears in an update is a new tool, and goes through the same path before being left switched on.
Notice what that corrects. The person using that system chose nothing, installed nothing and did nothing wrong: a new button appeared and they used it, because it was there to be used. Except the data going through it now goes somewhere nobody assessed.
For whoever wrote the rule, the effect is worse: the list still looks current. Nobody added anything to it — what actually happened is that things were added around it.
Ask, do not decide
The principle holding up the rest is short: whoever wants to use a tool that is not on the list asks, they do not decide.
That applies to the person who wants to try a new assistant, and equally to the update that arrived on its own. The difference between a company that knows what it uses and one that does not is not strictness: it is having a short path for asking.
Because the alternative to a short path is not people not using it. It is people using it without asking.
The five questions
Assessing a tool does not require a technical report. There are five questions, and anyone who can read a contract can answer them:
- Does the plan we pay for train on what we send it?
- Can it be used in a corporate account, with an administrator?
- Can we cut off the access of somebody who leaves the company, the same day?
- Where is the data stored, and for how long?
- Is there a usage log available?
The first eliminates more candidates than the other four
The first one deserves isolating, because it often decides on its own.
Plenty of good tools offer a free or personal plan in which what you send goes into training the model. That is not malice and it is not fine print: it is the price, and it is written down. The paid plan usually does not do it.
What changes everything is that this is a question about a contract, not about technology. Nobody needs to understand AI to answer it — they need to open the terms of the plan the company signed and look. And if the answer is yes, the tool is rejected for any data that is not public, however good it may be.
And a deadline, or the answer becomes "no" by exhaustion
The part that makes the path actually get used is missing: the decision comes within a few working days, and it is recorded — approved, approved for certain profiles only, or rejected with the reason written down.
The deadline is not bureaucracy; it is what stops "asking" from turning into "waiting forever". A request with no deadline is a slow no, and whoever gets a slow no twice stops asking on the third — they go back to solving it around you, which is exactly what the list existed to prevent.
And the written reason serves the next time: a tool rejected in March may be approvable in September, if what rejected it has changed.
The test
Think about the systems your company already uses every day, and answer:
Did any of them gain an AI feature in the last six months — and did somebody decide it could stay switched on?
If the first half is yes and the second is no, you have an AI tool in use that was never approved. And it did not sneak in: it came through the front door, in an update.