INTELIGÊNCIA ANALÓGICABlogSign in
PHASE 01 · ARTIFICIAL INTELLIGENCE

What makes it worse is not the mistake. It is hiding it.

There is a one-line clause that decides whether your AI policy will work, and almost no policy has it: what happens when somebody has already pasted what they should not have.

Every written rule covers the before — what is allowed, what is not, which tool. The after is almost never written down, and that is exactly where it gets decided.

The moment nobody planned for

Somebody pasted a chunk of a contract into a personal tool. They realised half an hour later, on their own, with nobody having noticed.

Now that person does a quick calculation: if I say something, what happens to me?

If the answer is "no idea" or "probably a telling-off", their rational decision is to stay quiet. Nobody saw. Maybe nothing comes of it. And the company has just lost the only window in which something could still be done.

The sentence that changes the calculation

The house material settles this with a direct instruction in the policy:

If you pasted something you should not have, say so immediately. Telling us early makes it possible to contain the problem — change a key, inform whoever needs to know, fix what can be fixed — and it is treated as what it is: somebody protecting the company.

And the principle underneath it, which is the whole essay in one line:

What makes it worse is not the mistake; it is hiding it.

It is not kindness. It is the containment window

It is worth being clear about the reason, because "we won't punish you" sounds soft, and that is not what this is.

Data that has left has a short period in which action is still possible: rotate the leaked credential, tell the client before they find out on their own, revoke an access, adjust a contract. Once that window closes, all that remains is documenting the damage.

The clause does not exist to forgive anybody. It exists so the company finds out inside the window. It is a risk-management decision, and the cheapest one there is: it costs one written sentence.

The tone settles this in advance

And there is an earlier part, which determines whether anybody will speak up months after the policy exists. It is the tone in which it was announced:

If the announcement sounds like "we are watching you", the team hides its use of AI (…). If it sounds like "we want you to use it, safely", the team adopts it with you.

The same set of rules produces both opposite outcomes, depending only on the opening sentence. A policy that arrives as a threat is read as a threat, and the answer to a threat is never transparency.

This is not permissiveness

The other side is worth saying, because a clause with no limit is worth nothing:

Making a mistake and reporting it is one thing. Deliberately going against the agreed rule, or staying silent about a leak you know happened, is another — and those still carry consequences, proportionate to what was done.

The distinction the policy needs to make explicit is not between a serious mistake and a minor one. It is between whoever got it wrong and said so and whoever got it wrong and hid it. Without that written down, the two look alike, and the team assumes the worse one.

And there has to be a name

The practical part is missing, and it is the one most often left out: tell whom?

It is a person with a name, not a department — governance without an owner does not happen.

"Tell IT" is not a recipient. "Tell Ana" is. The difference between those two sentences is the difference between a rule somebody can follow at eleven at night and one that first requires working out who to talk to — and working out who to talk to is exactly the friction that makes people give up.

The test

Ask the question your team has already asked itself in silence:

If somebody there pasted client data into a personal tool today and realised a minute later, would that person know who to tell — and what would happen to them?

If you are not sure about the second half, neither are they. And that is why you do not find out.