Buying the tool is not having governance
Let me start by admitting what is usually hidden: you can build the technical part yourself. It is simple code, and free alternatives exist. If the problem were the tool, there would be no problem at all.
A company notices its team is using AI without criteria. The almost automatic reaction is to look for a solution: something that blocks, filters, monitors. A licence that solves it.
And one exists. Technically, the control is a middleman between whoever asks and the model that answers — well-known code, with open and free options. Anyone with a technical person on hand builds it quickly.
What happens next is that it sits there, running and empty.
The tool answers one question
How to do it. That is what it is for, and it does that well.
The other three it does not answer:
- what may be done with AI here;
- who may do it, and with which kind of information;
- who answers if it goes wrong.
No licence comes with those answers inside — because they are not about software. They are about your operation: which information your company treats as confidential, what your customer contracts require, what is routine and what needs a second opinion.
A technical control without those decisions is a doorman with no guest list. It stands there, alert, and lets everything through — or blocks everything, which amounts to the same in terms of usefulness.
Where the real work is
It comes before the tool, and it is not technical.
Naming what is confidential. It sounds obvious until someone tries to write it down. Is the price on a proposal confidential? A signed contract? The commissions spreadsheet? Personal data is regulated by law — but which data, and in what situation?
Deciding what is allowed. Not in the abstract: for the sales team, for support, for whoever writes code. The answers differ, and writing them down is what turns "be careful with AI" into something a person can actually follow on a Tuesday.
Naming who answers. Every decision that matters keeps a human owner. If nobody knows who that is, the decision has no owner — it has a log.
Once that is done, the tool starts to be worth something. Before it, the tool is an expense with a feeling of safety attached.
Why the reverse order is so common
Because buying is fast and deciding is slow.
A licence is signed in an afternoon and produces the immediate sense that the matter has been handled. Writing down what is confidential in your company means gathering people, disagreeing and closing — and it produces no pretty screen at the end.
But the order matters. A tool bought first sits waiting for decisions nobody made, and the problem that prompted the purchase stays exactly where it was.
The test
If your company switched AI tools today — one supplier for another — what would survive of the way you use it?
If the answer is "nothing, we would start over", what existed was configuration, not governance. And configuration is the part you rebuild in a day.
What survives a change of tool is what was worth building.