AI Governance Starts With Visibility, Not Tools

By Jeff Reiter

Why AI Governance Must Start Before Platform Selection

Most organizations eventually get to the same question about AI:

Which platform should we use?

Microsoft Copilot? ChatGPT? Gemini? Claude? Something else?

It is a reasonable question.

It is also usually several questions too late.

Before leadership starts comparing platforms, AI may already be part of the organization’s daily work.

It might be a public AI tool someone started using because it made a task easier. It might be a personal subscription showing up on an expense report. Or it might be an AI capability added to software the organization has used for years.

None of those situations necessarily feels like an “AI implementation.”

That is exactly why the governance problem can start before leadership realizes there is one.

The Real First Mistake in AI Governance

The first mistake is often not choosing the wrong AI tool.

It is trying to govern an environment leadership has never actually inventoried.

That means the work starts before product selection and before policy.

You cannot govern what you cannot see.

AI Does Not Wait for a Formal Project

Government leaders are used to technology entering the organization through a recognizable process.

A need is identified.

Options are reviewed.

A purchase is approved.

IT implements it.

Staff are trained.

AI does not always arrive that way.

It can show up through a browser tab, a personal subscription, Microsoft 365, a transcription service, or a new feature inside software already in use.

That creates an uncomfortable possibility.

A police chief may believe the department has not adopted AI because nobody approved an AI project.

A city administrator may assume there is time to develop policy because no enterprise platform has been purchased.

Meanwhile, staff may already be using AI to draft, summarize, search, organize, or process work.

What AI Use Already Looks Like Inside Government Organizations

For police departments and government organizations, that work can involve records, personnel information, internal communications, investigative material, evidence-related details, resident information, or other sensitive data.

So I would not start the AI conversation with:

Are we ready to adopt AI?

I would start with:

Do we know where AI is already touching our work?

That question changes the conversation immediately.

Why Writing an AI Policy Too Early Backfires

AI policies matter.

But policy is not where I would start.

If leadership does not know which tools are being used, which accounts are being used, what information those tools can reach, or what AI capabilities vendors have already introduced, the policy is being written around assumptions.

It may describe the environment leadership wants.

It may not describe the environment staff are actually working in.

That is why the first useful step is visibility.

Six Visibility Questions to Ask Before Writing Any AI Policy

Which AI tools are actually being used?

Are employees using work accounts or personal accounts?

What AI subscriptions are already appearing on expense reports?

Which vendors have introduced AI features?

What organizational data can those tools reach?

Which uses were formally approved?

What usage or audit information exists?

For organizations using Microsoft 365 or Google Workspace, some of that investigation can begin with administrative and usage information already available in those environments. More detailed reporting may be appropriate when leadership needs deeper visibility.

The point is not the reporting tool.

Visibility is the first AI governance control.

Without it, leadership is not governing AI.

It is governing assumptions.

AI Is a Permissions and Data Governance Problem Before It Is a Productivity Decision

AI is easy to think of as a productivity decision.

Should we let people use it?

Which tool should we buy?

What will save staff the most time?

Those questions matter.

But they may not be the first questions.

For government leaders, AI can be an identity, permissions, vendor, records, data-handling, and accountability issue before it is a productivity issue.

How Excessive Permissions Amplify AI Risk

Consider something as ordinary as SharePoint access.

An employee may have accumulated access to sites, Teams, folders, or files over years of changing responsibilities.

Some of that access may still be appropriate.

Some of it may not.

That was already an access-control problem.

Now add AI that can help the employee find, summarize, connect, or work with information the account can already reach.

AI did not create the excessive access.

It changed what could be done with it.

That distinction matters.

AI often makes old governance weaknesses more consequential.

If permissions were already too broad, AI can make information easier to locate, combine, summarize, and use. That is why AI governance cannot be separated from permission reviews, least privilege, Microsoft 365 configuration, and data protection.

The important point here is not to solve the permissions problem inside the AI conversation. It is to recognize it before choosing the AI platform.

A more secure AI tool cannot compensate for access that was never properly governed.

And permissions are only one part of the inventory. Leadership also needs to look at something much easier to miss: AI capabilities arriving through vendors it already trusts.

AI Can Enter Through a Vendor You Already Trust

There is another way AI can enter the organization without feeling like a new technology decision.

Imagine a records platform your department has used for years adds an AI summarization feature.

It looks like a normal product update.

But the moment that feature begins working with organizational information, the questions change.

What information can it access?

Where does that information go?

How long is it retained?

Who reviewed the change?

Who decided the feature was appropriate for department use?

Those are questions that may never have been asked if everyone simply assumed:

We already use that vendor.

That is where an established vendor relationship can create a blind spot.

Why Approving a Vendor Once Is Not Enough

A system that was reviewed and approved three years ago may have capabilities today that did not exist when the original decision was made.

Approving a vendor once cannot mean approving every future use of your information automatically.

Someone needs to own the decision when a new capability materially changes how organizational data is accessed, processed, retained, or shared.

When that ownership is unclear, the technology decision is already sitting on top of a governance problem.

That is vendor governance.

And AI is making it much more important.

The Right Question When Evaluating AI Platforms for Government Use

There is a meaningful difference between using a public consumer AI tool and using an enterprise environment with administrative controls, defined data handling, centralized account management, and logging.

That does not mean free is automatically bad.

It does not mean paid is automatically safe.

It means leadership needs to understand what it is approving.

The better question is not:

Which AI is best?

It is:

Which AI environment fits the way we need to govern our information, users, records, and risk?

That changes the evaluation.

Now the conversation is not just about features.

It is about whether the organization can control access, understand how its information is handled, review usage, manage accounts, and explain why the platform was appropriate for the work being performed.

For a police chief, city administrator, or department leader, those are far more important questions than which platform writes the best summary.

AI Sprawl Can Hide in the Budget

Sometimes the first evidence of unmanaged AI is not an IT report.

It is an expense report.

One person is paying for one service.

Another department has something different.

Someone is using a personal account.

Another AI capability is already included in a vendor subscription.

None of those decisions may look significant by itself.

Together, they can create multiple tools, inconsistent data handling, separate accounts, duplicate spending, different levels of security, and no reliable picture of what the organization is actually using.

The obvious problem is cost.

The less obvious problem is control.

Tool Consolidation as a Governance Strategy

Tool consolidation can be both a cost decision and a governance decision.

Fewer approved environments can make it easier to manage access, apply consistent rules, review usage, train staff, and document how information is handled.

That does not mean every organization needs a single AI platform.

It means AI sprawl should not become the strategy simply because nobody noticed it happening.

Now the Policy Has Something Real to Govern

Once leadership understands the environment, an AI Acceptable Use Policy becomes much more useful.

Now the organization can make decisions based on what is actually happening.

Which tools are approved?

Which are restricted?

What information should never be entered into a public AI tool?

Who can approve a new use case?

Who reviews AI features introduced by vendors?

What should an employee do when they are unsure?

What happens if sensitive information is entered into the wrong system?

Who needs to know?

What an AI Acceptable Use Policy Must Clearly Define

For a police department, those answers need to make sense in the context of reports, records, personnel matters, evidence-related information, internal communications, and other sensitive work.

A policy that simply says:

“Do not enter sensitive information into AI.”

sounds reasonable.

But it leaves the hardest part to the employee:

What counts as sensitive in the situation I am dealing with right now?

The safe path needs to be clear enough that staff do not have to interpret the policy on the fly.

Good Governance Leaves Evidence

A policy is not useful because it exists in a folder.

It is useful because it is part of a governance process leadership can explain.

If an insurer, auditor, attorney, governing board, regulator, or member of command staff asks how the organization manages AI, there is a big difference between saying:

“We told everyone to be careful.”

and being able to show what leadership actually did.

Which tools were identified?

Which were approved?

What were staff told not to enter?

How is access controlled?

Who reviews new tools and vendor features?

Can usage be examined?

What happens when something goes wrong?

That is what I mean by defensible governance.

Not perfection.

Not a binder full of policies.

Evidence that leadership saw the risk, made decisions, put controls in place, and continues to manage them.

The Right Order for Building an AI Governance Process

AI governance does not need to begin as a massive technology initiative.

But it does need to happen in the right order.

See what you have.

Understand what it can access.

Decide what should be allowed.

Choose tools that support those decisions.

Write rules that reflect reality.

Keep watching what changes.

That last part matters.

AI will keep changing.

Vendors will add features.

Staff will find new uses.

Permissions will change.

New tools will appear.

A policy written once cannot keep up with that environment by itself.

A governance process can.

Six Questions Every Government Leader Should Ask About AI Governance

If you are not sure where to begin, start with six questions:

Do you know which AI tools your staff are actually using?

Do you have clear rules for what is approved, restricted, or prohibited?

Do you review new AI tools and vendor features before they are used?

Do you understand the security and data-handling differences between the AI products being used?

Would you know what to do if AI use exposed sensitive information?

Can you show what leadership has done to manage the risk?

We built the MSPCE handout around questions like these.

But the questions matter more than the handout.

They are meant to expose the places where an assumption is standing in for a control.

Because the most important AI governance question may not be:

What AI should we buy?

It may be:

Can we explain how AI is already being used today?

If the answer is no, that is where I would start.

AI Governance Requires Visibility, Not Just Policy

AI does not become governable because leadership writes a policy.

It becomes governable when leadership can see the tools, understand the access, explain the decisions, and show the controls.

That is why I would not begin with product demonstrations.

I would not begin with a blanket ban.

And I would not begin with a policy written around assumptions.

I would begin by finding out what is actually happening.

Because until leadership can do that, the organization is not really governing AI.

It is governing what it hopes is happening.

Discussing Practical AI Governance at MSPCE

At MSPCE, I’ll be discussing these issues with police chiefs, public-safety leaders, city administrators, security professionals, and IT leaders at the Midwest Security & Police Conference & Expo.

We’ll talk about practical AI governance: understanding current use, auditing the environment, evaluating appropriate tools, establishing acceptable-use standards, and building a process leadership can explain and defend.

RWK will also have our 6 Questions handout available at the conference as a practical place to begin.