AI Governance Should Accelerate Innovation, Not Slow It
CIOREVIEW >> Software Testing >> NEWS

Resident

Jeff List, Director of Information Technology

AI Governance Should Accelerate Innovation, Not Slow It

Jeff List, Director of Information Technology
Jeff List, Director of Information Technology, Resident

Jeff List

Adaptive Governance Champion

AI Changed the Governance Playbook

Over the past year, one thing has become pretty clear to me: the hard part of AI isn't getting people to use it - it’s figuring out how to embrace that reality without losing visibility, governance or trust along the way. Like many others, I started by looking at AI the same way we evaluate any new tech. Review the vendor, check the security posture, negotiate the contract, set up SSO and roll it out. Those things still matter, but AI changed the equation. Its not just another SaaS platform people log into once a week, it's becoming part of how they write, analyze, research, automate, make decisions, etc.

That's why I think the old model of simply approving or denying tools doesn't work anymore.

Replacing Gatekeeping with a Repeatable Process

Every week there's another AI platform someone wants to try because it saves them hours of work. One person wants to connect it to Google Drive. Another wants it integrated with Slack. Someone else has already found a way to automate a process that used to take half a day. Before long, IT is juggling dozens of requests, all with different levels of risk and business value and getting overwhelmed with the lift.

The easy response is to say no until everything has been fully vetted. The problem is that people don't stop looking for better ways to work just because IT hasn't approved a tool yet. Shadow IT didn't disappear; it evolved into Shadow AI and it's moving much faster. I didnt want IT to become the department that slows innovation down. I believe IT's job is to make it possible for people to innovate safely and do their best work. That means having a process that's consistent and quick enough that employees want to come through the front door instead of going solo.

  IT's job is to make it possible for people to innovate safely and do their best work.  

One approach I've found effective is creating a repeatable framework. My approach is to evaluate every AI tool using the same set of questions: "What data can it access? Does it support enterprise authentication? Can we manage users through our IDP? Does it only read data or can it write back to business systems? Are there audit logs?" Once those questions become standard, the conversation shifts away from opinions and toward measurable criteria. Teams understand why some tools move quickly while others require more review and it's our job as IT leaders to provide a consistent way to make decisions.

Creating Space for Responsible AI Innovation

Something I noticed along the way - the best AI ideas come from curious people who are simply trying to solve a problem in their own way. One person's small automation can end up saving far more time than anyone expected. Creating easy ways and places for those ideas to be shared is something I think every org should prioritize. Having a community where people can demonstrate what they've built, talk about what worked, what didn't and help others avoid reinventing the wheel is a huge advantage!

Looking ahead, the companies that adapt the fastest will have a better process for evaluating new technologies, governing them responsibly and helping employees adopt them. To me, that's where IT can and should provide value: not by acting as the "gatekeeper", but by building an environment where people can confidently experiment, knowing the right guardrails are in place. This is the sweet spot when governance becomes an enabler instead of an obstacle.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.