We’ve moved from ‘Wow’ to ‘How do we control this?’: What happens when AI adoption moves faster than AI governance?

We've Moved From 'Wow' to 'How Do We Control This?'

What happens when AI adoption moves faster than AI governance?

It’s amazing how fast the AI conversation has changed. Not long ago, almost every conversation opened with the same reaction. Wow. Look what it can do. Look how well it writes, how fast it summarises content. Look at the code it produced, the image, the answer. People were swapping prompts. Leadership teams were being shown demos. Everyone was scrambling to work out whether they needed ChatGPT, Copilot or something of their own. It felt like we’d been handed a glimpse of the future.

Now I’m hearing a very different question: how do we control this?

That shift tells you almost everything about where enterprise AI is heading. The problem is no longer getting people interested. They are interested. They are already using it. The problem is that in many organisations, AI adoption has moved faster than the organisation’s ability to understand, govern and secure what’s actually happening.

AI Didn't Wait for Your Strategy

I think some businesses assumed that AI would arrive the way every other big technology change did. Choose a product, do the security review, agree the business case, run a pilot, train people, roll it out. Nice and controlled. That is not what happened. Employees got there first. They opened ChatGPT, they tried Claude -they found tools that would write the presentation, analyse the document, make the images, take the notes, write the code and summarise the meeting. Some used personal accounts. Some used free tools. Some quietly pasted company information into systems nobody in IT had ever laid eyes on.

Then it got harder. AI started turning up inside the software businesses already owned. It wasn’t a separate tool you could approve or block any more. It was appearing inside browsers, productivity software, security products, the CRM, the meeting platform, applications people had used for years without thinking twice. That changes the whole governance problem. For a while we thought we could govern AI by choosing which AI tools people were allowed to use. That isn’t enough anymore. The business might be using AI before the business even realises it’s using AI.

A Policy Isn't The Same as Control

Most organisations I talk to now have some kind of AI policy, or they’re writing one. Good. But we need to stop confusing having a policy with having control.

Effective AI governance requires more than documented rules. It requires visibility into which tools are being used, what data they can access, who is using them and what actions AI systems are allowed to take.

You can tell people not to put confidential information into public AI tools, but can you actually see whether they’re doing it? You can publish a list of approved applications, but do you know which ones people are using that aren’t on it? You can tell everyone to check AI-generated answers and hope they do, but you don’t really know. You can say agents need approval, while agents are quietly being built that nobody’s mentioned to you. That’s where governance gets real. A PDF on the intranet is useful. It isn’t visibility. And without visibility, a lot of what we call governance is really just hoping people behave the way the policy says they should. That might have held up when AI was used occasionally. It doesn’t once AI is part of everyday work.

There’s another problem. Make the rules too hard, and people just go around them. I’ve watched this happen with technology my whole career. People very rarely wake up wanting to break company policy; they just want to get their job done. If the approved route takes three weeks and the unapproved route takes three minutes, sooner or later someone takes the three minute route. AI makes that temptation much bigger, because the three minute route is now genuinely brilliant. So good governance can’t only be about stopping things. It has to make the safe route the easy route. Sounds obvious. It’s surprisingly hard to actually pull off.

AI Agents Change the Governance Problem

Just as organisations are starting to get their heads round generative AI, the ground has moved again. AI agents change the governance problem because they can move beyond generating an answer to taking actions across business systems.

A chatbot mostly waits for you to ask it something. An agent can be handed a goal and then work through several steps to get there. It can search, use applications, call other systems and take actions. That’s exciting. It should also make you stop and think.

The moment AI goes from giving an answer to taking an action, the amount of trust you’re handing over changes completely. Who gave the agent access, and what can it see? What’s it allowed to change, and which decisions can it make on its own? What happens when it misreads something, or someone deliberately manipulates it, or one agent starts talking to another? And the most basic question of the lot: when it goes wrong, who’s responsible?

We’ve spent years building identity, access and monitoring controls around human users. We decide what someone can access, monitor what they do, strip permissions when they change role and investigate unusual behaviour. Now picture hundreds, maybe eventually thousands, of digital identities doing work across the organisation. That’s where AI governance is heading, and most businesses are nowhere near that conversation yet. That’s not a dig. The technology has moved incredibly fast. But pretending we’ve got more control than we really have isn’t going to help anyone.

Governance Can't Become the Department of No

There’s a flip side, because I really don’t want governance to become the thing that quietly kills every good AI idea. That’s just as bad. If every experiment needs 6 meetings, 3 committees and a 12 week approval, people stop bringing ideas forward. Or worse, they continue experimenting and simply stop telling you. I’ve experienced this first-hand.

Governance must protect the business without scaring everyone off the technology. People need to know what they can do, not only what they can’t. Give them safe tools and clear boundaries. Be straight about what information can and can’t be used. Give them somewhere to take an idea that isn’t a committee it vanishes into for a month. Make it easy to ask a daft question. And whatever you do, don’t punish curiosity or enthusiasm. You want people telling you what they’re experimenting with. The moment they’re frightened to admit they’re using AI, you’ve lost sight of it. And once you’ve lost sight of it, that lovely governance framework is governing the version of the organisation you imagine exists, not the one that actually does. Which is a dangerous place to be sitting while you feel completely in control.

Good AI Governance Should Help You Move Faster, Not Slower

So, we’ve gone from wow, to how, to control. First, we were amazed by what AI could do. Then we started asking how we’d use it. Now we have to work out how we use it without losing sight of our data, our people, our risks and, increasingly, the actions these systems are allowed to take on our behalf.

This is where a lot of our focus at MTI is going, and it isn’t into stopping AI. It’s about helping organisations actually see it: what’s already happening, where the data’s going, which use cases are worth pursuing, what controls they need, and how the models and agents starting to appear across the business are secured.

Then letting people get on and do something useful.

Because I don’t think the answer to uncontrolled AI is less AI. The answer is better control. Not the kind that slows everything to a crawl, but the kind that gives people enough confidence to move faster.

The organisations that get this right won’t be the ones with the longest AI policy. They’ll be the ones that know what’s really happening inside their business and are confident enough to let good ideas grow without losing control of them.

Here’s a simple test for your own business. Ask your IT team to tell you, right now, every AI tool being used across the company this week. Not the approved list. The real one.

If they can’t, you don’t have a governance problem yet. You have a visibility problem. And no policy on the intranet fixes that.

We spent the first part of all this asking what AI could do.

The more honest question now is whether you even know what it’s already doing.

This is the fourth article in a series from MTI’s Chief AI Officer exploring what successful AI adoption really looks like, from governance and security to agents, data readiness and measuring business value.

Next in the series: Is AI Creating Security Blind Spots?

What AI Agents are Actually Doing and Why Boards Should Be Paying Attention

Continue the conversation

The questions raised in this article are ones we’re discussing with organisations every day. From AI readiness and governance to practical adoption and security, MTI helps organisations create the foundations needed to turn AI ambition into real business value.

Talk to our AI team.

About The Author
Abba Abbaszadi is Chief AI Officer at MTI Technology, helping organisations adopt AI securely, responsibly, and at scale. With more than 20 years’ experience across cybersecurity, cloud, IT leadership, and digital transformation, he advises business leaders on turning AI ambition into practical, enterprise-ready outcomes.
 
Previously CIO at international law firm Charles Russell Speechlys, Abba led global innovation programmes spanning automation, blockchain, and AI. Combining enterprise leadership with hands-on founder experience in AI ventures, he brings a practical perspective on the opportunities, risks, and realities of AI adoption in today’s security landscape.