The AI Got More Powerful. Your Controls Need to Catch Up.#

Most companies have a rule about what gets installed on a work computer. AI may not trip it. There is nothing to install. Someone opens a browser, logs in, and hands over the job they're tired of doing by hand.
To me, that is the governance problem.
OpenAI's GPT-6 Astra, SpaceXAI's Grok Bot, Anthropic's Claude, and Meta's Muse point at the same shift: AI is moving from answering questions to acting inside software.
These systems can use a computer: open an app, read the screen, fill the form, click the button. OpenAI's own system card for Astra, the safety report it publishes with each model, puts it in the company's top cybersecurity tier once the model has the right tools and access. SpaceXAI's Grok Bot materials describe persistent bots that hold open sessions in your tools, repeat a routine you walk them through once, and keep working after you close your laptop.
These are great tools. That is the point.
A tool that can act inside software is a new worker in the business, and the business has to decide what that worker is allowed to touch, who it acts as, what gets logged, and where it has to stop.
The vendors already built the switches#
The problem is that the tools are good enough to matter.
The labs say the same thing from their side. Every one I've checked ships switches for what an agent can open, which account it runs under, and what needs a human yes. Most ship something for what gets written down, and that's the one where the detail varies most.
They built those switches because somebody has to decide where the line is, and it was never going to be them. It's going to be you.
That is a reason to stop treating AI use as a browser tab.
If a person in your company uses an agent to reconcile books, draft invoices, update a CRM, file a form, research a customer, send a message, or pull data from email, the governance question is operational.
The old policy, if you have one, was written for copy and paste#
Most small-company AI policies, if they exist, were written for the chatbot era.
They say some version of this: do not paste customer data into an AI tool.
That rule is still useful. It's also incomplete.
When an AI tool can look at the screen and act in the application, the risk moves past pasted text. It is access. It is identity. It is the approval line. It is whether the business can reconstruct what happened after the fact.
Your insurer, your bank, and sooner or later your biggest customer all ask the same thing in different words: can you prove the system is controlled?
Shadow AI showed up in 43% of the security incidents IBM studied this year, more than double the year before (Cybersecurity Dive on IBM's 2026 report).
Those are big companies. The habit isn't. 77% of US businesses now use AI regularly, up from 48% in July 2024, per Intuit's May 2026 report.
People will use the tools that help them work. Banning them on paper won't hold for long.
Five lines I would want on paper#
If I ran a 50-person company this week, I would want one page that answers these five things.
Last week I covered the four things to check before turning one agent loose: scope, a log, an owner, an off switch. These five govern the company around it.
1. Which tools are approved.#
Not every tool gets company data. Not every tool gets customer data. Not every tool gets browser or computer access.
The approved list is four columns: a name, an owner, an allowed use, and a data rule.
If a tool is not on the list, the answer is no until someone approves it.
2. Which accounts it can use.#
An agent reaches exactly what the credentials in front of it reach.
If it runs under a personal login, the business may not control the settings, the data controls, the retention, or the record. If it runs under a company-managed account, at least the business has a place to set rules.
The brand of the account doesn't matter. Ownership does.
Company work should happen on accounts the company can govern.
3. What it is allowed to touch.#
Write down the systems before the agent shows up inside them.
Books. Payroll. Email. CRM. Bank portal. Customer portal. Internal documents. Production systems.
For each one, decide whether AI access is allowed, blocked, or allowed only with a human watching.
This is where vague policy turns into an actual control.
4. Where the human approval line sits.#
Money moving. A message to a customer. A change to a record. A filing with a government agency. A contract term. A credential. A deletion.
The rule I like is simple: the agent can prepare the work, but a person gives the yes before anything hard to reverse happens.
The vendors build in a pause before things like a purchase or an outgoing message (OpenAI deployment safety). That helps. Your rule still has to say where your own line sits.
The vendor can't know your dollar threshold, your customer relationship, or your risk tolerance.
5. What record you can show later.#
This is the one owners skip.
If a bank, insurer, auditor, buyer, board, or customer asks how AI is controlled in your business, "we're careful" isn't an answer you can attach.
Your insurer is starting to ask. Aon's May read on AI risk says underwriters writing directors-and-officers cover are already signaling interest in AI governance, and they want to see evidence of it (Aon, May 2026).
One question worth asking your vendor before you write the policy: when the agent clicks something, what exactly lands in a log an administrator can read later, and on which plan?
The answers differ. Some log every step the agent takes; some log the conversation but not the individual actions; some leave the record to you entirely. Assume nothing until you've checked yours.
Most of the breached companies, big ones again, couldn't show anything written down. In IBM's 2026 breach study, 68% of the breached organizations had no AI governance in place to manage AI or detect its unsanctioned use (as reported by ComplexDiscovery). The most common control anyone had, a strict approval process for AI deployments, fell to 38% from 45%.
A dated page with approved tools, approved accounts, approved systems, approval lines, and logs is what you want to already have on the day someone asks.
A board did this before the ground moved#
A foundation's board approved an AI policy. We built it with them, from scratch.
The core framework took a few weeks: a data classification, an approved-and-prohibited tool list, and staff training. Committee review and board approval added a few months.
The tools they wrote it for were still chatbots. The parts that matter held anyway.
Who approves a new tool. What data can go where. Who signs off before anything sensitive moves. Where the record lives.
The list now needs a new row for agents that can use a computer. The framework still holds.
We run agents inside JOV the same way. The posts we publish now, this one included, are drafted by an agent and published by a person, and the approval line is one click that stays with the owner.
That's the work.
Not panic. Not banning. Not pretending every employee will wait for a quarterly policy meeting before using a tool that saves them time.
Govern the use that is already coming.
What I would do this week#
Ask your team, with no penalty for honest answers, which AI tools they are using and which company systems are open when they use them.
Then write the first page.
Approved tools.
Approved accounts.
Approved systems.
Approval line.
The log.
That page is the difference between "we think we're handling it" and proof.
You can write that first page yourself, and most owners should. The part that takes help is the next one: mapping which systems the agents can actually reach in your shop, and where the approval line belongs in each.
The tools are getting more powerful. Good. Use them.
Just don't let the first record of your AI governance be the question someone asks after something has already happened.
Let's walk through yours#
If you want to work through those five lines against your actual systems, schedule a 30-minute discussion. We'll map which AI tools are already in use, what they can reach, where a person should approve the action, and what proof you would hand an insurer tomorrow.
Sources#
- GPT-6 Astra System Card, OpenAI, September 3, 2026
- Grok Bot overview, SpaceXAI
- Anthropic merges Claude chat and Cowork in one interface, TechCrunch, September 16, 2026
- Cost of a Data Breach Report 2026, IBM and Ponemon Institute, July 29, 2026 (full report download-gated); shadow AI in 43% of security incidents, more than double the prior year's 20%, as reported by Cybersecurity Dive, July 29, 2026; 68% lacked AI governance to manage AI or detect its unsanctioned use, and strict approval processes for AI deployments fell to 38% from 45%, per ComplexDiscovery, August 1, 2026
- AI Risk 2026: What Business Leaders Need to Know, Aon, May 7, 2026
- AI That Acts, Needs a Boss, JOV AI, September 10, 2026
- AI Use Jumped From 48% to 77%. The Rules Didn't Move., JOV AI, July 23, 2026
- Intuit 2026 AI Impact Report, Intuit, May 12, 2026
- 92% of Nonprofits Use AI. Only Half Have a Policy. Here's What One Foundation Built., JOV AI, March 24, 2026