Episode Categories:
Resources:
Join the discussion on LinkedIn: Got something to say? Let us know on LinkedIn and network with other AI leaders
Upcoming Episodes: Check out the upcoming Everyday AI Livestream lineup
Connect with Jordan Wilson: LinkedIn Profile
Start Here Series in our Inner Circle Community: Join for free access
AI Governance: Five Operational Rules for Immediate Business Value
Maintaining meaningful use of AI in the workplace is far from a technology procurement issue. Current research shows that over 90% of employees only utilize AI for basic tasks—yet companies continue to invest in tool licenses without realizing significant returns. As the transcript from “Everyday AI - AI Governance in Plain English” highlights, the rapid evolution of AI’s capabilities has created a persistent gap between tool deployment and organizational maturity in AI governance. This article unpacks direct, actionable strategies—drawn from specific business cases, regulatory observations, and operational missteps—that business leaders can adopt to move from AI confusion to tangible impact.
The ROI of AI Governance: The Untapped Business Case
The bulk of AI spending does not translate to business outcomes. Companies report that while half have AI tools, only 12% use them for actual business value. Employees default to using AI for low-level tasks such as meeting note summaries, reflecting an institutional lack of operational governance and training on strategic use cases.
Best-in-class organizations aren’t simply adopting tools. They are systematically coaching every employee on role-specific, high-impact use cases, tracking where AI delivers value, and using metrics to inform continuous improvement. Focusing governance here shifts AI from a general productivity enhancer to a driver of core business outcomes.
Rule One: AI Inventory Management as the Foundation for Security and Value
Organizations are largely blind to their actual AI footprint. Over half still lack a systematic, up-to-date inventory of AI tools, largely due to “shadow AI”—unsanctioned apps and platforms employees adopt independently. IBM research cited in the episode shows that shadow AI contributed to 20% of tracked data breaches, with each incident costing an average of $670,000 more than non-AI-related breaches.
Proper governance begins with a thorough inventory: identifying every AI tool in play, both officially sanctioned and otherwise. Banning AI does not curtail usage—it merely pushes tool adoption underground, increasing unchecked risk. The recommended business approach is to inventory all tools, rapidly greenlight those that fit company standards, and train staff systematically. This transparent control drastically reduces risk, aligns with compliance expectations, and enables ongoing ROI measurement.
Rule Two: Risk-Based Classification for Efficient Oversight
Not all AI processes require the same level of governance. Borrowing from the EU AI Act, practical business governance groups tools and workflows by risk—unacceptable, high, limited, or minimal. For example:
Drafting generic communications: Minimal risk, minimal controls required.
Approving mortgages or healthcare coverage: High or unacceptable risk, requiring human review.
Efficient classification systems allow companies to apply guardrails where it matters most and avoid operational bottlenecks over low-risk functions. This targeted risk approach cuts compliance overheads and prevents “policy overkill” that slows progress without adding value.
Rule Three: Clear Ownership and Autonomy in AI Accountability
For any AI agent or tool deployed, it’s critical that ownership is immediately identifiable and that the responsible party has full authority to act in crisis. The “Everyday AI” episode points out that in the event of an agentic system failure (such as a workflow automation making unauthorized purchases), most businesses cannot name a single accountable individual within ten seconds.
Effective governance models designate ownership for each AI deployment—not just to IT, but across legal, operations, domain expertise, and daily users. This cross-functional, clear ownership model ensures both policy compliance and rapid response when issues arise, minimizing business disruption and liability exposure.
Rule Four: Living Playbooks—Not Static Policies
Traditional policy manuals quickly become obsolete in the face of fast-moving AI capability upgrades. The recommended shift is toward live playbooks detailing:
Task
Access requirements
Accuracy measurement
Reviewer roles
Escalation paths
A playbook-oriented model aligns IT, business, and compliance teams on not just what to avoid, but how to act effectively when ambiguity arises. Furthermore, responsibility for AI actions remains with the company—regardless of whether third-party agentic tools are involved—as emphasized by recent FTC guidance.
Rule Five: AI Governance as the Engine for Scaling, Not a Bottleneck
Organizations that perceive AI governance as “red tape” risk missing out on business acceleration. Data-driven studies show that companies with mature governance structure deploy new AI capabilities up to 40% faster and save on average $1.9 million per data breach versus their ungoverned counterparts.
Robust governance enables proactive scaling—quickly moving from pilot projects to full production—by removing hidden blockers before they escalate into legal or operational crises. Monthly review cycles (not annual or quarterly) are a tactical minimum, ensuring alignment with continually evolving AI features and regulations.
Monthly Review and Continuous Improvement: Governance in Practice
The recommended cadence is a mandatory, organization-wide monthly governance review. With AI capabilities and compliance expectations changing on a sub-annual basis, annual reviews are insufficient and expose businesses to significant risk.
This approach positions governance as a dynamic business enabler—a process for iterating on what works, surfacing shadow usage, and preventing high-profile failures (such as recent class-action suits linked to ungoverned healthcare and hiring AI tools). Successful organizations set up cross-functional teams to update playbooks, monitor tool adoption and impact, and manage risk in real time.
Conclusion: Structured Investment in AI Governance Delivers Measurable Results
For companies seeking real business value from AI, governance is not a checkbox exercise. The operational rules outlined here—AI inventory, risk classification, clear ownership, playbook development, and frequent review—transform AI from a potential liability to a competitive asset. Applying these direct, actionable strategies, derived from real-world failures and industry-leading research, establishes both the foundation for compliance and the runway for rapid growth.
For further detailed frameworks, access to private communities, and ongoing updates, decision makers can reference resources curated specifically for AI operational maturity and join discussions with other leading organizations addressing these same challenges.
Topics Covered in This Episode:
- AI Governance Explained in Plain English
- Why AI Governance Matters for Companies
- Deloitte AI Governance Statistics Breakdown
- Challenges in Governing Rapidly Evolving AI
- Real-World Lawsuits from Ungoverned AI
- U.S. vs. EU AI Governance Laws Overview
- Five Essential AI Governance Rules
- Shadow AI and AI Tool Inventory Risks
- Classifying AI Tools by Risk Level
- Assigning Clear Ownership of AI Systems
- Writing Playbooks Versus Policy Documents
- Governance as an AI Scaling Engine
- Importance of Monthly AI Governance Reviews
Episode Transcript
Jordan Wilson [00:00:18]:
Buying AI tools is the easy part. Getting your employees to actually use them for anything meaningful, that's where most companies fall apart. Section's own research shows over 90% of employees only use AI for basic tasks. That's not ROI. Section coaches every employee on real role specific use cases, tracks who's driving AI impact, and it gives you the data to prove it's working. For more, check out section at sectionai.com. If you're forced to have an opinion on stoplights, I think most people would fall in one of two camps. Either one, these stoplights are annoying.
Jordan Wilson [00:00:57]:
I'm trying to get somewhere and they're slowing me down or two, Hey, stoplights. Great. They keep people safe. And I think you can have the same two train of thoughts when it comes to AI governance. You could say, Hey, this is slowing me or my company down and it's annoying. Or, Hey, this is probably keeping us safe. This AI governance thing. But I don't think most people care or even know too much about AI governance for a variety of reasons, but probably the main one being AI's capabilities are changing so fast that it becomes almost impossible to govern them.
Jordan Wilson [00:01:39]:
I mean, when you even think about cars, cars have been the same for, like, a hundred and ten years. So the stoplights are relatively effective. Right? But AI isn't even the same this week as it was last week. So how can we keep up with governance and understand it and make it work for us? Well, that's what we're gonna be diving into on today's show. So let's get to the big picture here. And that's right now. According to a state of AI report from Deloitte, 74% of companies expect to use agentic AI within the next two years, but only about 21% report having a mature model for governance. So just about every single company wants to use autonomous AI that will act without someone watching over it, yet most people admit to not even having a plan.
Jordan Wilson [00:02:33]:
And compared to the prior year, state of AI reports from Deloitte, the number of companies reporting that they have a, mature model of governance has actually gone down. It's because companies can't keep up and is getting scary both in a good and bad way. So that's what we're gonna be tackling on today's show. And if you do stick around, here's what you're gonna learn. You're gonna learn why the governance rules that you built for chatbots are already broken, what real lawsuits against big companies reveal about ungoverned AI, and I'm gonna leave you with five operational rules that turn AI governance into a scaling advantage. Yeah. I'm gonna tell you the five AI rules that literally every company needs to know and follow because then you don't have to worry about this. Hey.
Jordan Wilson [00:03:25]:
What the heck is AI governance? I'm gonna tell you and how you can keep up with it. Alright. Let's get into it. Welcome to Everyday AI, and this is our start here series. It is the essential podcast series to both learn the AI basics and to double down on your AI knowledge. So, yeah, make sure you go start with volume one. Alright? And then listen to them in order if you're brand new here. And also if you're brand new here, make sure to go to starthereseries.com.
Jordan Wilson [00:03:49]:
That will give you exclusive access to our private and free AI community called the inner circle. Alright? And then there, you can listen to every single, episode from the start here series. We even have an ongoing playlist and keep everything updated in one easy to find space. Alright. And if you did miss our last episode, like I said, they all go in order. We talked about the AI labor shift, when it'll happen, and what it means for jobs. Alright. But today, we're talking about AI governance in plain English in the five AI rules that every company needs to follow.
Jordan Wilson [00:04:24]:
Let's start with definitions. All right. AI governance people think it's it's ethics. It's it's rules and it's sure kind of true, but more than anything, it is quite literally how your company operates when it comes to AI. It's the roles, the rules, and the controls that manage how AI works in your company. So it's not just who can use AI, but it's what data goes into the AI systems and ultimately what happens after. So that is, governance. Right? AI governance in a nutshell.
Jordan Wilson [00:05:01]:
It's the before, during, and after, and the who, the what, the why, and the how of AI. And it's not a debate on should we be doing this? It is an operational layer. It is foundational. And this is, you know, it's obviously gonna look a little different if you're a small business of 10 employees, versus if you're a company with a trillion dollar multiple trillion dollar market cap. And I know we have, listeners who represent both sides of of of of that pendulum. But, regardless, AI governance is extremely important. Right? So think of it and and this is obviously an extremely oversimplified, kind of, analogy here. But I'm sure at some point, you've you know, when working for your company, you had to sign, you know, some sort of, you know, computer report, some kind of a technology policy or something like that.
Jordan Wilson [00:05:56]:
Right? That says, here's how we use our computers. Right? It's like that, but it's ever evolving because the technology is ever evolving, which is why I think some people are kind of ignoring it. And because without proper AI governance, it is just kind of chaos in the streets. And here's the reason why it's well, it's problematic now more than ever. Because in, you know, in 2023 or in 2024, right, when AI governance was this big hot topic, because I think it took a year after ChatGPT's launch for companies to realize, like, oh, this is actually gonna be a thing that companies use. Right? I think as as these chatbots started to mature, right, but at the time, AI governance was, well, it's what happens if something is wrong when we use a chatbot to summarize a PDF or if it rewords an an email and it's not the right way. Right? The the repercussions were technically rather small, but fast forward to today. And obviously, AI agents can modify files, send emails, make purchases, and execute workflows.
Jordan Wilson [00:07:10]:
It's obviously so different because when AI just talks, governance is about accuracy. But when AI acts, governance is about accountability and it is about your fundamental, your, your, your foundational operation as a company. Because, you know, companies built governance, I think, originally for chatbots. Right? And they probably kicked the can in 2023, finally got it going in 2024, maybe got it approved in 2025. And by the time anyone's has read it in 2026, it it makes no sense anymore. And that's why companies according to Deloitte's study, which is a really good one, that's why companies feel less prepared this year, in infrastructure, data risk, and talent than they did the previous year. And I think the main thing is, well, now we are seeing this, you know, this true jump in agentic capabilities from these models. And I think to truly understand governance, you unfortunately have to look at, some of the cases of AI that have gone awry.
Jordan Wilson [00:08:22]:
Alright. And there's dozens of them, but probably some names that you've heard. Right? So UnitedHealthcare is facing a class action, suit as their AI tool, allegedly, denied elderly care at a 90% error rate. Right? Not a good thing. And this is okay. By the time the company realized it, it was too late because the AI was, allegedly making decisions and denying people, care that should have been given care. Workday faced a nationwide age discrimination suit over its AI hiring screening tool. Right? There's literally cases.
Jordan Wilson [00:09:03]:
I could talk about these for, days because there's hundreds of them. But this is the importance of government because those instances they didn't require, or there was no malicious intent involved. Right? Because I think most people assume when it comes to AI governance, well, hey, if our company and department and our people are just, you know, act acting ethically, you know, and being, you know, good, thoughtful humans, then we don't have anything to worry about when it comes to governance. Right? We're not doing anything illegal, and that's the exact opposite. Right? When we talk specifically the difference between, you know, AI being able to talk versus AI being able to act in agentic AI and, you know, autonomous loops of AI. You know, now we have, you know, this open claw, you know, surge that's really been, you know, popularized and legitimized, right, with, you you know, NVIDIA, the largest company in the world came out with, you know, their more secure version of it, you know, called the Nemo Claw. It is going to become very common for your company, whether you know it now or not, to have autonomous agents acting on your behalf. And I think maybe that heightens the need for taking AI governance seriously, because yeah, two years ago, you know, it was just like, oh, let's just, you know, put, put something on our website or, you know, put one little checkbox here and then we're done and we don't have to worry about anything.
Jordan Wilson [00:10:41]:
But now what happens when an agent didn't have a proper guardrail in place? What happens when you don't have an expert driven loop and you have a human in the loop, which is terrible, by the way? Right? That's when governance gets real and when the, the egg lands on your company's face. And one of the reasons why I think companies haven't yet done anything is, well, there's everyone's looking around for real rules. Right? They're like, alright. Well, just give us the law. We'll follow it. Right? I think sometimes, you know, it's it's it turns into this top down legislation. Right? And they're like, okay. Well, if we're not breaking any rules, that means we're doing the right thing and there are no rules, so we can do anything.
Jordan Wilson [00:11:28]:
And that's not the right thing. That's the wrong thing. Right? So right now in The US, there's no comprehensive federal law on AI. And I don't think there will be, at least not in this administration, and you can argue whether that's a good thing or a bad thing. That's not what I'm here trying to do. And president Trump signed an executive order outlaw outlawing states' abilities to legislate AI. Right? That didn't stop the states. The states are still, you know, approving things.
Jordan Wilson [00:11:57]:
And, ultimately, what's gonna happen is there's gonna be a showdown because there are states like Colorado and California that have, you know, not saying if they defied Trump's executive order, but they just went through with their, you know, state's laws on AI. And, ultimately, you know, nothing's gonna happen until a federal judge, you know, strikes strikes these state laws down. So until then, we're kind of left with this cloud of uncertainty, but at the same time, right, we have things like the e, the EU AI act. Right? Things that are actually going into effect, this August as an example. So I think a lot of companies are just kind of sitting on the sidelines, and they're in this wait and see scenario. You know, decision makers, which I think is extremely dangerous because a lawsuit is not going to care, you know, that you were waiting to see what the laws are. Right? Just because there is no true governance over AI doesn't mean that your company shouldn't take it upon itself to create that. Don't worry.
Jordan Wilson [00:13:03]:
I'm gonna give it to you, with our five rules. But before we go over those five rules, I gotta take a break. I gotta take a sip of water. Quick word from our partners. Here's a harsh truth. Your company is probably spending thousands or millions of dollars on AI tools that are being massively underutilized. Half of companies have AI tools, but only 12% use them for business value. Most employees are still just using AI to summarize meeting notes.
Jordan Wilson [00:13:33]:
If you're the one responsible for AI adoption at your company, you need Section. Section is a platform that helps you manage AI transformation across your entire organization. It coaches employees on real use cases, tracks who's using AI for business impact, and shows you exactly where AI is and isn't creating value. The result? You go from rolling out tools to driving measurable AI value. Your employees move from meeting summaries to solving actual business problems, and you can prove the ROI. Stop guessing if your AI investment is working. Check out section at sectionai.com. That's sectionai.com.
Jordan Wilson [00:14:18]:
All right. Got you paying attention to governance now, right? So here are the five rules that every company needs to follow. Period. I don't think there's really any exception to these rules. There's more rules that you can follow, but I think if you follow these five rules to the tee, I think that you are in a better place than 99% of the companies in The US. All right. Rule number one, know what AI you actually have. My gosh.
Jordan Wilson [00:14:49]:
I don't know if any company has a hold on this, partially because of shadow AI or what I predicted in 2023 would be called second computer AI. Apparently, that's not as good as shadow AI. Shadow AI is, you know, it's scarier, stickier. Right? But over half of organizations right now completely lack a systematic in inventory of their AI tools. And that's because, well, shadow AI. So a recent IBM report said that shadow AI was involved in 20% of all data breaches, Right? That were tracked in their report at least. And those shadow AI breaches cost companies $670,000 more per incident on average than the non AI or non shadow AI involved breaches. Alright.
Jordan Wilson [00:15:38]:
So obviously, there is a huge danger in you not knowing what AI is used across your company. We've had a couple, really good episodes, on everyday AI about shadow AI. We had one with the CEO of of, Aria, which was a really good episode. But you can't just ban certain AI tools. That doesn't get rid of your shadow AI or your AI sprawl. Because blocking that doesn't mean anything. That just means employees are gonna just do the same thing, switch over their Wi Fi network. Right? The tablet off the VPN somehow and still access their files that they sent to themselves in an email.
Jordan Wilson [00:16:23]:
People are always still going to use AI tools. So you might as well do the right thing, do a complete inventory, fast track, green lighting the correct ones that make sense for your organization, and then train the people on them. Right? What are the reasons why people are using other AI tools? They'll they probably have the capabilities and the access. They just don't know how to use it. So they're like, oh, well, I can do task c with, ChatGPT and task b with Copilot, but we only have Gemini. Well, you if you learned about Gemini, you probably realized that you could do all those tasks. Right? About now, you you know, at least when it turn like, when it comes to the the harnessing and the tool use, most most of the the big four, you know, you have about 80% feature overlap. Right? So it's not like, oh, you know, I'm I'm gonna use this because it can read PDFs.
Jordan Wilson [00:17:17]:
No. They can all do that now. It's not 2023. So and also, people think that banning AI eliminates the risk. Wrong. Makes it way worse. Alright? There's there's no way around it. You have to start implementing AI and an AI operating system across your entire organization, and you need to start moving all of your day to day knowledge work work tasks in there, all of them.
Jordan Wilson [00:17:43]:
Right? AI is becoming collaborative. It is becoming, dynamic, being able to work. Now it you can read and write. I mean, depending on when you're listening to this, this episode. Right? If you're listening in March 2026, this will make sense. If you're listening in January 2027, you're like, this is old now. Right? But in the past couple of days alone, right, what you can do with your phone has completely changed. Right? Now you can run Claude Cowork on your phone.
Jordan Wilson [00:18:12]:
You have agentic browsers on iPhones. Right? Everyone is gonna be using these tools. You banning them or your company banning them. Right? So if you're listening to this and you're one of those companies that have have banned AI, right, unless you're, you know, a Fortune 10 company that maybe there's things I don't understand. Otherwise, go ahead. Tell your CEO to talk to me, and I will tell said CEO that they're making an absolutely terrible mistake. Because even if you work in a highly regulated industry working with highly sensitive data, you see you can't avoid generative AI in large language models. You absolutely can't.
Jordan Wilson [00:18:49]:
Right? Even if you've somehow if you're in the point 001% that, you know, doesn't have any Internet, no cloud. Right? Everything's on prem locked down. Right? I mean, even the the the military, the government, everyone is using generative AI. You cannot use it anymore. So you have to map what problems are people are actually solving with the unauthorized tools. And then you need to teach them or provide them how to do that in an authorized and approved way. Right? That's it. Okay.
Jordan Wilson [00:19:21]:
Rule number two is you need to classify everything by risk level. So first, you have to understand what you have, what's being used, what's not being used, what's authorized, what's not, then you need to fix that part first. Then you need to classify everything by risk level. And, actually, this has already been done for us. Right? Just borrow the EU. Their AI act has four tiers. It's unacceptable, high, limited, and minimal risk. Right? So you need to assign everything by risk level because you don't have to apply the same level of guardrails to something that is minimal risk versus something that is unacceptable.
Jordan Wilson [00:20:00]:
Right? You don't have to have the same approval process, the same guardrails. So a tool drafting a generic welcome email, you know, that doesn't matter. It's, you know, it's a broom closet. It's not your highly classified room with all your company secrets. Right? So you don't need to put, you know, ten secondurity guards, in in laser beam lights and triple padlocks on the broom closet. Right? A tool deciding who gets a mortgage, that's yeah. That's a little heavier. Right? You need heavier controls.
Jordan Wilson [00:20:32]:
So for high risk decisions like hiring credit in health care, human review is always required. So it's gonna look different for companies of different sizes, different sectors. It right? Like, if you're have different sanctions, it's gonna look different. Right? Those four tiers. But for the most part, most people should be able to put most of their day to day processes under those four tiers. Right? So you don't govern everything the same thing. You don't put the, you know, the caution tape and the sirens on every single thing. That's probably only on your, you know, on your unacceptable list.
Jordan Wilson [00:21:09]:
Alright. Rule number three, assign clear ownership. Don't just kick something to IT. So there's a a quick test you can take. Right? So let's just say as an example, an AI agent goes off the rails and it's going to right? Go back and listen to my 2026 AI prediction and roadmap series. Yeah. A lot of it's already come true, and there is going to be an agent crash coming. Alright.
Jordan Wilson [00:21:32]:
So if an agent crash happens at your company and that's essentially when, you have a well meaning agent, right, that you think is properly set up and it goes and does something catastrophically bad. Okay. If that happens, can you with a 100% certainty name, the person who is accountable in ten seconds? Most people would say, oh, it's probably, you know, bill in it or, you know, Jane in finance, right? Like, most people could maybe say, oh, it's one of three. Unless you can definitively say instantly the one person and you know a 100% they're responsible, you don't even have the baseline of governance. You need clear ownership. Not only do you need clear ownership, but that person needs the authority to act without hardly any notice. Right? That person needs almost full full autonomy. Right? Maybe aside from, you know, the CEO or, you know, how big how big the organization is.
Jordan Wilson [00:22:33]:
But whoever that person is, if they are the person that has, direct and end ownership, They need the autonomy to make things happen quickly, to change the rules, to hit pause, to hit play, to hit rewind. They need it all. Alright? And you also do need as as much as I hate buzzwords, you do need a cross functional committee. You need an executive sponsor. You need someone in legal. You need someone in IT. You need a domain expert, and then you need a daily AI user. I think those are the five different people minimum that you need or the five different departments that you need because agents are going to be making decisions.
Jordan Wilson [00:23:10]:
Remember, it's not a human expert talking to, a chatbot and then the human expert making the decision. In many cases, this is someone who is unrelated to that domain who is creating agents. And then that agent is going and making decisions sometimes without the actual expert, the actual domain, expert, subject domain expert, even knowing what's happening. Or they're like, okay. Well, hey. Whatever. Whoever gave this agent directions on finance is completely wrong. We should have ran this by finance.
Jordan Wilson [00:23:46]:
Right? So that's who you need. You need the executive sponsor. You need legal. You need I IT. You need the domain expert, then you need the daily AI user. And why do you need the daily AI user in your company? Well, that's your frontline person. Right? That's your person that's actually probably using these tools way more than maybe the head of legal or your, you know, your IT director. Right? That's the person that's gonna say, like, hey.
Jordan Wilson [00:24:10]:
Wait. That's not how we're using this agent platform. We're taking completely different route. Alright? So rule four, don't write policies. Alright. I can guarantee you the best written policy from 2025 is antiquated. It is holier than Swiss cheese right now. Swiss cheese on a Sunday.
Jordan Wilson [00:24:38]:
Right? Because policy just says, do not do this. Right? Do not input sensitive data. A playbook tells you exactly who reviews what and when. Right? If you just have a list of of of things to not do, right, which is usually what policies are, it's not helpful. Every AI use case needs five answers. It needs a task, access, accuracy measure, reviewer, and an escalation path. All right. Every single AI use case that you deploy within your organization needs those things.
Jordan Wilson [00:25:14]:
And then outsourcing something to an AI agent does not outsource the responsibility. Actually, the FTC, right, the Federal Trade Commission here in The US, They're they they kind of shifted their focus away from, you know, Bitcoin, and it's going full full all in on AI. You are your company is ultimately responsible for any decisions that an AI makes. Right? So if you're using an fully autonomous, you know, agentic loop, right, if you if if you're using, right, OpenClaw, any of these things and something goes wrong, you don't get to point the finger at OpenClaw. You don't get to point the finger at, you know, OpenAI, Google, Microsoft, Anthropic, etcetera. No. It is on you. Right? So that's why you have to have those use cases have to be thoroughly vetted and you need playbooks on what to do, not just what not to do.
Jordan Wilson [00:26:09]:
And then rule five, you need to treat governance as the scaling engine and not the break. So here's what, here's what I mean by that. Right now, studies show that 75% of companies are stuck in pilot purgatory because they're just running small AI experiments endlessly. They can't get out of there. Right? Number one is because corporate policy moves too slow. Agentic AI moves too fast. But companies with mature governments who deploy new AI capabilities, they do it faster, 40% faster than their peers that don't. Right? So if you do have mature governance, you can get out of pilot purgatory because if you took care of steps one through four, it is actually no longer a stoplight that is stuck on green.
Jordan Wilson [00:27:04]:
It is a working stoplight that just or sorry, it's it's no longer a, traffic light stuck on red. It is a traffic light that is properly pulling the cars through and keeping them going at a high speed. Right? People think business leaders think. People on, you you know, Twitter, LinkedIn, whatever, people who are AI experts, they assume governance slows companies down, and it is the exact opposite. Because without governance, you cannot compete. You cannot keep up. There's going to be too many small roadblocks along the way, too many giant Chicago sized potholes. Your car's not gonna make it out of the lot y'all.
Jordan Wilson [00:27:52]:
Governance is the scaling engine, not the brakes. Alright. So, both studies from align AI and IBM said that rep, organizations with strong AI governance actually saved $1,900,000 per data breach on average. Right? A lot of this data just, goes back to data breaches because ultimately, like, that's that's where a lot of this is headed. Right? When agentic AI goes off the rails, everyone knows about it. And then you have to start diagnosing, and it takes a lot of time and a lot of money. And that's that's where we are unfortunately learning the good lessons about what we should do in governance when we learn where things go wrong. And the biggest thing where things go wrong is going back.
Jordan Wilson [00:28:42]:
I'm gonna I'm gonna just read these rules here one more time. Alright. I think it starts with not knowing what you actually have and not knowing what the capabilities are. Alright. So rule one, you have to know what you actually have. Rule number two, you have to classify everything at risk by risk level. Rule three, you need to assign clear ownership, not just kick it to IT. Rule four, write playbooks, not policies.
Jordan Wilson [00:29:05]:
And rule five, treat governance as the scaling engine, not the break. Alright? So that's not all. You and you might not like this part. You have to set monthly review cycles. Yes. Not yearly, not quarterly, monthly. Alright. Because a government policy that if if if you think you can set it once and forget it, that's literally like, you know, thinking you can repurpose a 20, 20 o six social media policy, change a couple words and use it for AI in 2026.
Jordan Wilson [00:29:42]:
Like, monthly review is the absolute minimum cadence to keep governance matched to reality. Oh, I've literally been doing this thing for more than three years every single day, and I'm not exaggerating when I say the last three months in terms of capabilities, what an AI can output and do have far outpaced the previous three years. Like I said, it is scary in a good and bad way. So you cannot just set something and revisit it once a year. That is a recipe for failure, but a recipe for success is to stick with us through the rest of the start here series. All right. Cause because we're gonna be guiding you along the way, whether you are brand new to AI or you're trying to keep up and double down. Thank you for going with us on this one as we went over AI governance in plain English, five AI rules every company needs to follow.
Jordan Wilson [00:30:34]:
I hope this was helpful. If so, do me a favor. And I'm not gonna keep this open forever, FYI. Right, just free, open, unlimited access to our community. So go to starthereseries.com. If this was at all helpful, alright, that's gonna give you free access to our community, and you can go check out every single episode in the start here series all in one easy to find space and also connect with, thousands of other people in our community right now who are doing the same thing you're doing. So, thanks for tuning in. Hope to see you back tomorrow and everyday for more everyday AI.
Jordan Wilson [00:31:09]:
Thanks, y'all.
