Everyone Has an AI Policy. Almost No One Has AI Governance.
Your staff adopted AI without you. The regulators noticed. Here's what to do about it — and the tool I just released to help.
The board meeting is going well. Then the newest board member — the one who reads everything — asks the question: “What’s our AI governance posture?”
The executive director smiles and slides a two-page document across the table. An AI policy. Downloaded as a template eight months ago, lightly edited, approved by unanimous consent. Everyone nods. Meeting adjourned.
Here’s the problem: that document answers none of the questions that actually matter. Who owns each AI tool in the organization? What data flows into them? How were they tested? Who’s monitoring them? What happens when one fails? A policy that can’t answer those five questions isn’t governance. It’s a permission slip you wrote to yourself.
I’ve spent my federal career — six agencies, CIO, CAIO, CTO, and Chief Digital Officer roles — watching organizations confuse having a document with having a discipline. AI has made that confusion dangerous.
The gap between adoption and governance has never been wider
The numbers tell the story plainly. Gartner research finds 68% of employees are using unauthorized AI tools at work — up from 41% in 2023. PagerDuty’s 2026 survey puts it at two-thirds of office professionals. Your people didn’t wait for your governance framework. They opened a browser tab.
The mission-driven sector is in the same boat, only smaller. The 2026 Nonprofit AI Adoption Report found that 92% of nonprofits now use AI in some capacity — but 47% have no AI policy at all, and only 7% report major strategic impact. Read those numbers together and the conclusion is unavoidable: the barrier isn’t access to AI. It’s the absence of a system around it.
Meanwhile, the regulatory clock is running. The EU AI Act’s high-risk obligations were set to bite on August 2, 2026 — conformity assessments, transparency duties, the works — with fines reaching 7% of global turnover. Brussels has been negotiating a Digital Omnibus that would push the high-risk deadline to late 2027, and U.S. companies have been watching that uncertainty closely. But if you’re treating a deadline extension as a reason to relax, you’ve misread the moment. The direction of travel is fixed. The only variable is how prepared you’ll be when enforcement arrives — from a regulator, a funder, an auditor, or your own board.

Governance is a decision architecture, not a committee
I’ve written before that real AI governance isn’t a working group that meets monthly to admire the problem. It’s a decision architecture: you inventory the use cases, assess the risks, assign the owners, train the people, monitor the outcomes. Then you iterate.
When an auditor — or a funder, or a journalist — comes calling, they don’t ask to see your policy. They ask you to prove five things:
Who owns each AI system. Not “the IT department.” A name.
What data it touches. Including the customer records your staff pasted into a free chatbot last Tuesday.
How it was tested. For accuracy, for bias, for the failure modes specific to your mission.
How it’s monitored. Post-deployment, continuously, with thresholds that trigger action.
What happens when it fails. An incident process that exists before the incident.
Most organizations can’t prove one of the five. The frameworks that structure this — NIST AI RMF, ISO/IEC 42001, the EU AI Act’s risk tiers — are not mysterious. They are, like FISMA and the NIST RMF before them, the architecture of responsible modernization. The problem has never been the frameworks. The problem is that translating them into working governance has required one of two things: a $200K enterprise platform built for a dedicated AI risk team, or a six-figure consulting engagement.
If you’re a nonprofit director, an association executive, or the ops leader at a 200-person company who got handed AI governance on top of your actual job — the “accidental AI owner,” as I’ve come to think of this role — neither of those was built for you. You’ve been left with free templates at the bottom and enterprise platforms at the top, and nothing in the middle where you actually live.
That gap is why I built GOVERNBOX.ai — and it’s live today
After three decades of building governance inside federal agencies, I’ve put that experience into a product. GOVERNBOX.ai, from my firm Gradient Descent LLC, is self-service AI governance for the underserved middle: nonprofits, associations, public-sector organizations, and small and mid-sized businesses. It’s released, it’s ready, and you can use it right now.
Here’s the premise. A non-technical leader should be able to sit down and, in under an hour, produce a defensible AI governance package — an AI use policy, an acceptable-use standard, a risk register, and a compliance crosswalk to NIST AI RMF, ISO/IEC 42001, and the EU AI Act. Not a template with your logo pasted on it. A package generated from a curated control library built on the controls auditors actually check — the ones most organizations miss — with every clause traceable back to its source control. No invented requirements. No jargon your board can’t read. And because the frameworks keep moving, your documents move with them.
It answers the five questions. Who owns it, what data it uses, how it was tested, how it’s monitored, what happens when it fails. On paper, with evidence, before anyone asks.
GOVERNBOX.ai is live, and I’m inviting all of you to use it. Start with the free AI Readiness Scorecard — ten minutes, no sales call, and you’ll know exactly where you stand against the five questions. If the results sting a little, generate your first governance package the same afternoon. Head to GOVERNBOX.ai to get started, or schedule some time with me if you’d rather talk it through first. And when you’ve run your organization through it, reply to this post and tell me what you found — reader feedback is shaping where the product goes next.

The bottom line
Your organization is already using AI. The only question is whether you’re governing it — or whether you’re carrying a two-page permission slip and hoping nobody asks the five questions.
It can be done. It doesn’t take a committee, a consultant, or a compliance team. It takes a decision — and now, a tool built for the people who have to make it.
Jim Tunnessen is a veteran federal CIO/CAIO and Founder & Principal of Gradient Descent LLC. ExecutiveTech is a reader-supported publication — to receive new posts and support this work, consider becoming a free or paid subscriber.
Sources & further reading:
Shadow AI Statistics: Key Data Points Every CISO Needs in 2026 (Airia, citing Gartner)
PagerDuty: Two-Thirds of Office Professionals Have Used Unauthorized AI Tools at Work
Nonprofit AI Adoption Hits 92% — But Only 7% See Major Impact (NonProfit PRO / Virtuous 2026 report)
EU AI Act Deadlines 2026–2027: Compliance Calendar + Fines (Legiscope)
EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines (Gibson Dunn)
U.S. Companies Face EU AI Act’s Possible August 2026 Compliance Deadline (Holland & Knight)


