Skip to content

What’s Your AI Governance Persona?

AI governance concept graphic featuring a digital brain inside a human-shaped lightbulb on a dark background.

The AI Governance Question Nobody Seems to Agree On

Ask ten business leaders what their AI governance strategy is and you’ll probably get ten very different answers. Some believe AI should be embraced without restriction. Others want to block it altogether. Many land somewhere in the middle, creating lists of approved tools and hoping employees stay within the lines.

AI adoption isn’t waiting for organisations to reach a consensus. Employees are already using ChatGPT to brainstorm ideas, Microsoft Copilot to summarise meetings, Claude to analyse documents, and Gemini to draft content. In many organisations, AI has become as commonplace as search engines or email.

Yet while adoption is accelerating, governance maturity often isn’t. That’s left many businesses operating in one of four distinct AI governance personas. The interesting part? Three of them create significant risk. Only one provides a sustainable path forward. Let’s take a look.

Persona #1: “She’ll Be Right”

Maximum Freedom. Minimal Oversight

This organisation trusts its people. There are no real restrictions, no formal governance framework, no approved tool list, and no monitoring.

The thinking goes something like this: “Our employees know what they’re doing. They understand what’s confidential and what’s not.”

It’s an understandable position. After all, nobody wants to create unnecessary bureaucracy, but AI changes how information moves. An employee who would never email sensitive information outside the business might think nothing of pasting an entire customer contract into a chatbot for summarisation. Another might upload source code for debugging assistance. Someone else may ask an AI platform to analyse confidential financial data. None of these actions are malicious. They’re attempts to work more efficiently.

When there’s no visibility, no audit trail and no governance, the organisation has little understanding of what’s actually happening. The result is maximum freedom and maximum uncertainty.

Persona #2: “Ban Everything”

Control Through Prohibition

On the opposite end of the spectrum sits the organisation that wants nothing to do with AI. AI tools are blocked, policies prohibit use, and employees are instructed not to engage with them.

At first glance, this appears safer, with risk reduced because approved AI usage is effectively zero. Unfortunately, so is visibility. Here’s the reality:

People use tools that help them get their work done.

When AI can save an employee many hours a day, many will find ways around the restrictions. They’ll use personal devices, create personal accounts, and access AI platforms outside corporate networks.

Is this resonates then congratulations. You’ve eliminated visible AI risk while simultaneously increasing invisible AI risk. You’ve also slowed innovation and productivity across the business. The AI adoption hasn’t stopped. You’ve simply lost sight of it.

Persona #3: “Only As Allowed”

Approved Apps Only

This is where many organisations currently sit. Leadership recognises AI has value and a small number of approved platforms are implemented, with employees instructed to use those platforms only.

Compared to the first two personas, this represents genuine progress. Policies exist. Governance exists. Approved environments exist. But there’s still a significant blind spot. Policies tell you what employees should do. They don’t always tell you what employees actually do.

Employees may continue experimenting with other AI tools alongside approved platforms. Departments may adopt niche solutions without informing IT. Individuals may bypass approved solutions if another tool better suits their needs. As a result, organisations achieve regulatory compliance on paper while retaining limited behavioural visibility. This creates what might be called governance comfort – the feeling that risk is under control without necessarily knowing whether that’s true.

Persona #4: Controlled Freedom

Governance at the Point of Use

The final persona takes a fundamentally different approach. Instead of trying to prevent AI use, it assumes AI use will happen. Because it will.

Rather than restricting innovation, organisations establish visibility, governance and control at the point where AI interaction occurs. Employees can access the tools they need and the business gains visibility into usage. Data protection policies can be enforced, risk can be monitored, and appropriate guardrails can be applied. The organisation remains innovative while retaining oversight.

This is where governance begins shifting from prevention to enablement, and that’s an important distinction. The most successful AI programmes aren’t built around saying “no.” They’re built around helping employees say “yes” safely.

Why Most AI Governance Strategies Fail

Many organisations approach AI governance using frameworks designed for previous technologies. AI behaves differently:

  • It’s not a single platform. It’s hundreds of platforms.
  • It’s not confined to one department. It’s everywhere.
  • It’s not simply software. It’s software that interacts with business knowledge, intellectual property, customer information and organisational decision-making.

Traditional governance models struggle because they depend heavily on employees following rules perfectly every time, but AI adoption moves too quickly for that.

Successful governance requires three capabilities:

Visibility

What AI tools are being used?

Context

How are employees using them?

Control

Can governance policies be applied consistently?

Without all three, organisations are operating with incomplete information.

The Future is Better Governance

Whether organisations like it or not, AI is becoming part of everyday work. Employees will continue looking for ways to automate routine tasks, teams will continue adopting AI-powered platforms, software vendors will continue embedding AI into existing products. This is why governance maturity is becoming such an important business capability.

Rather than slowing AI adoption, organisations need to accelerate it safely.

How Prompt AI Helps Create Controlled Freedom

The goal isn’t to block AI. It isn’t to blindly trust it either. The goal is controlled freedom. This is where Prompt AI from SentinelOne comes in.

Prompt AI helps organisations understand which AI tools are being used across the business, identify shadow AI activity, improve visibility into employee interactions, protect sensitive information, and apply governance controls where they matter most. Instead of relying on assumptions, organisations gain genuine insight into AI usage and can make informed governance decisions based on actual behaviour.

The result is a practical path toward confident AI adoption, where employees remain productive, innovation continues, and governance teams retain the oversight they need.

Ready to assess your own AI governance maturity?

Learn how Advantage and SentinelOne Prompt AI can help you move from uncertainty to controlled freedom.

Explore controlled freedom.

 

Facebook
Twitter
LinkedIn

Related Posts

We often talk about “the cloud” as if business data simply disappears into the internet. In reality, cloud services depend on very physical foundations. At the heart of Advantage Cloud is our data centre.
When users complain that systems are slow, the immediate response is often to question the internet connection. But increasingly, organisations are discovering that the real bottleneck sits much closer to home – the firewall.
If you follow cybersecurity news, you may have seen increasing references to “Mythos”. This is the latest in a growing line of advanced AI models, and like most new technologies in this space, it’s surrounded by a fair amount of hype.