When AI Governance Lands On The CTO's Desk

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Do you want developers moving as fast as the tools allow or every line vetted before it merges, even if it ships slower?

Rob Black, CISSP, is the CEO & Founder of Fractional CISO. He architects and implements AI and cybersecurity risk management programs.

getty​By the time most organizations get around to formally controlling AI usage, it’s been on the “payroll” for months, working nights and weekends, and reading the entire codebase. Until a formal AI governance program is spun up, it’s as if nobody approved that “hire.”

Large companies have a CISO (chief information security officer) to manage this, but most growing companies don’t. The fallback is usually the most senior technical person in the building, which often means the CTO or IT director.

If that’s you, you can get AI governance up and running without driving your devs (or yourself!) crazy. It all comes together in one document, an acceptable use of AI policy, where you capture what’s already in use, record which tools you allow and set out how people request new ones.

Like with cybersecurity, every AI governance decision flows from two questions: How much risk is your organization willing to accept? How do you want AI to be used at your company?

I’ve worked with clients across the spectrum, from the ones who want the technology nowhere near their codebase to the true believers trying new tools every week. Most companies will land somewhere in between.

There’s no single right answer, but there’s one wrong move: not deciding at all. An undefined position means scattershot and inconsistent AI usage at your company.

The trade-offs are the same as the software days: speed against quality and time to market against polish. Do you want developers moving as fast as the tools allow or every line vetted before it merges, even if it ships slower?

None of this should shock anyone in 2026: Your team is already using AI, approved or not.

If a tool helps someone hit a deadline, they’ll reach for it, and if the approved channel is closed, they’ll open a free personal account. Some of the software you already pay for has switched on AI features nobody asked for. So, the first move isn’t writing policy. It’s getting visibility.

For that, you want someone with total visibility into every dollar the company spends, someone who already sees the card statements, the expense reports and the vendor invoices—your accounts payable team. Have them flag anything AI-related and you’ll surface most of your shadow usage in an afternoon because people will happily use AI but rarely pay for a business license themselves. For the rest, you’ll have to directly ask employees to report any tools they’re using with free or personal accounts.

Once you have all current usage, you’ll need to decide which tools will continue to be permitted, which ones should be migrated to corporate licenses and which ones should be disallowed. You also must decide which tools are permitted to process which types of data. Not all AI tools are suitable for handling confidential or private health data, so employees must know what is and isn’t allowed for input in each tool.

This gets captured in a separate document, linked to your acceptable use of AI policy.

Employees need an easy way to request the approval of new AI tools, especially when those employees are software developers. Coding is currently the killer app for AI. It’s the clearest place the technology has paid for itself, and the market knows it.

New assistants, agents and editor plug-ins ship every month aimed squarely at engineers, who are bombarded with ads and news about each release. Hand these sophisticated users a slow request process, and they’ll use their admin rights to install whatever they please.

When developers do this, they aren’t intentionally being difficult. Your company gave them a job, and they’re using tools available to them to do it efficiently.

So, what do you do? Make the request process easy. Keep intake light: tool name, use case, data involved and what it replaces. Set a short, time-boxed review window so people know when to expect an answer.

Above all, be willing to say yes. A process that always says “no” will drive people to circumvent it.

That request process, your tool decisions and your data rules all live in one place: your acceptable use of AI policy. Well implemented, it tracks your leadership’s true risk tolerance.

You can tell your CEO or board, credibly and with specifics, that AI risk is under control.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/23/when-ai-governance-lands-on-the-ctos-desk/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business