Employees are not waiting for permission to use AI. They already have it, on personal accounts your company cannot see and cannot audit. This is a summary of the talk Jerod Brennen delivered at Columbus AI Week, "Say Yes Faster: Approving AI Without an AI Committee."

Sixty-seven percent of employees now access AI from personal, unmonitored accounts. Shadow AI has become the third most common insider risk in breach data, up fourfold in a single year, according to the Verizon 2026 Data Breach Investigations Report. Once customer data or source code leaves on a personal account, you cannot prove what left, delete it from the vendor, or show an auditor it never happened. Unmonitored means unrecoverable.


Security's Instinct Is Now the Risk

Every other department in your company approves things in days. Security is usually the one function still built around saying no slowly, because a slow no once felt safer than a fast yes. That instinct made sense when the alternative to a slow approval was doing nothing. It does not make sense when the alternative is an employee routing around you entirely.

The data backs this up. Companies that actively govern their AI use put twelve times more projects into production than companies that do not, according to the Databricks 2026 State of AI Agents Report, based on more than 20,000 organizations. Speed, not restriction, closes the shadow AI gap. Governance is the accelerant. The fastest defensible yes protects data better than any ban.


You Are Not Starting From Zero

Named, published frameworks already cover both halves of AI governance. You do not need to invent a new one. For employees using AI across the company, NIST AI RMF, ISO/IEC 42001, the EU AI Act, and the Singapore Model AI Governance Framework already define what oversight looks like. For AI your team builds into products, the same NIST and ISO frameworks apply, alongside OWASP's Top 10 for LLM Applications, OWASP's Top 10 for Agentic Applications, and MITRE ATLAS for adversarial threat modeling.

The problem most companies have is not a missing framework. It is a missing process for saying yes on a timeline that matches how fast the request came in.


The Four Gates

Four questions replace the committee. Each one has a named owner and a target turnaround measured in days, not weeks.

Run these four gates on every AI request

Gate 1: Data Is this customer, employee, or regulated data going into the tool? Owner: data steward. Same day.

Gate 2: Vendor Can this vendor retain, train on, or resell what you send it? Owner: IT or procurement. Two to three days.

Gate 3: Review Who signs off on the output before it reaches a customer or a decision? Owner: business owner. Same day.

Gate 4: Kill Criteria What measurable event ends this, and who is watching for it? Owner: security or compliance. Set once.

Two people run this. No committee required, and the gates work retroactively too. Audit what is already running in your company today, then gate it the same way you would gate a new request.

Gate 1: Data, in one sentence

Before anyone uses a new AI tool, classify what it will touch. Customer PII, employee records, and regulated data under HIPAA, PCI, or CUI each carry different obligations. If you cannot answer this question in one sentence, the request is not ready to move forward.

Gate 2: Read the terms, not the marketing page

Free and consumer tiers of major AI tools often reserve the right to train on your input by default. Enterprise agreements with explicit no-training clauses close that gap. Verbal assurances from a vendor do not.

Gate 3: A named reviewer, every time

Every AI-generated output that reaches a customer, a contract, or a business decision needs a named human reviewer before it ships. This is not about distrust of the tool. It is about having someone accountable when the output is wrong, and something will eventually be wrong.

Gate 4: Define the exit before the launch

Define, in writing and before launch, the specific conditions that trigger a pause or shutdown. An error rate threshold. A cost ceiling. A specific type of customer complaint. Assign one person to watch for it. Without this, a tool keeps running long after it stops working.


Four Companies, No Gates

Every incident below was disclosed publicly. None of them needed a new invention to prevent. Each one was missing a gate that already existed as a concept before the incident happened.

Company What happened Missing gate
Samsung, 2023 Engineers pasted proprietary source code and meeting transcripts into ChatGPT three times in 20 days. The company banned generative AI company-wide. Gate 1 and Gate 2. No data classification before use, no vendor review of where that data would live.
Air Canada, 2024 A support chatbot gave a customer false information about bereavement fares. A tribunal ruled the airline liable and ordered damages. Gate 3. No human review checkpoint on customer-facing chatbot output.
Alphabet, 2023 A factual error in Google's Bard launch demo wiped roughly $100 billion off Alphabet's market value in a single trading day. Gate 3 and Gate 4. No adequate pre-launch review, no kill criteria before a public release.
PocketOS, 2026 An AI coding agent with a fully permissioned API token hit an error and autonomously deleted the production database in nine seconds. Gate 3 and Gate 4. No confirmation step on a destructive action, no defined limit on what the agent could do alone.

Sources: Bloomberg and Forbes (Samsung); Civil Resolution Tribunal of British Columbia, Moffatt v. Air Canada; CNN and Reuters (Alphabet); ABC News (PocketOS).


What the Gates Would Have Changed

Run the same four incidents through this model and each one stops at a different gate before it becomes a headline. Samsung's proprietary code gets classified as restricted before any tool touches it, and any vendor without a no-training agreement gets blocked at the door. Air Canada's chatbot gets a human check on any customer-facing policy claim before it ships. Alphabet's demo error gets caught in review, with kill criteria defining what has to be true before a public launch proceeds. PocketOS's agent gets a required confirmation step before any destructive action, with Gate 4 scoping what the agent is allowed to touch alone.

None of these are exotic controls. They are four questions, asked before launch instead of after the incident report.


"We Don't Have the Headcount" Is Not the Real Barrier

A 200-person company does not have the resources for a massive AI governance committee, and it does not need one. Running the four gates on a single request takes two people and one afternoon. The barrier was never headcount. It was believing that governance requires a large, slow process instead of a small, fast one.


Start Monday

Your AI policy is not what protects you. Your approval time is. Pick one AI request sitting unapproved in your queue right now and run it through the four gates this week. Gate 1 classifies the data. Gate 2 checks the vendor. Gate 3 assigns a reviewer. Gate 4 sets a 90-day check-in. That is a defensible, documented yes in days, not months.

If you want a structured way to track this across every AI tool already running in your company, the AI Asset Inventory and Risk Register linked below walks through the same four gates, tool by tool.


How Aetos One Helps

Aetos One works with mid-market organizations that need governance built into the business, not bolted on as a separate committee. Our Guardian module puts a named fractional CISO in charge of exactly this kind of process design, so a shadow AI gap gets closed before it becomes a deal-killing finding or a headline.

Guardian

Named fractional CISO. Builds and owns the approval process, including AI-specific gates like the ones above.

Bastion

AI-driven security operations, with named analyst coverage watching for the exact conditions your kill criteria define.

Citadel

Continuous compliance automation, keeping evidence of every gate decision audit-ready.

If your company is running AI tools nobody has gated, schedule a 30-minute conversation.


Downloadable Resources

Get the full talk and the companion tracking sheet.

Presentation

Say Yes Faster: Approving AI Without an AI Committee

The complete slide deck from the Columbus AI Week talk, including the four gates, the four-incident case study table, and sourced statistics.

Download the PDF →

Spreadsheet

AI Asset Inventory and Risk Register

A working spreadsheet for logging every AI tool in use, scoring it against the four gates, and setting a review date. No governance committee required.

Download the XLSX →