
A logistics firm with roughly 450 staff has a CISO and a written policy against putting company information into ChatGPT. Nothing enforces it. No blocking, no approved alternative. The policy has been there for months.
That firm is ahead of most. Of more than 3,400 digital trust professionals ISACA polled in May 2026, 90% believed employees were using AI in their organisation. Only 38% said their organisation had a formal, comprehensive AI policy. A quarter had none at all.
ISACA 2026 AI Pulse Poll · 3,400+ digital trust professionals · Remainder not stated
A risk that belongs to three functions belongs to none of them.
Four conversations, one pattern
Across four separate conversations this summer we heard:
- A Money Laundering Reporting Officer at a financial services firm said the question wasn't his department.
- An IT contact said it sat with the CTO and he wasn't handling it.
- An InfoSec team asking their existing vendors whether they already covered it.
- At the logistics firm, the answer was that decisions are made centrally, so the local IT manager would need to raise it first.
AI tool risk fails the ownership test. To IT it reads as a security problem. To security it reads as a compliance problem. To compliance it reads as a productivity question the business is driving. Each reading is partly correct, which is exactly why the question keeps moving.
Why the standard advice does not apply
The published advice on this is written for organisations that can solve it structurally. Appoint a Chief AI Officer. Build a RACI matrix. Stand up an AI governance committee. A firm of 100 to 500 people has one IT Director who also handles procurement and a share of the helpdesk.
The key questions that remain unanswered are: which AI tools are being used here, and on which of them can staff paste client data or upload files?
The first question is a visibility problem and can take about five minutes to answer with a browser extension. The second is a decision, and it is usually more permissive than people expect. A tool can be fine for typing a prompt into and wrong for pasting a client file into. Treat those as the same action and the only option left is blocking everything.
The free audit answers the first question without committing anyone to the second. It reports which AI tools are in use across your browsers.
Ready to see what your team is actually using?