If you're forced to have an opinion on stoplights, I think most people would fall in one of two camps. Either one, these stoplights are annoying, I'm trying to get somewhere, and they're slowing me down. Or two, hey, stoplights, great. They keep people safe. And I think you can have the same two train of thoughts when it comes to AI governance. You could say, hey, this is slowing me or my company down and it's annoying. Or, hey, this is probably keeping us safe, this AI governance thing. But I don't think most people care or even know too much about AI governance. For a variety of reasons, but probably the main one being AI's capabilities are changing so fast that it becomes almost impossible to govern them. I mean, when you even think about cars, cars have been the same for like 110 years. So the stoplights are relatively effective, right? But AI isn't even the same this week as it was last week. So how can we keep up with governance and understand it and make it work for us? Well, that's what we're going to be diving into on today's show. So let's get to the big picture here. And that's right now, according to a state of AI report from Deloitte, 74% of companies expect to use agentic AI within the next two years, but only about 21% report having a mature model for governance. So just about every single company wants to use autonomous AI that will act without someone watching over it. Yet most people admit to not even having a plan. And compared to the prior year uh state of AI report from Deloitte, the number of companies reporting that they have a mature model of governance has actually gone down. It's because companies can't keep up and is getting scary, both in a good and bad way. So that's what we're going to be tackling on today's show. And if you do stick around, here's what you're going to learn. You're going to learn why the governance rules that you built for chatbots are already broken. Uh, what real lawsuits against big companies reveal about ungoverned AI. And I'm going to leave you with five operational rules that turn AI governance into a scaling advantage. Yeah, I'm going to tell you the five AI rules that literally every company needs to know and follow. Because then you don't have to worry about this. Hey, what the heck is AI governance? I'm going to tell you and how you can keep up with it. All right, let's get into it. Welcome to Everyday AI, and this is our Start Here series. It is the essential podcast series to both learn the AI basics and to double down on your AI knowledge. So, yeah, make sure you go start with volume one, all right, and then listen to them in order if you're brand new here. And also if you're brand new here, make sure to go to starthireseries.com. That will give you exclusive access to our private and free AI community called the Inner Circle. All right. And then there you can listen to every single uh episode from the Start Here Series. We even have an ongoing playlist and keep everything updated in one easy-to-find space. All right. And if you did miss our last episode, like I said, uh they all go in order. We talked about the AI labor shift, when it'll happen, and what it means for jobs. All right. But today we're talking about AI governance in plain English in the five AI rules that every company needs to follow. Let's start with definitions. All right. AI governance, people think it's it's ethics, it's it's rules. And that's sure, kind of true, but more than anything, it is quite literally how your company operates when it comes to AI. It's the roles, the rules, and the controls that manage how AI works in your company. So it's not just who can use AI, but it's what data goes into the AI systems and ultimately what happens after. So that is uh governance, right? AI governance in a nutshell. It's the before, during, and after and the who, the what, the why, and the how of AI. And it's not a debate on should we be doing this. It is an operational layer. It is foundational. And this is, you know, it's obviously going to look a little different if you're a small business of 10 employees versus if you're a uh company with a trillion dollar, multiple trillion dollar market cap. And I know we have uh listeners who represent both sides of that pendulum, but um, regardless, AI governance is extremely important, right? So think of it, and and this is obviously an extremely oversimplified um kind of uh analogy here, but I'm sure at some point you've, you know, when working for your company, you had to sign, you know, some sort of you know computer report, some kind of uh technology policy or something like that, right? That says here's how we use our computers, right? It's like that, but it's ever evolving because the technology is ever evolving, which is why I think some people are kind of ignoring it. And because without proper AI governance, it is just kind of chaos in the streets. And here's the reason why it's well, it's problematic now more than ever. Because in, you know, in 2023 or in 2024, right, when AI governance was this big hot topic, because I think it took a year after Chat GPT's launch for companies to realize, like, oh, this is actually going to be a thing that companies use, uh, right. I think as as these chatbots started to mature, uh, right. But at the time, AI governance was, well, it's what happens if something is wrong when we use a chatbot to summarize a PDF, or if it re-words an email and it's not the right way, right? The the repercussions were technically rather small, but but fast forward to today, and obviously AI agents can modify files, send emails, make purchases, and execute workflows. It's obviously so different because when AI just talks, governance is about accuracy. But when AI acts, governance is about accountability and it is about your fundament, your your foundational operation as a company. Because, you know, companies built governance, I think originally for chatbots, right? And they probably kicked the can in 2023, finally got it going in 2024, maybe got it approved in 2025. And by the time anyone's has read it in 2026, it makes no sense anymore. And that's why companies, according to Deloitte's study, which is a really good one, that's why companies feel less prepared this year uh in infrastructure, uh, data risk and talent than they did the previous year. And I think the main thing is, well, now we are seeing this, you know, this true jump in agentic uh capabilities from these models. And I think to truly understand governance, you unfortunately have to look at uh some of the cases of AI that have gone awry. All right, and there's dozens of them, but probably some names that you've heard, uh, right. So United Healthcare is facing a class action uh suit as their AI tool, uh, uh allegedly uh denied elderly care at a 90% error rate, right? Not a good thing. And this is okay. By the time the company realized it, it was too late because the AI was uh allegedly making decisions and denying people uh care that should have been given care. Uh Workday faced a nationwide age discrimination suit over its AI hiring screening tool, right? There's literally cases I could talk about these for uh days because there's hundreds of them, but this is the importance of government, because those instances they didn't require or there was no malicious intent involved, right? Because I think most people assume when it comes to AI governance, well, hey, if our company and department and our people are just, you know, act acting ethically, you know, and being, you know, good, thoughtful humans, then we don't have anything to worry about when it comes to governance, right? We're not doing anything illegal, and that's the exact opposite, right? When we talk specifically, the difference between you know AI being able to talk versus AI being able to act and agentic AI and you know autonomous loops of AI. You know, now we have you know this open claw uh you know surge that's really been uh you know popularized and legitimized, right? Uh with you know, NVIDIA, the largest company in the world, came out with you know their more secure version of it, uh, you know, called the Nemo Claw. Um it is going to become very common for your company, whether you know it now or not, to have autonomous agents acting on your behalf. And I think maybe that heightens the need for taking AI governance seriously. Because yeah, two years ago, you know, it's just like, oh, let's just, you know, put put something on our website, or, you know, we'll put one little checkbox here and then we're done and we don't have to worry about anything. But now what happens when an agent didn't have a proper guardrail in place? What happens when you don't have an expert-driven loop and you have a human in the loop, which is terrible, by the way, uh, right? That's when governance gets real and when the uh the egg lands on your company's face. And one of the reasons why I think companies haven't yet done anything is well, there's everyone's looking around for real rules, right? They're like, all right, well, just give us the law, we'll follow it, right? I think sometimes, you know, it's it's it turns into this top-down legislation, right? And they're like, okay, well, if we're not breaking any rules, that means we're doing the right thing and there are no rules, so we can do anything. And that's not the right thing. That's the wrong thing, right? So right now in the US, there's no comprehensive federal law on AI. And I don't think there will be, at least not in this administration, and you can argue whether that's a good thing or a bad thing. That's not what I'm here trying to do. And President Trump signed an executive order outlaw outlawing states' abilities to legislate AI, right? That didn't stop the states. The states are still uh, you know, approving things. And uh ultimately what's gonna happen is there's gonna be a showdown because there's states like Colorado and California that have uh, you know, not saying if they defied Trump's executive order, but they just went through with their um, you know, states laws on AI. And ultimately, you know, nothing's gonna happen until a federal judge, you know, strikes, strikes these state laws down. So until then, we're kind of left with this cloud of uncertainty. But at the same time, right, we have things like the E uh the EU AI Act, right? Things that are actually going into effect uh this August as an example. So I think a lot of companies are just kind of sitting on the sidelines and they're in this wait-and-see scenario, uh, you know, decision makers, which I think is extremely dangerous. Because a lawsuit is not going to care, you know, that you are waiting to see what the loss are. Right. Just because there is no true governance over AI doesn't mean that your company shouldn't take it upon itself to create that. Don't worry, I'm gonna give it to you uh with our five rules. But before we go over those five rules, I got to take a break. I gotta take a sip of water. Quick word from our partners. Here's a harsh truth. Your company is probably spending thousands or millions of dollars on AI tools that are being massively underutilized. Half of companies have AI tools, but only 12% use them for business value. Most employees are still just using AI to summarize meeting notes. If you're the one responsible for AI adoption at your company, you need section. Section is a platform that helps you manage AI transformation across your entire organization. It coaches employees on real use cases, tracks who's using AI for business impact, and shows you exactly where AI is and isn't creating value. The result? You go from rolling out tools to driving measurable AI value. Your employees move from meeting summaries to solving actual business problems, and you can prove the ROI. Stop guessing if your AI investment is working. Check out section at sectionai.com. That's S-E-C-T-I-O-N-AI.com. All right. Gosh you're paying attention to governance now, right? Uh so here are the five rules that every company needs to follow. Period. I don't think there's really any exception to these rules. There's more rules that you can follow, but I think if you follow these five rules to the T, I think that you are in a better place than 99% of the companies in the US. All right. Rule number one: know what AI you actually have. My gosh, I don't know if any company has a hold on this, partially because of shadow AI or what I predicted in 2023 would be called second computer AI. Apparently that's not as good as shadow AI. Shadow AI is uh, you know, it's scarier, stickier, right? But over half of organizations right now completely lack a systematic in inventory of their AI tools. And that's because, well, shadow AI. Uh so a recent IBM report said that shadow AI was involved in 20% of all data breaches, right? Uh, that were tracked in their report, at least. And those shadow AI breaches cost companies $670,000 more per incident on average than the non-AI or non-shadow AI involved breaches. All right. So obviously, there is a huge danger in you not knowing what AI is used across your company. We've had a couple uh really good episodes um on everyday AI about shadow AI. Uh, we had one with the CEO of uh ARIA, which was a really good episode. Uh, but you can't just ban certain AI tools. That doesn't get rid of your shadow AI or your AI sprawl because blocking that doesn't mean anything. That just means employees are gonna just do the same thing, switch over their Wi-Fi network, right? Tattle off the VPN somehow and still access their files that they said to themselves in an email. Uh people are always still going to use AI tools. So you might as well do the right thing, do a complete inventory, fast track green lighting the correct ones that make sense for your organization, and then train the people on them, right? One of the reasons why people are using other AI tools, they'll they probably have the capabilities and the access, they just don't know how to use it. So they're like, oh, well, I can do task C with uh Chat GPT and task B with Copilot, but we only have Gemini. Well, you if you learned about Gemini, you probably realized that you could do all those tasks, right? Uh about now, you know, at least when it turns like when it comes to the the harnessing and the tool use, most most of the the big four, you know, you have about 80% feature overlap, right? So it's not like, oh, you know, I'm I'm gonna use this because it can read PDFs. No, they can all do that now. It's not 2023. So, and also people think that banning AI eliminates the risk. Wrong, makes it way worse. All right. There's there's no way around it. You have to start implementing AI and an AI operating system across your entire organization, and you need to start moving all of your day-to-day knowledge work tasks in there, all of them, right? AI is becoming collaborative. Um, it is becoming uh dynamic, being able to work. Now it you can read and write. I mean, depending on when you're listening to this uh this episode, right? If you're listening in March 2026, this will make sense. If you're listening in January 2027, you're like, this is old now, right? But in the past couple of days alone, right? What you can do with your phone has completely changed, right? Now you can run Claude Cowork on your phone. You have agentic browsers on iPhones, right? Everyone is going to be using these tools. You banning them or your company banning them, right? So if you're listening to this and you're one of those companies that have have banned AI, right? Unless you're um, you know, a Fortune 10 company that maybe there's things I don't understand. Otherwise, go ahead, tell your CEO to talk to me, and I will tell said CEO that they're making an absolutely terrible mistake. Because even if you work in a highly regulated industry working with highly sensitive data, you see you can't avoid generative AI in large language models. You absolutely can't, right? Even if you've somehow, if you're in the 0.001% that, you know, doesn't have any internet, no cloud, right? Everything's on-prem locked down, right? I mean, even the the military, the government, everyone is using generative AI. You can't not use it anymore. So you have to map what problems our people are actually solving with the unauthorized tools. And then you need to teach them or provide them how to do that in an authorized and approved way, right? That's it. Okay, rule number two is you need to classify everything by risk level. So first you have to understand what you have, what's being used, what's not being used, what's authorized, what's not. Then you need to fix that part first. Then you need to classify everything by risk level. And actually, this has already been done for us, right? Just borrow the EU. Uh, their AI act has four tiers. It's unacceptable, high, limited, and minimal risk, right? So you need to assign everything by risk level because you don't have to apply the same level of guardrails to something that is minimal risk versus something that is unacceptable, right? You don't have to have the same approval process, the same guardrails. So a tool drafting a generic welcome email, you know, you know, that doesn't matter. It's, you know, it's a broom closet. It's not your highly classified room with all your company secrets, right? So you don't need to put, you know, 10 security guards uh and in laser beam lights and triple padlocks on the broom closet, right? A tool deciding who gets a mortgage, that's yeah, that's a little heavier, right? You need heavier controls. So for high-risk decisions like hiring credit and healthcare, human review is always required. So it's gonna look different for companies of different sizes, different sectors, uh it look right, like um if you're have different sanctions, it's gonna look different, right? Those four tiers. But for the most part, most people shouldn't be able to put most of their day-to-day processes under those four tiers, right? So you don't govern everything the same thing. You don't put the, you know, the caution tape and the sirens on every single thing. That's probably only on your, you know, on your unacceptable list. All right. Rule number three, assign clear ownership. Don't just kick something to IT. So there's a quick test you can take, right? So let's just say, as an example, an AI agent goes off the rails and it's going to, right, go back and listen to my 2026 AI prediction and romance series. Yeah, a lot of it's already come true, and there is going to be an agent crash coming. All right. So if an agent crash happens at your company, and that's essentially when uh you have a well-meaning agent, right, that you think is properly set up and it goes and does something catastrophically bad. Okay, if that happens, can you with a hundred percent certainty name the person who is accountable in 10 seconds? Most people would say, oh, it's probably, you know, Bill and IT or you know, Jane and Finance, right? Like most people could maybe say, oh, it's one of three. Unless you can definitively say instantly, the one person and you know 100% they're responsible, you don't even have the baseline of governance. You need clear ownership. Not only do you need clear ownership, but that person needs the authority to act without hardly any notice, right? That person needs almost full autonomy, right? Maybe aside from you know the CEO or you know how big how big the organization is. But whoever that person is, if they are the person that has uh direct and end ownership, they need the autonomy to make things happen quickly, to change the rules, to hit pause, to hit play. Play to hit rewind, they need it all. All right. And you also do need, as much as I hate buzzwords, you do need a cross-functional committee. You need an executive sponsor. You need someone in legal. Uh, you need someone in IT, you need a domain expert, and then you need a daily AI user. I think those are the five different people minimum that you need, or the five different departments that you need because agents are going to be making decisions. Remember, it's not a human expert talking to uh a chat bot and then the human expert making the decision. In many cases, this is someone who is unrelated to that domain who is creating agents. And then that agent is going and making decisions, sometimes without the actual expert, the actual domain uh expert, um, subject domain expert even knowing what's happening. Or they're like, okay, well, hey, whatever, whoever gave this agent directions on finance is completely wrong. We should have ran this by finance, right? So that's who you need. You need the executive sponsor, you need legal, you need IT, you need the domain expert, and then you need the daily AI user. And why do you need the daily AI user in your company? Well, that's your frontline person, right? That's your person that's actually probably using these tools way more than maybe the head of legal or your, you know, your IT director. Uh, right. That's the person that's gonna say, like, hey, wait, that's not how we're using this agentic platform. We're taking a completely different route, all right. So, rule four, don't write policies. All right, I can guarantee you the best written policy from 2025 is antiquated. It is holier than Swiss cheese right now. Swiss cheese on a Sunday, right? Because a policy just says do not do this, right? Do not input sensitive data. A playbook tells you exactly who reviews what and when, right? If you just have a list of of things to not do, right, which is usually what policies are, it's not helpful. Every AI use case needs five answers. It needs a task access, accuracy measure, reviewer, and an escalation path. All right. Every single AI use case that you deploy within your organization needs those things. And then outsourcing something to an AI agent does not outsource the responsibility. Actually, the FTC, right, the Federal Trade Commission here in the US, they're they they kind of shifted their focus away from you know Bitcoin and it's going full full all in on AI. You are all your company is ultimately responsible for any decisions that an AI makes, right? So if you're using a fully autonomous, you know, agentic loop, right? If you if if you're using right open claw, any of these things and something goes wrong, you don't get to point the finger at open claw. You don't get to point the finger at, you know, open AI, Google, Microsoft, Anthropic, et cetera. No, it is on you, right? So that's why you have to have those use cases have to be thoroughly vetted, and you need playbooks on what to do, not just what not to do. And then rule five, you need to treat governance as the scaling engine and not the break. So here's what here's what I mean by that. Right now, studies show that 75% of companies are stuck in pilot purgatory because they're just running small AI experiments endlessly. They can't get out of there. Right. Number one, it's because corporate policy moves too slow, agentic AI moves too fast. But companies with mature governance who deploy new AI capabilities, they do it faster, uh, 40% faster than their peers that don't. Right. So if you do have mature governance, you can get out of pilot purgatory. Because if you took care of steps one through four, it is actually no longer a stoplight that is stuck on green. It is a working stoplight that's just or sorry, it's it's it's no longer a a uh traffic light stuck on red. It is a traffic light that is properly pulling the cars through and keeping them going at a high speed, right? People think business leaders think people on you know Twitter, LinkedIn, whatever, people who are AI experts, they assume that governance slows companies down. And it is the exact opposite, because without governance, you cannot compete, you cannot keep up. There's going to be too many small roadblocks along the way, too many giant Chicago-sized potholes. Your car's not going to make it out of the lot, y'all. Governance is the scaling engine, not the brakes. All right. So uh both studies from Align AI and IBM said that report organizations with strong AI governance actually saved $1.9 million per data breach on average, right? A lot of this data just uh goes back to data breaches because ultimately, like that's that's where a lot of this is headed, right? When agentic AI goes off the rails, everyone knows about it. And then you have to start diagnosing, and it takes a lot of time and a lot of money. And that's that's where we are unfortunately learning the good lessons about what we should do in governance when we learn where things go wrong. And the biggest thing where things go wrong, it's going back. I'm gonna I'm gonna just read these rules here one more time. All right. I think it starts with not knowing what you actually have and not knowing what the capabilities are. All right. So, rule one, you have to know what you actually have. Rule number two, you have to classify everything at risk by risk level. Rule three, you need to assign clear ownership, not just kick it to IT. Rule four, write playbooks, not policies. And rule five, treat governance as the scaling engine, not the break. All right. So that's not all. You and you might not like this part. You have to set monthly review cycles. Yes, not yearly, not quarterly, monthly. All right. Because a government policy that if if if if you think you can set it once and forget it, that's literally like you know, thinking you can repurpose a 20 2006 social media policy, uh, change a couple words and use it for AI in 2026. Like monthly review is the absolute minimum cadence to keep governance matched to reality. Y'all, I've literally been doing this thing for more than three years, every single day. And I'm not exaggerating when I say the last three months in terms of capabilities, what an AI can output and do, have far outpaced the previous three years. Like I said, it is scary in a good and bad way. So you cannot just set something and revisit it once a year. That is a recipe for failure. But a recipe for success is to stick with us through the rest of the Start Here series. All right, because we're gonna be guiding you along the way, whether you are brand new to AI or you're trying to keep up and double down. Thank you for going with us on this one as we went over AI governance in plain English, five AI rules every company needs to follow. I hope this was helpful. If so, do me a favor. And I'm not gonna keep this open forever, FYI, uh, right, just free, open, unlimited access to our community. So go to starthireseries.com. If this was at all helpful, all right, that's gonna give you free access to our community. And you can go check out every single episode in the Start Here series, all in one easy to find space and also connect with uh thousands of other people in our community right now who are doing the same thing you're doing. So uh thank you for tuning in. Hope to see you back tomorrow in everyday for more everyday AI. Thanks, y'all.