A Marketing Coordinator Finds an AI Writing Tool on a Tuesday
By the end of the week, she’s pasted member survey data into it to draft a newsletter. Names, email addresses, and a few open-ended comments about member complaints. The thought of asking first never even occurred to her. There was no policy to point to and no one to check with. She is not being careless and there is no malicious actor.

Her manager finds out 3 weeks later, during an unrelated audit. The coordinator was just trying to get a newsletter out by deadline.
This is what AI governance failure actually looks like. A normal person doing normal work, inside a policy vacuum.
Most organizations find out what their AI policy is after something goes wrong. They write the rule in reaction, then post it in a shared drive next to the brand guidelines people aren’t looking at.
I’ve been building something different at the Y. A framework that gets ahead of the tool. A registry that tracks what’s already in use. Risk tiers that tell you where to look first. A review process that only takes a few hours.
Over the next few posts, I’ll walk through each piece. Starting with the registry, since that’s the part most teams skip and pay for later.
What would your team find if it looked today?