Read the full written lesson (~7 min)
Why Growing Use Changes the Risk
When one person uses one AI tool to draft an email, the risk is small and easy to see. But as AI use spreads through a team — more people, more tools, more tasks handed over — the risk doesn't just add up, it changes shape.
- You lose the overview. Nobody set out to lose track, but with five people each trying different tools for different jobs, no single person can say anymore what AI is being used for, where, or with what data.
- Mistakes compound. One wrong email is a fix. A hundred wrong emails sent overnight by an AI tool that was quietly automating a task is a crisis.
- Some AI starts acting, not just suggesting. Early on, AI writes a draft and a person sends it. Later, an AI tool might send it itself, book something, update a record, or reply to a customer — with a person only checking in occasionally, or not at all. That's a different level of risk, and it needs a different level of control.
This module is about the controls for that later stage — not because your organization has necessarily reached it, but because it's much easier to put guardrails up before you need them than after something has already gone wrong.
Shadow AI: The Tools You Don't Know About
"Shadow AI" simply means AI tools being used in the business that leadership doesn't know about and hasn't approved. It's not usually anyone acting badly — it's someone trying to be helpful and efficient, and grabbing whichever free tool solved their problem fastest.
The risk isn't the enthusiasm. It's that unapproved tools mean nobody has checked: does this tool keep our data? Does it train on what we type into it? Can it be trusted with a client's name, a medical detail, an account number? Every new tool is a new place your information can end up, and without a list, you simply won't know how many of those places exist.
The fix is simple and doesn't require technical skill: an approved-tool list. One page, one list — the AI tools your organization has actually looked at and said yes to, and a plain instruction that new tools get a quick check before anyone uses them for real work. It's the same habit as approving a new supplier before you pay their invoice.
Your Paper Trail: Records, Logging, and Compliance
If a client, an auditor, or a regulator ever asked "which of your decisions involved AI, and how do you know it was used responsibly?" — could you answer in five minutes? For most non-technical organizations today, the honest answer is no. That's the gap this section closes.
Two ideas do almost all the work here:
- Logging simply means keeping a basic record of what AI tools were used for, when, and by whom — even a shared spreadsheet row per significant use is enough at your size. You're not trying to record everything; you're trying to be able to reconstruct what happened if you ever need to.
- Records and training obligations are becoming a real, not theoretical, requirement. The EU AI Act, for example, includes a duty (Article 4) for organizations to ensure staff have a reasonable level of AI literacy before using it in the business — and regulators, insurers, and larger clients are increasingly asking to see that an organization takes AI use seriously, not just that it uses AI. Being able to show "here's our tool list, here's our training record, here's our logging" turns a vague worry into a simple, presentable answer.
None of this needs a compliance department. A shared folder with three things in it — your approved-tool list, a simple usage log, and a record of who's completed this training — covers the vast majority of what anyone will ever ask to see.
When AI Starts Acting on Its Own: The Human Stop-Switch
The newest and least familiar risk comes from AI "agents" — tools that don't just answer a question but carry out a chain of actions on their own: reading messages, updating a record, replying to a customer, booking something, moving files. This is Level 4 use: AI doing, not just advising.
This can be genuinely useful — but it removes the safety net of a human reading everything before it happens. The core rule that keeps this safe is unchanged from everything else in this course: AI advises, a human decides — and for anything an agent can do that would be hard to undo (send, pay, publish, delete, promise), that rule has to be built into the tool itself, not just hoped for.
In practice this means three guardrails:
- A visible pause point. Before an agent takes an action that talks to a customer, spends money, or changes a record permanently, it should stop and show a person what it's about to do — not just log it afterward.
- A real off-switch. Someone in your organization must be able to stop an autonomous process immediately, without needing IT support or a vendor call. If you can't say who that person is and how they'd do it today, that's the first gap to close.
- A limited leash to start. New autonomous use should start on low-stakes tasks with a human checking every output, and only earn more independence once it's proven reliable — the same way you'd bring a new employee up to speed.
Four Guardrails You Can Set Up This Week
You don't need a policy binder. You need four short, concrete things, written down and actually followed:
- An approved-tool list. One page. What's allowed, what needs sign-off first, who to ask.
- A simple usage log. One row per significant use — what tool, what for, who, when. A spreadsheet is enough.
- A named person with the stop-switch. One name, written down, who can halt any automated or agentic process today, without waiting on anyone else.
- A rule that autonomous actions pause before anything irreversible. Sending, paying, publishing, deleting, or promising something to a customer always gets a human look first, until you've deliberately decided otherwise for a specific, low-risk task.
These four things won't make your organization technical. They'll make it the kind of organization that can say, calmly and honestly, "yes, we use AI — and yes, we control it."