Nick Heddy serves as President and Chief Commerce Officer (CCO) at Pax8.
Most business leaders believe they know how AI is showing up inside their company. Their employees are indeed putting AI to work, but it’s often faster than leadership can govern it. In fact, roughly 78% are using AI tools their employer never approved, and nearly half of small and midsize businesses still have no AI policy in place, according to Pax8’s recent study.
Shadow AI isn’t just a productivity issue—it’s a trust, data and governance one. For SMBs, the exposure can be even sharper because they’re less likely to have the automated security controls, legal teams or compliance infrastructure that larger enterprises rely on to catch risk before it spreads.
When AI Adoption Outpaces Governance
We’ve already seen these risks play out in real workplaces. Earlier this year, an employee at Pennsylvania Bank (paywall) fed customer names, Social Security numbers and personal information to an unapproved LLM, even though the bank offered an approved tool for use. One employee’s efforts to work faster required the company to file an SEC disclosure, even though the incident didn’t involve any stolen credentials or network intrusion.
A large bank can absorb the cost of an SEC disclosure with in-house legal and compliance teams already on staff, but most SMBs can’t. With nearly half still operating without an AI policy, the same kind of well-intentioned shortcut is just as likely to happen—but the fallout, from regulatory exposure to lost customer trust, has the potential to cause serious disruption.
Governance Before Deployment
That’s the important distinction for business leaders: The goal isn’t to stop employees from using AI. The goal is to make sure AI is being used with the same discipline companies already expect from any other system that touches business-critical data.
Incidents like these don’t usually happen due to carelessness or malicious intent. Rather, the unapproved tool simply worked faster than the approved process, and leadership failed to thoroughly define the boundaries. When most of your employees are creating unsanctioned workarounds to get the job done faster, it’s critical for business leaders to take responsibility in building AI governance policies before providing access in any capacity.
Hardening these policies is timely, as SMBs increasingly adopt agents that work independently with business data. Enforcement of these policies should be automated, and they must adapt with the tool itself the moment employees are given access to AI.
Adapting A Governance Model You Trust
This governance model doesn’t need to be built from scratch. Most businesses already trust a version of it through cybersecurity. For many SMBs, that trust comes through a managed service provider (MSP).
SMBs should work with their providers to treat AI governance as an extension of the security services they already enforce: the same tool-vetting that keeps unapproved software off the network should apply to AI models, and the same access controls and audit trails should cover what those models can see and do. SMBs that set this expectation early can turn a trusted vendor relationship into a competitive advantage.
Every organization with a security program in place (whether run in-house or through an MSP) already trusts autonomous systems to act without human oversight, and these systems work in the background to protect business data. Firewalls block traffic, endpoint detection tools isolate suspicious files before they’re reviewed and shared, and identity management tools manage access and revoke it accordingly.
Both SMBs and large enterprises trust these systems because they’re built with the same core principles of governance: clearly defined boundaries for what the system can do and access, a complete audit trail of actions, escalation rules to dictate when human judgment is needed and assigned ownership for overseeing how security systems are processing data.
This is the template that can be used to govern every AI tool employees are given access to. Your providers can be tapped to help clearly define a tool’s boundaries—and that should happen before it touches sensitive data or source code, not after the tool is deployed. Some MSPs can also build an audit trail for AI to see what these tools are doing and set clear rules for what agents can do on their own versus with humans in the loop.
For example, agents should be able to freely access workplace data and files to produce accurate outputs, but privacy of information should be permissioned and tiered. Routine operational information can be treated differently from customer records, financial data or regulated information. When the decision involves sensitive data, human judgment should remain part of the process.
Like cybersecurity, ownership of these responsibilities should be shared across company leadership, so governance is everyone’s job.
Balancing Speed With Risk
Employees are already trusting AI systems with more business data than leaders are aware of. What you need to determine is whether this trust is properly governed, or if the gates to critical data are wide open. The answer lies in the cybersecurity practices leaders have long trusted. Building ownership, audit trails, access control and escalation architecture enables employees to use agents and LLMs freely while protecting personal data from ending up in the wrong hands.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

