Unit 1 / 12

Why Enterprise AI Policy? Foundation of Governance and Shadow AI

Gains:

  • Recognizing the risks of policyless AI use (shadow AI) with numerical examples
  • Understand that a good policy is not a list of prohibitions, but a framework that enables responsible use
  • Explain the people, process and technology pillars and stakeholder roles of AI governance

On a Monday morning, a midsize insurance company's chief compliance officer (the person responsible for the organization's compliance with laws and internal rules) opens his email to a surprise: a customer is asking if his health information "was written into an AI tool and where it went." A quick investigation reveals that an expert from the claims team uses a personal AI account to quickly summarize claims files. No one is malicious; No one thinks they are breaking the rules. Because there is no written rule. This gap is called shadow AI, and this module teaches you how to build a governance framework to fill exactly this gap.

Bringing AI into business is not as simple as installing ordinary software. AI influences decisions, processes personal data, can produce copyrighted content, and creates liability when it makes mistakes. That's why every organization that "uses" AI also needs a framework that "manages" it. In this first unit, we cover why a written AI policy is needed, the tangible cost of shadow AI, and the three pillars of governance.

What is shadow AI and why is it inevitable?

Shadow AI is the use of AI without the knowledge, approval and control of the institution. The word "shadow" comes from the name "shadow IT", which is given to software that is not approved by the IT department. Employees start using AI tools with or without a policy; because these tools are free, fast and make their work easier. Even having a ban does not stop the use, it only hides it.

Use without policy creates the following concrete risks:

  • Data leak: An employee may unknowingly paste confidential customer data or company secrets into an AI tool. Data goes beyond the control of the institution.
  • Penalties for non-compliance: Violation of KVKK (Personal Data Protection Law) results in an administrative fine of millions of liras; Violating the GDPR can lead to fines of up to 4% of annual turnover.
  • Decision based on misinformation: Decisions made relying on AI-concocted misinformation (“hallucination”) harm the customer and the organization.
  • Copyright and intellectual property issues: Use of the output may infringe someone else's intellectual property.
  • Loss of reputation: When uncontrolled use is reported in the press, brand trust is shaken.
Caution: Banning the use of AI completely is not a solution. Prohibition does not eliminate use; it just makes it invisible and uncontrolled. The aim is not to end the use, but to put it in a safe framework.

Three mini cases: the real cost of shadow AI

Case 1 — Leaked contract. A legal specialist pastes the entire text into an individual AI account to summarize a confidential 40-page merger agreement. The contract is not yet publicly available. The text is processed on the provider's servers and becomes available for prospective model training. The company delays the merger by 3 weeks to eliminate the risk of a possible information leak; The consultancy cost increases by approximately 250,000 TL.

Case 2 — Hallucinatory jurisprudence. An attorney attaches three “precedent decisions” from the AI ​​to his petition. Two of the decision numbers are made-up decisions that do not exist in reality. The court realizes this; The lawyer faces disciplinary process as well as loss of reputation. A one-line verification rule (verify each source against the official decision system) would have prevented this crisis.

Case 3 — Invisible savings. At the same company, the marketing team produces campaign copy 6 hours per week faster with a certified enterprise AI tool. However, this savings is not reported anywhere because the usage is unregistered. Management rejects the new licensing budget because it cannot see the benefit of AI. Shadow AI eliminates not only risk but also visibility of benefit.

What does good policy ensure?

A good AI policy is not a list of bans; It is a framework that enables responsible use. It does five things:

  1. Clarity: The employee knows what is allowed, what is prohibited, and what is subject to approval.
  2. Trust: Management can approve new projects knowing that AI is being used in a controlled manner.
  3. Compliance: Legal obligations (KVKK, GDPR, EU AI Law) are met systematically.
  4. Consistency: Different teams follow the same rules.
  5. Accountability: When there is a problem, it is clear who is responsible.

What is governance? three feet

AI governance is a set of rules and processes that determine how artificial intelligence will be selected, used, controlled and who will be responsible for it in an institution. Policy is the written document of this governance; Governance is the living system that brings policy to life. It is built on three legs:

foot

Meaning

Example in AI policy

human

Roles and responsibilities

AI controller, approving manager, data protection officer

Process

Rules and flows

New vehicle approval process, regular inspection, incident response

technology

Tools and controls

Approved vehicle list, access control, record keeping

If one of the three pillars is missing, the framework collapses: without the rule, the tool is useless, without the tool, the rule cannot be controlled, without responsibility, none can be owned.

A single department cannot do this job.

AI policy is not just the job of the IT department. A successful framework requires the participation of different units: legal/compliance (legal obligations and contracts), IT/security (technical controls and data security), human resources (employee training and codes of conduct), business units (actual usage needs) and senior management (approval, sourcing and corporate ownership).

Tip: Have a 30-minute meeting with a representative from each stakeholder unit before you start writing the policy. “What are you currently using or looking to use AI for?” question reveals both real needs and current shadow usage.

Putting AI to work: replicable templates

AI itself is an aid when setting up the governance framework — as long as its output is validated. The following templates speed up the work of this unit.

TEMPLATE 1 — Survey for baseline (shadow AI) scanning: "An 8-question anonymous employee survey draft is ready to map AI usage in our organization. Questions should cover: which tools, which tasks, which data types entered, training need. Output: numbered questions + answer type for each question (multiple choice/open)."

TEMPLATE 2 — Create a risk summary: "Consider the following AI use case: [paste scenario]. Give me a brief risk summary under the following headings: data privacy, compliance, hallucination, royalty, reputation. Label 'low/medium/high' and one-sentence rationale for each heading. Don't give legal advice; just list points to review."

TEMPLATE 3 — Stakeholder meeting agenda: "Prepare a 60-minute board meeting agenda to launch the AI ​​governance framework. Participants: legal, IT, HR, business unit, senior management. Write duration and expected output for each agenda item."

TEMPLATE 4 — Short briefing to management: "Write a half-page briefing titled 'Why we need an AI policy' to present to senior management. Include 3 concrete risks + 3 concrete benefits; do not use technical jargon; have a clear decision request in the last line."

Weak prompt / Strong prompt

WEAK: “Write AI policy.”-> The model produces a generic, non-institutional, unauditable text; does not reflect data classes, roles and regulatory context. GÜÇLÜ: "We are an insurance company of 50 people, subject to KVKK, we process customer health data. Propose a draft for the 'scope' and 'prohibited uses' sections of the AI ​​policy. Do not impose a final judgment; add a 'legal approval required' note in each article and leave the gaps to me."-> The model produces a context-appropriate, verifiable draft; The decision remains with you.

Common mistakes

  • Banning the use of AI altogether and making shadow AI invisible.
  • Letting IT write the policy only and excluding the real needs of the business units.
  • Starting to write rules directly from the existing shadow usage mapping.
  • Writing the policy in legal language in a way that the employee cannot understand.
  • Putting the policy draft produced by AI into effect without legal approval.
  • Talking about the risk but not measuring the benefit; thus losing the support of the administration.
  • Writing the policy once and forgetting to update it; whereas governance is a living system.

In summary

  • Shadow AI is inevitable in organizations without policies and poses data, compliance and reputation risks.
  • A good policy is not a ban list; It is a framework that enables responsible use.
  • AI governance is built on people (roles), process (rules), and technology (controls); If one is missing it crashes.
  • Policy is not the responsibility of a single department; It is the joint work of law, IT, HR, business units and senior management.
  • AI can help in setting up the framework, but every output must undergo human and legal approval.

Application task

Choose an organization you have worked for or dream of (let the industry, number of employees, and type of data it processes be clear). First draft an 8-question survey for shadow AI screening (you can use Template 1). Then write out three concrete risks that shadow AI could pose in this organization, adding a numerical estimated impact (penalty, delay, lost hours) to each. Finally, identify examples specific to your organization for each of the three pillars of governance (people, process, technology) and note which stakeholder unit will be responsible for this pillar.

checklist

  • [ ] I mapped the current (shadow) AI usage in my organization.
  • [ ] I wrote three concrete risks of lack of policy with numerical effect.
  • [ ] I prepared a briefing that conveyed both the risk and benefit of AI to management.
  • [ ] I have determined an institution-specific example and responsible person for the three pillars of governance.
  • [ ] I made a plan to include at least three of the stakeholder units in the process.
  • [ ] I subject every draft I produce with AI to legal/compliance approval.