Cisco found that about 75% of organizations already have an AI governance body — but only 12% consider it mature. Here's a practical, five-step way to close that gap.
To implement AI governance in organizations and enterprises, first build a central inventory of AI models, vendors, agents, data sources, and use cases (like on Nicklpass), and then assign each an accountable owner and risk rating. Next, set clear usage and data-sharing policies, control access and procurement, require stronger review for high-risk systems, train employees, and monitor incidents and performance.
Cisco found that about 75% of organizations have an AI governance body, but only 12% consider their governance mature.
You can't govern AI your organization can't see. So start by finding every AI tool your employees are using, and document who's using it, what you're paying for, and how it got into the company — that includes official tools, team subscriptions, and the random AI app someone bought on a corporate card six months ago.
Once you know what exists (like Claude, Copilot, AI agents, or built-in SaaS AI features), separate everyday AI from higher-risk use cases. A writing assistant like Perplexity doesn't need as many controls as a tool screening job candidates (like HireVue) or an AI system handling confidential customer data (i.e., Salesforce).
Decide who can use each AI tool (such as developers, marketers, or finance teams), which account they should use (company account, SSO login, or approved enterprise workspace), and who approves new licenses (i.e., IT, a team manager, or procurement).
Do not approve an AI tool and forget about it. Review usage after the first 30–60 days, then quarterly and before every renewal, to catch inactive users, sudden usage spikes, and licenses the business no longer needs.
AI governance is ongoing because employees adopt new tools, vendors add new features, and low-risk apps can quickly become critical to the business. Use what you learn from usage, incidents, new purchases, and employee requests to update your approved-tool list and controls.
After changes involving ChatGPT raised new concerns in 2026, discussions around continuing approved tools while reconsidering controls around company data has been trending.
In business, it usually means letting AI handle roughly 70% of repetitive or administrative work while humans own the final 30% that needs judgment, creativity, context, or accountability. Research supports the idea of keeping humans involved, but not the exact 70/30 split.
A study of 758 BCG consultants found AI improved speed and quality on suitable tasks, yet made people 19% less likely to get the right answer on a task outside AI's capabilities.
So start governing your AI's transformation and let Nicklpass bring your tools, usage, spend/ licenses all into one place so you can see what should be prioritized.
Nicklpass brings your AI tools, usage, spend, and licenses into one place, so you know what to prioritize first.